Problems involving software-blocking and start-up

Discussion in 'Malware Help (A Specialist Will Reply)' started by zackteach, Dec 22, 2009.

  1. zackteach

    zackteach Private E-2

    I was on a torrent site earlier today, one that I have gone to for a decent amount of time now, and my Avira Antivirus abrubtly started warning me of an infection of some sort of trojan virus. I had not downloaded a torrent at this point, I was simply using the search feature on the website. Anyway, it would warn me twice at the same time about the same trojan, or at least I believe it was the same trojan. The names were identical or extremely similar. I did end up downloading a couple things, and I've noticed since then that 1 file in particular will not allow me to delete it, it's always in use, even in safe mode. However, I was getting these warnings before that file had been downloaded.

    I simply told it to quarantine and delete these trojans each time, but for the next several minutes even after leaving the site and closing the browser (firefox), I got these warnings. I decided to restart my computer and after that, the program blocking began. Microsoft Security Essentials, Avira Antivirus, Malware Bites Antimalware, Super AntiSpyware all became unusable, even in diagnostic mode, even in safe mode.

    As a result, I do not have the name of the trojan that Avira detected. I wish I had written it down when I saw it, but I didn't exactly expect to be blocked out. Poor reaction on my part I guess, but now the other symptoms I have is various programs that make no sense being ran in my background. Through task manager, I can see iexplore for some reason, along with aimtbserver.exe and occassionally SkypeNames.exe and these are programs that normally are not running. I do have Skype, but it's not auto-start. On top of that, it takes a few tries for my computer to successfully boot. It'll get to the point where windows is supposed to kick in, but it has a seemingly random chance of just sitting there. Just now, it took 4 tries for me to finally get it going. Earlier, it took 2. Not sure if it's getting worse or if it's really just random.

    So that's my problem. Something nasty has gotten on my system and I'm at a bit of a loss on how to clean it off. I'm running a Windows XP system by the way. It would appear I also have a bit of a search-engine redirection problem too, though I think that's unrelated as it's been around for awhile and I've been ignoring it (which is unwise I know but I can be apathetic about things if they don't seem to be hurting anything otherwise).

    Any suggestions?
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please try doing the below:

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then doube click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running.


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log.

    Then try running these instructions: Using MGtools


    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  3. zackteach

    zackteach Private E-2

    Thank you for the reply my good sir (or ma'am).

    I've attached the logs you requested, and I ran the superantispyware online scan. That's actually the 2nd time I've ran it. This time I ran it, it didn't find anything significant as far as I know. Just Adware Tracking Cookie and Registry Cleaner Trial. The first time I ran it was shortly after I started having these problems, and it did find more things, which I removed and restarted after the removal.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The version of MGTools you have is very outdated. I do not know where you got this from as our READ me always hosts the latest version.

    I am going to have you download combofix and a fresh copy of MGTools next, and please remember when running MGTools that when HJT asks you to agree to the license that you do so. (You may have to click the button and agree twice, yes it's a bug)

    So let's get started -

    1. Go back to the READ ME and download a copy of combofix. Run it, and when prompted please install the recovery console.

    2. Now go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    3. Run the new MGTools.exe

    4. In your next reply attach:

    • C:\combofix.txt
    • C:\Mglogs.zip

    Thanks
    Kes
     
  5. zackteach

    zackteach Private E-2

    I downloaded Combofix, however I'm under the assumption that it's a blocked program now due to the fact that it simply won't do anything when I try to start the program. So as a result, I cannot provide a log from a program that's refusing to start :(

    As for MGTools, I downloaded it from the link you provided me. The first link, big bold letters saying MGTools in the first sentence of that post. I decided to delete the MGTools that was on my system and redownload it, but I don't know if that'll actually matter. Here's the log from that attempt.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I did not see ComboFix on your Desktop so where exactly did you download it to before you attempted to run it?

    1. Please go to add/remove programs and uninstall the following softwares, if you receive any errors just continue on with my next steps.

    • Messenger Plus! 3
    • Viewpoint Media Player
    • J2SE Runtime Environment 5.0 Update 10
    • J2SE Runtime Environment 5.0 Update 11
    • J2SE Runtime Environment 5.0 Update 8
    • Java 2 Runtime Environment, SE v1.4.2_01
    • Java(TM) SE Runtime Environment 6 Update 1
    2. If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.
    3. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O4 - HKUS\S-1-5-18\..\Run: [Hhreg] C:\WINDOWS\system32\m?config.exe (User 'SYSTEM')
    • O4 - HKUS\.DEFAULT\..\Run: [Hhreg] C:\WINDOWS\system32\m?config.exe (User 'Default user')
    After clicking Fix exit HJT.


    4. Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    5. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    6. Now please use MSConfig to put this machine into normal start up mode as requested in the READ ME.

    7. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from avenger.

    8. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
    Last edited by a moderator: Dec 24, 2009
  7. zackteach

    zackteach Private E-2

    I was dumb and downloaded Combofix to a folder on the desktop. I moved it to the desktop itself though and it still wouldn't run :\

    Avenger had an error during the run process, I thought maybe you'd wanna know that.

    Error: Invalid registry syntax in command: "[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\16304844" Only registry keys under the HKEY_LOCAL_MACHINE hive are accessible to this program. Skipping line. (Registry key deletion mode)

    That was the only error though.

    After restarting from Avenger, it took 4 tries to get my computer to successful boot up again and the issues I described earlier are still happening.

    Here's the log from MGtools :D
     

    Attached Files:

  8. zackteach

    zackteach Private E-2

    This is not meant as a bump, I just can't figure out how to edit my posts so I have no choice but to reply. At least it's only about an hour after my other reply.

    I found a combofixlog that I'm unsure where it came from, the date on it suggests it's several months old buuuuut there's stuff on it that I didn't have from the time period it claims to originate from, so I'm not sure what to make of it. Here you go.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.



    Make sure
    that you tell me if you receive a success message about adding the above
    to the registry!!! If you do not get a success message, it definitely did not work.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    After completing the above I would like for you to run SUPERantispyware and Malware Bytes, update both, run scans, and fix all each program finds. Attach logs regardless or not of if they found anything.

    Thanks
    Kes13!
     
  10. zackteach

    zackteach Private E-2

    Here's the new MGTools log, the registry edit was a success. However, Malwarebytes and Superantispyware still won't open. I tried to restart to see if maybe that'd help, since we just edited the registry keys. It took 3 tries to restart, and when it finally worked, it still wouldn't open the programs. :\
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    File::
    C:\WINDOWS\system32\H8SRTyveyfokocp.dll
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    2. Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    3. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.
     
  12. zackteach

    zackteach Private E-2

    None of my antivirus or antimalware type programs are operating at all at this point in time. I copied the text inside the quote box in to notepad and saved it with the CFscript filename to my desktop, which is also where the ComboFix.exe file is located. I dragged the text file on top of the exe file, but nothing happened. I did close all of my browsers before trying. I thought maybe something was still open that I couldn't see, so I restarted my computer (which surprisingly only took one try this time) and it still did not have any effect.

    I should note here that when I went to restart, I went into msconfig and disabled avira antivirus from trying to start whenever my computer is booted. I figured maybe that could be why, maybe it was running in the background or trying to run or something. Interestingly enough, I've restarted twice since then and it went normally after disabling avira. Perhaps that's why I was having restarting issues, it was conflicting with the virus.

    Anyway, it did not launch combofix. I followed the directions as stated, so I'm under the assumption that this is a rather damned frustrating thing.

    :(

    I still did the other 2 steps below however, so here's the logs.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  14. zackteach

    zackteach Private E-2

    I had no problems doing those steps, though it was interesting to note that after I restarted from using Avenger, a small box popped up in the center of my screen before the Explorer loaded. I couldn't see what it was saying though, because my computer restarted a split second after the box appeared. Other than that though, it went fine.

    Also, this suddenly allowed my antivirus programs and combofix to work again, so I ran combofix and have attached that log too. And somehow during combofix's scan, my avira antivirus picked up an infection (Which doesn't make any damn sense since it was off on start up and combofix didn't detect it being on either) but I wrote down the name of the trojan it detected, which it warned me about twice in a row. I'm thinking it's the trojan I got originally.

    Tr/Pck.Tdss.AA.2537 was the detection.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Getting there...

    1. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    Driver::
    qufdmuy
    Viewpoint Manager Service
    ATE_PROCMON
    
    File::
    c:\windows\048298C9A4D3490B9FF9AB023A9238F3.TMP
    C:\Documents and Settings\All Users\Application Data\sysReserve.ini
    c:\windows\system32\drivers\onsgv.sys
    d:\anti trojan elite\ATEPMon.sys
    
    Folder::
    c:\program files\Viewpoint
    
    Registry::
    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
    "NoSetActiveDesktop"=-
    "NoActiveDesktopChanges"=-
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    2. Now run TDSSKiller again.

    3. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix and TDSSKiller.

    4. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  16. zackteach

    zackteach Private E-2

    Thank you again, I had no troubles running the programs :)

    Here's the logs you've asked for. Sorry I took days to reply, I suck.
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your logs are now clean from what I can see! :)

    Just a few things now:

    Please ensure that you use MSconfig to put the machine into normal start up mode if you havent already done so. If you already are, then you must be using other software to control what's running at start-up.

    Use Windows Explorer to locate the following directory and delete it:

    c:\windows\048298C9A4D3490B9FF9AB023A9238F3.TMP

    Now install yourself the latest Java:

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Let me know if the directory deleted okay or not and then I can give you final steps.
     
  18. zackteach

    zackteach Private E-2

    The directory deleted just fine :) Thank you :)
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are welcome!


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds