Malware Problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by kvnpham, Jan 4, 2010.

  1. kvnpham

    kvnpham Private E-2

    OK, so basically a few days ago I began to receive bubble notifications that I had a virus and along with that my Windows Security Center kept giving me warnings and when I opened it it said everything was turned off...

    A bit before that Symantec popped up and said I had something but I left the computer because I was doing something else (thinking that it would just be some small thing that Symantec would quarantine or delete by itself) so I closed the window thinking I'd deal with it later but the next time I tried opening Symantec it wouldnt work..

    I'm not the only one who uses my computer (but I use it for the majority of the time) and I do recall before this happening my mother wanted to use my computer to look up a recipe for something.. That and sometimes my friends use it too while I'm at the telly playing games or watching a movie.. But generally they just stick to checking their Facebook for a couplea minutes.

    Also, I noticed in my Start menu that another Symantec program had installed itself without my knowing (so I just assumed it wasn't bad or anything) but later I googled it and it said it came with like Google Packs or something... So I uninstalled it. Randomly Google installer stops working and I have no clue why. Same with internet explorer

    Anyways, I had realized that I prob had a virus, spyware or malware or something so I began googling Fake Windows Security Center to find a fix (because everytime I try to open Symantec/Windows Defender it doesn't respond).. I came across this forum and used this thread: http://forums.majorgeeks.com/showthread.php?t=205284
    to try and fix it.. I ran AVPFind.bat to start and I have attached that log.. Then I did the superantispyware online scan and that removed some stuff and the Fake Windows Security Center no longer appears.. Also, while I was searching for stuff, occasionally it redirected me to a different page after I clicked on a search result and it happened more than enough for me to realize it wasn't the site redirecting me.

    Before I wrote this though I noticed occasionally a balloon popup that says my computer is infected with a virus and when I click it it gives me a help page that says I should try and remove a nonexistant thing from my uninstall/remove programs and it looks like an official windows thing and has a yes or no feedback option as to if it helped.. I just closed it and it only appeared a few more times (not during the writing of this post though)

    Anyways... most of that is just the background info but the basic problem for me now is this... Symantec/Windows Defender won't work. I have no clue where my real Windows Security Center is. I feel like my internet occasionally just slows down a lot (I have Fios), especially when I try and search Google (although it doesn't slow down all the time).. like basically I type in something to search press enter and then for some reason at the bottom of the browser it says stopped and I have to press enter a few more times or just wait a bit. The random google installer/internet explorer stops working occur (I use Firefox btw). That random popup that says I have malware (although I haven't seen it yet)

    I went through the basic Vista cleaning process thing and Superanti Spyware doesn't work, Malwarebytes doesn't work, combofix doesn't work.. (they all just don't respond when I click the program) Root Repeal is doing its thing right now but I'm posting this now because I have to go to sleep and it's more than likely that I'll have that log tomorrow. I've yet to use MGTools.

    Again the log attached is from APVFind.bat and is from before I ran the online scan..

    Also, irrelevant to the malware problem but for quite a long time my Windows update keeps failing Update for Windows Vista (KB973917) despite all the times I've tried.. There's three other important updates that I'll do once I rid myself of malware but they weren't checked to begin with which is why I didn't bother manually updating them... Two of them are Office Genuine Notifications and the third one is Update for Windows Vista (KB968389)

    Alright that's the gist of my problems, sorry for the wall of text just ask me any questions so I can clarify. I may have left out other symptoms of malware that I have forgotten but I'll post/update if I come across any others.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    At a minimum, we need the MGtools log to even attempt to get started.

    Also a question: Have you tried running any of the scanners in safe boot mode and what exactly happens?
     
  3. kvnpham

    kvnpham Private E-2

    OK, I've gotten the logs I could, they are attached..

    But a basic synopsis of my problems now are:
    Google searches ocasionally redirect to other search engines
    Google Installer randomly stops working
    Internet Explorer randomly stops working (I use Firefox)
    Symantec/Windows Defender close unexpectedly when I try and open it
    Some other symptoms that are minor but do cause an annoyance

    Attached are the MGlogs.zip and RootRepeal.txt (I left RootRepeal on overnight and it was still going... so I just stopped and made a log with whatever it got, it slowed down my computer waay to much and I needed it)

    Combofix, Malware Bytes and SuperAnti Spyware all close unexpectedly when run.

    Thanks for the help ahead of time!

    edit: safe boot mode?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's make the first round fix. There will be more after this but we need to do this step to uncover some other hidden files.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Windows\Temp
    C:\Users\Kevin\AppData\Local\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. kvnpham

    kvnpham Private E-2

    Everything seems to be working perfectly now! Thanks a lot!! Symantec popped up on startup and quarantined 8 items and cleaned 4 items. Windows Defender is working.

    I don't seem to have a Windows Security Center though, even after going to the control panel and clicking on it. When deleting the files in AppData/Local/Temp one file didn't delete because it was in use by another program... FXSAPIDDebugLogFile.txt even though it was last modified 8/26/08

    Files are attached.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually it did not find anything except what we had already removed and quarantined. Symantec was unable to find and remove the infection while it was active. Once we actually deactivated the infection, it just detected the files and registry entries we already removed which is quite useless.


    Not sure what you mean since this is a feature designed into Windows. Nothing we did in the last fix would change this. If Security Center was there before the last fix, it should still be there. It is possible that Symantec is the cause of any problems around this and it may need to be uninstalled followed by a reboot to see what happens. HOWEVER, we have a little more to do first so let's see what happens after doing the below. I want to be sure a few bad files are removed since they now showed in your logs after we deactivated the heart of the infection.

    I also want to see if we can get ComboFix to run now.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jan 11, 2010
  7. kvnpham

    kvnpham Private E-2

    The Security Center wasn't actually there... Part of the problem was that there was a fake Security Center that said everything was off and I needed to fix it but I actually couldn't.. That problem got fixed when I did the SuperAntiSpyware online scan thing but the actual Security Center doesn't show..

    Things are still working smoothly though aside from that... When I ran ComboFix it worked but I wasn't actually at my computer when it was running and the second time I came back to check it was shutting down and it stayed like that for awhile so I manually turned off my computer and turned it back on, but it seemed to work anyways and produced a log..

    Logs are attached.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you familar with running the Windows Registry Editor? I want to look at the HKEY_CURRENT_USER\Control Panel\don't load key which probably has an entry to tell it not to load the Security Center icon.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I decided to make it easier for you. :)

    Download and save the below to your C:\MGtools folder! ( It must be saved there to be sure it works properly.) Then double click on it to run it.

    CPidl.bat

    After running it, a new log should be added to the C:\MGlogs.zip file. Please attach the MGlogs.zip again. This will allow me to create a fix for the missing Security Center (that is if it shows up as disabled).
     
  10. kvnpham

    kvnpham Private E-2

    Alright, I ran it from that location... Zip is attached.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well it is not a problem with the registry having it disabled from loading. Let's see if the Control Panel file exists. Look for the below file:

    C:\Windows\system32\wscui.cpl

    Does it exist?
     
  12. kvnpham

    kvnpham Private E-2

    Yes it does.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Double click on it and tell me what happens.
     
  14. kvnpham

    kvnpham Private E-2

    Nothing
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Right click on the file and select Properties. Tell me the file Size: in bytes not KB.

    Also select the Version tab and tell me what File Version you see.

    Also when you right click on the file, do you see an option that says Open with Control Panel


    Also do the below.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Security Center
    • then right click the entry, select Properties
    • What does it show for Start-up Type
    • And what does it show for Service status:
     
    Last edited: Jan 20, 2010
  16. kvnpham

    kvnpham Private E-2

    1,689,600 and 1,691,648 on disk.. Yes I do see that option, it's in bold.

    I couldn't find Security Center on services.msc
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that means the service may have been deleted. However first I want to check to see if a required DLL is missing or not. I think it is. Look for the below file:

    C:\Windows\system32\wscsvc.dll


    Did you find it? If not, download the below and save it into your C:\Windows\system32 folder and then reboot and see if there is any change.

    WSCSVC

    Also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
     
  18. kvnpham

    kvnpham Private E-2

    Doesn't seem like there's any change.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then it would seem the service itself has been completely deleted. Not sure if we can fix this but let's give it a try.


    Ddownload the below and save it into your C:\MGtools folder

    FixWSC

    Now run the C:\MGtools\fixwsc.bat file by right clicking on it and select Run As Administrator. Let me know if you get an error messages and tell me exactly what they say. If you don't get an obvious errors, reboot and see if there is any change.
     
  20. kvnpham

    kvnpham Private E-2

    There weren't any errors but I don't notice any change either after the reboot.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not much left to try other than the below:
    • uninstall 100% of Symantec, reboot and then see what happens after reboot
    • Use System Restore to try to return to a point in time before the problems with Windows Security Center occurred.
    • Reinstall
     
  22. kvnpham

    kvnpham Private E-2

    Eh, I don't mind that much.. Everything else seems to work just fine so it's all good, thanks for your help!
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds