Malware related problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by tomschokker, Mar 29, 2014.

  1. tomschokker

    tomschokker Private E-2

    Hi,

    after having a blue screen yesterday my laptop has various problems. I walked through the steps of the forum and in the attached files you will find the logs, except for the MG Tools, since it does not run properly.

    First: my problems as far as I observed
    - unable to download from chrome,
    - i.e. crashes when starting
    - sound of programs is not playing (system sounds are)
    - unable to install programs (like NOD32, which is refused with the note: you have probably malware on your pc).

    Then, MG Tools:
    After running it as administrator, it gives a MS-dos window and disappears after it. The map C:/MGTools is present. It does not have the file DisableUAC.org (since i disabled UAC allready).

    In the logs you will find the results of the scans. I hope you can help me.

    Thanks

    Tom
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi and welcome. :)

    Can you try again with MGTools please, ensuring that you do indeed run it as administrator, that UAC is disabled and that your antivirus is temporarily disabled.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    • cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    • nwktst<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    • analyse <-- this attempts to run HijackThis. Be sure to click the Accept button twice in the license agreement popup or it will just sit there and wait.
    Now look for the C:\MGlogs.zip file and attach it no matter what happened while doing the above.
     
  3. tomschokker

    tomschokker Private E-2

    Hi Kestrel,

    I tried again. UAC is disabled and i rebooted. I ran it as administrator and lastly, i have no anti-virus installed as far as i know.

    Therefore, the cmd-commands do not seem to work.
     
  4. tomschokker

    tomschokker Private E-2

    When starting MG tools it gives an error in the cmd-prompt, which is visible for 1 second.

    Translated it says:
    xx is not recognized as an internal or external command, program or batch file.

    examples of xx are:
    - userinfo.bat
    - nwktst.bat
    - getmsrv.bat
    - getbrset.bat
    - analyse.exe

    Last error is: C:/MGtools/temp/GRKflag.log exists. Deleting it.

    As I said, this cmd-prompt is appearing for 1 sec and automatically closing.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, do this instead then:

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  6. tomschokker

    tomschokker Private E-2

    Thanks again for your answer.
    After opening OTL as administrator is give the next error:

    Exception EOleSysError in module OTL.exe at 000584A5
    Class not registred.

    I have had this error before by installing ccleaner yesterday evening.
     
  7. tomschokker

    tomschokker Private E-2

    Update:

    I fixed it to get a MGlog file. I will upload it asap, since im not able to upload from this malware-laptop.

    The problem of MGTools was solved when i copied the MGTools.exe into the map C:/MGTools. Was this known by you?

    I will upload the .zip asap.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I believe it's best run from the root C:\ yes, but there was a change made where it could be run from any location if necessary. As long as you've got the log, that's great. :)
     
  9. tomschokker

    tomschokker Private E-2

    See attached the logs of MGTools
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it remove all that it finds.

    Are you deliberately set up to use a proxy?
     
  11. tomschokker

    tomschokker Private E-2

    All hitman pro files are removed.

    No i am not aware of the proxy. can you explain to me what it means?
     
  12. tomschokker

    tomschokker Private E-2

    Attached you will find the results of the 5 scans after removing the files in hitman pro.

    Note: i still have the problem as initially described.

    ps. about the proxy: the only proxy i am aware of is my dropbox account. is this what you meant in your last post?
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This one??

     
  14. tomschokker

    tomschokker Private E-2

    Does not sound familiar to me. Can you explain to me How this proxy influences my laptop?
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It's more than likely been put there by junk or malware. I have not completed reviewing the logs yet. I need to eat badly. So will post back soon before the night's out. (I'm based in the UK just so you know) :)
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:9421;*.local;<local>
    • O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - (no file)
    • O2 - BHO: (no name) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - (no file)
    • O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
    • O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
    • O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - (no file)
    • O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
    • O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file)
    • O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file)
    • O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
    • O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
    • O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - (no file)
    • O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - (no file)
    • O9 - Extra button: Toon of verberg HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - (no file)
    • O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - (no file)
    • O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - (no file)
    • O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - (no file)

    After clicking Fix exit HJT.




    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Program Files (x86)\GUM8E9C.tmp
    C:\Program Files (x86)\GUT8EAD.tmp
    C:\Windows\tasks\AutoKMS.job
    
    :reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{BCC4FF34-EB40-4EC7-A0C5-6F13D35F7EA5}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  17. tomschokker

    tomschokker Private E-2

    Morning,

    Step 1 is finished in analyse.exe.

    Step 2 is not working. When launching OTM.exe from desktop he gives the same error as last time at OTL.exe:

    Exception EOleSysError in module OTM.exe etc..
    Class not registred.
     
  18. tomschokker

    tomschokker Private E-2

    Goodmorning Kestrel,

    Step 1 is completed.

    Step 2 is not working. The same error as last time in OTL.exe
    Exception EOleSysError in module OTM.exe
    Class not registred.

    Do I need to go to step 3 and 4 before finishing step 2?
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Replace the OTM step with all this:

    Delete these manually:
    • C:\Program Files (x86)\GUM8E9C.tmp
    • C:\Program Files (x86)\GUT8EAD.tmp
    • C:\Windows\tasks\AutoKMS.job

    ...and for this reg key, let's do this:

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now continue on. :)
     
  20. tomschokker

    tomschokker Private E-2

    the OTM step was succesful and i had the right message with the fixme.reg action.

    Attached you will find the logs.
    I did not find any program in the Adw-log that may not be deleted.

    System is still not running well
    - internet explorer still crashes at start up
    - google chrome is not fully working (cant upload for instance the log files from my malware-laptop)
    - sound is not working
    - error at laptop start up that 2 programs are not installed correctly.
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    None of the remaining problems sound like malware problems.

    What programs specifically?
     
  22. tomschokker

    tomschokker Private E-2

    Ok, is there anything you advise me to do in order to restore these problems?
    Because the strange thing is, after having that blue screen all these problem occured in once.

    The programs are:
    "ControlDeck"
    "Solution Menu" (from my printer)
     
  23. tomschokker

    tomschokker Private E-2

    additional note:
    when i try to install the latest version of ESET NOD32, he is still refusing because of malware on the system.
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Everything else is topic for the software forum (That's where you'd resolve non malware related issues)

    But not yet....
    Can you give me the exact error message please when you try to install NOD32, or even better, take a screenshot.
     
  25. tomschokker

    tomschokker Private E-2

    it says:

    #1:
    Installation error. Try again or download and install the offline installation program.

    #2:
    Installation is not completed.

    This is possible caused by malware. In order to check the system for possible threats, we advise you to use a specialized cleaning program. etc etc.

    Would you like to use such program?

    (when i click yes, nothing happens since i cant download anything).
    __

    ok. thanks for your self so far. This is the point where i should move to the software forum?
     

    Attached Files:

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  27. tomschokker

    tomschokker Private E-2

    after a scan time of over 4 hours: here is the log.
     

    Attached Files:

  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes I said it would take a long time. So.... it found some junk and a part of a crack which you must have downloaded for MS Office. I removed a part of that as well in my fix.

    Is the machine behaving any better? Are you able to install Nod32 now?? If not, I will be referring you onto the software forum at this point. :)
     
    Last edited: Mar 30, 2014
  29. tomschokker

    tomschokker Private E-2

    Okay. not able to install nod32, same error. Would it make sense if one of your malware-colleges takes a look at it maybe?
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I can ask for a second opinion yes. But I have reviewed your logs many many times and I am not seeing any malware or junk to remove now.

    Can you tell me what other software will not install besides NOD32 please?
     
  31. tomschokker

    tomschokker Private E-2

    first malware bytes also had problems, these were the same as at OTM.exe; "class not registrerd".

    Ok, thanks for your reviews. If it is not malware in your opinion, where do you think that these problems come from?
     
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It may be that you simply have software problems instead. TimW is on his way to take a look through this thread and the logs, too see if perhaps there's something I may have missed. Hang in there.

    Just for a test: see if you can install (But NOT run) this:

    Malware Bytes Anti-Rootkit

    Let us know. Also, I want you to give Ccleaner a run. (Not the reg scanner, just the cleaner itself)

    This is also something to have a look at and run.

    Windows Installer Cleanup Utility

    Perhaps NOD32 will install after you give that a go.
     
  33. tomschokker

    tomschokker Private E-2

    thanks for letting TimW reviewing it also.

    CCleaner ran and removed somethings.
    I am able to install the anti-rootkit.
    The windows cleaner is giving an error:

    "cannot find script-engine VBSscript for scripting. C:/.../local/temp/IMX000.tmp/StartMsi.vbs"

    edit: still not able to install nod32
     
    Last edited: Mar 31, 2014
  34. tomschokker

    tomschokker Private E-2

    oh and by the way: about the removing of the microsoft crack.
    Did you intentionally remove the part which makes programs like word and excel stop working?
     
  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You probably can't install it because you already have AV software:
    McAfee Security Scan Plus
     
  36. tomschokker

    tomschokker Private E-2

    Hi TimW,

    thanks for your suggestion. I uninstalled it, rebooted my laptop and it still is not able to install nod32.

    edit: do you have any idea what caused the problems at my laptop?
     
    Last edited: Mar 31, 2014
  37. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Crap......let me look some more. Did you run CCLeaner after the uninstall?
     
  38. tomschokker

    tomschokker Private E-2

    Yes. Now i did. No difference.
     
  39. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  40. tomschokker

    tomschokker Private E-2

    Yes downloaded and installed.
     
  41. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good!!! Run a scan and let me know if it finds anything.
     
  42. tomschokker

    tomschokker Private E-2

  43. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Great!! So how are things running now?
     
  44. tomschokker

    tomschokker Private E-2

    still the same. errors at nod32. internet explorer crashes. no ability to down- or upload. 2 programs at start up of the laptop still do not work.

    any further suggestions? :p
     
  45. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If MSE is running clean, then I can only suggest that you post in the software forum for further assistance. I don't believe this was ever a malware issue.
     
  46. tomschokker

    tomschokker Private E-2

    okay, thanks again for your support!
     
  47. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Kestrel13! and TimW are correct that there do not seem to be signs of malware but I would like to try running another tool just to be safe and to cure my curiosity. ;) So please do not run the final instructions from Kestrel13! yet. Do the below scan with ComboFix.



    Now download and save a copy of combofix.exe and save it directly onto your Desktop folder.
    • Then right click on it and select Run As Administrator. Do not disturb it by clicking in the window that opens or it may stall.
    • After it finishes, it may reboot your PC. Attach the C:\combofix.txt log that it creates.
    • If after running Combofix you discover none of your programs will open up because you receive the following error:
      • Illegal operation attempted on a registry key that has been marked for deletion
    • Then you will need to reboot your computer which will normally fix this problem.
    Also run the below Window Repair tool.

    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Repair MSI (Windows Installer)
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
     
    Last edited: Apr 1, 2014
  49. tomschokker

    tomschokker Private E-2

  50. tomschokker

    tomschokker Private E-2

    @chaslang, any idea why windows_repair wont start?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds