infected? can't run all tools or get logs

Discussion in 'Malware Help (A Specialist Will Reply)' started by egardner18, Mar 5, 2011.

  1. egardner18

    egardner18 Private E-2

    I'm pretty sure my system got pretty infected.

    Symptoms included being slow, unable to install any AV and make it work or run any online scan. Taskbar missing from bottom in all user profiles. It's not hidden or shrunk, just not there. It looks like the top of it there and if you put the curser there it gives the up/down arrow like you can click on it and expand it, but it doesn't allow it. You can right click on it and get the taskbar option like lock in place, hide, etc...

    Running WinXP SP3

    I was following your guide. I ran into various problems. Following are the errors and problems I ran into. The only log I'm able to supply is the MGtools log as I wasn't able to get logs from the other programs.

    1. Couldn't update Java. I'm running Java 6 update 20. There is update 24 but got "the system administrator has set policies to prevent this installation". I'm logged in as an admin, this is a home computer. I have never set any policies.

    2. Was Able to run Superspyware initially and scan. It found Rogue.AVGantivirus and Trojan.agent/gen-fakeAV and cleaned. On reboot ran Superspyware again, the splash screen came up then nothing. Task manager shows it as a running process, killed it and tried several times, including in safe mode with no luck. So no log.

    3. Moved on to Malewarebytes Anti-malware. Got "runtime error 372, failed to load vbalgrid from vbalgrid6.ocx. your version of vbalgrid6.ocx may be outdated. Make sure you are using the version of the control that was provided with your app.

    4. Tried combofix. Got the error "cannot run combofix with AVG installed" Only option is to click ok and then nothing. AVG is not installed it. It was at one time but stopped working, my son tried to update and I think that's where the rogue version came from. I have used the removal tool and still get the error.

    5. Tried rootrepeal. Error "error attempt to read from address 0x0116900".

    7. MGtools ran fine.

    There it, that's where I am. I'll attach the mgtools log. I'm kind of fed up and about to do a repair or clean windows install.

    Again I tried all these in normal and safe mode.
    No AV is currently installed.
    Any ideas greatly appreciated.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Does your copy of ZoneAlarm come with AV protection?

    You need to use windows explorer to delete these:
    E:\program files\AVAST Software
    E:\program files\NortonInstaller
    E:\program files\Panda Security

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. egardner18

    egardner18 Private E-2

    Tim,

    Thanks for your reply and help.

    First, no my Zonealarm does not have AV with it.

    Second. New symptom found, I can't copy/paste. Well, I can copy but then past is greyed out. So I had to type the lines into avenger.

    Task bar still missing. It's like you can see the top of it at the bottom of the screen, but can't expand it.

    Slow loading of windows still. About a 20 second pause of empty desktop before icons show up.

    Followed your steps, got errors for the registry portion, they are in the log. I'm familiar and comfortable with working in the registry, should I try to delete them manually.

    Here are the logs and thanks again.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's a bad idea to allow all users to have Admin. privileges!! You need to run SAS and MBAM on each user account.

    I think some of your issues are not malware related. You might want to try going to start / run / and type:
    sfc /scannow and have your Windows CD handy. Run it twice.

    If after doing the below you are still having those issues, you may need to post in the software forum and do a repair install.

    You should also uninstall AD-Aware as it is virtually useless these days. Then download and install an AV program.

    Use windows explorer to find and delete:
    C:\Documents and Settings\Ed\Local Settings\Application Data\npmiqbbwn
    E:\Program Files\AVG
    C:\Documents and Settings\All Users\Application Data\AVAST Software
    C:\Documents and Settings\All Users\Application Data\Norton
    C:\Documents and Settings\All Users\Application Data\NortonInstaller

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds