Logs Posted

Discussion in 'Malware Help (A Specialist Will Reply)' started by NCSUgeology, Jan 26, 2011.

  1. NCSUgeology

    NCSUgeology Private E-2

    I still get redirected in google, and the Resident Shield still shows Wininit.exe and explorer.exe infected.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please go here and download and run the AVG Removal Tool.

    Then run ComboFix and attach that log to your next reply.
     
  3. NCSUgeology

    NCSUgeology Private E-2

    comboFix attachment.

    I was in the process of deleting AVG when you posted.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your windows cd? We may need it to replace your infected explorer.exe.

    Let's do this first:

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Windows\System32\^-'pctlsp.log
    C:\Windows\System32\(O.pctlsp.log
    C:\Windows\System32\Er6pctlsp.log
    C:\Windows\System32\d,Lwpctlsp.log
    C:\Windows\System32\I®§špctlsp.log
    C:\Windows\System32\R™lSpctlsp.log
    C:\Windows\System32\R™lSŽ¡pctlsp.log
    C:\Windows\System32\R™lSO•ªpctlsp.log
    C:\Windows\System32\R™lS…Œ«pctlsp.log
    C:\Windows\System32\AUyv˜˜pctlsp.log
    C:\Windows\System32\XN?pctlsp.log
    C:\Windows\System32\X•Opctlsp.log
    C:\Windows\System32\ú6pctlsp.log
    C:\Windows\System32\¡;pctlsp.log
    C:\Users\Chris\AppData\Local\Bxeqehihevurij.dat
    C:\Users\Chris\AppData\Local\Ovigevoyox.bin
    
    Folder::
    C:\Users\Chris\AppData\Roaming\PC Tools
    C:\ProgramData\PC Tools
    C:\Program Files\PC Tools Security
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * MBRCheck log
    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  5. NCSUgeology

    NCSUgeology Private E-2

    Everything was a success through the combofix suggestion. After Combofix ran, it said it needed to reboot. When it came up I got the following message:

    Explorer.exe
    The Ordinal 874 could not be located in the dynamic link library shell32.dll

    Then I get the message that explorer.exe has stopped working and it continues to load windows, but the desktop is blank.

    I was able to get to this screen because a "download windows update" windo came up and i clicked that and IE came up.

    I did see that combofix did say it corrected explorer.exe. Also, I don't have my windows cd.

    I opened the Task Manager, and it shows explorer.exe in the list of Processes. I'm not getting redirected in google now either.
     
    Last edited: Jan 27, 2011
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-run Combo and get me the new log. Also, you did not run MBRCheck. I would like to see that log as well since you did have a TDL infection.
     
  7. NCSUgeology

    NCSUgeology Private E-2

    How do Open Combo since there aren't any icons on my desktop? It's a blank screen.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Control + Alt + Del to open task manager then type in explorer to start the process. That should get your desktop back. I thought you said that:
    What happens if you try starting in safe mode?
     
  9. NCSUgeology

    NCSUgeology Private E-2

    I ran combo again and have posted the log. I also ran the MBRCheck and attached the log.

    The first time I opened Task Manager, explorer.exe was listed in the processes. Since I ran combo again, it's not listed now. When I type in Explorer.exe as a new task, I get the error message "The Ordinal 874 could not be located in the dynamic link library shell32.dll"

    Also, when combo was doing it's scan, it said it had fixed the problem when it was going through it's Stage count.

    When I start in Safe mode, it's the same thing - a blank screen.

    I can't thank you enough for all your help with this.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok., so Combo reports that it found and fixed both explorer.exe as well as the Wininit.exe. So where do we stand? Do you have your desktop back? Your MBR is fine. Tell me what is happening now. And if you still have a blank screen, how did you run COmbo?
     
  11. NCSUgeology

    NCSUgeology Private E-2

    I still have a blank screen. I opened Combo through task manager.

    I'm running everything through task manager
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since you do not have your Vista disc, we will try having you make a boot disc where you should be able to do a system restore:
     
  13. NCSUgeology

    NCSUgeology Private E-2

    Just getting back to this. Here's where I am:

    I went to this site - http://neosmart.net/blog/2008/window...disc-download/, and created the disk they offer for free. I booted from the cd, but got the following error: E:\Sources\Install.wim could not be found. I've looked in every folder and the file isn't there. This seems like it's a boot disk, but my computer boots fine. Does the one you buy have differnt files on it?

    I've tried to do a restore from a back-up (one of teh selections on the disk), and I get the message "There is not a vaild back-up on this computer".

    It will let me do a complete system restore, but all the restore dates I have to choose from are dates with the virus, or dates where the explorer.exe is messed up.

    I went to this site - ISO Burner: http://www.snapfiles.com/get/active-isoburner.html - and tried to install the program, but I got the error "The Ordinal 874 could not be located in the dynamic link library shell32.dll. The file is zipped, and I can't open it without explorer.

    Also, how do you thank people. I see it on the right side of Tim's post. He's dealing with a dumbass, but he's been very helpful and very patient with me.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is there anyone from whom you can borrow a Vista disc? It needs to be the same version as what you have. Friends, neighbors or family?

    If you can, we need to do this:

    We need you to boot into the bios and change your boot order to CD drive as the first boot device. Insert the disc and reboot. Then enter the Recovery Environment. Once there you would type this:
    Once you are back to the C:\Windows> prompt of the Recovery Console, input the below commands one at a time each followed by the enter key. Read the notes further down which comment on these commands.
    copy D:\i386\explorer.ex_ explorer.exe
    cd system32
    copy D:\i386\winlogon.ex_ winlogon.exe
    exit

    NOTES:

    * the first command should cause the prompt to change to C:\windows\system32>
    * the second command should copy the compressed winlogon.ex_ file ( yes the underscore is the correct file name ) from the i386 folder of your CD into the system32 folder and rename it to winlogon.exe, the file will automatically be uncompressed. Notice the space after the copy and after the ex_
    * the third command should reboot your PC. Remove the CD and see if Windows will boot.
     
  15. NCSUgeology

    NCSUgeology Private E-2

    Ok, this is what I've come up with. When we bought this computer, we bought two, and one went to my mother-in-law at home. No disk was shipped with the computer, but I can get files off of that computer. It's the exact same make, model etc.

    Can I copy the needed files from that computer? I haven't been able to find anyone that has a Vista disk.

    I did copy the expoler.exe file from that computer and put it in the win32 directory, and launched it, and exploer came up. I got the shell error message at some point, and when I did a reboot, it was a blank screen as well.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Without being able to get your desktop to run, we have no way that I can think of to copy those files. Let's me consult with Chaslang as to how we might make this work. Hang in there for a while.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Question: Did you Mother-in-law make a restore cd? That's one of the first things that should have been done. Since they are the exact same make and models, you should be able to use it to restore your computer. It will of course remove anything you have done to personalize yours.
     
  18. NCSUgeology

    NCSUgeology Private E-2

    She has not yet, and I was going to do it for her once I got my mess straight.

    You're saying I'll need to back-up email and any files that I want to save inorder to use a restore cd correct? Or is it just like going back to a restore date where I don't lose and files, it just take windows back to a specific date.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    My thinking is that if she creates the restore disc ( actually a recovery disc ) it will have everything on it at the time she/you make it. And yes, you would need to backup all your email and personal files including pictures, etc. Programs that you have that she doesn't will be lost. It will recover your system to an image of her system.

    But without an OS cd, I can't think of any other way to fix yours! :(
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Next question: Can you boot into safe mode with Command prompt?
     
  21. NCSUgeology

    NCSUgeology Private E-2

    I copied everything that wanted to save to an external drive, said to hell with it, and took it back to factory settings. She's running smooth now.

    I've learned my lesson, created a restore disk, and installed everything you guys listed on "What we recommend" page.

    Thanks so much for the time and effort you spent in trying to help me. Where can I make a donation for the help you've given me?
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds