nasty virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by sam_blumberg, Feb 1, 2008.

  1. sam_blumberg

    sam_blumberg Private E-2

    hi guys
    I am having a true bad day with a nasty virus, and on top of all, of course it's happening the day of a truly important deadline.

    Symptoms
    computer boots easily only in safe mode.
    I need to try many times to boot windows in normal mode, usually I get a black screen after the original windows xp - i don't get to login. When I try multiple times sometimes I finally get the login screen and I can login in normal mode. I can't run any of these:
    no add remove programs
    no iexplorer
    no mozilla firefox
    I can't even run procexp.exe
    when I double click on these, I see them listed in tasks but they never run

    I am including a copy of the log of hijack this in safe mode and a copy I was able to run while running windows.

    I have run from safe mode online scans using bitdefender and awido and panda but have no found anything yet. I can't run trendmicro, it is killed before it can run

    I don't seem to be able to uninstall java from safe mode.

    Please, please, please help. I want to cry.
     

    Attached Files:

  2. sam_blumberg

    sam_blumberg Private E-2

    I can't even log in normal mode any more, I'll keep trying so I can't post results from combofix etc. what are my options from safe mode ? What can I do ? I can't even restore the system to a previous day, windows won't let me do it. SInce the reboot fails, windows says the restore was not successful
     
  3. Lev

    Lev MajorGeek

  4. sam_blumberg

    sam_blumberg Private E-2

    hi there
    sorry - earlier on I could not even log into the machine and run the tests. I later used somebody else's account (Erik) and I was able to run the tests and get you the included files.

    I did run AVG, and even though it seemed I have clicked where I needed in the reports, it did not generate one for me to include. It found only tracking cookies . Sorry I can't include it.

    I believe that I should create a new account to log in but I suspect the machine is still infected.

    What should I do ? Thanks
     

    Attached Files:

    Last edited: Feb 1, 2008
  5. sam_blumberg

    sam_blumberg Private E-2

    I re-run avg and did a quick scan
    it generated the report here included. Hope it helps.
    tx much
    Sam
     

    Attached Files:

  6. sam_blumberg

    sam_blumberg Private E-2

    still cannot login

    hi there
    Is there any additional information I can provide to get a little help ?
    I re-included here all together
    - combofix report
    - MGlongs report
    - AVG report

    I still can't load any programs after login - when I manage to login - the machine boots - it goes into the windows screen but 9 out of 10 times does not even get to the login screen. I try multiple times. When I finally get a login screen (typically after booting in safe mode and rebooting) I was able to use another user's account to login and run the tests you ask to.

    I run a few online scanners but could not find anything meaninful
    F-secure found W32/Stration.gen4

    It's strange I can't run trendmicro neither from the Erik user account nor from safe mode. I used to be able to run it though in the past. "something" kills house call before it can start.
    According to the combofix report the machine is still infected.

    Can you please suggest a course of action to get this lovely laptop back on track ? Thank you
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: still cannot login

    You should not post unnecessary messages. It causes you to loose your place in the work queue and makes it take much longer to get help. See the sticky thread: Don't Bump! It Only Hurts You!!! Your last post cost you more than a day longer in waiting time.

    Delete the below huge file wasting a ton of disk space which is critical to you since you don't have enough free disk space to properly run Windows XP.
    C:\1F7.tmp

    You only have 970,637,312 bytes free on your hard disk. You need to cleanup all unnecessary files to get more disk space or you will constantly have problems.

    Now immediately empty your Recycle Bin to make sure the above is not saved there.

    Uninstall the below old versions of software which will also free up a bunch of diskspace:
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.2_14
    Viewpoint Media Player

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  8. sam_blumberg

    sam_blumberg Private E-2

    thank you sooooo much chaslang
    so so much
    and sorry for the earlier multiple post

    Here attached you will find the logs from the instructions you sent

    I am also included the result on the online kaspersky scan I run while waiting from this forum, it skipped so many files, just in case it can be useful

    As far as results my computer boots ok now and I can log into the Erik user account easily.
    I get this notepad window twice at boot time
    [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787
    and windows has tried and finally succeeded to install ActiveSync 4.5
    I could not stop the window
    Please wait while Microsoft installs ActiveSync 4.5
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    This is not a Malware Forum issue. You should discuss this in the Software Forum if it continues to happen. It just sounds like Microsoft ActiveSync software is trying to reinstall for some reeason. Do you use ActiveSynce to syncronize a hand held device to your PC?

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds