Malware removal: help with Step 1

Discussion in 'Malware Help (A Specialist Will Reply)' started by jizaref1, Dec 26, 2009.

  1. jizaref1

    jizaref1 Private First Class

    I have downloaded all the necessary tools to run, and have read through all FAQ and READ ME.

    My understanding is that all of these tools should be run in "Normal" startup mode. The problem is that Normal startup mode cripples my computer in 2 critical ways:

    1. Speed of a turtle so that almost nothing can be achieved before system freezes. Sometimes I cannot even fully start up -- there is something hanging up at the end of my startup sequence.
    2. My internet connection will often go down -- either the wireless receive won't pick up the functioning network, software interefernce, or something else.

    Is it useful at all to run all of these utilities in Selective or Diagnostic mode and post those logs? If not, can you help me get up and running in Normal so that I can run the rest of these tools?

    Let me know whatever information you need to get started. I will be patient and wait my turn and not bump my post. But I will try to get this working in Normal while I wait for your response.

    Thanks in advance,
    Jeff
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You can run in safe boot mode if that is necessary. All the instructions are saying is that we prefer normal boot mode, but they do say that safe mode is okay if you cannot boot in normal mode which somewhat fits your problem even though you can bootup. ;)
     
  3. jizaref1

    jizaref1 Private First Class

    I have restarted in Normal mode and Super AntiSpyware seems to be running for now. In Normal mode the program seemed to hang-up mid way through the scan without finishing. Even when I turned off Kernel searching as suggested, same hang up problem. Is it possible to tell if this is malware, a registry issue, or something else?

    I can try to run each of these in Safe. And if needed, I can run through the procedure stepwise again in Normal if you ask me to.

    Thanks again,
    Jeff
     
  4. jizaref1

    jizaref1 Private First Class

    I know this might delay an answer to my original post or assistance, but I need to ask another question before I proceed. I am patient and will wait.

    I suspect a lot of problem with startup and shutdown and slow system performance can also be due to registry issues. I have uninstalled software recently in hope of speeding up system performance (e.g. removing Norton and other large utilities). Also new things have been installed in hopes of fixing the issues.

    My question is this: would it be better to run a Registry cleaning utility such as Registry Easy (http://www.download-registry-cleaners.com/reviews-and-comparison) before proceeding with these Malware cleaning steps?

    If I can fix the registry, maybe I can startup in Normal mode and give you more of the information you need?

    Thanks
    Jeff
     
  5. jizaref1

    jizaref1 Private First Class

    Logs posted, see attached.
    Everything run in Safe Mode as Normal startup stalls at desktop.
    CCleaner run on Registry before sequence.

    MBAM stalled about 2/3 through, didn't crash, just stopped for 3 hrs and did not change files so I had to restart.

    Here are log files for the other successful runs.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should only be doing what we asked you to do and this we specifically told you not to do. Running registry cleaners is not recommended and while infected can even be dangerous.


    You have a Master Boot Record infection. We will need to boot to the Recovery Console ( you installed it while you installed ComboFix) to remove this infection.

    Now boot to the Recovery Console and run the fixmbrto clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    After running the fixmbr command and boot back to normal mode, continue with the below.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. jizaref1

    jizaref1 Private First Class

    I know the Recovery Console is installed as I see it as a selection option when starting up in Safe Mode.

    I have read the Microsoft instructions and select Recovery Console, but I get a blue screen warning me that an error has been found and that I need to check disc for errors and restart.

    Thanks again
    Jeff
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then try running the below tool from Prevx

    Prevx 3.0 use the button that says Download Prevx 3.0

    After running it, continue with my previous instructions from the point where it says "Now run Ccleaner...."
     
  9. jizaref1

    jizaref1 Private First Class

    I was able to locate my original Windows XP system CD in a box in the attic.

    I then succesfully ran the Recovery Console from the disc and fixmbr was able to be used, so I did not need Prevx 3.0.

    Things are now working much better! :)

    I was able to start up and run in Normal mode.
    Internet connection is up and running.
    System speed is notably improved.

    I have posted my MGtools log here and will wait for the next step.

    Thanks so much so far,
    Jeff
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First, please run Startup Manager and undo whatever you did with it. It should not be used to control startups and was just added to the do not use list here: Dealing with Startup Process for the same reason as other tools. It uses MSconfig keys and makes them look like orphaned keys which need to be deleted. You have lots of things apparently trapped in MConfig keys including things from software that does not even appear to be installed anymore (like Symantec)

    You also have multiple antivirus programs running (Authentium - from your ISP - , ESET NOD32 and left overs from Symantec). Since ESET does not appear to be properly installed anymore nor Symantec, we will remove there leftovers.

    You also have PestPatrol AntiSpyware (from your ISP) and CounterSpy running which also not a good idea. Your PC must be running rather slowly with all these duplicated security programs installed.

    Now please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)

    If ESET NOD32 appears in Add/Remove programs uninstall it since the below instructions are going to forcefully remove it anyway.

    Also uninstall CounterSpy to avoid the conflicts with PestPatrol that you have from your Verizon Security Suite.

    Now goto Control Panel -> User Accounts, and delete the Help Assistant account that came from the MBR infection.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.
    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Administrator\Local Settings\TEMP
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. jizaref1

    jizaref1 Private First Class

    chaslang,

    I tried running every step of the instructions as carefully as I could, but had a few minor difficulties which I will describe. Overall system is running well enough, with reasonable startup and shutdown speed, program switching, and internet access.

    I clicked back ON as many items as possible. System is still starting up fine in Normal mode. But there were a few (about 4) items that I could not click ON as I get an error message: “Couldn’t enable/disable selected item. Couldn’t open subkey.” Let me know if this matters and if you need the names of these few entries.

    I did not realize my ISP (Verizon FIOS) had installed Authentium and PestPatrol and that they were running. After these steps are complete, please verify that I have properly uninstalled these conflicting systems. There is an item called “Verizon PC Security Checkup” listed in Add/Remove programs which cannot be removed by clicking “Remove.” Is there any other way to forcibly remove this software? Pest Patrol and Authentium are not listed individually.

    ESET NOD32 was installed as trial antivirus/firewall after I uninstalled Norton. With all the bugs in my system, apparently both the install and uninstall of NOD did not work properly. I have all functions turned off, but I after I ran Combofix I still see the ESET Smart Security icon in my system tray and ekrn.exe in my Task Manager and I cannot force quit it. I want to remove all of this and start from scratch.

    The Help Assistant account was not listed in my User Accounts Control Panel.

    I ran Combofix and MGTools as directed.

    Logs are attached.


    Thanks,
    Jeff
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We will remove the Verizon stuff and ESET now to cleanup the effects of having all of these conflicting security programs installed. We will also remove some other unnecessary items (non-malware) that are wasting resource.

    Did you run the Norton Removal Tool as requested last time? If not, make sure you run it right now before continuing. If you did run it last time then just continue.

    I suggest that you uninstall the below two registry cleaner tools that you don't need and should avoid using unless instructed by an expert to do something specific with tools like this:
    Eusing Free Registry Cleaner
    RegCure

    Now also uninstall Startup Manager which you really should not use as stated in the READ & RUN ME.

    Now click Start, Run and copy and paste the below into the Run box and click OK.

    C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\8\INTEL3~1\IDriver.exe /M{40ACEAF4-1EB2-45FC-90C3-6810700C0595}

    If this runs, it should uninstall the Verizon PC Security Checkup software.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
    O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.verizon.net/checkmypc/includes/MotivePreQual.cab

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. jizaref1

    jizaref1 Private First Class



    chaslang,

    I see a few of the items that you have removed, thanks. Since a lot of these things had wasted system resource, how do I know if I can click remove on many other things in Add/Remove that I have no clue regarding their function or necessity? For example, things like 3ivx MPEG-4 5.0.3, ffdshow, DirectShow Dump, and Learn 2 Player. Is there an easy way to identify if something is malware vs bloatware vs unnecessary?


    This did not seem to be successful. I did as directed and the InstallShield uninstaller window opened. About 10% into the progress bar I heard a small click from the PC tower and uninstall stopped. No error message, no OK button, simply back to my desktop. If I try clicking Remove under the Add/Remove Control panel for the Verizon software, I get the same uninstall exit.


    Combo ran without a problem. But as it was writing the log, there was a blue screen system crash. The PC was running without any other action or mouse clicks, it simply went blue, with a "DRIVER_IRQL" error message before I needed to manually restart. So the program ran but I have no new log to attach. Would you like me to run it again or something else?



    System seems to work well with rapid Startup and Shutdown, and fast program switching without stalling.

    I have a few questions which might pertain to what you have done so far. If you find these questions are more pertinent to the software forum, please let me know and I can ask there when we are done with this debugging. My questions are these:

    1. You had previously asked me to remove the Help Assistant from my Users Control Panel, which you said was a remnant of my MBR infection. This was not there for removal when I checked. Is it gone or do I need to so something else?

    2. I am now running the system "bare" without antivirus or antispyware continuously running. Am I able to yet install new software? Norton seemed like a system hog which is why I happily just removed ALL of it. I was thinking either NOD or AVG -- is one better than the other according to MG?

    3. There are still some items in Add/Remove that I still cannot get rid of, including Google Earth, Google Gears. I click "Remove" and it says I need to use CD-Rom or removable disc, which obviously I don't have because it was probably a download a while ago.

    4. There is other software I would like to install, so will you let me know when it is safe to do so? These include Firefox (so I can stop using vulnerable Internet Explorer), Quicktime Pro, and my new network HP Printer software.

    5. I was previously unable to successfully install Windows updates higher than XP SP2. Is it safe to try adding SP3 or SP4 now? Would you recommend I do so?


    MGtools.zip log attached.
    Combofix log not attached for reasons detailed above.


    Thanks again for your assistance.
    Jeff
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If it was malware, we would have told you to uninstall it. Eveything else is something you or someone else installed and may use. You need to check these out yourself. Google can helo. ;) Otherwise post questions in the Software Forum for non-malware topics.

    No! It's gone now.

    Protection is covered in final instructions. If you are going to purchase an antivirus then I would suggest it rather than AVG since AVG has become too much of a resource hog for my liking.

    Post in the Software Forum for non-malware items. You may need to reinstall and then uninstall.

    Since we are finished you can do what you want after completing final instructions below. Note: While FireFox is still a useful browser to have, it actually has more vulnerabilities then current versions of Internet Explorer. The old statements like "use FireFox because it is safer" or "it will protect you" are not true anymore since malware attacks it since it is so popular now. See the below:

    http://news.cnet.com/8301-27080_3-10417785-245.html?tag=rtcol;pop

    Part of final instructions. There is no SP4 .....yet.


    Your logs are clean but you should delete the below left over folders:
    C:\Documents and Settings\Jeffrey and Alisa\Application Data\ESET
    C:\Documents and Settings\All Users\Application Data\RegCure
    C:\Program Files\Eusing Free Registry Cleaner


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds