Unable to complete "Read me First" steps

Discussion in 'Malware Help (A Specialist Will Reply)' started by texoz, Dec 22, 2009.

  1. texoz

    texoz Private E-2

    Hi there!
    I diligently followed all the steps in "Read me First" but have come to an impasse when doing the final cleaning steps. I was able to run the SuperAntispyware scan, but can go no further. Even after renaming the .exe file for Malwarebytes, the program gets hung up when installing. The combofix will not run either.

    I am pretty sure I have malware defense infection, as when I tried to update my AVG it told me to uninstall the malware defense first, but I cannot find it to uninstall it. My Spybot will not run, nor will the above programs. Any advice would be greatly appreciated!
    Thanks in advance!
     
  2. texoz

    texoz Private E-2

    Assistance please with malware. Logs attached.

    :)I have attached logs from MGTools, ExeHelper, SAS, and AVPfind. I am unable to execute the cleaner files mentioned in "Read me First." Any help would greatly be appreciated!
    Thank you,
    Miki
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please try doing the below:

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then doube click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running.


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log.

    Then try running these instructions: Using MGtools


    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Note to Kes. Merged and third soft deleted.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTE: You are not running any anti virus on this machine!!! It's no wonder you are infected, by having no anti virus installed and protecting you, you are leaving your machine wide open to attack.

    We will ensure that you install some a little later on, but for now, we have some work to do:


    1. If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    2. Please go to add/remove programs and uninstall the following software:

    • RegistryDefense

    Did you knowingly install the below software?

    Spyware.GuardMon monitoring software <--- if you didn't then please also uninstall it.

    3. You have TeaTimer running, please see the link below for how to disable it, otherwise it is possible it could hinder our progress or block a fix.

    How to disable Spybot's TeaTimer

    4. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O2 - BHO: (no name) - {3EBBD0F6-1F1F-48A0-89DC-C7505D56E92A} - (no file)
    • O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    • O4 - HKLM\..\Run: [VBouncerDL] C:\PROGRA~1\VBouncer\VBouncerInner1113.exe
    • O4 - HKLM\..\Run: [UpromiseRemindU] wjview /cp:p "C:\Program Files\UpromiseRemindU\System\Code" Main lp: "C:\Program Files\UpromiseRemindU"
    • O4 - HKLM\..\Run: [system] dcomx.exe
    • O4 - HKLM\..\Run: [SpyHunter] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    • O4 - HKLM\..\Run: [Shoppers and Schedulers Instant Messenger] C:\Program Files\Instant Messenger\Messenger.exe
    • O4 - HKLM\..\Run: [Open Site] C:\Program Files\Open Site\opnste.exe
    • O4 - HKLM\..\Run: [NetMeter] C:\PROGRA~1\NETRAT~1\NetMeter\NetMeter.exe
    • O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
    • O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    • O4 - HKLM\..\Run: [Hotbar] C:\Program Files\Hotbar\bin\4.3.9.0\Hbinst.exe /Upgrade
    • O4 - HKLM\..\Run: [EnigmaPopupStop] C:\Program Files\SpyHunter\PopupBlocker\EnigmaPopupStop.exe
    • O4 - HKLM\..\Run: [Anti-Trojan-Watch] C:\Program Files\Anti-Trojan-55\ATWatch.exe
    • O4 - HKCU\..\Run: [prutjct] C:\WINDOWS\SYSTEM32\prutjct.exe
    • O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
    • O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\4.bin\MWSOEMON.EXE
    • O4 - Startup: Virtual Bouncer.lnk = C:\Program Files\VBouncer\VirtualBouncer.exe
    • O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\4.bin\MWSOEMON.EXE

    • It is not wise to place ANY site into your TZ.

    • O15 - Trusted Zone: http://*.arise.com
    • O15 - Trusted Zone: http://support.webchartmd.com
    • O15 - Trusted Zone: http://www.webchartmd.com

    • O16 - DPF: {819EDD4C-7EB6-4D97-B831-D68B57E7D3ED} -

    After clicking Fix exit HJT.


    5. Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    6. SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    SystemLook

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :Dir
      C:\WINDOWS\System32\T.COM
      C:\WINDOWS\System32\TASKMGR.COM
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    7. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    8. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger and also the log from syslookup: SystemLook.txt

    9. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
    Last edited: Dec 23, 2009
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Texoz, I added folders for deletion to my fix, refresh your page and then run the fix if you are about to.
     
  8. texoz

    texoz Private E-2

    Let me start off by saying THANK YOU for your response. I had unintentionally "bumped" by posting a couple of times. This was due simply to my doing more research while waiting for a reply and generating logs. I followed instructions in another of your posts regarding AVP Fine and exe.helper last night. I was then able to execute most of the files in the "Cleaning instructions" with the exception of Root Repeal. I then reinstalled AVG and updated it. (I had let it lapse for a week or 2 and was infected while I waited to get enough money to renew it.)
    :(
    I then used Autoruns to disable a lot of programs at startup.

    I logged on tonight to find your reponse below and followed all your steps. I have attached the logs. Please let me know if I need to do anything else. Things seemed to go pretty well today.
    Thanks again!
    Miki
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please attach the log from when you ran it on Dec 22nd.

    C:\combofix.txt
     
  10. texoz

    texoz Private E-2

    Here you go. There are 2 logs. Ran it once before I was able to execute Malware Bytes and then later after I was able to get it to run.
    Miki
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. FYI You are running combofix from the wrong directory.
    You need to take it out of the folder you have it inside of and place it directly on the desktop before we continue.

    2. You neglected to disable messenger. Run this again:

    If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    3. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    After clicking Fix exit HJT.

    4. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    File::
    C:\Documents and Settings\All Users\Application Data\sysReserve.ini
    C:\WINDOWS\Downloaded Program Files\QDow.dll
    C:\WINDOWS\Downloaded Program Files\slghex.dll
    C:\WINDOWS\Downloaded Program Files\slgwebinstall.dll
    
    Folder::
    c:\program files\BenefitBarIE
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/QDow.dll]
    "{26E8361F-BCE7-4F75-A347-98C88B418322}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/slghex.dll]
    "{7D731A83-6C80-4EA4-9646-5E06A0513274}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/slgwebinstall.dll]
    "{7D731A83-6C80-4EA4-9646-5E06A0513274}"=-
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    5. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    • C:\WINDOWS\TEMP
    • C:\Documents and Settings\Miki Blumenthal\Local Settings\TEMP

    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    7. Let us know of any problems you may have encountered with the above instructions.
     
  12. texoz

    texoz Private E-2

    Thanks for your further response. I have done all the items below, but when I run Combofix with the CFscript, it runs, reboots the computer, and then says it is creating a log. This screen stays and will not go away. I have tried it a number of times. If I close the screen, no log is created.
     
  13. texoz

    texoz Private E-2

    Yea! Logs attached!

    The 3rd time was a charm. I have followed all your steps and have attached logs below. While running the GetLogs.bat program, a box popped up with the following message:

    Please help us to improve Hijack by reporting this error.
    Details: An unexpected error has occurred at procedure.
    modRegistry_IniGetString9sFile=system.ini, sSection=boot, sValue=shell) Error #5 - Invalid procedure call or argument.
    Windows version: Windows NT 5.01.2600
    MSIE versino: 7.0.5730.13
    Hijack This version: 20.2
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/QDow.dll]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/slghex.dll]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/slgwebinstall.dll]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.
     
  15. texoz

    texoz Private E-2

    Okay, here you go! Thanks for your help so far! BTW, I am still getting the same error message regarding Hijack This (see earlier post) when I run GetLogs.bat.

    Miki
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your logs are clean :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  17. texoz

    texoz Private E-2

    I can't thank you enough for all of your time and efforts to help me. Happy New Year!! :)
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    and the same to you :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds