IE9 does not display

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Sharkp, Feb 6, 2012.

  1. Sharkp

    Sharkp Private E-2

    I had the Vista Security 2012 virus and removed it with your instructions and thought all was well. However, now opening IE9 the page does not load completely. Some pictures and wording is not there its white. I changed the home page to default and it says "Everythingy.com" three times. I uninstalled Adobe Flash and attempted to reinstall it and it says it cannot run because "Only a single instance of this application can run." Yet in the Program and Features it is removed. I ran Malwarebytes, Microsoft Security Essentials, FixNCR.reg, RKill as well as TDSSkill. I also ran hijackthis and mbrcheck per the instuctions and would appreciate if someone would kindly help me. Please let me know if I can provide anything further. I have attached both the hijacklog and mbrcheck log.
     
  2. Sharkp

    Sharkp Private E-2

    Sorry trying to figure out how to attach log.
     
  3. Sharkp

    Sharkp Private E-2

    Sorry here are the logs. Thank you in advance.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    Then continue on with these instructions.



    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  5. Sharkp

    Sharkp Private E-2

    Thank you for your help. One thing Im now noticing I cannot do for example is on the laptop when in this forum under attach files, "manage attachments" is not accessible. I cannot click on it. As well I remember the same happened when trying to click on a "fix it" in Microsoft website. Here is the log you requested and I will continue with the rest of the instructions.
     

    Attached Files:

  6. Sharkp

    Sharkp Private E-2

    SuperAntispyware Scan Log
     

    Attached Files:

  7. Sharkp

    Sharkp Private E-2

    Malwarebytes log
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want to see logs from running Combofix and MGTools too please. Thanks.
     
  9. Sharkp

    Sharkp Private E-2

    Im sorry its taking so long. Im having a difficult time with Combofix. When following the instructions for Combofix and downloading it to the desktop I double click the icon and it gets to the screen "Scanning for infected files ... This typically doesnt take more than 10 minutes however scan times for badly infected machines may easily double." That is as far as it goes for over 30 minutes. I dont even get the window status update. As the instructions state Im moving to the next step which is running RootRepeal and will post when finished.Thank you!!
     
  10. Sharkp

    Sharkp Private E-2

    Hello and thank you so much for your help. I'm feeling like things are more of a mess than when I started. The problem still persists. It was initially that the pages of IE9 didnt completely load ie some pics and wording etc. I also noticed some download links I cannot click on and download(initial problem). I especially cannot download Adobe Flash(initial problem). I've clicked on the correct download and it does nothing. I have also recently gotten "The recycling bin in C:\ is corrupt. Do you want to empty the recycle bin for this drive?" The Explore does not even look right. When I click on Explore all users, under folders it says in order Larry, Public, Computer and under Computer Local Disk (C:), HP_Recovery (D:), DVD RW Drive (E:) and the Network, control panel and recycle bin.

    In running the MGtools.exe it ran and I got the command prompt window which said my zip would be in C:\MGlogs.zip, however, its nowhere to be found. I clicked on close in the window because it said it was saved. Did I do something wrong. I did do a search in the MGtools file and found some txt that I believe is in the log you are looking for and have attached 4 txt logs. If these are the logs you need I can attatch the rest. Im really sorry.

    The Combofix screen says "Scanning for infected files ... This typically doesnt take more than 10 minutes however scan times for badly infected machines may easily double." That is as far as it goes for over 30 minutes. I dont even get the window status update.

    The RootRepeal when trying to open would restart the laptop. This happened 3 times so I stopped and went to the next step.

    Please let me know further instructions.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You have attached logs from inside the actual zipped file that I want to see! So you do have it. I must see it as it contains everything. :)
     
  12. Sharkp

    Sharkp Private E-2

    Sorry for not understanding but I dont actually see a zip file. What I do see is the MGtools folder under the C drive and under that is "temp" folder. Withing that temp folder are 8 other folders ERDNT, NTSPU, NTUKB, SPF, VSP1, VSP2, XPSP2, XPSP3 with a sysrest.txt document 4 kb. The only "zip" is zip.exe in MGtools. The files I attached are individually withing MGtools folder not in a zip. :confused
     
  13. Sharkp

    Sharkp Private E-2

    Ive put the txt in a zip folder and attached it. There are other files that are bat files, cmd and exe files as well. Please let me know what is next if this is what you need.
     

    Attached Files:

  14. Sharkp

    Sharkp Private E-2

    I deleted Combofix from the desktop and downloaded it again renaming it something else before saving to the desktop. I restarted in safe mode only and double clicked on the renamed Combofix and after it finally came back with the message "Rootkit.Zero.Access. It has inserted itself into the tcp/ip stack". It continued to run and then finally stated again it and asked to restart. Once restarted screen is black however Combofix is running FINALLY with the stages. I will post with the log when it finishes.
     
  15. Sharkp

    Sharkp Private E-2

    Combofix log
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall this junk.
    • Ask Toolbar

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "My Faster PC"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{362269bd-c93c-460f-9255-3bd667eb7f0a}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{a5b9c0f5-5616-47cd-a95f-e43b488faccf}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{46F55567-052E-48D3-914D-34F0C729283D}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A6BBD89F-080B-4585-A747-24566477196F}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{DD2C6EAE-3F93-43ED-B776-5E530B020B2F}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{EA55BF8B-5A7B-4149-9BEE-1158D0D60753}]
    Folder::
    c:\program files\consumersoft
    File::
    C:\Users\Larry\AppData\Local\f2113fc1
    C:\Users\Larry\AppData\Roaming\3f0d3fdf
    C:\Users\Larry\AppData\Roaming\Microsoft\Windows\Templates\44dff28c
    C:\ProgramData\84e2a78c
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.




    Download Cleano 0.61

    Download it to your desktop, Right click the cleano.exe file and run as admin > and place check marks in the boxes as follows (click on link below to see image)
    Cleano image



    • Click clean now and exit the program.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  17. Sharkp

    Sharkp Private E-2

    Combofix.txt and MGtools.zip attached. System slow to shutdown and slow to start up. when connecting to internet it still does not display full page. Could this be due to no Adobe Flash/Java? I attempted to click on a download for Adobe and it does not start. Seems better but still internet trouble. Prior to these steps an attempt to update windows failed.
     

    Attached Files:

  18. Sharkp

    Sharkp Private E-2

    When I attempted to attach MGtools it says I already attached this file. What should I do?
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It means that you are trying to attach the old one I'm afraid, so try again, if necessary re run MGTools.exe and then attach the new MGlogs.zip.
     
  20. Sharkp

    Sharkp Private E-2

    Ok thanks working on it right now. Just a quick question and correct me either way. If I do a system recovery will that take care of this virus and was it in the partition?
     
  21. Sharkp

    Sharkp Private E-2

    Sorry I know what I did. Here is the log.
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing anything wrong with the partitions and I am not seeing any signs of bad files anywhere else.

    OK, I want you to download Mozilla Firefox Let me know if you can use that browser.
     
  23. Sharkp

    Sharkp Private E-2

    I appreciate the help you have provided up to this point, however, we have chosen to reinstall the operating system back to factory setting. We have done that and are currently in the process of the many updates that follow. Thanks again.
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK no problem. You're most welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds