Inaccessible Windows Xp

Discussion in 'Malware Help (A Specialist Will Reply)' started by ComputerHelp1, Apr 1, 2010.

  1. ComputerHelp1

    ComputerHelp1 Private E-2

    Hello. I have been fighting a malware infestation of some sort for the past 9 hours or so but I'll try to condense my story for all of you. First I'd like to say that I physically cannot carry out the procedures in the floated thread on removing malware for reasons I will explain shortly so please don't just refer me to that.

    It started somewhat randomly earlier today. I was browsing the internet like I normally would (I don't go to bad/shady sites and didn't do anything different today) and I started experiencing some pop-ups that I dismissed as Adware. I know it's not known for being a great program but Spybot has always been great for me. I thought I'd just run that like I normally do when I have a problem and it'd be over quickly. Unfortunately I seriously underestimated this malware infection.

    I first realized it was different when I couldn't open task manager. Apparently it was "disabled by the administrator" who hasn't gone on his account in two years on this computer... Hurrying up with getting Spybot out I began searching Google for some answers as to what was going on as chaos ensued on my computer. I eventually did get the task manager back through a registry editor but I had a lot worse problems to deal with. I caught it just in time before it completely uninstalled AVG and had to continually ignore the warnings of Firefox being an "extreme danger to my security."

    The most active program was called User protection (sorry the capital p key won't work on this computer; I'm pasting p whenever I need it) ironically. It was like any other fake anti-virus malware except this one seemed much more aggressive and possibly let more malware into my computer. I tried downloading Malwarebytes' Anti-Malware but found that the actual site was inaccessible to me (all other sites were fine though) and that I could not download the necessary .exe file seperately as the guide I was reading instructed me to do. Spybot was able to handle a bit of the malware (deleted ~190 bad things) but some problems persisted. To make a long story short I was basically stuck.

    So feeling hopeless I decided to clean out my recycling bin. That's when it went crazy. One file wouldn't delete with a stoplight icon and was 0KB in size. I thought it was strange but left it there and tried leaving the recycling bin. The computer didn't like that and froze up on me clearing out all of the desktop and start bar. I couldn't right click or bring up the task manager. This is the state of it whenever I restart the computer.

    I've tried safe mode but nothing loads. Well nothing except for a fake anti-virus with a stoplight icon that would appear after a few seconds. I tried doing a repair installation but have not been able to complete it yet from it stopping at some steps. Right now it keeps getting stuck at the part where after it is installed it wants to help me "set up the computer." I try to click next but it always seems to be frozen at that one spot.

    Does anyone have an idea on how to fix this problem? Is anyone familiar with this type of malware? After doing some research it seems to belong somewhere in the Vundo family of viruses based on the "symptoms" I've seen. I can't find anything on the fake anti-virus that uses a stoplight icon though. I wish I could at least log on to try getting more information but unfortunately I'm stuck at that point of nothingness on the screen but my background. All I can give is some system specs that I know (it's an old computer):
    -It's a Dell Dimension 4600
    -OS: Windows Xp of course
    -I think 2GB of RAM

    I'm not sure what else would be useful. If there's something I can find out without having to log on I'll find it and post it here if you let me know. Thanks for any help.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Frequently, MGTools.exe will run when nothing else will. Did you try running that or combofix? Even try a rename if you need. Rename Combofix.exe to 123.com and MGTools.exe to Kestrel.com and let us know how you get on.
     
  3. ComputerHelp1

    ComputerHelp1 Private E-2

    Update: I was able to get on my computer by reinstalling windows. However I know the problem is not yet completely solved as one of the fake anti-viruses remains. The stoplight one I was talking about seems to be called Security Guard. Right now I'm running Malwarebyte's Anti-Malware to try to get rid of some but I wasn't able to update it before starting the scan. I kept getting an error when I tried to search for updates so I'm hoping that maybe by scanning now I'll be able to update once it cleans some things out?

    I found that all of the browser restrictions on that computer are the same - no Malwarebytes' site; no downloads from there (had to use a USB to transfer); and the windows updates site is inaccessible as well.

    If Malwarebytes' doesn't fix the problem enough to allow me to fix the rest does anyone have an idea of what I should do next?
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes. Try and complete as many of the steps as you can. Tell me exactly which steps failed, run what you can, and attach what logs you are able to attain.
     
  5. ComputerHelp1

    ComputerHelp1 Private E-2

    Okay, I have some good news and bad news. The good news is that my computer seems to be in a good working condition. Right now I'm using it without any websites blocked and not really any interference from malware that I can tell. However, the bad news is that I'm not convinced I really got it all. After what happened yesterday I'm sort of paranoid over this. I've dealt with small problems with adware and not very serious viruses, but yesterday's "attack" was so sudden and malicious that I'm really afraid of it coming back.

    I was able to do a lot of the steps from the floated thread, but not every scan. I did a SAS scan and an updated MBs' Anti-Malware scan. I'll try to upload the logs if I can figure out how to do that.

    Currently I'm updating Windows (XP 32-bit) as much as possible. It's on 80 out of 87 at the moment, and then I'll check to make sure I'm up to service pack 3 (or would the updates include that?).

    The first attached file was the first scan in MBs' Anti-Malware, and the second is from the second (after updating) scan. I can't seem to find a log for SuperAntiSpyware. I hope it didn't get deleted... Where should I look for a log from an earlier scan?

    Is there anything you can see from the other files that I should be concerned about? Do you think there would still be some malware left even after doing a few scans?
     

    Attached Files:

    Last edited: Apr 1, 2010
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your SAS log should be retrievable here:
    Please do not make any changes to your PC unless I ask you to whilst I am working with you to remove malware! Do not attempt to update to sp3 yet.

    Which scans couldn't you complete? What tools couldn't you run. You must tell me, and describe error messages. I at least need to see logs from running MGTools.exe before we even make a start and ideally a log from running combofix too.

    Just take your time, and we'll get through it. :)
     
  7. ComputerHelp1

    ComputerHelp1 Private E-2

    Okay I have a log from MGTools and didn't try Combofix yet since the guide told me not to do it unless specifically asked by someone. I guess I can try doing it today. I also couldn't find my SAS log under Application Data. There wasn't even a folder for SuperAntiSpyware there. Could it be possibly located somewhere else? I hope the MGTools log will be useful for now.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well I had asked for it to be run, yes. :)

    Yes, and I will have you run CF very soon but do not run it until I tell you to. I must go to work now, so will review your logs as soon as I get back.
     
  9. ComputerHelp1

    ComputerHelp1 Private E-2

    Okay thank you for your help. I guess it's a good thing then that I didn't finish running Combofix. For some reason it kept warning me that AVG will interfere with the running of it... except I completely uninstalled it already. Do you know why it might still be saying this and if (when you tell me to) I should still continue with the program ignoring that warning?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just so you don't have to wait for Kes to get back ....go ahead and run ComboFix and ignore the warning if you have already uninstalled AVG. ( Please go here and download and run the AVG Removal Tool. )

    Attach the log so she will have it when she returns.
     
  11. ComputerHelp1

    ComputerHelp1 Private E-2

    Okay, I ran ComboFix, but something strange happened at the end:
    1. A shortcut for Internet Explorer appeared on my desktop. Is this normal?
    2. A weird "G" for Google appeared on the bottom right near the time as one of those programs. It said it blocked an attempt to change my settings. Then the "G" program disappeared. Was this part of ComboFix or something else?
    3. Also, after scanning, ComboFix said it needed to restart my computer. It warned me not to do it manually, so I let it do it, not wanting to mess anything up. The guide I was following never mentioned rebooting, so was it supposed to do that?

    When it rebooted it started right back up, and I have the log attached. I hope it helps.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's do this now as you ran MGTools.exe before running combofix.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  13. ComputerHelp1

    ComputerHelp1 Private E-2

    Sorry for the late reply. I was busy this weekend. I ran MGTools again. Here is the log.
     

    Attached Files:

  14. ComputerHelp1

    ComputerHelp1 Private E-2

    Oops, I think I just redid a normal MGTools scan like the first time. Sorry for misreading your post. I hope I didn't mess anything up... I followed your instructions exactly this time going inside the MGTools folder and then clicking that file. Here's the new attachment (can't find the edit button to put it in my last post).
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. So you uninstalled AVG..? Did you use the avg removal tool which Tim linked you to?
    I am seeing remnants from avast and also what McAfee software do you currently have installed?

    2. I see almost every user of this machine has admin priviledges. This is not a wise idea.

    3. Please go to Add/Remove programs and uninstall the following software:

    • Java(TM) 6 Update 7
    4. Are you set up to use this proxy? I suspect not, so if not, please include it in our list of fixables.

    5. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    6. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    ottnncy
    
    DirLook::
    c:\documents and settings\All Users\Application Data\SGDUAAED
    
    File::
    c:\windows\Srijonafazeqeqa.dat
    c:\windows\Phowadaza.bin
    c:\windows\SYSTEM32\fceebcfeb_z.dll
    c:\windows\SYSTEM32\ppqss.tmp
    c:\windows\SYSTEM32\wycdd.tmp
    C:\Documents and Settings\Mom.D7386W41\Local Settings\Application Data\uMqB8Hu2bCXlI
    C:\WINDOWS\system32\higujata
    
    Folder::
    c:\documents and settings\All Users\Application Data\AVG Security Toolbar
    c:\documents and settings\Mom.D7386W41\Application Data\AVGTOOLBAR
    c:\documents and settings\All Users\Application Data\Viewpoint
    c:\program files\Alwil Software
    C:\Program Files\AskBarDis
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    7. Also delete all files in the below bold folder except ones from the current date (Windows will not let you delete the files from the current day).
    8. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    9. Let me know how the machine is behaving now.
     
  16. ComputerHelp1

    ComputerHelp1 Private E-2

    1. Yes, I used the tool to remove it, but it seems that ComboFix keeps saying it's still active when it's not... I'm not sure why Avast is still left after I uninstalled it, and I'm not sure on McAfee. It was put in years ago and has never really been used. I'm not sure how to uninstall it either since there's nothing under Add/Remove Programs to remove for it (except the Security Center I think which needs everything else to be removed first).

    2. I'm not sure how almost everyone got Admin priviledges; I thought only 1 had it. I'll have to change that if everyone still remembers their passwords...

    3. Okay, I removed it.

    4. Not sure what that is, but I added it to the list.

    5. Done.

    6. Log should be attached.

    7. I tried deleting the two files left in there, but it said they were currently being used, even after exiting all programs. Are they viruses of some kind or is it ok to leave them?

    8. It should be attached too.

    9. The computer has been fine for the past few days. I haven't noticed anything out of the ordinary, but I hope doing what you told me to gets rid of all of the malware for good so I can start over. Thank you so much for the help.
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Looking much better.

    Just a small tidy up to take place now:

    1. What do you know about the below bold file?

    c:\documents and settings\All Users\Application Data\SGDUAAED\SGSRYAMNBZD.cfg

    With a date of: 2010-04-01 07:45 If you do not know then please delete the whole SGDUAAED folder.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    SecCenter::
    {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    
    File::
    C:\$AVG8.VAULT$
    C:\Documents and Settings\Mom.D7386W41\Local Settings\temp\~DFE41.tmp
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MCAgentExe"=-
    "MCUpdateExe"=-
    "MSKDetectorExe"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    and ....

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  18. ComputerHelp1

    ComputerHelp1 Private E-2

    Thank you so much for your help. I'm glad the malware is finally gone. However, I'm afraid I encountered another problem.

    When trying to update Windows, I came across this error when trying to install Service Pack 2:

    "Files that are required to run Windows properly have been replaced by unrecognizable versions. To maintain system stability, Windows must restore the original versions of these files.

    The network location from which these files should be copied, C:\WINDOWS\ServicePackFiles\i386/rtcres.man, is not available.

    Contact your system administrator or insert Windows XP Service Pack 2 Source Files now."

    My options are: Retry, More Infortmation, and Cancel, all of which do not help. Do you know what might be causing this problem and what to do to get around it? Is it malware related at all?
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm afraid you will have to ask in the software forum. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds