Read the Read Me First thread and problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by paulzie32, Feb 21, 2010.

  1. paulzie32

    paulzie32 Private E-2

    Hey all,
    Well, I had some how downloaded av.exe and have had nothing but problems. I even had AVG running at the time and it missed it some how. I used a restore point and that seemed to get rid of it, or so I thought. Unfortunately, I lost Microsoft Excel and Word. I don't know how, but the shortcuts go no where. Then today (three days later) I started getting Windows Antivirus popups again... or was it Microsoft? I forget... but I knew it was av.exe. So, I tried another restore and when it rebooted, AVG found av.exe this time. I removed it and not even internet explorer worked. I then did a full restore and this time I got Internet explorer working.
    So, since the last time (a few years back) that I had a virus, you guys really helped, I came here and searched for av.exe (as it's still in the system). I found a thread referring the OP to the READ ME FIRST thread, which was what you referred me to last time too. I started following it and got to running Super Antispyware. I ran it and it found two locations of av.exe. Unfortunately, I didn't make a note of where as the directions stated to reboot and then go to preferences and copy the log. Well, the program is gone after the reboot. The shortcuts are there as are the start menu items. But when I click on any of them I get a popup
    "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Windows cannot find 'C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe'. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search."

    I even went to the start menu and tried the repair link and it didn't work.
    What should I do next?
    Also, I have the frigging virus on my laptop and another PC in the house! I have no idea how I got it either! The other guy said it was from Winrar. I did recently install it on all my computers Right from Their Website!!!
    TIA for the help.

    Paul
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And what about all of the other requested logs? Do you have those? Were you able to run them?

    I cannot help you without at least seeing logs from MGTools and ideally from combofix as well.
     
  3. paulzie32

    paulzie32 Private E-2

    Well, No. I didn't go any further because I thought if I did, there may be no way to recover the log from SAS.
    But I guess you're saying I should have so I'll finish it now and attach the other logs.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK. I'll be here waiting :)
     
  5. paulzie32

    paulzie32 Private E-2

    Ok, I just tried to install Malwarebytes' Anti-Malware and I got the same message I got when I tried to reopen SAS. I even tried downloading it again and saving it to my desktop. After downloading and getting the option to "open" I tried and got the same message -
    Windows cannot find 'C:\Documents and Settings\Owner\Desktop\mb.exe'. Make sure you typed the name correctly and then try again. To search for a file, click the Start button, and then click Search."
    The Executable File is RIGHT THERE too. I even checked to see if SAS is still installed and it is! The SAS folder is there C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    So, what is causing me to not click anyof these files? It's the same thing that's preventing me from opening many of my other programs like Excel, Word, Notepad, Wordpad, etc.
    Anyideas?
    Do a system Restore again?
    Help :-(
     
  6. paulzie32

    paulzie32 Private E-2

    AAH! I figured it out!!! I right clicked and 'open as...' and a window poped up with a few keys and " Which user account do you want to use to run this program?"
    Current user was selected and there was a check in "Protect my computer and data from unauthorized progam activity

    This option can provent computer viruses from harming your computer or personal data, but selecting it might cause the program to function improperly."

    So, I unchecked and can now install. I tried with SAS and even though the message doesn't pop up, It also doesn't load the program... Will post any logs I can save after all installations
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes just continue and and do what you can :) Attach logs when you are ready.
     
  8. paulzie32

    paulzie32 Private E-2

    Ok... I ran all programs and didn't run into any errors. Unfortunately, many of my shortcuts still do not work. I've tried opening many of the programs on my desktop or from the start menu and I get errors like those below

    "XXX" cannot run because of missing or invalid registration information. Please reinstall.

    Problem with Shortcut
    The parameter is incorrect.


    Problem with Shortcut
    This action is only valid for products that are currently installed.


    But yet all programs are still in C:\Program Files\
    For instance, if I try to run Microsoft Excel (a program I use a lot for work), I get the third message listed above. When I got to the Programs folder and open Microsoft Office folder and click Excel.exe I get
    "Microsoft Office
    This application must be installed to run. Please run Setup from the location where you originally installed the application."


    It came installed on the computer! I have no idea where it was originally installed.
    Anyway... If you can help with those problems, great. The logs are all attached.... Except the one for SAS as the max no. of attachments is 4... I'll attach it to next message

    View attachment combofixlog.txt

    View attachment mbam-log-2010-02-22 (11-32-28).txt

    View attachment MGlogs.zip

    View attachment RRLog.txt
     
  9. paulzie32

    paulzie32 Private E-2

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Do not attempt to upgrade just yet, but just to let you know you should have SP3 or at LEAST SP2 installed by now. Not doing so will leave you more at risk.

    2. And downloading torrents for cracked software is always a nice quick way to get infected :( You need to stop doing this.

    3. What software are you using from symantec?

    4. SAS is out of date but we will deal with that later.

    5. You have missing files which you can replace using your windows XP CD.

    We will see how your computer is running after doing that as well as the below:

    6. Now we need to use ComboFix to remove some files/folders and clear up from the avg that you were using.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\Owner\Local Settings\Application Data\0rTsTo
    C:\Documents and Settings\Owner\Local Settings\Application Data\102kpasP22m
    C:\Documents and Settings\Owner\Local Settings\Application Data\rGu4hX2
    C:\Documents and Settings\Owner\Local Settings\Application Data\v66l66MW5Tq
    C:\System32\ALCXMNTR.EXE
    
    Folder::
    c:\documents and settings\Owner\Local Settings\Application Data\fykdqw
    c:\documents and settings\Owner\Application Data\AVG9
    C:\$AVG
    c:\program files\AVG
    c:\documents and settings\All Users\Application Data\avg9
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AlcxMonitor"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    7. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    8. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  11. paulzie32

    paulzie32 Private E-2

    Ok, completed as much as I could. Unfortunately, I no longer have the disks, do you know of another way to get those two - wscntfy.exe and xmlprov.dll ?. This computer was one from my office and was set up and used by another employee before I got it. So, Aside from Excel and Works still not working, I suppose the rest works ok.
    As for my other computers, should I use this same thread to post the logs for them too?
    As for the final two logs, they're attached. What do they say? all better aside from those two files?
    View attachment log.txt

    View attachment MGlogs.zip

    Oh yeah... I'm not using any Symantec software anymore. It expired and I never renewed it.
    Also, How do I upgrade to SP2 or SP3?

    Which of these Malware, Spyware or Antivirus programs should I keep and which (along with logfiles) should I get rid of?

    Thanks
    Paul
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then please do the below:

    Go to add/remove programs and uninstall:

    • LiveReg (Symantec Corporation)
    • LiveUpdate 1.80 (Symantec Corporation)

    Next, please give the Norton Removal Tool (SymNRT) a run > reboot your machine and then run it again for good measure.

    You can discuss this in the software forum.

    You also need to install some anti virus!

    Keep SAS and MBAM, the final steps I give you will remove the rest.

    Also, you can discuss the replacement of the missing files in software too.

    Now if all is running okay apart from the afore-mentioned then:

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds