Please help ive tried everything

Discussion in 'Malware Help (A Specialist Will Reply)' started by NoobyTron, Jun 29, 2009.

  1. NoobyTron

    NoobyTron Private E-2

    Hi and thank you to any potential helpers to sum it up about 3 days ago my computer froze and when i rebooted it was completly taken over by viruses i cant run sas spybot combo fix or mbam i click it and it just does nothing i tried to run cf in safe mode but has an error message i was able to run symantec and found about 20 diff kinds of trojans and quarentined them but nothing was fixed all my restore points were removed to and i couldnt open hikackthis as well please help ill be trying to fix this around the clock i dont want to reformat
     
  2. NoobyTron

    NoobyTron Private E-2

    by the way i did the read and run me first thing but i cant get any of the programs to run
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome :)

    1. Have you tried the below:

    TDSSserv Non-Plug & Play Driver Disable


    2. Also have you tried running MGTools.exe in safemode as you only mentioned combofix but I also understand that you did say none of the tools would run.

    3. Could you get RootRepeal to run?

    4. Let's also try this:

    Go to the C:\MGtools folder and locate the RunMB.bat file and double click on it to run it. This will attempt to make a renamed copy of the Malwarebytes program (named mgmb.exe) and then it will attempt to run this re-named version. If this runs, it will try to perform a QuickScan. Allow it to finish, then fix all the malware it finds. Then save the log. Attach this log if it does run.

    5. Let me know how you get on :)
     
  4. NoobyTron

    NoobyTron Private E-2

    Ok im not sure if im posting this right but first of all thank you very much for the help ive managed to get most of the stuff running and i will now try and atempt to post the results please further instuct me on what to do thanks again
     

    Attached Files:

  5. NoobyTron

    NoobyTron Private E-2

    These are all the tests results i tried to post them correctly let mr know if i did thanks again
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi :)

    whilst I am going thru the logs you have given me, could you please attach the whole mglogs.zip ---> C:\mglogs.zip

    Thanks
    Kes
     
  7. NoobyTron

    NoobyTron Private E-2

    Hey again and thanks again for helping im going to try and send it let me know i do thanks
     

    Attached Files:

  8. NoobyTron

    NoobyTron Private E-2

    wont let me upload winfiles.txt but these are the rest i think
     

    Attached Files:

  9. NoobyTron

    NoobyTron Private E-2

    heres part 1
     

    Attached Files:

  10. NoobyTron

    NoobyTron Private E-2

    part 2 was to big had to
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    did you not locate the mglogs.zip zipped file which is sitting right on your c drive or should be? Ideally I don't want you attaching them seperately, and besides so far you haven't attached entirely all of the logs that are included in the mglogs.zip

    Take a look in your c drive and see if you can attach the actual zipped file whilst your still online :)

    Thanks
    Kes
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    okay I'll work off what you gave me. But next time it's much easier if you attach the whole zipped file :)
    Will get back to you with a set of instructions as soon as possible. Thanks for your patience during this time.

    Kes
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please disable Spybot Search and Destroy's "Teatimer" function as it will interfere with my fix... to do this please see the below:

    How to disable Spybot's TeaTimer

    2. Also go to add/remove programs and uninstall Viewpoint Media Player as requested in the R&R.

    3. Now I would like for you to run scannow as you have a missing file that will need replacing. scannow should take care of this, please see the below:

    Running SFC Scannow


    4. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    After clicking Fix exit HJT.


    5. Now we need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    ae3c6cb
    
    
    File::
    C:\gklrwl.exe
    C:\ccu.exe
    C:\qfi931.exe
    C:\xxqkc.exe
    C:\c9hxft.exe
    c:\windows\system32\drivers\ae3c6cb.sys 
    C:\-1672281366
    C:\WINDOWS\010112010146118114.dat
    C:\WINDOWS\0101120101464849.dat
    C:\WINDOWS\934fdfg34fgjf23
    C:\WINDOWS\ld12.exe
    C:\WINDOWS\sysguard.exe
    C:\WINDOWS\system32\tpsaxyd.exe
    C:\WINDOWS\system32\iehelper.dll
    C:\WINDOWS\system32\comsa32.sys
    C:\WINDOWS\system32\wiawow32.sys
    C:\WINDOWS\system32\drivers\391042d2.sys
    C:\WINDOWS\system32\drivers\ae3c6cb.sys
    C:\Documents and Settings\_\Local Settings\temp\103828432mxx.dll
    C:\Documents and Settings\_\Local Settings\temp\20.tmp
    C:\Documents and Settings\_\Local Settings\temp\a.exe
    C:\Documents and Settings\_\Local Settings\temp\dailybucks_install.exe
    C:\Documents and Settings\_\Local Settings\temp\db.exe
    C:\Documents and Settings\_\Local Settings\temp\fhkutyd42jnh4rikdtyjnghjn44.exe
    C:\Documents and Settings\_\Local Settings\temp\fhkutyd42jnh4rikdtyjnghjn42.tmp
    C:\Documents and Settings\_\Local Settings\temp\install.48349.exe
    C:\Documents and Settings\_\Local Settings\temp\office.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\office.exe
    
    Folder::
    C:\32788R22FWJFW
    c:\documents and settings\All Users\Application Data\12274844
    c:\documents and settings\All Users\Application Data\IHVOBEKABH
    c:\documents and settings\All Users\Application Data\DZUOBEKABH
    C:\WINDOWS\System Volume Information
    C:\Documents and Settings\All Users\Application Data\McAfee
    
    DirLook::
    c:\documents and settings\_\Tracing
    c:\documents and settings\All Users\Application Data\~0
    c:\program files\PC
    
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "LowRiskFileTypes"=-
    "sysldtray"=-
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    6. Also delete all files in the below bold folder -- except ones from the current date (Windows will not let you delete the files from the current day).
    7. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix

    8. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  14. NoobyTron

    NoobyTron Private E-2

    could not find these when running hjt now i had to skip the step with windows sp2 cd because i dont have the disk but wil be getting it soon from a friend does that matter? O2 - BHO: BHO - {8567edfa-408c-43e9-b929-4c25c04f5003} - C:\WINDOWS\system32\iehelper.dll
    O4 - HKLM\..\Run: [sysldtray] c:\windows\ld12.exe
    O4 - HKCU\..\Run: [LowRiskFileTypes] C:\WINDOWS\sysguard.exe
     
  15. NoobyTron

    NoobyTron Private E-2

    C:\Documents and Settings\_\Local Settings\temp
    how do i delete these ?? at what chance to the offer me to delete anything? i just got done with the combo fix will be posting all the results just wondering how i do this step where do i go to remove C:\Documents and Settings\_\Local Settings\temp
    files?
     
  16. NoobyTron

    NoobyTron Private E-2

    so far
     

    Attached Files:

  17. NoobyTron

    NoobyTron Private E-2

    here i think
     

    Attached Files:

  18. NoobyTron

    NoobyTron Private E-2

    i had to seperate winfiles into 2 section because it wouldnt upload the whole thing because it was to big
     

    Attached Files:

  19. NoobyTron

    NoobyTron Private E-2

    part 2
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It would have much easier had you attached the whole zipped file as opposed to seperating them like you have which I explained in a previous post.

    It makes it harder for you, and would be much easier for me to download a single file. Not to worry... I shall go thru your logs and get back to you as soon as I can. :)
     
  21. NoobyTron

    NoobyTron Private E-2

    Hey sorry about that im just not sure how to attach the whole file or i probably do i just couldnt figure it out anyway thanks again and im still waiting on the windows sp2 cd when i get that i will do the step i had to leave out and also i was wondering when i did the combofix step i did it in safe mode does that matter? and i dont have the windows recovery cinsolke installed cause theres no internet connection in safe mode if this matter at all please let me know what to do thanks alot
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please put this machine into normal start up mode, you should not be using msconfig to control start-up's as it is chiefly a diagnostic tool for trouble shooting purposes.

    2. Please go to add/remove programs and uninstall the following software as requested in the R&R:

    • Viewpoint Media Player

    3. Use Windows Explorer to find and delete the below bold file: (Let me know if you were able to successfully do so)

    c:\windows\bf23567.dat


    and finally...

    4. If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  23. NoobyTron

    NoobyTron Private E-2

    Hey thats for all the help so far i was unable to remove c:\windows\bf23567.dat im not sure what u mean by use windows explorer but i tried with IE and it took me to a blank page also my comp is running ok besides that fact that i cant log in as admin if i right click a program and click run as it says current user (IB-BE629C563508) and if i click run as admin it needs a password and i never made a password so i dont no what the hell is going on lol
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Using Windows Explorer:

    Right click start > choose "explore" and then navigate to C:\WINDOWS directory, double click that > look VERY carefully for the file in question bf23567.dat and see if it lets you right click and delete it. Let me know!

    The other issues you are having will have to be worked out in the software forum as it is not malware related. :)
     
    Last edited: Jul 9, 2009
  25. NoobyTron

    NoobyTron Private E-2

    MAN O MAN i retsrarted msconfig in normal mode and all types of chit popped up now i cant even get online my devices got big yellow ?'s on them im typing this from my laptop
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    step 1 of the READ & RUN ME told you how to control startups where it gave the below:

    Read this to better understand why not to use MSconfig: Dealing with Startup Processes


    Please get me a new mglogs.zip now by doing the following:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Thanks
    Kes
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds