Too many issues to list

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kjhower, Apr 27, 2011.

  1. kjhower

    kjhower Private E-2

    First of all, I want to mention that I am running Win XP Pro SP2. I am also on a network where 3 of the 8 computers had different virus/spyware/malware issues over the last 2 weeks. Our breakroom computer I was able to wipe out the hard drive and reinstall Windows. The other computer was fine after running Malware Bytes. My computer however is completely messed up. I have attempted virtually everything and I am at a complete loss what to do next.

    The symptoms (random and can't link them to eachother):
    1) Windows Update icon on the system tray is yellow and suggests that it is Downloading, but always at 0%. I tried to go online and run the update, but the web page comes up with an error.
    2) Google redirects in Firefox
    3) Random sites and pop-ups (Mind Quiz and Crush Alert) show up randomly
    4) Internet Explorer (never used until I ran thru the clean up process) freezes up and I have to Ctr+Alt+Del to close it.

    What I've done to fix the problem:
    1) Ran several anti-virus, anti-spyware, anti-malware programs. The only "notable" thing it found was what it called a "Worm:Win32/Rorpian"
    2) Ran thru your house cleaning procedures and that's when I encountered the IE problem. I did not reset the router yet because it resets the IP addresses and we end up with lots of work to get it all set back up to working condition with printers, etc. I can and will if you believe that to be a problem after reviewing info I give you. I was also unable to rund the TDSSKiller program (it gets to about 80% and gets blocked).
    3) I foolishly paid for Spyware Doctor who apparently is not able to help me fix this problem (or at least I am not confident in their ability since the first process they had me do did not find a problem).
    4) I have not run ComboFix or RootRepeal because I believe the instructions suggest stopping before that and waiting for your professional help.

    So, there you have it. I am at a complete loss as to how to remove something or fix something that none of the software programs can find. I hate to throw more time and money at this problem without more specific help. I am very close to wiping out this hard drive and starting from scratch, but I was hoping the fixes would be faster than backing up my system and reinstalling all the stuff again. There are several programs used for work and I can use them right now without a whole lot of problems. I would lose an entire day of work (or more) if I had to delete and reinstall the whole system. Hopefully you can help me with this issue before the weekend, otherwise I may just make this my weekend project. :(

    I look forward to your response!
     

    Attached Files:

  2. kjhower

    kjhower Private E-2

    Here are a couple other logs that I found. Apparently the TDSSKiller completed a log every time I tried to run it, so maybe that wasn't a problem. I am only including the last TDSSK log along with the MBRCheck log.

    Let me know if it is necessary to run the ComboFix, RootRepeal and MGtools programs in order to have a good picture of the problem.

    Also, you will notice that I included 2 MalwareBytes files. The first one lists the infection (which I believe was the original or early on in the problem scheme) and the current one shows no infections. I didn't know if that info would help or not so I just included both.

    Thanks!
     

    Attached Files:

    Last edited: Apr 27, 2011
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    You need to use your Windows XP CD to boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    After running the fixmbr command then boot back to normal mode Windows and try running TDSSkiller now. Then attach the log. Also explain if you are still having any malware problems.
     
  4. kjhower

    kjhower Private E-2

    Thank you for the help/info. I wasn't completely sure about whether or not the recovery console was going to erase any of my data, so I made sure that I had everything backed up. ;) Once I had it all backed up, I was able to run the recovery console and the fixmbr. The boot up after that was normal and quite a bit quicker than it had been previously. I ran the TDSSKiller and I will attach that file, but it doesn't appear to have found anything. I also wanted to try out the other problems to see if I could make them happen again and so far I haven't had any problems. Right now it looks like my auto updates is downloading and not at 0%, the malwarebytes' found no issues, my internet is not redirecting, and my spyware doctor found 94 minor infections (tracking cookies, etc). So, I think that we are in the clear for now. Thank you for your help and I am curious if the fixmbr was the main problem all along or if it was a result of a virus/malware or something like that. I will probably be trying all the other "cleaning" tricks on a couple other computers on our network to see if that resolves some of their issues as well. Let me know if the tdsskiller file shows something different or if you have any other suggestions to clean things up or avoid future problems.
    Thank you again!
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    As I said, you had a Master Boot Record infection, and what we did fixed that. But some malware may remain, so I would like to have you do the below.

    Run Combofix and MGTools as per the instructions in the READ & RUN ME FIRST. Malware Removal Guide (Follow the link for your operating system)

    Then attach the C:\MGlogs.zip

    If anything is still hiding we will find it and remove it.
     
  6. kjhower

    kjhower Private E-2

    I have run both of those programs as directed and I am attaching the files. I know you didn't ask for both, but I figured that I have a limited work schedule so it would be easier to leave both of them and not have to worry about you needing the other one later.

    Let me know what you find.

    Thanks!
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall below outdated Java.

    • J2SE Runtime Environment 5.0 Update 6
    • Java(TM) 6 Update 24
    • Java(TM) 6 Update 3
    • Java(TM) 6 Update 5
    • Java(TM) 6 Update 7

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    C:\Documents and Settings\All Users\Application Data\{2162CCC0-3A5F-4887-B51F-CE5F195B3620}
    Folder::
    c:\documents and settings\Kim\Application Data\DriverCure
    c:\documents and settings\Kim\Application Data\ParetoLogic
    c:\documents and settings\All Users\Application Data\ParetoLogic
    NetSvc::
    srv58C
    srvE5C
    Driver::
    srv58C
    srvE5C
    Registry::
    [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\srv58C]
    [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\srvE5C]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  8. kjhower

    kjhower Private E-2

    Everything went very well with the processes you asked me to run.

    The only thing I noticed was that after running ComboFix, my web browser went back to Internet Explorer as the default and placed the icon on my desktop. There were no problems with it and I know how to change it, but it's just something I noticed. Other than that, everything seems to be running well.

    Thank you!
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Much better! :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  10. kjhower

    kjhower Private E-2

    Alright...things were going well until I completed all the steps and then decided to follow your suggestion to update my Win XP. It installed updates and restarted twice, and then it had 1 install left, which was the SP3 update. My computer started to install that update and it was taking a while, but seemed to be OK. For some reason, it seemed to have stalled (said it was running, but after 15 minutes it seemed as though it was hung up). Also, during this process, there was a pop-up box that said "Dr Watson postmortum debugger..." I didn't write it down when I saw it (I know, I should know better), but it didn't have an "x" button so all I could do to get rid of it was hit the close button. I realize that may not be the best thing to do, but I wasn't sure if it was a program installed during the update process, or what. Then, when my computer shut down, it came back with the blue screen (I didn't write that down either). I used the power button to shut down and when it restarted it gave me the option of normal start, safe mode, last known good config. I chose last known good configuration since I figured I had re-enabled the system restore and I had already rebooted my system a couple times after that. So, after rebooting in the last known good configuration, I was unable to get online. I can see my network and work on that and other computers are able to get online (that's how I'm sending this now), but I get an error every time I try to open Firefox or IE. I also don't think that I am able to download e-mails in Outlook, but I haven't spent a ton of time waiting to make sure that nothing comes thru. So, it may be some setting that has something to do with internet access but not network access. Looking for some help and an idea about how to resolve this.
    Thank you!
     
  11. kjhower

    kjhower Private E-2

    OK. I had thought that it didn't install SP3, but it must have installed it partially. So, I went to my add/remove programs and removed the SP3 and rebooted. After it restarted, I was able to open Firefox and IE and get online. I didn't/don't have any more time to deal with it today, but it appears to be back up and running. Maybe you can give me some advice as to why this might have happened and whether or not I should attempt it again.
    Thanks again for your help!
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Issues to discuss in the software forum I'm afraid. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds