One messed up computer!!...

Discussion in 'Malware Help (A Specialist Will Reply)' started by jrs40jas3, Oct 11, 2007.

  1. jrs40jas3

    jrs40jas3 Private E-2

    This is a computer I am trying to help a family member fix... It is running XP SP2 and at least 2 or 3 times everyday the computer needs to be restarted because it will not let you get into ANYTHING. All it says is you do not have the right permission to view "this or that." I know it probably has many viruses and malware on it, but I dont know where to go from here. I have run all the programs in the "Read and Run" section minus the "BitDefender." When I clicked the link for BitDefender it keeps telling me "Cannot Find Server." Also CCleaner ran but there was so much stuff taken off the the file is to large to attach? But the rest of the logs are attached. Thanks!!

    Josh
     

    Attached Files:

  2. jrs40jas3

    jrs40jas3 Private E-2

    here are the rest of the logs...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Work on the below while I look thru the rest of your logs!

    Contrary to what was requested in the READ ME, you have two antivirus programs installed. You need to uninstall one now! Since you have a whole security suite installed (probably from your ISP which is Earthlink) it would be easier right now to just uninstall AVG 7.5

    Now uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    Java 2 Runtime Environment, SE v1.4.2_03

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After completing the instructions in message # 3, continue with the below.

    Goto Add/Remove Programs and uninstall the below
    CounterSpy <--- we are finished with this trial now
    Deal Info

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - Startup: PowerReg Scheduler V3.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!
     
  5. jrs40jas3

    jrs40jas3 Private E-2

    Ok im sorry bout the double up on the AV. thought I had gotten rid of the AVG. I uninstalled the Java and restarted the computer but im stuck on the install of the current version. I get this error (see below) and then it says install failed. Any suggestions?

    Internal Error 2755. 1624, C:\Documents and Settings\Compaq_Owner\Application Data\Sun\Java\jre1.6.0_03\jre1.6.0_03.msi

    Thanks again!!
    Josh
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just skip the reinstall of the new java for now and complete all other steps. Then come back to the java reinstall.
     
  7. jrs40jas3

    jrs40jas3 Private E-2

    Did not see "Deal Info" in the list?

    I will try and install Java while you are looking into these logs. I appreciate everything you all do. You all have fixed my laptop and hopefully we can get this computer back to normal!

    Thanks a million!!
     

    Attached Files:

  8. jrs40jas3

    jrs40jas3 Private E-2

    pt 2 of logs... went ahead and attached the CCleaner log also?
     

    Attached Files:

  9. jrs40jas3

    jrs40jas3 Private E-2

    Tried to install the Java again and still getiing the same "Internal Error" message (see above)? Any suggestions?

    Thanks again!!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean! Are you having any malware problems?

    Try running the below to cleanup possible bad installations issues with Java or any other program.

    Windows Installer CleanUp Utility


    Then try reinstalling Sun Java.
     
  11. jrs40jas3

    jrs40jas3 Private E-2

    Ok... still having the same problem... When I tried to install the "Windows Installer CleanUp Utility" It would not even get to the downlaod screen and it would have an error, "Iexplore.exe - Application Error: An unknown software exception (0xc06d007f) occured in the application at location 0x7c812a5b." I hit OK then it came up and said that it was unable to launch restart.exe because I dont have the right permissions? Should I restart the computer and get all my permissions back or is this do to malware/viruses?

    I have also tried to get you some fresh logs after all of this but this is the error message I get for all of them... "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item."

    Thanks Again!!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you logging into an account that has administrator priviledges? Double check in Control Panel, User Accounts to see how your account is described.

    Also what happens if you boot into safe mode? Do all the same problems exist?
    What happens if you use a differenet user account in normal mode (assuming you have another user account)?
    What happens if you use the user account named Administrator in safe mode?


    Also look into the IE7 add-ons (Internet Options -> Programs -> Manage add-ons) and tell me what you see.
     
  13. jrs40jas3

    jrs40jas3 Private E-2

    The account they are using does have administrator priviledges. It is also the only account that they have. I ran CCleaner in safe mode under the administrator account and it worked fine. Safe mode under the normal user name works like it should. But when I log in under a normal boot, thats when things start to mess up. It will not reconize ANY file extensions. It will not pull up Control Panel, Task Manager, Command Prompt, "Run" command. I have to forcefully shut the computer down by holding the power button on the computer tower for a number of seconds... Also I cannot open IE in normal mode? Will you get the same info if i booted into safe mode and told you what was in the add-ons? Im pretty good with computers but whatever is causing this has got me stumped!! :confused Once again I appreciate you helping me with this. Thanks again!!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you saying that file extensions are not recognize in normal boot mode? Like no .EXE files will run?
    What about desktop icons ( .lnk files)? Can they be double clicked to run anything?

    If you boot into safe mode and create a new user account (for test purposes) and make it an admin account, can this account be accessed in normal mode and do things run properly.

    On the problem user account, log on in safe mode and get the below logs and attach them here:
    • GetRunKey
    • ShowNew
    • HijackThis
     
  15. jrs40jas3

    jrs40jas3 Private E-2

    NO .exe files will run. When you double click on some of the desktop files they act like they are gonna pull up at then it just stops working. All the others will give that message I stated eariler about the permissions.

    Attached are the files you requested for the problem user.

    I have yet to try out the new user, due to the fact that the computer is not able to get an IP address? This happened on this past restart...
     

    Attached Files:

  16. jrs40jas3

    jrs40jas3 Private E-2

    The computer is not acting up since it has not been able to connect to the internet? Could something be wrong with the internet connection? Also just noticed that the Java is in the Add/Remove Programs after this past restart? Although it was giving us that message? Doesnt make sense? :Confused
     
    Last edited: Oct 11, 2007
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you mean! You seem to be having all kinds of problems. Most of which may not be malware.

    Well I'm not sure what you meant but yes something is wrong if you cannot connect.

    Not according to you newfiles.txt log.

    What message and when are you getting it?

    Please click Start, Run, and enter msconfig into the run box and click OK.
    On the General tab of the System Configuration Utility choose Selective Startup.
    Then Uncheck the boxes for Load System Services and Load Startup Items.
    Then click Apply and OK.
    Then reboot into Normal Mode.

    Now tell me if any of the problems have changed. Do not try to connect to the internet though since this will not work with those items unchecked.
     
  18. jrs40jas3

    jrs40jas3 Private E-2

    Ive done a little research and ive gotten the "updated" java to install and the internet is working. I have also taken off the "Earthlink Protection Suite" because it was a piece of junk that earthlink installs and expects you to use. I have followed your steps in the "Protect your computer from malware" and have installed Avast!, Comodo FW, Spyware Blaster, and left the SpyBot. Everything seems better (running faster, no permission troubles...) after I did the selective startup. I attached some fresh logs for you to look at...

    Thanks again.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is the direction I was headed in with the selective startup procedure. I was going to show you how things would work without it loading and then with it loading. ;)

    You did not get all of the Earthlink junk removed and now you have mutliple antivirus applications running.


    Notice all the below in your HJT log which is from Earthlink
    Also the below Earthlink items shows in your Uninstall Programs List and may be in Add/Remove programs. You should decide whether any of this junk is required just to get access.
    Also you should uninstall the below left over from Symantec:
    LiveUpdate 1.90 (Symantec Corporation)
     
    Last edited: Oct 11, 2007
  20. jrs40jas3

    jrs40jas3 Private E-2

    I dont really know how to use Hijack this... So I dont know which ones to fix and which ones to not fix. :confused

    Also I am in the process of running Avast! after troggling the system restore but it is finding MANY (30 or 40 so far!!), Trojan Horses and Worms, in the C:\System Volume Information\... I am moving them all to "The Chest." Is there something we missed to have overlooked all these?
     
    Last edited: Oct 11, 2007
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You would use HijackThis just like we did previously but first you have to determine what you need from this Earthlink stuff. I doubt that very much of it is required but I cannot answer that since I have never used Earthlink. You definitely need to uninstall some of it since you now have Avast and Authentium (aka Command) Antivirus running. Also the below is considered adware:
    O4 - HKLM\..\Run: [ELNKProxy] C:\WINDOWS\surfmonkey\smproxy.exe


    Disabe System Restore and leave it disabled (just for now). Then run a scan with Avast. Does it still find things in System Restore.
     
  22. jrs40jas3

    jrs40jas3 Private E-2

    Well you arn't missing anything special... :D I have talked to the person that owns this computer and they told me to leave the Parental Controls and the Total Access Core Apps on there (which is part of the software). Everything else I have taken off.

    I didnt install Authentium? Havent heard of it?

    Fixed it in Hijack...


    Yes... and Ive tried to manually delete but it wont let me into the folder. Avast! also found 4 things in the C:\Windows\system32 folder...

    kernel32.dll (C:\WINDOWS\system32)
    pskavs.dll (C:\WINDOWS\system32\ActiveScan) (Win32:CTX)
    winsock.dll (C:\WINDOWS\system32)
    wsock32.dll (C:\WINDOWS\system32)

    Are these a problem?

    Also, I ran a SpyBot scan and it found 3 different items:

    Microsoft.Windows.RedirectedHosts (80 entries)
    Microsoft.WindowsSecurityCenter.AntiVirusDisableNotify (1 reg change entry)
    Microsoft.WindowsSecurityCenter.FirewallDisableNotify (1 reg change entry)

    Attached are some fresh logs... let me know if you need any others.

    Thanks again for all your help!!! :cool
     

    Attached Files:

    Last edited: Oct 11, 2007
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is part of the Earthlink/TotalAccess stuff. We will see if we can manually stop if later.


    Is System Restore still disabled? Even if your answer is yes, the files/folders here are still system files/folders and they are also hidden which requires that you use special procedures to remove them if the restore points (RPs) do not go away when SR is disabled. You will have to give me a log from Avast that shows the problem restore points.

    All of these are totally incorrect. The active scan one is even mentioned in the READ & RUN. The other 3 files are necessary Windows system files. Are you sure your copy of Avast is current and has all updates?


    Attach a log from Spybot but the last 2 are not problems. They just mean you are not set to Windows system defaults and that is because you are using your own antivirus and firewall. I'm not sure what the first is.

    Why are you using MSconfig? See the READ ME. If you don't need those items to ever load, uninstall them or permanently remove them.

    Let's now remove Authentium AV.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to DvpApi
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pastedvpapi into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.

    After reboot, delete the below folder:
    C:\Program Files\Common Files\Command Software
     
  24. jrs40jas3

    jrs40jas3 Private E-2

    Yes System Restore is still Disabled... See attached for the log.

    I knew they looked familar... but I just could not place where I saw them. so do these need to be restored out of the vault? Also, my Avast! has all the current updates. I updated it as soon as I installed it.

    See attached...

    There are some programs that are not in the Add/Remove Programs list or in the start menu that are still in the startup list that are not used. I have yet to figure out how to get them off...

    Done with no errors!! :)

    Also attached are some fresh logs.

    Thanks!
     

    Attached Files:

    Last edited: Oct 12, 2007
  25. jrs40jas3

    jrs40jas3 Private E-2

    pt 2 of logs.

    Thanks!!
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Go back to Normal Startup mode with MSconfig and then use HijackThis to permanently remove the startups.

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
      [*]It will create a folder named HostsXpert in whatever folder you extract it to.
      [*]Run HostsXpert.exe by double clicking on it.
      [*]click the Make Writeable? button.
      [*]click Restore Microsoft's Hosts File and then click OK.
      [*]Click the X to exit the program

    Now let's see if we can remove those restore points that did not go away.

    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the log from Avenger
     
  27. jrs40jas3

    jrs40jas3 Private E-2

    Got what I wanted off except of LogMeIn? Cant get it off?

    Attached are the Avenger and CCleaner logs.

    Also I will be out of town till next tuesday, so I wont be able to do anything with this computer until then. Have a good weekend!

    Thanks!!
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note, we do not need Ccleaner logs.

    You installed it, so if you don't need it uninstall it like I said in message # 23 when I said the below
    The Avenger did not find any of those restore points so I would have to assume they were already gone. Is Avast still detecting problems? Before running a scan with Avast, empty any quarantines or backups it may have made.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds