Malware Problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Act, May 20, 2011.

  1. Act

    Act Private E-2

    I followed the instructions at http://forums.majorgeeks.com/showthread.php?t=139313 but I wasn't able to run MGtools; it created the folder but didn't run or anything.

    The problem I was having was that my Windows XP system was infected with some kind of malware that affected the administrator accounts and made the desktop and pretty much anything in C:/ Documents and Settings access denied. I also cannot open all programs in those users and when I boot in safe mode, the keyboard only types numbers when I press the letter keys. After running the scans, combofix seems to have dissappeared together with its logs as well as root repeal. Should I go ahead and log on to the user and hope it was fixed?
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.
    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
     
  3. Act

    Act Private E-2

    Alright it worked. Here's the upload for MGtools. Do I have to run combofix and Rootrepeal again? because their logs disappeared from my system.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, try to run Combofix again. Also, go to C:\MGTools\analyse.exe and run it. This is really HJT, so attach the log. Then go to C:\MGTools\fixATTR.bat and run it.

    Then tell me what issues are still happening. You really should not have allowed the "Children's" account to be an Admin, account.
     
  5. Act

    Act Private E-2

    When I booted up my comp and logged on to my user (Children), a text file called "desktop.ini" automatically pops up and states:
    =======================================================
    Desktop.ini
    [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787
    =======================================================
    Also there's a strange "Thumbs.db" icon on the desktop.

    In regards to issues that are still happening, all my Admin accounts excluding "Children" are still out of commission. When I log onto them I get the message:
    ==================================================
    C:\Documents and Settings\[Username]\Desktop is not accessible.
    Access is denied.
    ==================================================
    and then the background (which never shows up in the first place), is replaced with a blank background that only has "My Documents" (not accessible), "My Computer" and the "Recycle Bin." I cannot open "All Programs in the Start menu and this problem seems to affect all the Admin accounts except "Children". I appreciate your committal to this thread. Attached are the logs you requested.

    p.s. The only thing special about the "Children" account is that, it was originally created for the children, but that changed after they got their own computer and I renamed it to my name and now use it for administrative purposes. The login screen states the account as my name but everywhere else on the computer, it is still recognized as "Children".
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Both desktop.ini and thumbs.db are showing because we have hidden files showing. It's normal.

    I want you to try running a new tool on this account. Go HERE and download the file RogueKiller to your desktop.
    * Close all the running processes
    * Under Vista/Seven, right click -> Run as Administrator
    * Otherwise just double-click on RogueKiller.exe
    * When prompted, type 1 (SCAN) and then Enter
    * A report should open, attach the log to your next reply. (RKreport could also be found next to the executable)
    * If RogueKiller has been blocked, do not hesitate to try a few times more. If it really won't run, rename it to winlogon.exe (or winlogon.com) and try again.
    * Attach the log.

    You need to uninstall one of these:
    Norton
    MSE
     
  7. Act

    Act Private E-2

    I didn't know I had MSE still installed. I reinstalled it and then uninstalled it again, so hopefully it should be off the system now. Here's the log you requested. Also included are the files in RK_Quarantine.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run this:
    TDSSkiller - How to run

    Then go to C:\MGTools\fixAttr.bat and run it.

    Then go to C:\MGTools\FixFA.bat and run it.

    Is the main Administrator account also affected? No desktop or access to the start menu?
     
  9. Act

    Act Private E-2

    Yes, the main Administrator account is also affected. Also sometimes for a brief second after I log on, I can only type numbers even when I hit the letter keys the numbers alternate from 0-9 even if I hit the same letter, the number changes. Here are the logs you requested. Fixattr.txt was too large for the forum requirements so I put it in a zip file.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please click Start, All Program, Accessories and you will see ( among other things ) a Command Prompt entry.
    • Right click the Command Prompt entry and select Run As Administrator.
      • It is critical that you run it this way.
    • If you do this properly, a command prompt window will open with a title of Administrator Command Prompt.
    • Enter the below commands ( in bold black ) at the command prompt each followed by the enter key. Try each command!!!! The bold black are commands. The purple/brown is merely informational.
    cd \ <-- this changes to the root folder and the prompt should change to C:\>
    attrib -h -s * /S /D <-- this will try to remove the hidden and system attributes on all files and folder. Note there are spaces before -h, before -s, before * and before each /
    attrib -h -s *.* /S /D <-- a redundant command match possibly other file names and folders due to using *.*

    Let me know if this helps.

    Please download and save the below to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe


    Now run it. Did that help?
     
  11. Act

    Act Private E-2

    Everything was 'Access Denied' for both attrib searches. The admin accounts are still out of commission, and my keyboard seems to be affected now, I can only type numbers even when I hit the letter keys the numbers alternate from 0-9 even if I hit the same letter, the number changes. I had to type this up with on-screen keyboard,
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try doing this:

    click start, run, type cmd press enter. Now enter this command

    attrib -s -h -r c:/*.* /s /d

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2


    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :folderfind
      smtmp*
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds