malware has damaged my microsoft programs

Discussion in 'Malware Help (A Specialist Will Reply)' started by drgrim, Jul 4, 2006.

  1. drgrim

    drgrim Private First Class

    Ok..lets try again here. I obviously was too quick off the mark and posted in the wrong section as I havent had any suggestions from anyone as yet. Here's my previous post as i think the info is still relevant. I have been trying everything I can think of including all the steps that were mentioned in the "Before you post" section but I still cant use, uninstall or reinstall any of my microsoft office pro 2003 or Internet explorer. The only microsoft program that seems to be ok is windows media player.

    Hi all...Last week I had a problem with Internet Explorer 6. After being online all week I closed the pc down friday night and went to bed. When I started my system up the following morning I could connect successfully to the net but could not fully open any web pages at all. I only got a white screen and the cursor hourglass. Waited ages and nothing would open. Now normally when this happens(it has in the past due to spyware etc) I do a scan with Avast, spybot s&d and adaware personal SE and then get onto google to find out how to remove the nasty that these have found if they cant do it themselves. Due to explorer not working at all and a week of stuffing about for many hours a friend gave me a copy of the Mozilla Firefox Browser. Bingo!! ..now at least I can see web pages!!. But...since I have installed and am using Firefox every time I get an email with a .pps or word doc, excel..etc..any office program type file (I am running MS office pro 2003 and XP SP2)i get windows installer popping up saying it needs to install some update so the program can view whatever it is im trying to open but always comes up with an error saying it cant find this CAB file or that (varies..have tried this about 20 times today)and to point it in the direction of the file. I checked my CD and the damn files its asking for are on the bloody cd!! (can you tell Im nearing the end of my tether here!!??) but it doesnt recognise them and wont proceed. I have tried uninstalling (which wont work due to the same error) or reinstalling (with the same result) I have visited hundreds of forums today seeking guidance to no avail. It seems every thing microsoft has been affected (suprise suprise!!) by this damn trojan. BTW..the trojan was Win32.Trojan.gen{Delphi} and also found Win32.1stbar_L which Avast seems to have removed but I have doubts.




    Ok..thanks for steering me to the "Read me first before asking for support" section.
    I have followed all the steps in that and found nothing..at all. The only steps I couldnt follow were the online scanning options as they will only work in IE and I cant use IE or any other Microsoft browser or program. I figure the trojan I had damaged something and specifically attacked the microsoft software on my pc. I have absolutely no sign of any malware at all now but still have the problems with my software..(which is why I posted here) . I cant reinstall anything as I keep getting the error message saying windows installer cant find the "......CAB" file even thought I point it to the relevant file on my installation cd which I can open but it cant.
    I still cant use any program from Microsoft Office at all or do anything with Internet explorer..including update or download the latest as I have to be using IE to download IE( or so I am told at the web page). If I could use it then I wouldnt need to download it!!!
    So!!....anyone have any Ideas as to where to start???
    PLEASE HELP!!:rolleyes:
    Drgrim
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problems (at least the majority of them) really do not sound like malware to me and if you ran ALL of the READ ME (except the online scans) and found nothing, it also more than likely confirms you are not having malware problems. However, follow the directions in step 7 of the READ ME and I will take a look at your HijackThis log to see it it shows anything.
     
  3. drgrim

    drgrim Private First Class

    Hi chaslang. I did have a couple trojans which started all this. I believe I did successfully remove them as I have had no luck finding any trace of them since Avast did its wonderful thing. I have been a little dubious though due to the fact that I still cant use IE or office programs since the removal of the trojans. Hijack this log follows.


    I am still using firefox as a browser to access the net as I havent been able to do much of anything else. Am considering total reinstall of XP but would rather not as I dont have capability to back up my files at the moment.
    Cheers
    drgrim
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow the directions in the READ ME properly.

    • you are running Spybot's Teatimer and should no be
    • you installed HijackThis exactly where step 7 specifies not to install it. Please install it correctly now. Do this before continuing.
    Now also Disable Spybot's TeaTimer
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!


    You could have serious problems.


    Did you install this:

    http://www.symantec.com/avcenter/venc/data/spyware.comsurveilsys.html

    I do see it running.



    Do you know what the below process is:
    O4 - HKCU\..\Run: [CM] "C:\PROGRA~1\VCM\cm.exe" 212.150.243.4
    O4 - Startup: VCM.lnk = C:\Program Files\VCM\cm.exe

    Based on information I have, if you did not install this, it could be a serious financial risk. See:

    http://www.liutilities.com/products/wintaskspro/processlibrary/cm/
     
  5. drgrim

    drgrim Private First Class

    Ok. Sorry about that..I was obviously too tired when I did all that last time. Teatimer is disabled and I scanned again...all ok. Hijack This is now installed correctly and have attatched a new scan. (I hope I have done it right this time).
    I may have installed http://www.symantec.com/avcenter/venc/data/spyware.comsurveilsys.html
    some time ago for a previous problem but I cant be sure.
    As for these two..
    O4 - HKCU\..\Run: [CM] "C:\PROGRA~1\VCM\cm.exe" 212.150.243.4
    O4 - Startup: VCM.lnk = C:\Program Files\VCM\cm.exe
    I know nothing about them. I did find the folder VCM in program files but after looking through it I am none the wiser as to what it is. Should I delete it?? I did check add/remove programs to see if I could see it there but it isnt listed.
    Should I fix the two 04 items from hijack this ??
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Symantec Network Drivers Service ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Symantec Network Drivers Service

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.


    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {BE2ED590-CA49-46B5-8CCE-244FB2E0D1AA} - (no file)
    O4 - HKLM\..\Run: [klp] C:\WINDOWS\system32\PAL\PCS\explorer.exe
    O4 - HKCU\..\Run: [CM] "C:\PROGRA~1\VCM\cm.exe" 212.150.243.4
    O4 - Startup: VCM.lnk = C:\Program Files\VCM\cm.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/06f1c32e1589f5aa2d06/netzip/RdxIE601.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\system32\PAL <--- the whole folder
    C:\Program Files\VCM <--- the whole folder
    C:\Program Files\Common Files\Symantec Shared <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  7. drgrim

    drgrim Private First Class

    Ok...Ive gone through all that. I still cant get IE to work or any of office. Office programs are still bringing up windows installer. which I cant understand. Should I try to uninstall or reinstall office?
    HJT log attatched.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. Your other problems are not issues for this forum. But before I send your to the Software Forum, please just do the below quick scan.

    Run the below procedure and attach the newfiles.txt log.

    Using ShowNew
     
  9. drgrim

    drgrim Private First Class

    OK..here it is.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's clean too. You'll have to address your remaining issues in the Software Forum.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  11. drgrim

    drgrim Private First Class

    Thanks for all your help chaslang! I really appreciate it. Will follow the next lot of instructions and head to the software forums. Just one thing...after I did that last thing with "newfiles" I ended up with two icons on my desktop that I cant remove...they look like theyre greyed out like when somethnig is downloading but hasnt finished and when I try to delete them I get an error message saying that "cannot delete file. Cannot read from the source file or disk." Any ideas??
    Cheers
    Drgrim
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They are not from ShowNew. (unless perhaps you downloaded it to your Desktop and extracted it to your Desktop). All it does is scan various folders on your PC and create a text log for you to upload. This log merely contains a listing of new files from a bunch of folders.

    Drag the icons to the Recycle Bin. Try it in Safe Mode if necessary.
     
  13. drgrim

    drgrim Private First Class

    DUH..I didnt think of that..must be getting tired again. Thanks!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So is everything OK now?
     
  15. drgrim

    drgrim Private First Class

    That got rid of the desktop icons ok. I still cant use office or IE6. Have just posted in the software section.Cheers
    DrGrim
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good luck!
     
  17. drgrim

    drgrim Private First Class

    Thanks
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds