loony-I trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by Pete22, Dec 18, 2009.

  1. Pete22

    Pete22 Private First Class

    Hello Geeky friends:

    Someone wanted to play games on my sister's emachine 625 with winxp sp3.
    However, the link was gone from the menu.

    I tried going into add/remove windows components but received this message:”
    From Windows Xp Setup it is a message that says Please wait.
    Then another message said was unable to open information file msmsg.inf.
    Contact your system administrator. The specific error code is Ox2 at line 0.
    Behind it is a message that says Please wait.
    The third message said the application could not be initialized.

    So I ran AdvancedSystemCare.

    It came up and told me I was infected with the Loony-I trojan. I read a little about it and found out it pretends to be part of winamp media files but is not. The file is winampa instead.

    So I started the “Read and Run” process.
    I noticed that winampa wanted to start at startup so I stopped it from doing that.

    I ran the rest of the files. I hope I did it right, I tried very hard to follow the directions, except for combofix which I could not download.

    When I was done, I wanted to see if it was fixed. Or if I needed to send you an email. I ran AdvancedSystemCare again. It no longer said I was infected with the Loony-I trojan....
    But I did not get the all is well answer I wanted.

    I thought maybe that I just needed to fix the files that loony had corrupted so I ran sfc /scannow. I was able to reinstall all the files but one. I do not know how to tell which one did not reinstall. However, I
    the games are still missing, and I still get the same messages if I try to install them.

    I also noticed that the sound icon is no longer in the task bar. When I try to add it, I get the message:
    Windows cannot display the volume control on the taskbar because the Volume control has not been installed. To install it, use add/remove programs in the control panel.

    Of course that does not work.

    What should I do now?

    Pete22

    P.S. Thanks to all of you who are in training and all of you Major Malware helpers. Now when a friend comes with a computer problem I don't panic any more! I just know its time to write my geeky friends again. Thanks for helping me to help my friends. :)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to finish it and do what it says! That is, attach the requested logs.

    ComboFix is back up. Run it and attach the log.
     
  3. Pete22

    Pete22 Private First Class

    Hello Chaslang:

    I'm sorry the logs were not attached to my message.

    I attached them to something!!!!!! Maybe my christmas letter. :-o


    Here are the first 4 logs


    Pete22
     

    Attached Files:

  4. Pete22

    Pete22 Private First Class

    Its eating the attachments!!!!

    Chaslang,

    Here is the combofix log.

    I keep getting notified that the host file has been changed.

    Thank you for your help.

    Pete22
     

    Attached Files:

    Last edited: Dec 21, 2009
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not have and did not have the Loony-I trojan. If you did, you would have had the below registry entry;
    The inability of AdvancedSystemCare to know the difference between the valid WinAmp and the trojan is just inexcusable. The file that you disabled using Glary Tools (which by the way the READ & RUN ME stated not to use) is the valid WinAmp program that you have installed. Does it need to load at start.... no! But either way you do not have this infection.

    You do have a few miscellaneous non-malware things to fix though. One of them is a missing system file.

    Please delete the below and in the future follow our instructions properly. This is not where MGtools.exe was to be downloaded or run from.
    C:\Documents and Settings\LenNae\My Documents\Downloads\MGtools.exe


    Shutdown AVG, PCTools Firewall, and WinPatrol before doing the below.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 16

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

     
  6. Pete22

    Pete22 Private First Class

    Hello Chaslang,

    Deleted the below
    C:\Documents and Settings\LenNae\My Documents\Downloads\MGtools.exe

    Uninstalled to be sure they would not run: AVG, PCTools Firewall, and WinPatrol

    Made notepad file of info and added to desktop.

    ComboFix uploaded new version and ran.

    After reboot, now installed the current version of Sun Java from: Sun Java Runtime Environment

    Downloaned and ran MGlogs.

    Ooopp forgot to run CCleaner. So I will redo the MGlogs.

    Ran CCleaner and MGlogs
    Redone. Ok.

    Checking computer:
    reintalled AVG, PCTools Firewall, and WinPatrol
    -Still No Games
    -Volume control still not installed
    -Still receive same error messages when I try to add/remove windows components.


    I ran several other programs. I don't see any other problems.

    Checked preview to make sure attachments are attached! ;)

    Ready for more orders.

    Pete22
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These are topics for the Software Forum since there was no malware found in your logs. We just fixed a couple non-malware issues including a missing system file. I suggest that you do the below and then post remaining issues in the Software Forum.

    Sounds like one problem is that your c:\windows\inf'\msmsg.inf file may be missing.

    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System Rile Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.



    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds