Masters!!! your loyal follower needs your help again!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by griggi63, May 24, 2008.

  1. griggi63

    griggi63 Private First Class

    Good afternoon Honorable Gentlemen. I need your help again. I am trying repair a friends computer that was apparently hit by some sort of virus/malware through an email attachment. She states that it came from a friendly source and trusted it and the "blamo" flashing blue screen...scads of porn popups she panicked and just pulled the plug. Her husband tried to fire it back up and error after error no connectivity...etc etc.
    Well my first step as you instruct is to go to add/remove programs....only there seems to be no way to get there now. A lot of control items have dissappeared. Rather than fly blind, I figured i would stop at this point and ask your advice before i went any further.....also i did notice multiple spyware programs and seems to have "norton.....(yuk) antivirus installed although not sure which version. Will patiently await further instructions, and thank you in advance for any and all help!!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you boot into safe mode?

    Can you download the tools to a diff. computer and transfer to the infected one with a thumb drive?

    ComboFix does not require an install, so I would try that first.

    I assume you have not been able to do a system restore.?
     
  3. griggi63

    griggi63 Private First Class

    Yes, can boot into safe mode. and i do have a thumbdrive to put the downloads on...i am on my pc, i do not have the other pc on the net at the moment. I did try combofix, but not sure if working or not, a little rectangular bar opened and filled with green squares, but there was no confirmation of anything so i do not know the result. Did system restore to 30 days prior, seemed to slow down the errors but are still there. the system resources in the task manager shows 100% usage and fluctates up and down, but not very far down, and if you go into running processes there are items usage rates go up and down and seems like processes flash on and off. I have never seen anything like this before....so i am very unsure what to do first.

    Also, i am in administrator under safe mode, but access is denied to installing and running ccleaner and add/remove programs...something about a rundll error.

    PS....doesn't seem to like safemode...screen keeps going black and removing all icons and toolbars, then have to reboot.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download and run the MGTools.exe ....it should be on the root drive (C:\MGTools ...) but if you can get it to run from the desktop...do so for now and attach the C:|MGLogs.zip
     
  5. griggi63

    griggi63 Private First Class

    i do not know where to download MGTools from....

    Scratch that....i found it, you have changed some things around since the last time i was here, please excuse my error....if possible i will ad it to this through edit.
     
  6. griggi63

    griggi63 Private First Class

    ok, in safe mode....from the desktop i get this....

    16 bit ms-dos-subsystem(blue bar)
    C:\windows\system32\cmd.exe
    C:\windows\system32\autoexec.nt. the system file is not suitable for running ms-dos and microsoft windows applications. Choose close to terminate the application.
    you can choose "close" or "ignore"...choosing ignore does nothing keeps popping up...choosing close will not close it says" the process cannot access the file because it is being used by another process
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is explained in the Using Mgtools link. Please follow the instructions given in the link.
     
  8. griggi63

    griggi63 Private First Class

    CHASLANG!!! nice to hear from you again....Ok i think i was a little impatient. it ran its course and this is what i have obtained.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please refer to the fix if you have errors running MGLogs, that Chas referred you to, pertaining to the warning you got...your log was empty. Also when you run the C:\MGtools\GetLogs.bat file after doing the fix, make sure you accept the HJT license....
     
  10. griggi63

    griggi63 Private First Class

    i had ran the fix right after i reread the mgtools instuctions and reran it, but i had already posted the first file and didnt want to jump my own thread (and also was not sure that the info was not on the original file. my apologies. here is the new file....
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you letting it run until it is completely finished?

    It is missing the four logs that I need....the newfiles.txt, runkeys.txt, and hijackthis.log, and procdll.txt.

    What about the MalwareBytes log....will that also not run? What about SUPERAntiSpyware

    Did you download ComboFIx and try to run it?
     
    Last edited by a moderator: May 24, 2008
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The fix for the 16 bit MS-DOS Subsystem error has to be saved into the system32 folder which is the default. Is that where you save it when you ran one of the below two:
     
  13. griggi63

    griggi63 Private First Class

    only ran the xphomefix, and i believe we did just put it in the wrong place. Right now we have started over from basically step 1 of README to see where we went wrong , some things that weren't working before are now and able to run. i apologize, i somehow got lost in the instructions for the xpfix. We have just basically started from the beginning and i am writing down step by step what he have done with results of what can run and not run and the results. Sorry about all the confusion, i have never seen a system as bad as this, and with the pc just shutting down or locking up during some of the procedures it is making it very difficult to keep track....hence the hand writtin log i am making now that i will post along with the logs that i am able to get.
     
  14. griggi63

    griggi63 Private First Class

    Ok, to this point this is what we have done after the mishmosh.

    1. Ran ccleaner
    2. at this point there is no ad/remove or control panel
    3. Did not do SunJava as system is not on net
    4. MSconfig was done
    5. Norton was previously uninstalled
    6. Since only being able to run in safe mode could not run SuperAntispyware.
    7. Spybot-updated manually and ran.
    8. Malwarebytes ran...log will be included...after reboot system managed to stay in normal mode Control panel is back, checked ad/remove for unknowns none present. At this reboot...AVsystemcare ws attempting to install, went in task manager and stopped it. Also at this time Spybot refired on its own so we let it run its course and it found a few more items and fixed them. Since normal startup was obtained, took a step backwards and ran SuperAntispyware...log will be included.
    9. Combofix, ran....but would not allow the special instruction("%userprofile%\desktop\cf.exe" /killall) to start process...had renamed icon as instructed and just double clicked desktop icon and it fired....whether this will still give results needed i don't know but will attach log that it provided.

    At this point we are running the MGtools....since can only post 3 items i figured to give you this info while we run the MGtools...
     

    Attached Files:

  15. griggi63

    griggi63 Private First Class

    Ok MGtools ran ...no errors this time....only discrepancy was that the window did not close itself...log attached.

    At this time we have not put it in online as we are waiting for instructions for anything else that needs done....am looking for a way to remove the AVsystemcare and that will be the only thing done until we hear from you.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes it is quite a mess...you ( they ) are running without anti-virus software and without either SP2 or SP3.

    Please use add/remove programs to uninstall:
    Java 2 Runtime Environment, SE v1.4.2_03
    Viewpoint Manager (Remove Only)"
    Viewpoint Media Player

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it(Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.
    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now download and install:
    Java Runtime 6
    An anti-virus program

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  17. griggi63

    griggi63 Private First Class

    a couple items you wanted me to fix in analyse were not there, but i checked the rest that you mentioned. I copied the fixme and put it on the desktop but when i double click it, it will ask if i'm sure i want to ad it, i click yes it gives me an error of cannot import...error accessing registry.... I did not want to go any further....should have i done this in safe mode?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What was the full message? Did it say it You can only import binary registry files from within the registry editor?

    If so, you need to create the registry patch properly. No blank lines should be above the REGEDIT4 line and make sure you included the REGEDIT4 line.
     
  19. griggi63

    griggi63 Private First Class

    It says...

    Cannot import C:\DOCUME-1\Don\Desktop\fixMe.reg: Error accessing the registry.

    And i also noticed that some old windows updates were trying to install including sp2, but it would fail saying another process was using (i cant remember which process name). so at this point i'm kind of dead in the water.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Skip the registry patch for now and continue.
     
  21. griggi63

    griggi63 Private First Class

    Ok, went ahead and skipped the fixME.
    ran avenger...log included.
    ran atf
    Ran the Java runtime 6

    at this point a reboot dont remember why(this was last night)...and the automatic updates came up to install xp-sp2....figured i would try to let it do its job and it ran this time.

    installed AVG8 and let it do a full system scan and removed whatever it found.

    MGtools\getlogs.bat.....mglogs.zip included.

    Still as of this time i have not yet put the pc online. have been doing all downloading through a flashdrive and transferring info back and forth.

    fixME.reg is not yet functional.
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet! .....looking very good.

    Right click the desktop fixMe.reg and delete it.

    Now lets try again with non-critical patching:
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Did that work?

    Your logs are clean!

    Tell me how things are running.
     
  23. griggi63

    griggi63 Private First Class

    OK. what a difference. Seems to running very well. Any further instructions or logs you need? I am sending this from the actual pc now. I just put it on line and let the windows updates do its thing (56 in all including IE7). I have AVG8 running, and let the turned windows firewall back on (did not want to change this yet till i talked with the owner).
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet....good to know.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type "%userprofile%\Desktop\cf" /u in the runbox and click OK.
    * Note: The space between the cf and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  25. griggi63

    griggi63 Private First Class

    Ok, my friend....all is done. except the combofix was already gone...i'm thinking from previous step/mishap not sure, but its nowhere to be found. I am instructing the owner on what to do next and providing links to the MG forums to keep their pc safe and let them decide which other options they want to take.

    Cant thank you enough and as always you guys are truly a godsend to those of us who know how to jack up a pc.

    Thank you Master Tim, Chas, Attitude and all who fight.

    God Bless
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    On behalf of us all..you are welcome...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds