Malware not allowing programs to run - Suggestions?

Discussion in 'Malware Help (A Specialist Will Reply)' started by gpet, Jun 22, 2008.

  1. gpet

    gpet Private E-2

    The Windows XP Cleaning thread is awesome and has helped me greatly in the past but the new malware that my son "found" will not allow me to run any programs and doesn't load my desktop. I would appreciate any help that can be offered.

    The fake Windows Security Center warning is present and it even runs while I am in Safe Mode so the only thing I have been able to do is run CC Cleaner and get a HijackThis log. I appreciate how you feel about the HijckThis logs so I won't attach it unless you ask. I've identified some culprits such as TCNTAXDN.exe and iftuyszv.exe

    Also, I cannot open any type of explorer windows like My Computer or Control Panel unless I'm in Safe Mode. I'm working off my laptop now which is a different computer. Any next step?
     
  2. abri

    abri MajorGeek

    Hi gpet,
    Welcome to Major Geeks!


    Can you get MGTools to install and run? Will combofix run? If not, please use the Manage Attachments button down below the reply window to attach the HJT log you got.

    Thanks.
    abri
     
  3. gpet

    gpet Private E-2

    I tried to copy them from flash drive to infected computer while it was in safe mode but can't. I'll reboot into safe mode with networking and try to download and run them that way and get back to you.
     
  4. gpet

    gpet Private E-2

    It seemed like some of the malware was blocking the programs (MGTools & Combo) but I was able to run Malwarebytes Anti-Malware so here's where I'm at: It removed enough crap to allow me to copy and run MGtools. I now have a log for MBAM and MGTools (which is in a zip file).

    I don't want to restart into normal mode yet unless you say so. Please let me know what you would like me to do next and what logs you'd like to see. Oh, and Vundo has been confirmed.
     
  5. abri

    abri MajorGeek

    Hi gpet,

    You didn't attach your logs. Please see if you can get CCleaner installed and run it at the default setting in Safe Mode. Then see if you can get Combofix downloaded and installed. If you run it in Safe Mode first, please be sure to attach the log here before you continue. For most of the scans, if you rerun them, they will overwrite the previous logs and we lose the information if you don't attach it to us before you run the scan again. Let's see where you get with that.

    Attach the MGlogs.zip (when you use the Manage Attachments button down below the reply box you'll find the MGlogs.zip directly under C:\ ) and attach the MalwareBytes log.

    Then try CCleaner and Combofix and attach the Combofix log if you're able to run it.

    Thanks.
    abri
     
  6. gpet

    gpet Private E-2

    OK, I was able to run all programs and get logs. Because I started out of order with Anti-malware I ran some twice but renamed the logs so you can see them both if needed. I'll attach the Combo logs here and the Anti Malware & MGtools logs to my next reply. Sorry for the delay but since its my desktop I can't bring it to work and it seems that is the only place I have been lately.

    My most recent combofix log is too big to attach. It is 337kb!!!????!!! I have no clue what the heck is in there making it so big. I broke it into two logs (part 1 and part 2).
     

    Attached Files:

  7. gpet

    gpet Private E-2

    Here are the other logs, thanks for all your help Abri (and for not closing this thread)! Like my other reply the logs with 7.3 in the title were the ones done today.

    -Greg.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please put your system into Normal Startup mode with MSconfig as requested in step 1 of the READ & RUN ME. Also please run Malwarebytes again and make sure you fix/quarantine everything it finds. Your last log shows that you took no action. Save a new log.

    Also please run SUPERAntiSpyware and save a log.



    Now run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKCU\..\Run: [Zmcftnf] "C:\Program Files\Common Files\s?stem32\?hkdsk.exe"
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O23 - Service: Plug and Play (RPC) (PlugPlayRPC) - Unknown owner - C:\WINDOWS\portsv.exe (file missing)

    After clicking Fix, exit HJT.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • new Malwarebytes log
    • SUPERAntiSpyware log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. gpet

    gpet Private E-2

    Logs are attached. Everything seems to be okay (except for needing to uninstall a bunch of old programs and/or changing the default settings of a lot of programs so they don't automatically load at startup now that MSconfig is in normal mode.

    There is an update for Java, should I allow that to install? Also I noticed that Java is not enabled for Firefox. Should I enable it?

    Thanks again, and again, and again. :-D

    -Greg.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below steps will take care of a bunch of these fore you. ;)

    That was in step 1 of the READ & RUN ME but the below will also address this.

    Yes.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment Standard Edition v1.3.1_02
    Java 2 Runtime Environment, SE v1.4.2_01
    Viewpoint Media Player (Remove Only) <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
    O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. gpet

    gpet Private E-2

    Everything seems to be running fine (although that is what I thought last time).

    Logs are attached as well as more thanks!!!

    -Greg.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download and run this:Dr.Web CureIT

    Let me know if it finds anything. Then do the below:


    Start by downloading a tool we will need - Pocket KillBox


    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.


    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\temp\bca4e2da.$$$
    C:\WINDOWS\temp\ed47fa.$

    C:\WINDOWS\temp\fa56d7ec.$$$
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. gpet

    gpet Private E-2

    Temp files were gone before pasting from clipboard. Everything seems to be good, let me know.

    -Greg.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did Dr Web CurIT find anything?


    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds