Please Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Friskypants, Apr 28, 2010.

  1. Friskypants

    Friskypants Private E-2

    Hi,

    Any help with my computer issues would be much appreciated.

    I followed the procedures in the Windows XP Cleaning Procedure and I'm still experiencing problems with search results redirecting me to other websites and XP Defender continues to show up sporatically. I'm not sure if it's the virus/malware but internet connectivity is also temperamental.

    I ran all of the listed scanning programs EXCEPT for Combofix. When downloading it I got a prompt saying something about the contents of this folder not being allowed to be changed. I tried several times to download to other locations but not luck. I've attached the logs for the other programs though.

    Thanks in advance.

    -Mike
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi and welcome. I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. :)
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Before we continue you must use msconfig to put this machine back into normal start up mode.

    2. Please go to Add/Remove programs and uninstall the following software:

    3. If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    4. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.


    5. Now please double-click the RootRepeal.exe previously downloaded.
    • Select File then Scan
    • On the Select Drives form select drive C by "ticking" the box for drive C and click OK
    • When the scan is complete - highlight each of the following file(s) (one at a time if more then one is listed) by left clicking it. Then use right mouse click and select the Wipe File option only for each file.

      • c:\windows\temp\asat0000.tmp
    • After Wiping all files, immediately reboot your pc!
    After reboot, continue with the below.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    7. Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).

    8. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    9. Now run combofix at this point.

    10. Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    11. Tell me how the computer is behaving now.
     
    Last edited: Apr 28, 2010
  4. Friskypants

    Friskypants Private E-2

    Hi Kestrel13!,

    Thank you for your response and taking the time to help me with my computer problems. Please bear with me since I'm fairly computer illiterate.

    Since about yesterday any programs I try to open prompts me with the "open with" list. I choose the appropriate program and the program opens like normal. Msconfig.exe just did the same but i browsed for the file and was able to open it. After changing the startup to Normal, I get a message saying an error was returned while trying to change services and I should be logged in as an administrator, which I already am. I tried it over again and the Normal Startup is selected already so I'm assuming it worked?

    Add/Remove Programs won't open. I get an error "C:\windows\system32\rundll32.exe Application not found" I'm not sure what this means or if there is a way around this.

    I did disable windows messenger, but I'm not sure if I should continue with the other steps if I can't complete the Add/Remove step.

    Thank you,
    Mike
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Continue on with what steps you ARE able to complete :)
     
  6. Friskypants

    Friskypants Private E-2

    Hi Kestrel13!,

    So i completed what i could, but I ran into some problems along the way.

    1. Add/Remove Programs will not open for me so I skipped that.

    2. I can't seem to access my antivirus/antispyware program(McAfee) to disable it, but I went ahead with the steps anyway.

    3. Ran RootRepeal.exe. Was not able to wipe all the files. Particularly C:\hiberfil.sys. The program would just freeze up and stop responding when attempting to do so. I tried it a couple times but same result each time.

    4. Installed and ran Avenger. Got and error message saying "invalid registry syntax in command" for the [hkey_local_machine\..." I tried just copying the "Files to delete" portion and that worked, but not the "Registry keys to delete"

    5. Deleted files in
    Except for Asat0000.tmp, I got an error message about that file being in use.

    6. Computer still will not allow me to download and run Combofix

    7. All programs that I try to run require me to "open with". I've been browsing for the program file to run it. So far I haven't been redirected to random sites from search results on google.

    Thank you for your help.
     
  7. Friskypants

    Friskypants Private E-2

    I forgot to attach the MGLogs.zip
    Thanks again for your help!
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Error in my syntax on the BHO's, I apologise, but all is well on that side of things, I now need to address a new file that has appeared and kill off some more. Let's see if we can make some progress.
    I did not ask you to wipe C:\hiberfil.sys with RootRepeal! It's a valid file.

    1. Navigate to the C:\MGtools folder and double click the FixFA.bat file to run this batch file which will run very quickly. So we will see if this helps your access to add/remove programs. If so uninstall what I previously requested:

    • Ask Toolbar
    • J2SE Runtime Environment 5.0 Update 4
    • J2SE Runtime Environment 5.0

    If it does not help, just continue on.

    2. Use windows explorer to find and delete any remnants from using avg (they are all folders):

    • C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\avG
    • C:\Documents and Settings\All Users\Application Data\avG
    • C:\Documents and Settings\HP_Administrator\Templates\avG

    3. Open up MalwareBytes now, click on the update tab > let it update > re-scan > fix all it finds > and attach a log regardless of if it did find anything or not.

    4. Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.

    5.
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    6. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\WINDOWS\TEMP

    7. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this , and also attach the new logs from both MBAM and SAS.

    8. Let me know how the machine is behaving now.
     
  9. Friskypants

    Friskypants Private E-2

    Hi Kestrel13!,

    The computer seems to be running fine now! It's only been about an hour but I was able to complete all the steps in your last instructions and computer seems to be back to normal. I attached the logs. Please let me know if you see anything of concern.

    Thanks so much! I owe you big time!

    -Mike
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I do apologise for the delayed response. I have had to do alot of over time at work due to people being off sick. :(

    1. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    2.
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    3. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    4. Don't forget to install the latest java ;)

    5. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  11. Friskypants

    Friskypants Private E-2

    Hey Kestrel13!,

    No worries about the delayed response. I appreciate that you're helping me out despite being busy with work.

    All the steps went smoothly, i think.
    One thing that caught my eye:
    While deleting files from the Temp folders, there was one file that wouldn't delete. Iadhide5.dll It says it wasn't created on the current date but I keep getting an error message when trying to delete it. "Can not delete Iadhide5: Access is denied
    Make sure the disk is not full or write-protected and that the file is not currently in use"
    Judging by the name I wasn't sure if it was something I should be concerned about.

    I attached the logs from the MGtools scan and Avenger as well, just in case.

    thanks again!
    Mike
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks for understanding :)

    Those logs look good now. Let's just do this to finish off -

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. Friskypants

    Friskypants Private E-2

    Hi Kestrel13!,

    Thanks for all your help. I completed all the steps in your last reply and everything seemed to be fine.

    But I keep getting pop tabs. With Firefox open, a tab will open on it's own for some advertisement. and my internet connection will disconnect once or twice a day. Any idea what else I could do to fix this problem?

    Thanks again!
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello there. :) What happens when you use adblocker plus? Do the pop up's still occur then? What do the pop up's say? Could you describe them?
     
  15. Friskypants

    Friskypants Private E-2

    Hi Kestrel13!,

    I installed the adblocker plus and I haven't experienced any pop-up tabs yet. Typically they appeared to be a fake news article, i think from CNN, about making money by working from home.

    Computer seems to be running a little slower, but that might just be in my head. Internet connection seems to fail more often now. About once every other hour. It's a wireless network so randomly it'll say it can't detect a network and repairing it doesn't fix the problem. Restarting the computer gets it working again though. Maybe my wireless card needs to be replaced?

    Thanks again!
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This is topic for the networking forum, where you can post and get help regarding the problem.

    You're most welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds