PC FUBAR from Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by riccoar, Oct 26, 2008.

  1. riccoar

    riccoar Private E-2

    OK, so I'm surfing the web when it closes. My AVG is disabled and I can't open IE anymore. I believe it was AntiSpywareXP2008 or something like that. I've run damn near every fix: Vundo, Smit, Winsock, etc.. And yes I realize that the guys who are reading this are telling themselves "How stupid id this guy?" Anyway, I was able to get AVG 8.0 loaded back and ran with no finds. However IE will not open up. I've even tried to removing old Java and those attempts only result in errors. I have updated Java to 6 Version 10. Here is a Hijack log:

    Logfile of Trend Micro HijackThis v2.0.2


    I'm at my wits end with this damn thing. Please HELP!
     
    Last edited by a moderator: Oct 26, 2008
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide

    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. riccoar

    riccoar Private E-2

    Thanks, Tim. I posted before looking. I'm in the process now. I have all the stuff downloaded and I'll have the results later tonight.
     
  4. riccoar

    riccoar Private E-2

    Read and Run Me First Complete. No Luck! So here is my scenario. I was logged into a messageboard and all the sudden my IE shutdown and my AVG disappeared. Windows Security pops up and says no Anti-Virus software found. Then up pops a screen with AntiVirusXP2009 telling me it has detected a Trojan virus. It starts scanning and promptly forwards me to a page telling me they will sell me their software to fix problem. At this point IE will not open and I can't open AVG even though I can see it in Explorer. Downloaded several things and ran them. VundoFix, WinsockxpFix, Malwarebytes, Regedit, HiJackThis. No fix. Never deleted anything from HiJackThis. I'm pretty sure the running of Malware was what made me able to get rid of the AntiVirusXP2009 and allow me to get AVG back up and running. Only problem I have now is when I click on IE it comes up with hour glass for a second, the window flashes for a nano second and closes. FWIW, I was not able to run MGTools because it did the same thing. Window would open real quick and close even faster.
    First three attaches are SuperAntiSpy log, Malware Quick1, and Malware Full2.
     

    Attached Files:

  5. riccoar

    riccoar Private E-2

    Next set of logs: ComboFix1, Combo Quarantined, SpyBot files.
     

    Attached Files:

  6. riccoar

    riccoar Private E-2

    Next set: SpyBot Sched, CClean log, and HiJackThis log.

    Thats all the info. I'll wait for suggestions.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have a lot still to do, and I need the C:\MGLogs.zip from running the C:\MGTools.exe.
     
  8. riccoar

    riccoar Private E-2

    Won't let me upload it. Says invalid file. Here are some logs from when I just ran the GetLogs inside of MGTools.
     

    Attached Files:

  9. riccoar

    riccoar Private E-2

    More.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  11. riccoar

    riccoar Private E-2

    Here they are.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet.....your logs are clean.

    If you are not having any other malware issues, it is time to do our final cleanup:

     
  13. riccoar

    riccoar Private E-2

    I'll do these steps when I get a chance a little later tonight. Why will the IE still not open up?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have another browser installed? Does it work? What version of IE do you have?
     
  15. riccoar

    riccoar Private E-2

    I'm running IE 7. Also, when I try and get rid of the old Java 6 Update 7 it tells me "Internal Error 2753. RegUtils." I'd like to scrub Java all together and just re-install and do the same with IE. When you click on IE it starts to open the IE for just a brief second and then closes. You can even see it flash into Task Manager for a brief second and then disappear. What would be the best way to scrub IE and Java and start over? Or what do you recommend?
     
  16. riccoar

    riccoar Private E-2

    I'm also keeping SuperAntiSpyware, Malwarebytes, and CCleaner. I was using Regcleaner.exe but CCleaner seems to be a better utility.
     
  17. riccoar

    riccoar Private E-2

    OK. I loaded Firefox and it works. Something must be up with IE. I found a program script to remove Java. It's called Uninstall-java.bat Can't upload the file for review. I went back out and reloaded Java 6 Update 10 afterwards. However Java 2 Runtime Environment, SE v1.4.2.03 and Java 6 Update 7 still show in Control Panel. The script could not remove these I guess.
     
  18. riccoar

    riccoar Private E-2

    And it also appears my Microsoft Office has been uninstalled. How? I have no idea.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am at a loss as to how you lost office....some of these issues should probably be addressed in the software forum. You could try uninstalling IE7 and then reinstalling. Make sure you run CCleaner and reboot before re-installing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds