Trojan/Virus/Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lirpa, May 27, 2008.

  1. Lirpa

    Lirpa Private E-2

    Hey there. I am new to these types of forums so be patient with me :) Yesterday I downloaded a video codex and all of a sudden my pc went crazy the next time I rebooted. I searched the forums across the web and downloaded and installed some programs people suggested. Also, I am now getting a icon in my system tray saying that I have a version of widows that cannot be validated. I followed this sites clean up procedures and it cured some of my issues but some still remain. This is what I still see:

    In my task bar next to my clock it says Virus Alert!! and its in miliatary time. I cannot change this. I was getting mad popups saying I was infected using IE. I have since downladed Firefox. In my start menu, many options missing ie Run,Control Panel, Search ect. The only way for me to get to these is by using the windows key and shortcut. Also, when opening up my computer there is no C drive. The only way I can get to the root of C is by typing C: in a search window and opening container. I dont know what else is wrong but this is what I do see. If you can give me any pointers, I would appreciate it. Thanks for your time in reading
     

    Attached Files:

  2. Lirpa

    Lirpa Private E-2

    Heres 4th log
     

    Attached Files:

  3. Lirpa

    Lirpa Private E-2

    I should also point out that these logs are the most current. After running each program they all have found things on my pc to fix and has done so.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    First please refer to the instruction in the READ & RUN ME for using Spybot and disable Spybot's Teatimer.

    Then download and run this Norton Removal Tool (SymNRT) because you still have components of Norton install but are already using AVG8. Run the tool twice but reboot each time after you run it.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O20 - AppInit_DLLs: kus109.dat

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.
    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. Lirpa

    Lirpa Private E-2

    Heya Chase,

    I did everything you had posted and all were a success. I had no problems doing any of them. My system clock is back, all my start menu options are present and I really dont see anything else wrong but then again I havent been doing much on it. I still do not see the c: in my computer. It is really annoying to have to run c: just to get to it so If you have any ideas about that, Id be thankful. Here are the 2 new logs. Lemmie know if you see anything else. Thanks for your time.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we still have a little to do. Apparently the fixME.reg patch did not work. Did you receive a success message? Did you run it where requested? That is, after running ComboFix? Also you have been running AutoRuns and have malware items trapped with it. This is not the correct way to remove malware. You need to delete malware. Please run AutoRuns now and select the Everything tab. Then go down thru the whole list any make sure that everything is checked. After doing this, exit AutoRuns and then reboot your PC. Then run the previous fixME.reg patch again. Make sure that you get a success message.

    • Now right click on your Desktop and select Properties.
    • Then click the Desktop tab
    • then click the Customize Desktop button.
    • Now in the next window that comes up click the Web tab.
      • Make sure at the bottom that Lock desktop items is unchecked.
    • Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too.
    • Then click OK.
    • Click Apply. And click OK.

    Now tun C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O24 - Desktop Component 0: (no name) - (no file)

    After clicking Fix, exit HJT.


    Then attach another new MGlogs.zip file.
     
  7. Lirpa

    Lirpa Private E-2

    Hello again, Yes I followed your last instructions to a T and yes I had a succes message. I did what you said ran autoruns, checked everything, rebooted, ran fixme with sucess, followed desktop settings but when you said :

    "Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too"

    There was nothing in the box to check delete as well as no current home page. I ran analyse.exe delete the 3 u told me to and have attached my new logs. I still do not have c: and still have the icon in my taskbar saying my windows cannot be validated. Please let me know if you see anything else. Thanks again for your time. I know you do on your own time and I really do appreciate it.
     

    Attached Files:

    Last edited: Jun 1, 2008
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's wait until we finish all cleanup and see what happens. ;)

    This also may be a topic for the Software Forum, but is you Windows XP license valid?

    I suggest you download and run the Genuine Diagnostics tool at this link http://go.microsoft.com/fwlink/?linkid=52012 , then click the Windows tab, Copy to Clipboard, then paste the report into a response message in this thread?

    It may be necessary to install the most recent version of WGA Notification which is found here: http://go.microsoft.com/fwlink/?linkid=69498.

    Please uninstall AVG8 for now, it may be getting in our way and it also does not appear to be properly installed/running anyway. Uninstall it before continuing.



    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - AutorunsDisabled - (no file)
    O2 - BHO: (no name) - {5951B3E0-0C64-4B6C-89D6-C829E1167E46} - blank (file missing)
    O3 - Toolbar: atfxqogp - {C48F0939-992C-45C8-A9C2-B97A22D9B4BD} - blank (file missing)
    O4 - HKLM\..\Run: [a8d266e4] rundll32.exe "C:\WINDOWS\system32\noqrnmxg.dll",b
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Administrator\Local Settings\Temp

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now I want to get the current version of MGtools onto your PC. Please download it from the link in the top section of this Using MGtools and refer to those instructions for where to download and how to run it. (basically save to C:\MGtools.exe and then doubleclick MGtools.exe to run it).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. Lirpa

    Lirpa Private E-2

    Hey there Chase

    Yes my windows is valid. This started at the exact same time as my other symptoms. Ive never had problems updating using windows update and now I am not able too. After looking at the log from the test, I noticed that the key they have in the log doesnt match what I have on my cd. Also says both windows and my office isnt activated however, when I go to start, all programs, accesories, system tools, activate windows it says that it already is. Same goes for office, when I go to activate, says it already is. Which of course is the case as these are both legit. I followed your instructions with no problems. Had a success message for the fixme. I do see my hard drives now. Thanks cause that was annoying. I still have avg uninstalled but I dont see any other issue except the windows validation thing. Here are the logs you wanted. Please let me know if you see anything else. Thanks again for your time.
     

    Attached Files:

    Last edited: Jun 2, 2008
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay your logs are clean, I suggest that you do the below and then post your validation issue in the Software Forum or you will have to contact Microsoft about it.

    Re-install AVG now or whichever antivirus program you want to use.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds