I can't get past the first steps

Discussion in 'Malware Help (A Specialist Will Reply)' started by ADG11, Aug 11, 2010.

  1. ADG11

    ADG11 Private E-2

    I had CCleaner previously installed and when I tried to open it a warning pops up saying the file is infected. I tried downloading it again but the same error message appeared.

    I also downloaded SAS and MalwareBytes and MGTools but they are not installed yet. When I try to open the icon to install them the same warning message appears saying the file is infected or not found.

    Common error messages read : OLEACC.dll was not found, ssu.exe is infected, mb.tmp is infected.

    Also, this program called 'Security Suite Innovative protection for your PC' made its way onto my computer. It has a green/yellow shield with slashes in it as its logo. It keeps telling me I have a virus but I know that this must be a malware program
    I had my PC out because I stepped on the screen and when it was returned this was on it. I contacted the people who did the repair and they are of course saying they did nothing but change the LCD screen.

    I am running Windows Vista 64-bit version.

    You guys are great and have helped me out greatly in the past. So if you need any more information please let me know.

    I look forward to hearing from you.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try this:

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.

    Now download and Run exeHelper from Raktor
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Now run this: Using Malwarebytes Anti-Malware

    Now run this: Using MGtools


    Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans
    • exeHelper log
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.


    If you are not able to run MGTools.exe in normal mode after completing the above then please try using safemode.
     
  3. ADG11

    ADG11 Private E-2

    That first bit helped a lot and the pop ups stopped and I was able to run the programs. Only I forgot to run CCleaner at the beginning....if thats a problem I can run them again.

    Thanks for the help
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Does your copy of Spysweeper have antivirus? If not you need to install some once we are finished removing malware!

    Please put this machine into normal start up mode by using msconfig if you have not already done so, before we continue.

    Please go to Add/Remove programs and uninstall the following software:

    • Ask.com Toolbar
    • Java(TM) 6 Update 20
    • Java(TM) 6 Update 6

    Use windows explorer to locate and delete the below leftover folder from avast!

    • C:\ProgramData\Alwil Software

    If you did not deliberately set this proxy yourself then please include it in the HJT fix below:
    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :Files
    C:\Users\Andrew\AppData\Local\epcvjqfoc
    
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "entlhjyo"=-
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    Run SUPERantispyware as per the instructions in the R&R.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this, also attach the SAS log and answer my question about antivirus.

    Tell me how things are running now!
     
  5. ADG11

    ADG11 Private E-2

    I don't know how I did this but those error messages from Security Suite came back and won't let me run anything. I tried running the rkill programs like before but keep getting messages saying they are infected.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then try and complete my instructions in safe mode if you were not able to do so in normal mode.
     
  7. ADG11

    ADG11 Private E-2

    When I tried it in Safe Mode I got an error message saying Windows Installer was not working or not installed correctly.

    I right-clicked on My computer and went to Manage. Then services and applications then services. Then I right clicked on Windows Installer and clicked Start but it said I could not perform that function in Safe Mode. I tried doing it normally but the virus is blocking me from doing anything.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Forget uninstalling Java and the Ask Toolbar for now, what else of my instructions were you able to complete in safe mode?
     
  9. ADG11

    ADG11 Private E-2

    I got as far as running and HJT, deleting/fixing those 2 problems. I could not download OTM because I cannot connect to the internet.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now boot back into normal mode and continue on with OTM as instructed. If you REALLY cannot do this in normal mode then try with safe mode with networking. :)
     
  11. ADG11

    ADG11 Private E-2

    I finally got all the way down to running SAS but when I click SAS.exe to install it I get an error message of "This application has failed to start because OLEACC.dll was not found. Re-installing the application may fix this problem."

    I tried restarting and downloading it again, but no go.

    I attached the log from OTM and pasted it just in case.
     

    Attached Files:

    Last edited by a moderator: Aug 12, 2010
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now try running combofix as per the instructions, in normal mode if possible!! Rename it first to kestrel.com and if you cannot get it to run in normal mode then try safemode.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  13. ADG11

    ADG11 Private E-2

    I ran MGTools.bat first and got a log.

    Then I tried to run combofix but it said it did not work on my machine. I have Vista 64bit
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Of course! (64 bit) my bad. Reviewing your logs now.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please try doing the below:

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then doube click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running.

    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.
     
  16. ADG11

    ADG11 Private E-2

    After 2 hours of scanning SAS found 1 problem. Except after I rebooted the computer I cannot find the log for it. I think this was because I didn't install SAS originally, I just used it directly from the website. Or maybe I just am looking in the wrong place. But it did find one thing wrong and all I can remember was the first couple words dealt with '_OTM.....'.......sorry

    On the positive side I attached the AVP log.
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Give this a run. See if it finds anything because apart from what we removed earlier, I am not seeing any malware.

    Using ESET's Online Scanner

    Attach the ESETScan.txt to your next reply.
     
  18. ADG11

    ADG11 Private E-2

    So I had been running the scan for a good 4 hours and it was 95% complete. I walk away for a second and my computer decides to manually shut down to install updates. It did find one error, something dealing with Win32.

    I guess I will just start running it again. So my guess is that it will probably take another 4 hours.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well it might be worth it, so give it a go.
     
  20. ADG11

    ADG11 Private E-2

    Finally finished the second run through. No threats were found and it didn't create a log. Sorry about screwing it up the first time.
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  22. ADG11

    ADG11 Private E-2

    Hi Tim, things seem to be running well. The Security Suite program is gone, which I think caused most of the problems.

    I have Webroot Spy Sweeper but I don't think it covers me under Virus protection. Do you recommend any programs?

    Thanks for the help!
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean. I would just suggest you read the last link on How to Protect yourself.

    ( You need to rename ComboFix back from kestell.com )

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  24. ADG11

    ADG11 Private E-2

    Great!

    Thank you both for helping me! I really appreciate it! You guys are great as always!

    Have a great day!
    Andrew
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome from both of us. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds