Help! Laptop (Vista) Detects Virus - Can't run or execute files

Discussion in 'Malware Help (A Specialist Will Reply)' started by cash415, May 27, 2010.

  1. cash415

    cash415 Private E-2

    I just got a message from my Antispyware Soft that my computer is being attacked. I don't have the full version so I can't delete the the viruses. I tried to install CCleaner so I can get a log but my computer can't execute anything right now. I can't even uninstall from the control panel. I need help!

    I am running a laptop with Windows Vista.
     
  2. cash415

    cash415 Private E-2

    Here are some viruses listed on my Antispyware Soft.

    Backdoor.Win32.Small.x
    Downloader.Win32.Delf.cgx
    PSW.Win32.OnLineGames.rlh
    GameThief.Win32.OnLineGames.tnys
    Downloader.JS.Agent.sg
    Downlaoder.Win32.Braidupdate.c
     
  3. cash415

    cash415 Private E-2

    i restarted my computer but still the same, can't execute any files. i can't even connect to aim. when i tried to restart my computer it said that someone else was connected to my computer. i need help with this! hopefully no one is stealing my information right now
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.


    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post )


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.


    Then try running these instructions: Using MGtools


    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • a log from online SAS scan if you could make one
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  5. cash415

    cash415 Private E-2

    ******************************************************************************
    * AVPFind.bat - (c) 09/01/2009 By Chaslang *
    * *
    * Helps to identify potential AntiVirus Pro infected system DLL files and *
    * possible replacement files to use during cleanup. *
    * Mod: 11/25/2009- Use Desktop instead of root folder for log *
    ******************************************************************************

    Windows OS is

    Microsoft Windows [Version 6.0.6002]

    ============= Finding copies of cngaudit.dll =================================
    "C:\Windows\System32\cngaudit.dll" 11776 11/02/2006 02:46 AM
    "C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll" 11776 11/02/2006 02:46 AM

    ============= Finding copies of netlogon.dll =================================
    "C:\Windows\System32\netlogon.dll" 592896 04/10/2009 11:28 PM
    "C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll" 592384 01/20/2008 07:24 PM
    "C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll" 592896 04/10/2009 11:28 PM

    ============= Finding copies of scecli.dll =================================
    "C:\Windows\System32\scecli.dll" 177152 04/10/2009 11:28 PM
    "C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll" 177152 01/20/2008 07:24 PM
    "C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll" 177152 04/10/2009 11:28 PM

    ******************************************************************************
     

    Attached Files:

  6. cash415

    cash415 Private E-2

    exeHelper by Raktor
    Build 20100414
    Run at 20:28:17 on 05/27/10
    Now searching...
    Checking for numerical processes...
    Checking for sysguard processes...
    Checking for bad processes...
    Checking for bad files...
    Checking for bad registry entries...
    Resetting filetype association for .exe
    Resetting filetype association for .com
    Resetting userinit and shell values...
    Resetting policies...
    --Finished--

    exeHelper by Raktor
    Build 20100414
    Run at 02:56:49 on 05/28/10
    Now searching...
    Checking for numerical processes...
    Checking for sysguard processes...
    Checking for bad processes...
    Checking for bad files...
    Checking for bad registry entries...
    Resetting filetype association for .exe
    Resetting filetype association for .com
    Resetting userinit and shell values...
    Resetting policies...
    --Finished--
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good. Now keep going with the other instructions and please refrain from posting inline logs, just attach them rather than post inline also. :)
     
  8. cash415

    cash415 Private E-2

    SUPERAntiSpyware Scan Log
     

    Attached Files:

  9. cash415

    cash415 Private E-2

    Hopefully I did this correctly. I couldn't access notepad so I had this done while being on Safe Mode. Please let me know if there is something I missed out. Thanks
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode and I am not referring to safe mode.

    2. You are currently using this machine with no antivirus installed. After we are finished you must install some.

    3. I see this running in your logs, is it something you know is present on your machine, something you use?

    4. Please disable BitTorrent from running at start up whilst I am working with you to remove malware!

    5. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    6. Use windows explorer to find and delete the below bold folder.
    • C:\Users\User1\AppData\Local\tqnvmuyiv

    7. Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.



    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    8. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    9. Now I would like for you to reboot into normal mode and download and run combfix as per the instructions here:

    A guide and tutorial on using ComboFix

    *Do not use if using 64 bit Vista*

    10. Try now to uninstall this outdated version of java:

    • Java(TM) 6 Update 18

    11. Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    12. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    13. Tell me how the machine is behaving now?
     
  11. cash415

    cash415 Private E-2

    1. Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode and I am not referring to safe mode. DONE

    2. You are currently using this machine with no antivirus installed. After we are finished you must install some. WILL DO

    3. I see this running in your logs, is it something you know is present on your machine, something you use? PLEASE DELETE

    4. Please disable BitTorrent from running at start up whilst I am working with you to remove malware! DON'T HAVE THIS RUNNING AT START UP

    5. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished): NO ANTI-VIRUS INSTALLED

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: CAN'T RUN DUE TO VIRUS. THE PROMPT STATES THIS, APPLICATION CANNOT BE EXECUTED. THE FILE ANALYSE.EXE IS INFECTED.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, then are you able to run combofix?
     
  13. cash415

    cash415 Private E-2

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It works just fine. Malware could be blocking you from downloading the file. Can you use another PC to download it onto disk or flashdrive and then try running?

    Also try this: Navigate to C:\MGTools\FixFA.bat run that and see if it allows you then to run Hijackthis and combofix if you fail to download onto flashdrive or disk.

    Let me know how you get on.
     
  15. cash415

    cash415 Private E-2

    I was able to access the site but when I tried to download Combofix the malware blocked me from accessing it. I will try and download Combofix to my zip drive and run it using my laptop. I also tried running C:\MGTools\FixFA.bat but the malware also blocked it.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let me know the results of combofix once you've transferred it.
     
  17. cash415

    cash415 Private E-2

    ComboFix Log
     

    Attached Files:

  18. cash415

    cash415 Private E-2

    I am currently stuck at step 10. Everything from steps 1-9 has been completed. When I try to install Java(TM) 6 Update 18 this is the message I get "C:\Users\User1\Downloads\jre-6u20-windows-i586-s(2).exe. The directory name is invalid.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You may have to sort out java issues in the software forum as I only have time to remove malware.

    Running from: c:\users\User1\Downloads\ComboFix.exe <--- I need combofix.exe to be run from your desktop so please move it there or else final steps will not work.

    Bit Torrent is still running at start up, I can tell from your logs.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
    Last edited: May 29, 2010

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds