My results of READ & RUN ME first

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mrs_Constantinople, Nov 17, 2010.

  1. Mrs_Constantinople

    Mrs_Constantinople Private E-2

    Hello folks:)

    Before I go on I just thought I would post the result of my malwarebytes scan that reported some infections:

    The reason I have posted this here is because although the above have been removed by malwarebytes I've noticed that they reappear when I run a new scan-this has happened three times now.

    The windows task manager has been disabled by the administrator-this is the sign that comes up when I press ctrl+alt+del and I have tried one or two recommended steps but I still cannot access task manager when I press ctrl+alt+del.

    Ok so onto the steps on the 'read me first and run'

    I have copied all important data and programmes onto my usb stick:)

    Step 2: Uninstalling Multiple Protection Applications

    I had comodo and it just wouldn't update even when I tried to update it manually (I was on automatic update) and since two weeks passed since I last managed to update the database I tried to install avira but it seems that comodo had an issue with avira (also avg and avast) and so I deleted comodo as I really wanted an av and thought that deleting it would help.

    Anyhow I have tried to turn windows firewall on but it keeps on getting turned off for some reason:eek. I cannot install any anti virus or firewall onto my computer:(

    Step 3: House Cleaning

    Have tried this and don't have any of the mentioned programmes on my computer.

    I have emptied my recycle bin and always empty it when I put something in it.

    * Download and install CCleaner

    I have installed it but nothing happens when I click it, I've tried to run it from C: prog files, desktop, start menu but still nothing happens.

    Step 4: Configuration & Setup

    Have tried this but it won't work-it starts to install but halfway through vanishes and nothing happens.

    Step 5: Uninstall Known Malware and Unwanted Software

    I have uninstalled known malware but then the information above (from malwarebytes) about certain malware reappearing is something of concern to me.

    Step 6: Disable Any Disk Emulation Software (like Daemon Tools..etc)

    I have done this and it is disabled!

    Also this might help out the folks here:

    I recently upgraded from windows 98 to XP and took my laptop to the computer shop to have this done as wasn't confident to do so myself. I was not given the cd for this xp installation-something that the guy said would happen if the engineer installs xp onto a computer.
    The guy also installed kaspersky 2010 (yeah I know there are some concerns over the reliability of kaspersky but better have something and search the web for an alternative than have nothing at all) when I checked it at the internet shop I got into kaspersky, however, when I took it home it didn't work and I could not get into it.

    Also I had a few win32 sality.og infections on my computer and I installed AVG rmsality to get rid of these infections and it got rid of them.


    I hope that this information does help you folks:)

    Thanks for reading this.

    Regards
    S.
     
  2. Mrs_Constantinople

    Mrs_Constantinople Private E-2

    I would try step 7 concerning xp cleaning procedure but I don't know if I have 32bit or 64 bit, as nothing happens and I cannot install the programme that checks to see which one I have.
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hi, Mrs. Constantinople

    Referring to your comments on each step taken sofar:

    Step 2 --> Have you uninstalled all but one anti-virus program?
    Step 3 --> Instructions will be given to try and fix that
    Step 4 --> Did you try manually checking for your OS version?
    Now do this -
    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right-click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif

    Usage instructions
    • Once downloaded, double-click the Rkill desktop icon to run the tool.
      *Remembering to Run as Administrator if using Vista or Windows 7
      [*] It is normal for a black DOS window to appear briefly and disappear, indicating the tool being ran.
      [*] If not - delete the file, repeat the process and attempt to use one of the remaining links until the tool runs.
      [*] Do not reboot until instructed.

    NOTE: If you are having problems running Rkill, try running one of these renamed copies of RKill.com:
    Once you've gotten one of them to run then try to immediately run the following.

    Now download and Run exeHelper from Raktor
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Now run this: Using Malwarebytes Anti-Malware

    Now run this: Using MGtools

    Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans
    • exeHelper log
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.

    NOTE:
    1. If you have problems downloading on the problem PC, download the tools and the manual updates for Malwarebytes onto another PC and then burn to a CD. Then copy them to the problem PC. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  4. Mrs_Constantinople

    Mrs_Constantinople Private E-2

    Hello dr.moriarty:)

    Ok so I have followed your advice and here are the results/answers:

    At the present moment I have no anti-virus as I cannot download and install one-have tried avira, avast, avg and even had kaspersky but could not get into kaspersky at all and so deleted it.
    I did have comodo but it stopped updating-long story as it caused other problems and I deleted it from my comp.

    I did the check as was recommended and this is what came up:
    System:
    Microsoft Windows XP Professional Version 2002, Service Pack 3.
    So it looks like I have 32 bit.

    The exeHelper, mglogs.zip and mbam logs have all been attached.

    Ok it might also interest you to know that I did the quick scan on malwarebytes and checked all the infected files and clicked to remove them and then saved the log-so the computer rebooted to delete the files.
    Half an hour later out of curiosities sake I re-did a quick scan and the same infected files came up again (I followed the instructions on this forum exactly as they told me to-this is what has been happening ever since I installed malwarebytes and the same infected files come up every time I do a quick scan-deleting them seems to have no effect!)

    Ok I hope that this information is of use to you and thank you for the recommendations.

    I will await for any replies.

    Kind regards.
    S.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I saw a few things in your temp folders that need to go, however, it looks like you may not have made the agreement to run HJT when you ran the MGTools. Please go to C:\MGTools\analyse.exe and run it. Do a system scan only. Attach that log when it is finished.
     
  6. Mrs_Constantinople

    Mrs_Constantinople Private E-2

    I did get the hijack this and clicked on the agreement so don't know what has happened here.
    Anyhow I have run MGTools as you've requested and hope that I followed the correct steps this time:-o
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You have less than adequate memory to run current versions of Windows
    At an absolute minimum, you need to double your memory to 1 GB but 2 GB is highly recommended, as recommended in Step: 1 of the R & R ME FIRST guide.

    Please attach these logs:
    Delete this, as it's no longer needed and not where you were instructed to save it.
    C:\Documents and Settings\user\My Documents\Downloads\MGtools.exe

    *If you didn't set the below policy-
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    - then fix it with the below instructions:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Using Windows Explorer - navigate to and delete these folders:
    • C:\Documents and Settings\user\Local Settings\Application Data\COMODO
    • C:\Documents and Settings\All Users\Application Data\Comodo
    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    *Open CCleaner
    • Select "Cleaner" > "Run Cleaner" <---use this function ONLY!
    • Then - click on Tools > Uninstall > and then at the bottom right - Save to text file.
    • Close CCleaner

    Refer to the instructions in the below link, and run ComboFix:
    Windows XP Cleaning Procedure

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right-click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\combofix.txt
    • Requested SAS logs
    • CCleaner's Uninstall List.txt
     
  8. Mrs_Constantinople

    Mrs_Constantinople Private E-2

    Have followed all the advice you have mentioned above but here are some errors I encountered:

    SUPER ANTI-SPYWARE:

    First-I cannot find any logs of super anti spyware and I didn't even attempt to move them or anything!
    The version I installed and downloaded has stopped working and when I try to click it, this error comes up:

    COMBOFIX: Managed to download and install but when I click it, a black screen appears for 1-2 seconds and then it disappears.

    STILL NO LUCK WITH CCLEANER: I can download and install it but when I click onto it, it comes onto screen literally for a second or two and disappears, have deleted it and downloaded/installed it again but it still only appears for a second or two-have downloaded and installed from 2 other sites but still all it does is appear for 1-2 seconds on screen and disappears.

    Ok then have attached the requested logs.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The logs are right where dr.moriarty said they would be in his last message. You just needed to attach them.


    However, the reason you are having a problem fixing this is apparent in the runkeys.txt log which is part of MGtools. Registry editing and also Task Manager will be constantly getting disabled which is due to the Sality infection you have. This can be seen by the below seen your system.ini file.

    [MCIDRV_VER]
    DEVICEMB=64020022999

    For additional info, see W32/Sality.ai also see the below. There are many forms of Sality:

    Virus:Win32/Sality.R

    Virus:Win32/Sality.AT


    These types of infections frequently require a reinstall to properly removal all traces and to fix the damage it causes.

    You can try the below tools but I have never seen them work properly:

    http://free.avg.com/us-en/win32-sality

    http://support.kaspersky.com/viruses/solutions?qid=208279889
     
    Last edited: Nov 22, 2010
  10. Mrs_Constantinople

    Mrs_Constantinople Private E-2

    I think a reinstallation sounds like a good idea.
    By the way I was not given a cd when I had xp installed onto my laptop so I'll assume I need to get one. I could go back to the shop but I had a run in with a guy who works there and don't really want to go back-well there are other shops.

    Sorry if this is off topic but just a quick question-is it possible for me to get an xp cd and install windows myself or will it be too complicated?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you need the CDs. There is supposed to be a Recovery CD.

    Just getting any copy of Win XP Professional ( which is what you have ) may not be sufficient. I'm not sure all the drivers for your laptop would be included. You also need to make sure you have your Windows XP license key so that you can reactivate Windows. This key may be on the bottom of your PC as shown in documentation in the below link. Perhaps you can get some info from Fujitsu. Like in links like below:

    http://uk.ts.fujitsu.com/rl/servicesupport/techsupport/lifebook/index.html

    Also see: http://ts.fujitsu.com/support/downloads.html


    Note: This is an old slow laptop with an inadequate amount of memory installed to properly run current versions of Windows XP and above (probably also the reason why you did not install any protection software on it and got infected ). Are you really sure you want to spend time and money trying to purchase a copy of Win XP Pro?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds