Missing LOTS

Discussion in 'Malware Help (A Specialist Will Reply)' started by Kyser Sose, Jan 24, 2007.

  1. Kyser Sose

    Kyser Sose Private E-2

    Hello to everyone here today. I first tried to start a thread in the Welcome section and was directed to post here instead. Below was my post...

    I had asked a friend of mine to get a copy of PhotoShop for me, what he did was give me a copy of PhotoShop that he downloaded from some P2P sharing place. I think he has said "Bear-Share"? Anyhow, as soon as I inserted the cd and tried to install, I, in matter of seconds recieved NUMEROUS pop-ups both from the internet and Norton Anti-Virus. I couldn't stop it at all except by turning the power off. I have gone through (with Microsoft cust. serv. on the phone) deleting files and such. I have also done steps 1-5 from the "Run & Read Me First" in the Malware Removal section. Everything is out of my computer (so i'd like to think) but whatever came upon my comp that day had already done it's deed. I have alot of files that seem to be missing. When I go to my Programs folder, there are alot of folders that are rather transparent in color than the rest. I also cannot perform System Restore for this is gone too. I cannot use alot of my programs, like iTunes, GIF Animator, Norton Anti-Virus, etc. While on the internet, there are alot of times where I cannot download cetain files. At the bottom tool bar reads something like Javascript() blah blah blah and nothing happens. I have already downloaded the most recent Java but still no dice. I am also getting alot of pop-ups from "localsrv.net" and I forget the other one. To be a little clearer, all my programs that aren't there anymore or do not work are not from the results of deleting files but occurred right after trying to install the bad PhotoShop program. I am using a Toshiba Satellite A45-S150, Win XP - Service Pack 2. Can anyone please help me with this unusual problem or point me in the right direction? I really thank you in advance for reading long and poor grammared story.
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Your still infected. People constantly, the majority, get infected for using pirated shareware programs, movies, music and porn they know they should not be. These infections can be avoided.

    Rant off. Moving to malware for assistance.
     
  3. Kyser Sose

    Kyser Sose Private E-2

    Thanks Major for the quick reply.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  5. Kyser Sose

    Kyser Sose Private E-2

    Thanks for the response. I will finish with the process as soon as I get home from work and post results.
     
  6. Kyser Sose

    Kyser Sose Private E-2

    K, I have done the required "READ & RUN ME FIRST" list. I have (will include all attachments) ran all programs and went through all proccesses except for PandaActiveScan. I had first tried in safe mode w/networking then in normal mode and both times resulted in the same conclusion...when I press scan now after putting in minor info, it doesn't do anything at all. Like what happens alot of times, at the bottom bar, it reads: "javascript:javascript:validar_formu0;" when curser is on top of scan now button. Also when running GetRunKey and ShowNew a window immediately pops-up reading: "C:\WINDOWS\system32\cmd.exe - C:\WINDOWS\SYSTEM32\AUTOEXEC.NT. The system file is not suitable for running MS-DOS and Microsoft Windows applications. Chose 'close' to terminate the application" When I press close, it pops-up a couple more times, then opens the txt file window.

    Attached are both the CounterSpy and BitDefender files.
     

    Attached Files:

  7. Kyser Sose

    Kyser Sose Private E-2

    Attached are the GetRunKey and ShowNew files. Thanks again in advance.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have looked at both the Counterspy and the bitscan results, you will see that most of your problems are from downloading P2P software that is infected with viruses.

    Re-Run Counterspy and have it remove/quarantine everything it finds.


    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    You did not run HijackThis as requested.
    Now re-run and attach the logs for:
    ShowNew
    GetRun
    HiJackThis
     
  9. Kyser Sose

    Kyser Sose Private E-2

    Thanks TimW for your help in this matter. I will re-run all that you asked and post but first, when you asked me to copy "[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
    "SuperHidden"=dword:00000001" to my desktop as fixME.reg and save as all files. It asks me if I am sure that I want it to merge and when I input yes, a window opens saying that the specified file is not a registry script. You can only import binary registry files from within the registry editor.
     
  10. Kyser Sose

    Kyser Sose Private E-2

    TimW - Here are the requested attachments...
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What we are trying to do is show the hidden files on your computer, as most malware will install itself as hidden. We need to "unhide" those files.

    There are two ways to do this:
    First: How to view hidden...

    or:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select Do a system scan only. Look for the below lines (you may not always find both of them) and select them but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
    R3 - URLSearchHook: (no name) - _{8C964387-A36D-DAEB-4FF5-F35A644B14B6} - (no file)
    O4 - HKLM\..\Run: [cyovrwmA] C:\WINDOWS\cyovrwmA.exe

    After clicking Fix, exit HJT

    Now attaach new logs for:
    GetRun
    ShowNew
    HJT
     
  12. Kyser Sose

    Kyser Sose Private E-2

    I had already setup the comp so that it would show all hidden files and such. Copying the bold text as you said worked this time around. I ran Hijack and did a scan only and found all three files, exited all applications and intenet browsers and fixed. Here are the updated files that I hope will help. BTW, I really do appreciate all the free help and time dedicated in helping people.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please follow the directions for downloading and running ShowNew ( your logs are basically empty so follow the fix for XP (Pro or Home).

    ShowNew

    This should also be done for :GetRunKeys

    Then attach the new logs.
     
  14. Kyser Sose

    Kyser Sose Private E-2

    Those extra info on how to fix the error messages was not on the original READ & RUN ME FIRST page so I apologize. Here are the new files....
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No apology is nessecary ...There can be multiple reasons that the logs were semi-blank, so it wasn't your fault.

    Do a search for: C:\WINDOWS\cyovrwmA.exe and delete it if found.

    Are you still having any problems? If so, what?

    If not, you may uninstall any programs that we asked you to install.
     
  16. Kyser Sose

    Kyser Sose Private E-2

    Hey TimW - I have found and deleted the file. The problems that I am still having are as such: Norton Anti-Virus and System Restore only opens to an all white blank screen, alot of the programs do not work at all, like iTunes, program to sinc our pics from the camera, animator, etc. only opens up an error window saying that the program has encountered a problem and needs to close (this happens to alot of my programs), when I open the Recycle Bin and press "empty recycle bin", a quick-finder window pops-up instead. I can empty by right clicking Recycle bin and "empty recyle bin". Awaiting the next steps to hopfully fix all that is err.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download and install (make sure you update when it asks) the below:

    SUPERAntiSpyware

    And then run a Complete Scan (not a Quick Scan) on your system. When the scan finishes, save the log and attach the log here so we can see how effective it was. Please be patient as this can take quite awhile since it is running a very comprehensive scan. It would be best if you ran it and then did nothing else on the PC while the scan is running. Therefore try running it when you don't need the PC or even run it while you sleep.

    Then attach new logs from ShowNew and HijackThis.
     
  18. Kyser Sose

    Kyser Sose Private E-2

    TimW - Here are the new updated files, hope these will shed more light...
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  20. Kyser Sose

    Kyser Sose Private E-2

    TimW - Here is the updated HJT log file. All previous problems stated above are still, well problems. My computer IS responding ALOT quicker now though.

    Tell me TimW, would my problem be more of a software issue since I am not able to run programs like Norton and perform System Restore operation? I do not have a Windows cd to load, but if I did, would it erase everything that is on my computer or would it just load missing items? Thanks again for your time in this matter.
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You could be having problems that were related to the malware. I would suggest you uninstall Norton and other programs that are not working.
    You would need an XP disc that was your same version (ie; Pro or Home) and then do a repair installation:
    Wordy xp repair install:
    http://www.informationweek.com/windows/showArticle.jhtml?articleID=189400897

    Then reinstall those programs.

    You may wish to post in the software section for further instructions.

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  22. Kyser Sose

    Kyser Sose Private E-2

    TimW, I just wanted to thank you one more time for all your help.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds