malware probs!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by ncjharris, Apr 27, 2009.

  1. ncjharris

    ncjharris Private E-2

    Hi there!

    Having some trouble with some malware.
    Been running S&D, Ad-aware and avast, in both normal and safe mode and during bootup, all of which finds various problems, but all of which return after a reboot.

    Have tried to download and run the software and online versions of the software as in the pinned thread, but it either doesn't allow me to install or run, or crashed ie when ran.

    attached is my HT log. I hope someone can look at it and help me out - I am sure its something thats booting up when I boot up.

    Oh, i have a folder called windows2/ as i had to reload windows a while ago - thats the old folder.


    If you need any more info, please let me know.
    Thanks!!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!


    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.

    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide


    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid addtional delay in getting a response, it is strongly advise that after completing the READ & RUN ME you also read this sticky Don't Bump! It Only Hurts You!!!. Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. ncjharris

    ncjharris Private E-2

    Hello and thanks for the reply.

    As per my original post, I have tried the instructions contained within the post you listed, and either completed, or failed where the programmes would not run,
    For the purpose of prudence, I'll list out what I have done;

    TDSSserv - not in Device Manager.
    Recycle bin - emptied
    Quarantine folder - emptied
    Malware programmes - none to remove
    Sun Java - computer will not let me uninstall (JS2E Environ 5 - "unistaller can not be found"
    MSconfig - in normal mode
    CCleaner - run (in both normal and safe mode)
    Folders/Files - all types visable
    Clean up (for windows XP) - undertaken as below.
    - SAS, downloaded. Will not install/run, even when renamed - "MSIEXEC is not a valid Win32 application"
    - Anti-Malware, downloaded. Will not install completely - "run-time error '0'"
    - Combofix, downloaded to Desktop. Will not run - small status bar appears, icon appears on start bar, then both dissapear.
    - MGtools, downloaded to c:\ - will not run properly, creates MGtools folder, but displays message "windows cannot find 'getlogs.bat'"

    I can't run, and therefore post logs, for these programmes. The only programme I can run is Hijack This - log was attached to previous post.

    I run Avast as reisdent and S&D and Ad-aware on regular basis to ensure my system is clean.

    My symptons are generally;
    browser windows opening on casino websites.
    new mail messages opening in MS Outlook to be sent to "info@webcomms4u.co.uk" (sometimes others)
    problems when logging on (explorer doesn't appear to start automatically).
    several instances of SVChost running in task manager

    I am not too sure what I did before these happened to indicate where they come from. There has been no change in my surfing habits (only I use this comp) and I don't download and run attachements without first scanning.

    Your help would be appriciated!
     
  4. ncjharris

    ncjharris Private E-2

    Hi there.

    I don't mean this as a bump to my thread and I have read the sticky on it, but I would appriciate it if someone could let me know if they are looking into my issues.

    Many thanks.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The bump cost you days. :(

    If we are going to have to use HJT, you should rename it to analyse.exe.

    But lets do a few things with it now.

    Make sure you have disabled TeaTimer from running:
    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run HJT by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator) (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now see if you can run the other scans and attach the logs if you get them.
     
  6. ncjharris

    ncjharris Private E-2

    Ok, thanks.

    Not with the comp in question until tommorrow, but will carry out what you have advised then.

    One thing - is there anyway you can notate on the forums that an answer to a post is pending - my bump wasn't intentionally done to move me up the board (on the contrary, I mentioned I read the sticky on it), but I didn't know if I would be better off trying for help elsewhere if you guys were mega busy.
    Just a suggestion.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We have been working the oldest to newest threads, as our policy states. We have also been very busy on the forums of late and have been mostly working from page 11 or 12. We are just now moving down to page 7, which is where you are now.

    When we get to your thread, it is answered, so no "pending note" is required.

    Posting on multiple help boards is very much frowned upon. It becomes a waste of time for the volunteers who do this. If you wish to seek help on another board, you should let us know so we can close your thread here.
     
  8. ncjharris

    ncjharris Private E-2

    Ok, well I followed your instructions,

    fixed the HJT entries (although not all of them were there)
    and copied the text for The Avenger.

    The PC did reboot, and when it restarted everything looked fine and dandy.
    Avast kicked in with a boot scan (which is does now and then, may have been left over from a previous session) which it completed.

    But now when I try to log in, it logs me straight back out again. This happens under all users and in both safe and normal mode.

    In detail - I get the XP splash screen, the blue select account screen appears, i click on my user name and it goes through 'applying settings' etc, then it instantly says 'saving settings' and i'm back at the log in screen.

    I tried to repair windows with the XP disc, incase the above scans removed something, but i still get the same trouble. Any ideas?

    I am exclusively here.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  10. ncjharris

    ncjharris Private E-2

    Ok, cheers will do and come back to you/
     
  11. ncjharris

    ncjharris Private E-2

    Ok, tried that, to the letter, no luck - again, both in safe and normal mode.

    Don't know if it helps, but if the computer is left in the log in screen, then I get an error message 'program failed to start'.
    It varies as to which one it it, sometimes svchost or another system process, sometimes a long list of characters.
    I get the option to either cancel or ok, ok terminates the programme and it says cancel debugs, but either way, it makes no difference, I still can't log in.

    Any other ideas?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will need to use your xp cd to boot into the recovery console. Once there you will need to change directory (CD) to the C:\Windows\system32 folder. Once there, type DIR and look for userinit.exe.

    If it is not there, you need to change back to the cd drive ( assuming it is the D drive) and type this:
    expand d:\i386\userinit.ex_ c:\windows\system32\userinit.exe

    Let me know how that goes. If you get an error message, then type this:
    expand d:\i386\userinit.ex_ c:\windows\system32\
     
    Last edited: May 28, 2009
  13. ncjharris

    ncjharris Private E-2

    ok dokey.

    file was not found in windows installation.

    First command line text didn't work - error message "Unable to create file userinit.exe

    Second command line text did work - "1 file expanded".

    I exited and shutdown - shall i attempt to reboot/log in?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, indeed!
     
  15. ncjharris

    ncjharris Private E-2

    Ok, Yeah that worked!

    I had to re-register Windows with the key and when it logged on a lot of processes failed and had to be closed by windows, but i'm there.

    Ok, will now pick up where we were before couldn't log on and report back.
     
  16. ncjharris

    ncjharris Private E-2

    Ok.

    Running through the tools on the thread "Windows XP Cleaning Procedure".

    SuperAntiSpyware - run & complete. Found several hundred items - removed and rebooted.
    Malwarebytes Anti Malware - installs, but can't run - get several window "encountered problem and must close" windows.
    Combofix - starts to run, but "freeware implementation of Reg.exe" performs and illegal operation and needs to close. Also get error message about wrong OS.
    MGtools - installs and appears to run the .bat files. Some logs generated, but with different names. As attached.

    I also re-ran Hijack this - log attached.

    Thanks.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need the entire C:\MGLogs.zip as well as the SAS log.
     
  18. ncjharris

    ncjharris Private E-2

    ah, 10-4.

    please see attached.
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are using a very old version of MGTools!!! Please go back to the Read and Run First instructions and download the latest version!! Let it overwrite your previous install and then run it and attach the new log!
     
  20. ncjharris

    ncjharris Private E-2

    oh, ok redownloaded from the link on the MGTools post.
    New logs attached.
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not let it overwrite you old version (just open the runkeys or newfiles log to see the version date).....download from here:
    MGtools

    Make sure you save it to the root drive ( usually would be C:\..). Then run it.

    Prior to running it, run MBAM and attach that log as well.
     
  22. ncjharris

    ncjharris Private E-2

    ok, followed the link again, downloaded and ran it.
    no logs, so i manually ran the .bat files listed on the MGtools post.
    These are attached, though i dont think that they all ran - i have attached the .txt files that are timed as when i ran it.
    MBAM will not run - error message stating it has to close.
    Also attached the HJT log from within MGTools.

    Oh, it wont let me attach some files as I have already posted them in this thread.
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Again the MGLog was virtually empty. And I am confused as the one log you attached indicated you have both:
    c:\windows
    C:\WINDOWS2
    Can you explain that to me?

    Download The Avenger by Swandog469, and save it to your Desktop.

    The only thing I can do with the lack of logs is to have you do this:
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Extract+ avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip
     
  24. ncjharris

    ncjharris Private E-2

    Ok, thanks.

    Firstly, as in my first post, Windows2 is my current windows install - i had to reinstall windows due to a problem with it booting up before I came here for help.

    Running through your actions;

    Antivirus/Antispyware software all disabled.
    fix.bat created and run.
    HJT entries deleted.
    Avenger downloaded and extracted.
    Avenger will not run - I get the message "avenger.exe has encountered a problem and needs to close"
    MGtools will still not run and post logs. However, I attach again what it produces when I run the three .bat files manually (GetRunKey, GetUnKey and Shownew). (it won't let me attach getunkey.txt as it is already in this post)
    Also attached are two logs that save in the MGTools folder itself rather than in MGlogs.zip.

    I tried all of the above in normal and safe mode too.
     

    Attached Files:

  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    At this point, what I suggest you do is to copy all your important data and files to a cd or thumb drive, then do a complete reformat and re-installation. Running two copies of windows on the same partition is probably a major part of your problems.
     
  26. ncjharris

    ncjharris Private E-2

    to be honest, i was coming on here to say that was what i was going to do - i logged on today to do just that and have encountered the same unable to log in error when windows starts. I have a spare hd somewhere and i'll run this one as a slave and transfer the files across, reformat it, reinstall windows then make it a master and transfer the files back across.

    thanks for your help anyway and patience at the begining.
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. Good luck. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds