Malware affecting add/remove programs and system icons

Discussion in 'Malware Help (A Specialist Will Reply)' started by nooonjj, Jan 18, 2011.

  1. nooonjj

    nooonjj Private E-2

    Did the read me first but I made a mistake and ran combofix twice so I lost the first log. Also, rootrepeal kept freezing when loading.
    Alot of infections were removed but my desktop and control panel icons are still affected and I still cant remove certain programs like toolbars and a program called desktop organizer which is showing an error whenever I boot up.

    Thanks.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you. :)
     
  3. nooonjj

    nooonjj Private E-2

    Hi Kestrel :),
    Here is a screenshot of the icons on desktop and control panel. Combofix corrected the My Computer icon on the first run.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    Try using Your Uninstaller to uninstall Micro Formatica Desktop Organizer.

    Also uninstall the below software via normal means (add/remove programs)

    • Ask Toolbar
    • Java(TM) 6 Update 15
    • Java(TM) SE Runtime Environment 6 Update 1

    What other toolbar are you trying to get rid of or have I already covered that?

    Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.

    Malware Bytes
    is also outdated, so open up the program, locate the UPDATE tab, let it update, re-scan, and fix anything it may find. Attach the log into your next reply, regardless of it's findings.

    What is this ?
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    C:\MAL
    c:\windows\system32\474BF6B8C0C1CFC6C94B21CE6D231A54
    c:\documents and settings\All Users\Application Data\62AF
    c:\documents and settings\Guest\Application Data\Search Settings
    File::
    C:\WINDOWS\Temp\SEP23.tmp
    C:\WINDOWS\Temp\SEP6.tmp
    C:\WINDOWS\system32\212056479
    C:\WINDOWS\system32\643694264
    C:\WINDOWS\system32\747213491
    C:\WINDOWS\system32\c73eec8
    C:\WINDOWS\system32\sl1833052941
    C:\WINDOWS\system32\st1106C.manifest
    C:\WINDOWS\system32\st1106O.manifest
    C:\WINDOWS\system32\st1106S.manifest
    c:\documents and settings\Pearline911\hiebgltvji.tmp
    c:\windows\system32\2C.tmp
    c:\windows\system32\2B.tmp
    c:\windows\system32\57.tmp
    c:\windows\system32\mfc4232.dll
    Folder::
    c:\program files\SmileyCentralIE_1w
    c:\program files\SmileyCentral_1vEI
    c:\documents and settings\Pearline911\Local Settings\Application Data\iMesh
    c:\program files\iMesh Applications
    Registry::
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{36D9CE8C-5BD1-5860-8B0F-D57FC0AE8025}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{8b0d31e7-0331-43cc-87cd-a472317f1305}]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=""
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!

    Why are you not using any antivirus??
     
  5. nooonjj

    nooonjj Private E-2

    Ok, MsConfig is back on normal.
    Still cant uninstall Micro Formatica Desktop Organizer
    also couldnt uninstall Java(TM) 6 Update 15

    Trying to get rid of all toolbars, like IObit Toolbar v4.1

    Redid SUPERAntiSpyware and Malware Bytes as instructed
    After the reboot, Micro Formatica Desktop Organizer started up without an error

    I don't know what this is:
    there was a lot of stuff on the desktop that I moved into one folder "tmp".


    Ran C:\MGtools\analyse.exe but only saw this line:

    ComboFix ran ok

    I couldnt install the new java version because it said it was unable to uninstall the older version

    The icons are the same. Also, didnt mention this before, but cant access the recycle bin at all.

    Yea :(, I thought avast was on here but Im not the main user of this box.
     

    Attached Files:

  6. nooonjj

    nooonjj Private E-2

    Here is a screenshot of the add/remove error. At first the message was different, it said something like Couldn't remove "This can occur if you are running windows in safe mode, or if the windows installer is not correctly installed". I read an article in the microsoft knowledge base and typed in the commands msiexec /unregserver and msiexec /regserver. Maybe things are worse now, I really dont know.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is Micro Formatica Desktop Organizer something you knowingly installed? I need to have a word with one of the others about something before we proceed. Hang in there I will not forget you.
     
  8. nooonjj

    nooonjj Private E-2

    Thanks.
    Yes, it was knowingly installed.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try Revo Uninstaller.
    Choose the option on the bottom of the list (#4). Be very careful while deleting the bolded registry items ONLY!! This software will create a system restore point for you as well prior to uninstalling a software program.

    Any luck?
     
  10. nooonjj

    nooonjj Private E-2

    Wow, it worked great. It removed Desktop Organizer, Java, and all the toolbars.
    I was able to install the new version of Java.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now then... how about the desktop situation? Has that be corrected since the removal of that program? :confused
     
  12. nooonjj

    nooonjj Private E-2

    No, the icons are still the same. Also, I didnt mention this before, once the desktop loads during startup a window flashes but too fast to see what it is. And the start menu will be unresponsive for about a couple minutes, just the startmenu, I can highlight desktop icons. Then itll become responsive and the other programs that run at startup will load.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  14. nooonjj

    nooonjj Private E-2

    I installed Avast antivirus and it did a boot-time scan. The start button doesn't freeze anymore, the icons and recycling bin are the same.
    I ran GetLogs.bat after.
     
  15. nooonjj

    nooonjj Private E-2

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The MGlogs.zip did not attach.
     
  17. nooonjj

    nooonjj Private E-2

    logs again
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I will review those logs right now, however you may have to work this out in the software forum.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    FileLook::
    C:\Documents and Settings\Pearline911\Templates\DownloadInfo.initmp
    File::
    C:\WINDOWS\system32\1106P.manifest
    C:\WINDOWS\system32\DesktopExplorer.tlb
    Folder::
    C:\Documents and Settings\Pearline911\Application Data\DeskOrganize
    C:\Documents and Settings\Pearline911\Application Data\IObit
    C:\Documents and Settings\Pearline911\Application Data\Micro_Formatica
    C:\Documents and Settings\Pearline911\Application Data\Search Settings
    C:\Documents and Settings\Pearline911\Local Settings\Application Data\Micro_Formatica
    C:\Documents and Settings\All Users\Application Data\62AF
    C:\Program Files\IObit
    C:\Program Files\Micro Formatica
    C:\Program Files\Free Offers from Freeze.com
    C:\Program Files\PC Optimizer Pro
    C:\Program Files\SpeedItup Free
    C:\Documents and Settings\All Users\Application Data\IObit
    C:\Documents and Settings\All Users\Application Data\PC Optimizer Pro
    C:\WINDOWS\system32\474BF6B8C0C1CFC6C94B21CE6D231A54
    Registry::
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{df07101b-46d4-4a98-af68-0333ea26f113}"=-
    [-HKEY_CLASSES_ROOT\clsid\{df07101b-46d4-4a98-af68-0333ea26f113}]
    [-HKEY_CLASSES_ROOT\DesktopExplorer.DesktopExplorerBand.band]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      C:\Documents and Settings\Pearline911\Templates\DownloadInfo.initmp
    • At the upload site, click the browse button.
    • Use Windows Explorer to navigate to the file(s) we need scanned and click "submit file"
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

    Could you please get this: DownloadInfo.initmp into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:
    log retrievable @ C:\collect.zip

    Run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Are things running any better?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds