Need Serious Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by CandyMan69, Apr 12, 2008.

  1. CandyMan69

    CandyMan69 Private E-2

    I am working with xp pro and I currently picked up a virus/trojan from a flash drive that disguised it self as a picture folder, and it is not been detected by macafee or adware, it has disabled the task manager, the run option on the start menu as well as control panel and the shut down option. when i try to access control panel from the printers and faxes menu i get the message that the administrator has disabled the rights and i am the administrator. i accessed the computer management and turned off system restore but i just cant get to the registry to get rid of this pest, could you assist with a script to get access the registry and or something to get rid of this virus????
     
  2. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

  3. CandyMan69

    CandyMan69 Private E-2

    I am currently following the steps to remove malware but i am now at combo fix but i still do not have run on my start menu nor do i have back task manager, what do i do in order to run combo fix properly?????
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you were able to at least save ComboFix to your Desktop, then just run it by double clicking on it.
     
  5. CandyMan69

    CandyMan69 Private E-2

    tried to run combo fix by just double clicking however all that happens is it creates a folder with all the files in it and thats it. I should also let you guys know that this virus has also disabled the command prompt along with the other stuff i spoke of previously. I am wondering if i should try and run mgtools still???? This virus seems to be progressing as it generated a script named start on the c:\ at 3:58 am this morning which i just deleted. It also seems to be a low level virus that replecates as everytime i tried to delete the source file it just recreates it, darn i need help!!!!!! i might have to reformat all my hard drives if i cant find a solution soon
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try this!

    Run SDfix by following the directions in this link Using SDFix.
    • When finished, it will produce a log ( C:\SDFix\Report.txt ) for you. This long must be attached when you return to report your status.
    Yes! But have you also tried running SUPERAntiSpyware and Malwarebytes Anti-Malware first?
     
  7. CandyMan69

    CandyMan69 Private E-2

    Tried runnig SDFix however the batch file did'nt run. Dont have RUN on the start menu, in safe mode or normal mode so i cant run the step to enable command promt. i ran catch me which scaned but did'nt find anything on the machine, however sumthing is there. I have attached a pic shot of the registry changes that spybot picked up, however as they are corrected by spybot the virus rewrites them.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to continue on with all steps in the READ ME.

    What about these?
    • SUPERAntiSpyware
    • Malwarebytes Anti-Malware
    • MGtools
     
  9. CandyMan69

    CandyMan69 Private E-2

    Hey guys i re ran all the cleaning steps. As was happening before i was unable to run sdfix and combo fix as i still dont have access to command prompt or run. I have attached the logs that were generated and in the system log you will see the virus folder called "pictures.exe" which is causing all my troubles. I am doing some hectic research and it might be w32/rungbu-A virus but i am not sure as it is not being picked up or detected by any scan. It would seem this is a new virus???? but what to do but continue trying to find a solution, later on guys i am out of here
     

    Attached Files:

  10. CandyMan69

    CandyMan69 Private E-2

    Did some more research it is not w32/ rungbu-A virus.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still need to see the log from MGtools that is requested in the READ ME. This is the MGlogs.zip file.
     
  12. CandyMan69

    CandyMan69 Private E-2

    Because i dont have admin rights the command prompt gives me a disabled message hence MGtools cant get to run, nor SDFix so i dont have those logs
     
  13. CandyMan69

    CandyMan69 Private E-2

    Hey guys i sent a sample of this virus to http://www3.ca.com/support/vicdownload/ they found out that it was "Win32/Smeesni.A" strain so i am go'n to try this solution and let u guys know how it works out. Thanks for all the help so far
     
  14. CandyMan69

    CandyMan69 Private E-2

    Hey guys just letting you all know that i have back control of my system. I ran the virus scan that i posted a link to earlier and it cleaned the virus, i had to re-run spy bot and restart to enable the registry keys and i just did over the instructions in "read & run me first". So thanks again but this thread can now be closed. IRIE:D
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome; however based on some items I did see in the logs you did attach, I still recommend that you attach a log from MGtools now.
     
  16. CandyMan69

    CandyMan69 Private E-2

    Hey here is the log that you requested, however i got an error message that i seem not able to fix. Anyway let me know what you think
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to cleanup your Desktop!! A cluttered Desktop is great hiding place for malware. Move everthing you wish to save off your Desktop other than shortcuts. If you really want to have MSconfig on your Desktop, make it a shortcut to the real program and not an EXE file.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKCU\..\Run: [000] C:\Documents and Settings\kclarke.STATINCOMP\Application Data\csrss.exe

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!


    Are you the one who set the below programs up to not be allowed to run?
     
  18. CandyMan69

    CandyMan69 Private E-2

    The registry script "fixme" was successful, i cleaned up the desk top and ran the steps. Yes i set up the programs not to be run. i also attached the logs for you to look at, and the machine seems to be running ok. Thanks again for your help.:)
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just use analyse.exe to fix the below line:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    Other than that, your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we had you run Avenger, you can delete all files related to Avenger now.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
     
  20. CandyMan69

    CandyMan69 Private E-2

    Thanks again for all the help you gave me, but i think i am in the clear now :D thanks will be using your steps to avoid getting infected again
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds