Tried everything on my own - Need to fix ASAP!

Discussion in 'Malware Help (A Specialist Will Reply)' started by blackfrancis, Apr 20, 2009.

  1. blackfrancis

    blackfrancis Private E-2

    Thank you in advance for your time!! I use my computer for everything!!

    flec006.exe, wintems.exe, winupgro.exe... (random set of numbers).exe, this is killing me!! Please help!! Attached the logs from what my computer would let me run.

    BitDefender Quickscan: let me run it. (How I originally found the filetypes aside from task manager.)
    Malwarebytes Anti-Malware: let me run it.
    SuperAntispyware: "not a win32 application."
    CCleaner: does absolutely nothing when I click on it.
    Combofix: "not a win32 application"
    MGTools: let me run it.

    Quick note: when running MGTools, I had one popup error.

    C:\MGTools\temp\GRKflag.log exists. Deleting it!!
    Getting System Information
    POPUP: The system could not find the file specified.

    (I assume this just means it couldn't find a previous log file created from a previous scan with MGTools??)

    :confused
     

    Attached Files:

  2. blackfrancis

    blackfrancis Private E-2

    Still haven't been able to fix anything, and tried to install my Rogers Online Protection, everything but the virus/antispyware scanners will work, which is what I need, errr!! Sorry for posting again, just thought I would post a new MGTools log and Malwarebytes so if anyone reads this they can tell me if I haven gotten better or worse?? I'm still reading through to other threads to find a fix on my own as well. Thanks!
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You last MBAM log indicates that you didnt fix what it found.

    You also did not make the HJT license agreement.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\user\Local Settings\temp\

    Now download and install:
    Java Runtime 6

    Now I want you to see if you can run SAS and ComboFIx. Attach those logs if you can.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (make sure you do the HJT agreement). Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  4. blackfrancis

    blackfrancis Private E-2

    Tried to run Avenger, but gets the same old "Not a Win32 Application" Error. :confused
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  6. blackfrancis

    blackfrancis Private E-2

    Ran the procedure, here is the log.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now run the Cleaning step.
     
  8. blackfrancis

    blackfrancis Private E-2

    Yay so I was able to run the scans. Logs are below.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. blackfrancis

    blackfrancis Private E-2

    Ok, so ran combofix, ccleaner, and got the mglog. Attached them.. things seem to be running alot better than before... And I have successfully installed Rogers Online Protection which was full of erros before.. Thanks for your help, and I hope I'm clean!! :-rolleyes
     

    Attached Files:

  11. blackfrancis

    blackfrancis Private E-2

    ... actually, I'm not getting errors now with my programs.. but my computer is sooooo slooooow.... takes forever for it to do anything.. and internet explorer will just close or fail to open webpages until a second attempt due to it's incresed slowness..
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which programs? And you have to tell us the exact word for word errors???

    Before reinstalling Rogers RPS, did you first uninstall ALL of it and then reboot before reinstalling?


    A big reason why your PC is slow is due to having half the minimum amount of RAM I recommend for Windows XP. Your log shows the below:
    Code:
    Total Physical Memory 512.00 MB 
    Available Physical Memory 146.54 MB
    This is too small an amount of free RAM. Double your RAM to 1 GB.

    In addition the amount of stuff the Rogers Security Suite is running is not helping you.

    You are not supposed to be using MSconfig to control startups. See step 1 of the READ & RUN ME. You even have necessary services for Windows Defender and your Rogers Software disabled. If you don't want to use Windows Defender you should have uninstalled it but not while disabled with MSconfig which leaves orphaned registry entries.



    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll (file missing)
    O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)

    After clicking Fix, exit HJT.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: May 7, 2009
  13. blackfrancis

    blackfrancis Private E-2

    "Which programs? And you have to tell us the exact word for word errors???"
    Sorry about not explaining, I meant with my security software programs, that I wasn't getting the "Not Win32 App.." error anymore.

    If Rogers Security Suite software wasn't helping anything, what types of security programs should I use on a regular basis for prevention? I have removed it, set the MSConfig back to normal, and restarted before running the tasks you asked for.

    This is too small an amount of free RAM. Double your RAM to 1 GB.
    I cannot afford to double the RAM yet.

    Completed what you asked, and attached the log below.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It did not uninstall completely. I will give you another fix to try to remove it.

    Okay then you will have to live with the performance issues and possibly slow start up. I will make some more non-malware suggestions below that can help a little and we will clean up some left overs from no longer installed applications like Roxio which is still trying to load a service.


    There are two items from Rogers still installed. Uninstall the below:
    Rogers Servicepoint Agent 2.0.21
    Rogers Update Manager


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now. Some items may not be found after uninstalling other Rogers software.

    O4 - HKLM\..\Run: [RogersServicepointAgent.exe] "C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe" /AUTORUN
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)

    Also optionally fix the below to help improve performance. They are unnecessary startups.
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: May 7, 2009
  15. blackfrancis

    blackfrancis Private E-2

    Thanks for getting back to me and sorry for the late reply, I was out of town for a couple weeks.

    I have attached the logs below.

    I would also like to mention the issue of a ScanningProcess.exe that is always running on my PC? If I stop the task it just starts again, and takes up about 50% of my usage? When I researched it I found that mostly it is associated with ZoneAlarm, which I don't have, and not sure how to stop it from running?

    Things are running better, but again just wanted to ask you what you might reccomend as far as programs I should be running to protect my computer from virus, malware, etc., as Rogers was too much for too little... Any input you could give me on that as well would be greatly appreciated!
     

    Attached Files:

  16. blackfrancis

    blackfrancis Private E-2

    BTW will not let me post MGLog because it's already in the thread even if I rename it..?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to follow my instructions so that a new log is created before you try to attach the same file again. You did not run C:\MGtools\GetLogs.bat as requested.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is due to your Rogers software that we were removing. Once all of it is removed, you will not have this problem. Do not reinstall their software anymore.
     
  19. blackfrancis

    blackfrancis Private E-2

    Sorry!! I must've forgotten to run it. Here are the new logs, and I have gotten rid of Rogers software for good. Things run great without the Rogers. Now however I have no protection software running on my computer, do you have any reccomendations?

    Thanks again for your help!!
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Covered in my final instructions below since your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  21. blackfrancis

    blackfrancis Private E-2

    Thanks again for your help, so great to have everything running smoothly again!!!
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds