Multiple Virus' can't install antivirus

Discussion in 'Malware Help (A Specialist Will Reply)' started by Chefdad, Aug 4, 2008.

  1. Chefdad

    Chefdad Private E-2

    I have a dell inspiron B130 notebook( it's a friends) That would not boot windows normally only blue screen. It will only boot in safe mode. When you boot in as his user account most things are missing. If you click on the start button a couple of programs show up in the list but, log off, run, search, control panel, my computer ect. is all gone it will not allow task manager to run. It will not allow you to install any software from this account even though it has administrator privileges it says that the administrator has limited the account. At the bottom where the clock is it says virus detected. On the administrator account the missing things are there. It let me install a copy of avg I had on disk but it was 4 yr old and when I tried to update it the computer wouldn't allow it. It seems that he had norton and mcafee on there but all that is left of them is a few empty folders, no exe files or anything else. It will not let me install any type of antivirus at all, As I tried to install spybot S&D,spyware blaster,Trojan remover,spyware doctor,Super antivirus software, and the windows malicious software removal tool, I also tried to rename them. Even as administrator it says that the administrator has limited the account and won't let me install anything. It did let me install xoftspySE scanner. The scanner came up with 937 definitions found,11 running processes, 937 objects recognized,538 registry keys identified,194 registry values identified,173 files and 32 folders. Names of things are
    Backdoor PcClient GC Trojan
    GetMirar
    Tibs LDS Trojan
    Downloader Zlob HVG Trojan
    Downloader Exchanger BW Trojan
    Downloader Agent NVW Trojan
    Downloader Agent ALI Trojan
    180Soulutions
    MyWebSearch
    FunWebProducts
    Veiwpoint
    MyGlobalSearchToolbar
    Direct Revenue
    Zango Toolbar
    HotBar
    PlayMP3z Adware
    Hope this helps someone point me in the right direction, Thanks for any help in advance.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.



    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. Chefdad

    Chefdad Private E-2

    Multiple Virus's

    I have a dell inspiron B130 notebook( it's a friends) That would not boot windows normally only blue screen. It will only boot in safe mode. When you boot in as his user account most things are missing. If you click on the start button a couple of programs show up in the list but, log off, run, search, control panel, my computer ect. is all gone it will not allow task manager to run. It will not allow you to install any software from this account even though it has administrator privileges it says that the administrator has limited the account. At the bottom where the clock is it says virus detected. On the administrator account the missing things are there. It let me install a copy of avg I had on disk but it was 4 yr old and when I tried to update it the computer wouldn't allow it. It seems that he had norton and mcafee on there but all that is left of them is a few empty folders, no exe files or anything else. It will not let me install any type of antivirus at all, As I tried to install spybot S&D,spyware blaster,Trojan remover,spyware doctor,Super antivirus software, and the windows malicious software removal tool, I also tried to rename them. Even as administrator it says that the administrator has limited the account and won't let me install anything. It did let me install xoftspySE scanner. The scanner came up with 937 definitions found,11 running processes, 937 objects recognized,538 registry keys identified,194 registry values identified,173 files and 32 folders. Names of things are
    Backdoor PcClient GC Trojan
    GetMirar
    Tibs LDS Trojan
    Downloader Zlob HVG Trojan
    Downloader Exchanger BW Trojan
    Downloader Agent NVW Trojan
    Downloader Agent ALI Trojan
    180Soulutions
    MyWebSearch
    FunWebProducts
    Veiwpoint
    MyGlobalSearchToolbar
    Direct Revenue
    Zango Toolbar
    HotBar
    PlayMP3z Adware


    When I started the Read &Run me First I could only boot in safe mode. I was not able to install any antivirus software or a firewall. Norton and mcafee were on there but all that was left were a couple of empty folders. I went in to add remove software and removed all sorts of tool bars and other programs(mp3 players, internet games and anything else that wasn't needed. What it wouldn't let me remove I went in and deleted all the files and folders for. Tried to empty recycle but was not allowed access. I changed msconfic startup to normal. It would not let me update the java runtime. I downloaded and burned the following programs on a good comp. superantispyware,spybot,combofix,mgtools,and malwarebytes.
    It would not let me install anything except malwarebytes.
    After running malwarebytes and removing objects it let me boot windows normally. I signed into his user account but logoff,search,run,control panel, ect. were still missing. I went back into administrator in safe mode and created a new user account. I then booted windows normally and signed into the new account. Everything is under the start menu on this account.

    I did receive the error message:: Cannot Find File ///c:/windows/privacy_danger/index.htm

    I then tried to re-install all of the antivirus software again. It let me install superantivirus. which I ran. then repair broken network connection (WinSock LSP Chain). And re booted.

    I tried to use IE to download zone alarm but no matter what you type in the address bar you get redirected to some other site. Links go to places other than the intended site. It will not install zonealarm from disk either. I also re installed firefox and it installed fine but just won't run.
     

    Attached Files:

    Last edited: Aug 5, 2008
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Multiple Virus's

    Please do not start new threads for the same problem you have already posted about. I'm merging you back to your first thread.

    You need to attach the rest of the requested logs and also explain only what problems remain.
     
  5. Chefdad

    Chefdad Private E-2

    Sorry about the multiple threads but it says at the bottom of the xp cleaning procedures that if you still have a problem" Start a new thread and clearly describe in detail the problems you are having and how long ago they started. Think about what you were doing at the time."
    As far as additional logs I have already stated that it won't let me install or run the other programs so there are no additional logs.

    As of right now, 90% of the main user account is gone. Start button features, program files,control panel ,all gone. Other than malwarebytes and superantispyware, I am unable to load any antivirus or spyware remover at all. I am also not allowed to install a firewall. I was allowed to install firefox(from cd) but it will not run. Internet explorer takes you to sites other than what you clicked on, even typing in the url takes you somewhere else. Most of them selling something other times it's a search engine of sorts.When you are able to click a downloadable link IE stops it automatically. Even after I disconnected the laptop from the internet wire, IE still tried repeatedly to get out even though it wasn't running. The main user account has a big Virus Detected at the bottom next to the clock.
     
  6. Chefdad

    Chefdad Private E-2

    Sorry for the double post, I tried to edit but found out there was a time limit.
    IE repeatedly tries to get you to Work offline even after the internet wire was removed. I also tried to install avg and adaware but I just keep getting the message that the admin has restricted this account. It happens no matter what account you use even admin in safe mode. Also after a couple of tries to install antivirus from cd it blocks access to the cd drive and I have to shut down and reboot to try again.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you actually attempt to run MGtools.exe? It does not do a windows install and quite often will run inspite of problems like this. If it runs (even if only partially) attach the requested log.

    Your SUPERAntispyware log shows that it was not updated to the current definitions. Please try to get it to update and let me know if you can or not. Either way please run another scan with it and attach another new log. Also run Malwarebytes one more time and attach the new log from it too.

    Also tell me what your user account name is so I can try to make up a special fix to attempt to restore some user priviledges.
     
  8. Chefdad

    Chefdad Private E-2

    Here are the logs. I had tried to run mgtools but I had no control of IE to even download it and it wouldn't let me copy it from the cd to the c drive
    I have managed to restore the admin privileges to his user account ( THADS ) and most everything that had disappeared are now restored.
    I have run avg,ad-aware,asquared hijackfree,fixvundo,trojanremover,windows malicious software removal tool,ccleaner,avast,superantispyware,malwarebytes,spybot,combofix, windows registry repair and the mgtools.
     

    Attached Files:

  9. Chefdad

    Chefdad Private E-2

    Here is the last log
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is the name of the computer and domain, not the name of the User Account. I don't need the user account name now as it is in newfiles.txt log.

    Before we can continue you MUST uninstall either Avast or AVG8. As stated in the first steps in the READ & RUN ME, you must not have multiple antivirus programs installed. After doing this, attach a new log from MGtools by doing the below.


    Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
     
  11. Chefdad

    Chefdad Private E-2

    ok i removed avast. here is the new log
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O24 - Desktop Component 0: Privacy Protection - (no file)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. Chefdad

    Chefdad Private E-2

    I received a success message on the regedit. The computer seems to be running fine. It boots normally. Admin privilages have been restored. i was able to install a firewall. IE is acting normally and actually going where you want. things keep popping up when I run scans so I'll just keep plugging away at it.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  15. Chefdad

    Chefdad Private E-2

    I have been away but wanted to say thank you for all your help. I got everything out and it is running great. If there is anything I can so to help out the site let me know. Patrick
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds