NTLDR is missing message + Zlob virus issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by 94TRDcelica, Feb 13, 2008.

  1. 94TRDcelica

    94TRDcelica Private E-2

    Hi, first post here from a noobie. Ive had this virus called a js/downloader agent that AVG detects and puts in the virus vault but it keeps coming back. Ive been through the malware removal guide sterp by step befoe but didn't post the logs and it worked for a bit and then came back.

    Anyway, today I deleted all the logs and files and uninstalled the sypware programs etc to restart the process.

    I got up to the point where I did the combofix log and then I found a few other files in my c:/ so i deleted them. Then I restarted and it wouldn't boot, instead I got a NTDLR is missing, press any key to restart error message, ctrl alt del doesn't work so I have to reboot manually by pressing the button. I then went to try and boot from the XP CD it gets to the screen that says press any button to boot from CD drive, I press a button and the NTDLR screen comes back adn around I go again and again. Can anyone help or am I proper F****d????

    As soon as I resolve this little issue I can post up the logs. Im not hugely literate with virus, MS-DOS, booting procedures etc my knowledge is limited so any info in English would be hugely appreciated!

    Thanks

    TRD

    PS Im using XP Pro
     
  2. 94TRDcelica

    94TRDcelica Private E-2

    Ah I have managed to reboot my system using the boot floppy disk, seems to be ok at the moment. thanks for reading anyway! I will be posting a new thread shortly with the log files.

    Thanks

    Chris
     
  3. 94TRDcelica

    94TRDcelica Private E-2

    Right I have done all the virus checks and they all came back saying its clean, however I know for a fact that it isn't as I'm still getting the pop up for AVG saying js/downloader agent.

    I have attached the log files for each of the scans hopefully someone might be able to detect a way of removing it?

    Thanks

    TRD
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm not seeing any malware ....could you tell me the exact message and path that AVG is reporting?

    In the meantime ....
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  5. 94TRDcelica

    94TRDcelica Private E-2

    Hi, thanks, I did the MGtools analyse.exe but the protocols reappeared after a reboot.

    I have now attached a .jpg of the AVG message that appears. I hope that helps!

    Chris
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes...you need to delete all of your temp internet files!

    To do this, right click start / explorer and under your account scroll down to and expand Local Settings ...click on Temp Internet files and delete the contents of all the folders.

    OR: download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program
     
  7. 94TRDcelica

    94TRDcelica Private E-2

    Right i've done that and the message still reappears. note: it tends to appear when using programs that access the internet such as dream weaver and Firefox.

    This morning I ran CCcleaner and ATF and MGtools\analyse.exe (deleted 015 protocols), shut down my virus shield and shell extension then turned off system restore.

    I then ran combofix, spybot, AVG anti spyware and MGtools.exe followed by MGtools\analyse.exe again and the reports are attached below. (It wouldn't allow me to attach another combofix.txt file because I have already uploaded one)

    I restarted the system and turned my AVG shield and shell extension back on as well as system restore - It was running sweet for about 5mins and then pop, AVG comes up with the usual message. I'm lost for ideas now! Esp as all the virus scanners came back saying that the system is clean, grrrr!

    Any ideas? Anyone?

    Thanks for your help so far, the ATF works really well!

    Chris
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you using a proxy server to surf the web? And you didn't reset the 015 lines...

    Please re-run HJT and check those entries....then check your setting in spywareblaster and spybot ...make sure that "Automatic cleanup of winsock connectivity" some setting like this is checked (do you run BOClean?).

    Again tell me the exact path to the message.
     
  9. 94TRDcelica

    94TRDcelica Private E-2

    Yes, I manage a website using a proxy server, via dreamweaver.

    I did reset the 015 lines but they come back after a restart. Should I run Hijack this in safe mode?

    How do I set automatic cleanup of winsock connectivity? And I ran BOclean if found some spyware which was removed but didn't solve the js/downloader.

    The path is...."C:\Documents and Settings\Chris Newnham\Local Settings\Temporary Internet Files\Content.IE5\90USZRCK\wpad[1].htm"

    The letters and numbers after IE5 vary.

    Thanks
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you right click on start / go to explorer and scroll down to that file (expanding the folders as you go ...) you will find numerous folders under the
    C:\Documents and Settings\Chris Newnham\Local Settings\Temporary Internet Files\Content.IE5\.....empty all of them as well as all temp files under other users.

    If it recurs ..it is where someone keeps going to on the web.
     
  11. 94TRDcelica

    94TRDcelica Private E-2

    Yep! I followed the path and had to enter the content.IE5 extension because the file was hidden. Opened it up and it revealed folders with of the which the names of each folder corresponded to the numbers after .IE5 that AVG was picking up. There appear to be four or five different codes/groups of numbers related to the JS/downloader gent

    I deleted the files of which all they contained were snippets of cookies from random web pages that I had visited. The only file it would not let me delete was called index.dat, it seems to be some sort of notepad file with a load of code!

    It does occur whenever I or a program is accessing the web. Just can't seem to shake it though!

    The 015 protocols still reappear after a reboot.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The index file is needed and won't go away ..it is not a virus.

    Run a new MGTool.logs and let me see it again ...we need to fix the protocols...did I ask if you had the same problems with FireFox? DO you have an idea as to what program that you launch creates the files? (Got the flu and am a little brain dead)
    Do you not have an active firewall ...which would alert you to anything trying to access the web.
     
  13. 94TRDcelica

    94TRDcelica Private E-2

    Ok - i have attached the latest MGtools log file.

    Programs associated with the virus are: IE, Firefox, Dreamweaver and Outlook, sometimes it occurs randomly in word etc but I usually have my outlook open all the time so it could be feeding from that.

    I currently have a COMODO firewall, I did a scan the other day with and it spotted something, I deleted it and it hasn't got rid of the virus. The firewall is active.

    Thanks
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First:
    Download SDFix and save it to your Desktop.
    • Run the SDFix.exe by double clicking on it.
    • Allow it to install into the default location which is normally c:\SDFix
    • Now please reboot your computer into Safe Mode (see this if you don't know how: Starting your computer in Safe mode )
    • When you have booted into safe mode, open the C:\SDFix folder and double click RunThis.bat to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services or Registry entries found and then prompt you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
    • Attach the Report.txt file to your next message.
    Notes for possible problems running SDFix:
    • If this error message is displayed when running SDFix:
    The command prompt has been disabled by your administrator. Press any key to continue . . .
    Please goto Start Menu > Run > then copy and paste the following line: ​
    %systemdrive%\SDFix\apps\swreg IMPORT %systemdrive%\SDFix\apps\Enable_Command_Prompt.reg
    Press OK then run SDFix again​
    • If the Command Prompt window flashes on then off again on XP or Windows2000
    Please goto Start Menu > Run > then copy and paste the following line:​
    %systemdrive%\SDFix\apps\FixPath.exe /Q
    Reboot and then run SDFix again​
    • If SDFix still doesnt run, check the %comspec% variable
    Goto Start Menu > Right click My Computer > click properties > click Advanced Click Environment Variables and check that the ComSpec variable points to cmd.exe %SystemRoot%\system32\cmd.exe
    • SDFix uses ERUNT to create a registry backup in this location: %SystemRoot%\ERUNT\SDFix\
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Tell me how that went.
     
  15. 94TRDcelica

    94TRDcelica Private E-2

    Ok - thanks! I have run it word for word and attached the report.txt file

    When I ran the MGtools without any other programs running and clicked fix I then re-ran the scan and they reappeared! And whilst writing this message the AVG pop up appeared!!!!

    Do you want me to run the MGtools in safe mode too? I'll try it anyway!

    Chris
     

    Attached Files:

  16. 94TRDcelica

    94TRDcelica Private E-2

    Oh! Also it got rid of all my bookmarks of which im a bit annoyed about as I had alot of important references to sites and sources.

    Is there anyway of restring these?
     
  17. 94TRDcelica

    94TRDcelica Private E-2

    Ok - I just restarted in safe mode and did a spybot and AVG scan and they came up with nothing! I then did an MGtools scan in safe mode and the 015 protocols have gone - I guess that's a good thing?

    Im now back in normal mode with all my spyware programs running and am awaiting the alert!

    Still have not got back my bookmarks

    Chris
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know ..and here is a LINK to restoring your bookmarks.
     
  19. 94TRDcelica

    94TRDcelica Private E-2

    Hey, the computer has been running for a week now without any stupid AVG pop ups and completely virus free. So a massive thanks for sorting that out, I know it sucked but we got there in the end!

    Couldn't restore my bookmarks so did it manually which hasn't been too much of a biggy as there were some crappy bookmarks that needed getting rid of anyway!

    Thanks again!

    Chris
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Glad to hear it ...here is the final cleanup:
    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds