dangerous to myself and my system

Discussion in 'Malware Help (A Specialist Will Reply)' started by oldjack, Oct 1, 2008.

  1. oldjack

    oldjack Private E-2

    Hello ladies and gents of MAJORGEEKS,
    I finally did it. I joined in desperation. I downloaded and clicked install instead of delete on program that had a nasty in it. It has chewwed through my system so it won't even boot my Windows XP sp3. it will boot live linux cd though. it was a trojan that I thought I got rid of and I even deleted all files I could find for that date and checked regedit. so here are the specs in hardware. intel core2quad6600; abit fatality fp-in9; 2 maxtor sata 160gb drives(no raid setup); 2 2gb ddr2 patriot memory @pc6400; 2evga geforce 7600gs w/256mb in sli; and 2 samsung dvd-rw's
    software of importance windows xp home w/sp 3 ,AVG antivirus(although I tried several other free ones from zdnet when things started to go south on this system),nvidia firewall,spybotsearch and destroy, a couple other things one like HJT and a taskman re enabler(trojan wasnt letting me acces it or my C drive in MY COMPUTER or regedit after awhile).
    It took out my profile and admin as well as several other profiles and it was redirecting web traffic to other pages so i'm usung old laptop to send this.
    I know it may be asking much,but I really need some documents and access to a couple of other things, so if there' s a way to do that before we reach formatting I would appreciate the help. thanks in advance.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide

    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. oldjack

    oldjack Private E-2

    I have tried all options after using F8 key (safe,safe w/network,safe w/cmd prompt). a couple of times I got as far as start of safemode screen (safe mode in corners but screen is black) mouse pointer moves (no icons) and keyboard disabled(no Num lock even though enabled it in bios). usually hang there, HD light will flicker every 1-2 seconds. if it doesnt get that far it gives list of system32\drivers and hangs at windows\system32\drivers\Mup.sys. Is there another way to safe mode??
     
    Last edited: Oct 2, 2008
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you saying that you can not get into windows in either normal or safe mode?
     
  5. oldjack

    oldjack Private E-2

    no safe mode at all and no normal modes
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  7. oldjack

    oldjack Private E-2

    I am in safe mode thanks to you and system restore... had to do a lot of repair in system32 to get there. before I proceed to kill all malware I need to know if I should get back deleted admin profiles so I can get my lost files(documents andsettings) and is there an easy way to undelete them enmasse? the files appear to be there (I managed to install Restoration version 2.5.14).
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I think it would be wise to remove the malware first and then re-create the user accounts.
     
  9. oldjack

    oldjack Private E-2

    I have tried to go through the read and runme 1st. windows installer says unable to install SAS.exe. ( tried it in safe mode as admin. and says"the system administrator has set policies to prevent this installation"). ran all others... do you want logs or wait 'til you help me run SAS??
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Give me the logs that you have, please. :)
     
  11. oldjack

    oldjack Private E-2

    Iam trying to send logs but keep getting popup (even after disabling blocker)
    Thoughts???
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why are you disabling your pop up blocker? If you can post...you just need to scroll down to manage attachments and attach them to your post.

    If there is some other reason....then save them to a disc or flash drive and use a different computer to attach them.
     
  13. oldjack

    oldjack Private E-2

    Sorry , I mis-typed. let me clarify... when trying to attach logs I hit manage attachment then brouse. I get a message (apparently from popup blocker) that popup has been blocked(yada yada). I checked settings and turned off popup blocker(checked settings and it has line asking if I want to turn popup blocker on). is there another way to get the logs to you (Idon't think you want a cut/paste from possible infected system)
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't understand how that stops you form attaching.....but, are you using IE? Do you have another browser installed such as FIreFox?

    As I mentioned, you can copy the logs to a disc or flash drive and use a different computer.
     
  15. oldjack

    oldjack Private E-2

    sorry again Ihavent gotten much sleep trying to fix this( i should have finished reading last part of your post). files will not attach on affected or backup(laptop) systems. files appear to upload(flashing lights on router for that connection) the I get message from majorgeek site: Your submission could not be processed because a security token was missing.

    If this occurred unexpectedly, please inform the administrator and describe the action you performed before you received this error.
    I assume you have admin. priv. and can explain/fix/help
    all I was doing was uploading logs and mgtoolszip
     
    Last edited: Oct 4, 2008
  16. oldjack

    oldjack Private E-2

    same message when using firefox(and apears to upload as well)
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK.....not sure ..then go ahead and copy and paste each log one at a time and I will recopy and attach them.
     
  18. oldjack

    oldjack Private E-2

    here is hijackthis.log
     

    Attached Files:

  19. oldjack

    oldjack Private E-2

    here is combofix.txt
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need two more logs from within the mglogs.zip ---newfiles and runkeys.
     
  21. oldjack

    oldjack Private E-2

    not sure what you need from mglogs.zip so here it is(all)

    *****************************************************************************

    Sorry this is so long and thanks for the patience BTW windows installer not working (maybe why I cant install SAS.exe)
     
    Last edited by a moderator: Oct 4, 2008
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All I want is what I asked for....which was the Newfiles and the RunKeys...not the getUnKeys ....try again. :)
     
  23. oldjack

    oldjack Private E-2

    Got them.....
    ___________________________________________
     

    Attached Files:

    Last edited by a moderator: Oct 4, 2008
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The scans took care of whatever was going on malware wise...although you need to find and delete:
    C:\Temp.

    Your other issues should be addressed in the software section.

    Now we need to clean up from all those scans:
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you get a success message, then it is time to do our final steps:
     
  25. oldjack

    oldjack Private E-2

    registry modification a success:-D
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds