Massive infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by Captain Drift, Sep 10, 2010.

  1. Captain Drift

    Captain Drift Corporal

    Hello All,
    I have been asked to look at a friends PC, it is running XP SP2, and is heavily infected.

    I atempted to run through the guide on here, but then got stuck
    I removed previous Java instalations, and cannot install the latest version
    I removed Stop an scan antivirus ( thought it was malware)

    Installed Revo uninstalled and removed lot of unwanted programs
    Installed Ccleaner and removed 2GB of files and cleaner the registry

    Super Antispyware- unable to install
    Ran SAS portable- removed 30 items , rootkits, trojan ( No log)
    Ran Malware bytes- Removed 180 items ( log attached)
    Unable to unzip Root Repeal
    Unable to run Combo fix
    Unable to run MG tools - Some components are missing

    I am unable to open Notepad, or wordpad.
    TCP/IP is removed so no direct internet connection.

    I am unable to install anu AV software.
    MS Security Essentials - Missing some components.
    Avast! - Will install, but will not open
    AVG- Causes STUB.EXE to give errors
    Clamwin portable - Wont run

    Any ideas from now on please?
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I assume that you had MBAM fix all that it found, as your log indicates no action taken. Try doing the scans in safe mode.

    You need to tell us exactly what errors you get when you try to run MGTools.
     
  3. Captain Drift

    Captain Drift Corporal

    I have now managed to run all the tools.
    I had to copy across the c:\Windows\I386 folder and all the applications from the C:\windows\System32.
    Also running the Kaspersky Virus Removal Tool.

    Here is the logs
     

    Attached Files:

  4. Captain Drift

    Captain Drift Corporal

    Here is the last 2 Combofix logs..
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing anything else in your logs. I do question this:
    C:\WINDOWS\system32\lamelayo --> if you don't know what this is related to, delete it.

    We can do some additional cleaning:

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    What issues are you still having? And what did you mean about having to copy across the c:\Windows\I386 folder and all the applications from the C:\windows\System32.
     
  6. Captain Drift

    Captain Drift Corporal

    As some programs like wordpad and notepad were not working, i copied these across from a working pc, so I could use the programs.

    Issues I am still having:
    I am unable to connect wirelessly to my Sky router ( Sagem f@st 2504).
    The wired connection is not working, there are no lights on the port, Wirelessly, i have installed the Belkin F5D7051 (V1).
    With Wireless connection I can see the router, but cannot connect.

    Am I now clean from malware?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    So I can double check that you are clean.
     
  8. Captain Drift

    Captain Drift Corporal

    I have rerun MG tools and attached the file.
    thanks for the help
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am going to delete that last attachment as there is something wrong with it. If you can, just attach these three files:
    Runkeys
    Shownew
    HJT
     
  10. Captain Drift

    Captain Drift Corporal

    Here are the files,
    Everything is working okay now, just no Internet connection. I am unable to connect to my wireless router about 6 foot away.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat on your desktop.
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    I am not seeing any malware in those logs. As to your internet issues:

    You can try opening SAS / preferences / repairs and scroll down to your internet connection.

    Have you tried hard wiring to your router? Does it work that way?

    I may need to send you to the networking forum.
     
  12. Captain Drift

    Captain Drift Corporal

    Cheers Tim,
    I have run what you said and still no difference. I am unable to acquire an IP address wirelessly. Wired the PC dos not detect a cable is connected and no light on above the port. I have reset the ip [ipcnfig /all] and run all of the items in SAS repair tab.
    I am not sure what else to try?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sounds to me like your nic card is dead. If the light isn't going on when wired, you aren't going to acquire an IP address. You might consider buying a USB wireless tongle. They run around $40. You should post in the networking forum or hardware to further inquire about this issue.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  14. Captain Drift

    Captain Drift Corporal

    No Internet ISSUE RESOLVED.

    I manually assigned an IP address, rebooted ad everything is now working.
    Not sure why it cannot automatically obtain an IP address.
    Happy Days. Now to update from Sp2
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know!! Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds