Not sure what's causing problems!

Discussion in 'Malware Help (A Specialist Will Reply)' started by beccaa0033, Feb 18, 2010.

  1. beccaa0033

    beccaa0033 Private E-2

    I was working on trying to fix my mother-in-law's pc with the Read And Run Me First post when I realized it wasn't helping, well not totally anyway.

    A few strange things are happening. First, certain programs won't run or save progress (like Word). Also, computer options won't stay the way I select them, such as the option to Hide Extensions and Show Hidden Folders. No matter what I select, when I open it up again it's back to the original selections. I noticed that it happened when I right clicked on the Start menu and selected Properties. I tried to add IE to the start menu (because everything that was on the left in the start menu is now gone), but it wouldn't put the icon there and when I checked the properties it was unchecked. I'm also having problems with the keyboard typing double, as in "ddoouubbllee" and backspacing doesn't help because it double backspaces.

    When cleaning the computer, SuperAntiSpyware seemed to work okay, but when it was time to restart the computer it just kept rebooting when Windows was loading. I had to restart in Safe Mode then restart in Normal Mode, then it started okay.
    Malwarebytes gave an error when installing saying that it couldn't create a registry key, but I clicked ignore and it seemed to finish installing and run okay.
    Combofix had a little trouble running. It gave a message saying something like "The current date is ~" and "Combofix will run in limited mode." It didn't show all the steps being run, only step 46. It found a few things and took several minutes to create a log.
    It was when I ran RootRepeal that I discovered that certain files were still hidden, even after changing that option in Folder Options.
    I ran MGtools and at the end it said a zip folder was created, but I couldn't find it. I did notice several logs in the MGTools folder but I wasn't sure which files to grab, so I'm not including them in this post.

    The computer is not connected to the internet because I brought it to my house and I didn't want it infected anything else on my network. This means I wasn't able to update any of the programs mentioned above.

    Here are the logs I do have:
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    It works much better when you use the proper versions of the programs. You are EXTREMELY out of date with SUPERAntiSpyware, Malwarebytes and ComboFix. Uninstall ( you MUST uninstall) what you have and download what we asked you to install in the READ & RUN ME. Make sure you UPDATE SUPERAntispyware and Malwarebytes during the installation as requested. Attach new logs.

    The log is right where the procedure said it would be. C:\MGlogs.zip It is not in the MGtools folder. You will have to run it again after doing all the new scans with correct versions of the programs.
     
  3. beccaa0033

    beccaa0033 Private E-2

    I used copies of what was on my husband's computer. I didn't realize they were so out of date. I'll try again.
     
  4. beccaa0033

    beccaa0033 Private E-2

    Also, there is a program called "Command on Demand for Command Software" in the Add/Remove Programs list. Is this safe or should it be removed? I don't know if my mother-in-law put it on there or not.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Part of Authentium Antivirus. Ignore it.
     
  6. beccaa0033

    beccaa0033 Private E-2

    The frustration continues! I have been away for the past week so I haven't been able to continue trying to fix the computer until today.

    One of the biggest problems I'm having is that I cannot connect to the internet, which is one of the issues my mother-in-law said was happening at her house. I tried booting into Safe Mode, but there is no option to do that when booting up. I've tried the ESC key as well as all of the 'F' keys.

    I can't update any of the malware removal programs. Also, as I said before, I still cannot make certain changes. Such as, every time I select show hidden files and show file extensions and click apply, as soon as I close the window it reverses what I did.

    Is there anyway to get SUPERAntiSpyware and Malwarebytes WITH the updates so I don't have to rely on the internet?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The instructions in the READ & RUN ME for each of these tools give you manual download links for updating. I suggest that you use them.


    You still need to attach the log from MGtools. It does not require any updates after installing and you still have not attached this log. Until you do, we cannot help you. As suggested earlier, you should run it again after properly updating and rescanning with the other tools. If for some reason, you still cannot manage to get SAS and MBAM updated, just attach the C:\MGlogs.zip file so that we can try to get started.
     
  8. beccaa0033

    beccaa0033 Private E-2

    Let's hope I didn't screw anything up this time!

    I updated SUPERAntiSpyware and Malwarebytes. Neither of them found anything after running.

    Combofix ran fine, but during the first few steps a bunch of programs kept opening up, such as a birthday calendar, an identity login window that said there was no identity logged in, some sort of EULA, and even SUPERAntiSpyware opened up, among several others. I had to close them as soon as they opened. Then, after completing all the steps and deleting some files, it said the computer needed to be restarted, so I clicked ok. When the computer restarted, Combofix never came back up. So, no log file was ever created. Also, at the beginning when it tries to back up registry keys, it said it failed because access is denied. I was logged in an administrator account.

    I suppose RootRepeal and MGTools ran ok. The computer is still having problems. I am wondering if there have been changes made under the administrator account that is not allowing certain things to happen, or change. I've noticed that when trying to access certain areas I get the "Access is denied" message, even though the account I'm logged into has administrator rights, or at least is suppose to. And when I right click and try to run as Administrator I'm asked for a password, which I'll have to see if my mother-in-law has.
     

    Attached Files:

  9. beccaa0033

    beccaa0033 Private E-2

    I have the combofix log now. I simply created a new administrator account and logged into it and combofix popped up and created the log. Also, I am now able to do all the things (like view hidden files and file extensions) that I couldn't do in the original account.

    The only thing I can't figure out is why the original account is so restricted when it's shown as an administrator. And, how do I give back all that account's permissions like it had before?

    Here is the combofix log file:
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have not been following instructions properly.
    • You have multiple antivirus programs running (McAfee Security Center and Microsoft Security Essentials). The first instructions in the READ & RUN ME tell you that you must not do this. You must uninstall one of these now and then reboot immediately. And if you decided to uninstall McAfee then after reboot run this: McAfee Consumer Product Removal Tool
    • You are using a 5 month out of date version of ComboFix and not what we asked you to download in the READ & RUN ME. Delete this copy. Do not run ComboFix again unless I request it.
    • Also you have MGtools.exe on your Desktop and we specified that it needs to be save and run from the root folder of the Windows boot drive which is C:\MGtools.exe. Just delete the copy on your Desktop now.
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Command On Demand for Command Software
    J2SE Runtime Environment 5.0 Update 5
    Java(TM) 6 Update 11

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - (no file)
    O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - (no file)
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [combofix] C:\ComboFix\CF15584.cfxxe /c C:\ComboFix\Combobatch.bat
    O4 - HKLM\..\RunOnce: [combofix] C:\ComboFix\CF15584.cfxxe /c C:\ComboFixCombobatch.bat
    O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} (CSS Web Installer Class) - http://threats.freedom.net/viruscenter/onlineviruscheck/cabs/cssweb.cab

    Optionally you can fix the below unnecessary starups that are wasting system resources and slowing down startup.
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
    O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    O4 - Startup: TrueAssistant.lnk = C:\Program Files\TrueSwitchAT&TMembers\TrueWizard.exe

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. beccaa0033

    beccaa0033 Private E-2

    As I said before, this is not my computer, so I didn't have permission to delete McAfee, that is until yesterday evening. Up until then, I disabled everything I could in McAfee except for the firewall which was an oversight on my part. As far as Microsoft Security Essentials, I don't know where to go to disable it, much less remove it, if possible.
    As far as Combofix is concerned, I don't see how it's possible that it is 5 months out of date since I just downloaded it Friday and replaced the old one with the new one. I even double checked it after you mentioned it and made sure it was the newer one.
    MGTools was an oversight on my part because I am constantly going back and forth between this computer and hers with a flash drive.

    As far as the latest procedures went, some things did not go real smooth in the troubled account. McAfee Consumer Product Removal Tool, C:\MGtools\analyse.exe, The Avenger, Ccleaner, and C:\MGtools\GetLogs.bat seem to run ok except the text file for The Avenger did not pop up after reboot, but it was in the root directory.

    While in the troubled account, Disable/Remove Windows Messenger gave an error message about an INF file, fixme.reg wouldn't work because it wasn't allowed to make changes to the registry, and trying to install Sun Java gave the following error message:

    Error 1330.A file that is required cannot be installed because the cabinet file C:\Documents and Settings\Application Data\Sun\...\Data1.cab has an invalid digital signature. This may indicate that the cabinet file is corrupt.

    I was able to run those last three in the nem administrator account I created without any problems. The troubled account is still having issues. I noticed that while logged into the new account that when I tried to view the bad account in Windows Explorer it said Access Denied. The troubled account is still very restricted, even though it is lidted as an admin account.

    Also, when I ran anylise.exe, O4 - HKLM\..\Run: [combofix] C:\ComboFix\CF15584.cfxxe /c C:\ComboFix\Combobatch.bat and O4 - HKLM\..\RunOnce: [combofix] C:\ComboFix\CF15584.cfxxe /c C:\ComboFixCombobatch.bat were not there. I did delete Combofix, as you requested, but it was the last thing I did. Everything else I did in the exact order you requested.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is in Add/Remove Programs just like other programs that are installed including McAfee. All you had to do was uninstall Microsoft Security Essentials.

    Sorry about that! I was still looking at your first log which showed ComboFix 09-10-20.03. I needed to recheck it to see what was found on the 1st run and forgot about the new log. The second log is from the newer version ( ComboFix 10-02-25.02 )

    Okay then we may need to use ComboFix to make these changes.

    Probably due to the same limitation on registry editing.

    This will not fix everything since some steps are specifically related to the problem account and running them on another account fixes the other account not the problem user account.

    What exactly were you trying to view.

    Since you are running XP Pro, have you looked at Global Security Policies to make sure that changes have not been made to change permissions for this user account? Click Start, Run, and enter gpedit.msc and click OK. Look under the following areas:


    Computer Configuration ->> Windows Settings --> Local Policies -->
    • User Right Assignment
    • Security Options
    Also under Computer Configuration ->> Windows Settings --> Software Restriction Policies - to make sure no software restrictions have been instituted.

    Then you should check User Configuration and in each of the areas under it (like Software Settings, Security Settings....etc) make sure you see Not Configured under everything ( that is unless someone created polices that they want here ).

    I'll look thru your new logs now an create a new fix using ComboFix to try and overcome the issue with some locked registry keys. We will have to restore some items that ComboFix will incorrectly delete ( like C:\WINDOWS\system32\CLRVIDDC.DLL ) which I restore last time with Avenger.

    Question: Who installed SpeedyPC and what was done with it? Did problems begin after using this?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Another set of questions:

    1. Which account is the new account you created? Is it the one named Admin?
    2. Which account is having problems? Is it the one named Compaq_Administrator?
     
  14. beccaa0033

    beccaa0033 Private E-2

    You are correct on both of your last two questions. "Admin" is the new account and "Compaq_Administrator" is the one with problems.

    To answer your question about SpeedyPC, my mother-in-law installed it because she thought it would help clean up her computer and speed it up some. She confirmed that after installing it and using it one time, that is when she began to have serious problems, which included not having access to the internet and not being able to make changes to documents, among other things. She told me that it was ok to uninstall it and that she has been trying for almost a week to get a hold of someone to get her money back. They claim to have a 60 day money back guarantee. Would you like me to uninstall it now?

    By the way, today is the first I have heard of this program causing problems. She didn't tell me about it before.

    Everything in the Global Security Policies appears to be in order.

    Also, I wasn't trying to view anything in particular in the Compaq_Administrator account, I was just trying to see if I could view it at all.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I already removed some of it it one of the fixes since I did not trust it and most of these programs do not do anything that you yourself cannot easily do. Registry cleaning should be avoided. It is rarely necessary and when done, it should not be to juist blindly fix everything that pops up. So in reality, only under expert advice. Let's ignore it for now since I basically stopped it from running already.


    First download combofix.exe and save it to your Desktop. It needs to be run (as show below) while logged into the problem account. Shutdown Microsoft Security Essentials before running the steps below.




    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).




    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  16. beccaa0033

    beccaa0033 Private E-2

    Nothing has changed. When the computer restarted after running Combofix, the combofix.txt was not created. I waited for the program to come up to create the log but it did'nt. I checked the root directory, C:\, but it wasn't there. I logged out and logged back in and still nothing. It was when I logged into the Admin account that Combofix came up and created the text file.

    When I ran MGtools I forgot to delete the old MGlogs.zip folder, but I think it updated everything, so here it is along with the combofix.txt file.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problems may not be due to malware. You may have registry hive corruption. You can either try using System Restore to go back to an older restore point to see if it cures the issues or you may want to just use the new user account you created and delete the old one.
     
  18. beccaa0033

    beccaa0033 Private E-2

    I was thinking of doing that. I agree that there doesn't seem to be any malware, I just needed to be sure. I've never seen this problem before. It must have gotten really screwed up when she ran the SpeedyPC.

    Thank you for all of your time and efforts.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Since you are not having other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds