Need lots of help please

Discussion in 'Malware Help (A Specialist Will Reply)' started by merlin101, May 12, 2009.

  1. merlin101

    merlin101 Private E-2

    I have something going on with my computer and I can't figure out how to fix it. Problems listed below I have found so far. I'd post some here but I have no internet access, so downloading files from the internet is not an option at the moment. Any help is greatly appreciated.

    No internet access
    Task manager disabled by adminstrator
    registry editing diasbaled by adminstator
    Spybot won't run
    Can't access external devices via USB
    CD/DVD's won't run
    AVG brings up a partition error
    Big Flashing Warning box on the screen
    Error message- Windows No disk Exception processing message c0000013 parameters 75b6bf9c 4 75b6bf9c 75b6bf9c
     
  2. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    You need to provide more information: Brand and model of computer, operating system and any service packs
    Did you change any hardware or install software before this happened?

    Have you pressed F8 at startup and tried safe mode and/or last known good configuration?

    Please state the exact error you see.

    and what is the warning?
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Classic symptoms of malware, so that could be a possibility.
     
  4. merlin101

    merlin101 Private E-2

    Thank-you for your response.
    I have a Dell Dimension 4600.
    Windows XP Home Edition Version 2002, Service pack 2
    The AVG error says:
    Partition table(MBR) Reading error

    The flashing Warning box is on my backround instead of what I normally have there. It is now a completely black Background with Warning flashing in the middel, something about dangerous spyware being found.

    I have tried safe mode and last good known confirguration. I tried system restore, and I can not complete the restore process.

    No hardware or software changes were made prior to this happening. Wife visits blogs and facebook quite often though, probably picked up something there.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    As suspected, you now need to take a look thru this:

    READ & RUN ME FIRST. Malware Removal Guide
     
  6. merlin101

    merlin101 Private E-2

    Yes, I saw that however I can not get onto the interent to download the programs you are recomending in the cleaning guide.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do you not have access to another computer at all?
     
  8. paul leeds

    paul leeds Private E-2

    reformat hard drive?
     
  9. merlin101

    merlin101 Private E-2

    I have access to another computer (laptop from my work) but I don't know how to get the downloaded files onto the computer with the problem. I can not access external devices via my computer, nothing shows up.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can not access your cd drive? That would be the preferred method --> copy the scans and programs to cd and transfer to the infected computer.

    If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I now see you stated that you can not access USB or your cd/dve drive. At this point you need to do a repair install to try to get you running enough to try to do the R & R instructions.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Or another possibility to try and get started is to take the hard disk out and put it into another (well protected) PC as a slave drive. And then scan/clean the infected hard disk while in the other PC. Afterwards, try putting it back into the original PC and booting up.

    Another option would be using the below procedure to restore to an older registry hive predating the problem

    http://support.microsoft.com/default.aspx?scid=kb;en-us;307545&sd=tech
     
  13. merlin101

    merlin101 Private E-2

    OK, I was able to get one of the CD drives working and ran the programs in the read me run me malware thread. I think it caught everything, I have attached logs.
    I am still having 2 problems but probably unrelated to the malware. When I try to restart my computer it doesn't always restart, and when I click on start, all programs it doesn't bring up any programs that are in the c/program files folder.
     
  14. merlin101

    merlin101 Private E-2

    I don't think the logs posted the first time, trying again
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should have started a thread in the malware forum to be posting your logs!!

    We will do some cleaning, but then you will need to start a thread in malware and attach the new logs that I request once we are finished here.

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 4"
    J2SE Runtime Environment 5.0"

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now let's use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    [ If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\OLDF.tmp
    c:\windows\system32\doguvuvo.exe
    c:\windows\system32\ckbus
    c:\windows\system32\doguvuvo.exe
    c:\windows\system32\maroradi
    c:\windows\system32\nwzpphdq
    c:\windows\system32\zfhhyubaz
    c:\celkadaa.exe
    c:\okex.exe
    C:\WINDOWS\9g2234wesdf3dfgjf23
    C:\DOCUMENTS AND SETTINGS\Harvey\LOCALS SETTINGS\Temp\x5nmz.exe
    
    Folder::
    c:\windows\system32\ckbus
    c:\windows\system32\maroradi
    c:\windows\system32\nwzpphdq
    c:\windows\system32\zfhhyubaz
    C:\WINDOWS\9g2234wesdf3dfgjf23
    
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "WinSys2"=- 
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"="" 
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000000
    "UpdatesDisableNotify"=dword:00000000
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] 
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now download and install:
    Java Runtime 6

    Now start a thread in the malware forum, reference this thread and attach the logs there!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  16. merlin101

    merlin101 Private E-2

    logs for thread "need lots of help please"

    TimW per your request attached are the logs you asked for. From my thread in the software section.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looking much better. We just need to do a little junk cleaning, so use windows explorer to find and delete:
    C:\1949691939
    C:\WINDOWS\dump6cd3.tmp
    C:\WINDOWS\dump6dfc.tmp
    C:\WINDOWS\dump6ea9.tmp
    C:\WINDOWS\dump75bc.tmp
    C:\WINDOWS\dump94fc.tmp
    C:\WINDOWS\dump952b.tmp

    And then use add/remove programs to uninstall your old java:
    Java 2 Runtime Environment, SE v1.4.2

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  18. merlin101

    merlin101 Private E-2

    Everything is running much better. Only issue I have left is when I go to Start~All Programs, I get a very short list and none of my programs are there like excel, paint, word, etc.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is something to pursue in the software forum. It is a relatively easy fix.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds