Control panel disabled by malware/pop-ups for bogus AV/slow running

Discussion in 'Malware Help (A Specialist Will Reply)' started by mvarrow, Dec 4, 2007.

  1. mvarrow

    mvarrow Private E-2

    Hi,

    I have the problems listed in the title, can you help? I'm no expert but have posted the logs as requested. Any help would be greatly appreciated.

    Best,
    MV
     
  2. mvarrow

    mvarrow Private E-2

    Attachments, here: :eek:
     

    Attached Files:

  3. abri

    abri MajorGeek

    Hi mvarrow!
    Welcome to MajorGeeks!

    1) Please do a scan with hijack this and fix the following items. Make sure all browser windows are closed when you hit fix.


    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [version] C:\WINDOWS\System32\timoty.exe
    O4 - HKCU\..\Run: [froody] C:\WINDOWS\System32\timoty.exe
    O4 - Startup: PowerReg Scheduler V3.exe
    O4 - Startup: PowerReg Scheduler.exe
    O4 - Startup: setings.exe
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O16 - DPF: {11010101-1001-1111-1000-110112345678} - ms-its:mhtml:file://C:eek:o.mht!http://198.88.20.155/targ.chm::/win32.exe
    O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - (no file)

    Just close hijackthis once you are finished.

    2) Next I would like for you to disable Teatimer in Spybot. You can do this by double-clicking on the program to start it from the desktop or by starting it from All Programs. At the top of the screen go to Mode and make sure advanced is clicked. Then look for the Tools button on the left-hand side of the window towards the bottom. Click on this. On the left side of the next window you'll see a red and white shield labeled Resident. Click on this. In the middle of the page that opens there are two items, SD Helper and Teatimer. Make sure that Teatimer is unchecked. Then close Spybot.

    3) Your hijackthis was not installed correctly and therefore won't have listed everything which may be wrong. Please go to the READ & RUN ME FIRST. Malware Removal Guide and follow ALL the instructions. When requested, use those which apply to your operating system. After you finish, please post the requested logs to us so we can look more closely at your computer. It IS infected and it will need some further work to finish cleaning it.

    abri
     
  4. mvarrow

    mvarrow Private E-2

    Ok, thanks abri.

    Have done as requested. New file attached.

    MV
     

    Attached Files:

  5. abri

    abri MajorGeek

    Hi mvarrow!
    Your MGlogs indicate that the MGTools.exe didn't run correctly.

    [EDITED BY CHASLANG]

    Download this GetRunKey.zip file into your C:\MGtools folder. Extract the GetRunKey.bat file from the ZIP file into the C:\MGtools folder thus overwriting the current version that is there. We will get a new log from this later.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Please follow the instructions here.


    1) Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 3

    2) Reboot

    3) Please download and install: Java Runtime 6

    4) Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    5) Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    6) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    7) After you have completed all of the above, please attach the Avenger log and the MGlogs.zip

    abri (& chas :) )
     
    Last edited by a moderator: Dec 6, 2007
  6. mvarrow

    mvarrow Private E-2

    Hi there - thanks again,

    Sorry for the delay - I've been away. I will be back on my machine tonight (UK time) and will do as you advise but I have one problem:

    One of the symptoms of my infection is that access to the control panel, add/remove programs, etc. seems to have be disabled and my administrator account seems to have a password that I never set up.

    So I will have difficulty with the first step (java uninstall). Is there a way round this or should I complete the rest of the procedures and post the results regardless?

    Best, michael
     
  7. abri

    abri MajorGeek

    Just do what's possible. If you can't do something, just go on.

    abri
     
  8. mvarrow

    mvarrow Private E-2

    Ok,

    All done.

    Had some error messages such as 'registry editing disabled see administrator" but have performed every step.

    MV
     

    Attached Files:

  9. abri

    abri MajorGeek

    Hi mvarrow,

    Did you catch the edit Chaslang made to my post number 5 and were you able to do what he requested? Your MGTools.exe is not running correctly so we're missing important data that we need about your registry. Also, some of the files Avenger shows as having been successfully deleted have not been deleted according to your MGlogs. As there are a number of unrelated problems at work here also involving some of your computer functions, I have asked Chaslang to help you further with your thread.

    abri
     
    Last edited by a moderator: Dec 12, 2007
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download the current version of MGtools.exe to C:\ like you previously did. It was just updated. Then run MGtools.exe which will create a new C:\MGlogs.zip file. Please attach this new log file. This version should hopefully be able to create a proper GetRunKey log for us. Then we will continue.
     
  11. mvarrow

    mvarrow Private E-2

    Hello again and Happy New Year,

    I have attached a new file which will hopefully be complete this time.

    Please note that I did receive an error message (ProcessDll.exe - Application Error "The application failed to initialize properly (Oxc0000135). Click on OK to terminate the application.")

    Thanks again for your help, I'll be at home for the near future so won't be so delayed in replying again... MV
     

    Attached Files:

  12. abri

    abri MajorGeek

    Hi mvarrow!

    I'm not sure what steps will work if you are being blocked from administrative priveleges. If you can't do one step, try the next one.

    To begin with, if you have more than one resident antivirus program, please uninstall any other. Some of the antivirus companies have a special removal tool to get rid of their files. In case you need to uninstal McAfee use the McAfee Consumer Product Removal Tool (SymNRT)

    Then continue as follows:

    1) Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\System32\msanton.exe
    O4 - HKLM\..\Run: [hhaxanyd] C:\ntjudwce.bat
    O4 - HKLM\..\Run: [afesdaht] C:\brflqutl.bat
    O4 - Global Startup: startup.exe

    After you click fix, just close hijackthis.


    2) If you do not use Windows Messenger (not to be confused with MSN Messenger!!) I would like you to run Disable/Remove Windows Messenger

    3) Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    4) Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    5) Now run CCleaner in the default setting with the Windows tab as the one that's on top. Don't check anything which isn't checked.

    6) Please run C:\MGtools\GetLogs.bat and attach the fresh MGlogs.zip it generates along with the Avenger log.


    Let me know how things are running now?

    abri
     
  13. mvarrow

    mvarrow Private E-2

    Hi

    Struggled to remove my Network Associates (McAfee?) AV program but your removal program seems to have disabled it - although the program files remain.

    Other steps seemed to work. Currently not getting the fake warning (although it sometimes comes back on restart) but still have control panel (and it's functions) disabled.

    New logs attached. Cheers,

    MV
     

    Attached Files:

  14. abri

    abri MajorGeek

    Hi mvarrow!

    1) Run Avenger again as you did in step 12, only this time use the contents of this box:
    2) Download and install Erunt. Use it to create a backup of your registry.

    3) Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    4) Now run CCleaner again.

    abri
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds