Unable to post all logs from Read and Run Me First

Discussion in 'Malware Help (A Specialist Will Reply)' started by timmay, Aug 8, 2009.

  1. timmay

    timmay Private E-2

    Hello,

    I am running Windows XP.
    The only antivirus program that I have installed is Spyware Doctor however I am unable to activate it due to infection.
    Unable to view hidden files - tools tab does not have Folder Options choice.
    Ran SUPERAntiSpyware as SAS successfully. Rebooted and now unable to access program to get log: Error - "Windows can not access the specified device, path or file. You may not have the appropriate permissions to access the item.". I verified with msconfig that I am still in Normal Startup and my user account is Admin level.
    I am unable to run Malwarebytes program and receiving same error as above: "Windows can not access the specified device, path or file. You may not have the appropriate permissions to access the item.".
    Started ComboFix but program terminates after a few seconds. The program does not do anything after small dialogue box with a load bar and "ComboFix" text.
    Attempted to run RootRepeal, however error message that states: "Error - invalid PE image found!".
    Successfully ran MGtools.exe and have attached the logfile.
    I apologize that I was not able to provide more logs. The notable virus names that I saw are Home AntiVirus 2010, Braviax and several Trojans and Rogues.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Spyware Doctor is an antispyware program not an antivirus program. PC Tools does make an antivirus program though. So did you purchase Spyware Doctor with their antivirus? Why did you wait until you were infected before installing protection. I see you only installed Spyware Doctor on Aug 8th which is after you were already very very badly infected and obviously as you can see it was not a good idea to run unprotected. After the fact installation frequently will not work as is the case for you.

    It appears that you may not have accepted the license agreement for TrendMicro HijackThis when you ran MGtools. Did you see this license agreement popup? Did you click the Accept button twice?

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now see if you can run SUPERAntiSpyware, Malwarebytes and ComboFix.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Then attach the below logs:
    • C:\avenger.txt
    • the logs from SUPERAntiSpyware, Malwarebytes and ComboFix if they ran.
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Aug 10, 2009
  3. timmay

    timmay Private E-2

    Hello Chaslang. Thank you for the reply!

    I originally had McAfee Anti-Virus Gold installed at the time of the infection. It identified a Trojan but was not able to remove it (it kept reappearing after quarantining). I was referred to PC Tools and purchased Spyware Doctor and Registry Mechanic at the store. I have not purchased the AntiVirus online as I am leery about providing credit card info while infected. I plan to purchase if I can get me PC clean again. I was able to activate Spyware Doctor after running SAS.exe the first time (last post) and ran a scan which cleaned 200+ infections.

    I did not see a HijackThis license popup.

    I successfully ran MessengerDisable.exe.

    Successfully executed avenger.exe. SAS.exe stated that my PC was clean (no infections) but I am unable to produce the log as after reboot SAS.exe will not start again (error: "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item"). Malwarebytes closed on it's own after about 5 seconds after I selected 'Scan' and will not reopen (same access error as SAS.exe). ComboFix.exe would not execute and gave the following error: "Incompatible OS. ComboFix only works for workstations with Windows and XP".

    In addition, I am unable to place my PC in safe mode. The safe mode screen does not allow me to choose an option. It always times out on restart from last point.

    Attaching the 2 logs I was able to produce. Thank you!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so my statement that you have no antivirus protection is still currently correct. ;) And this may be a reason for why you are now so badly infected.


    You don't need to run SAS to get the logs. They are autoamatically saved for you as long as the program finishes running the scan.

    You could have a new form of infection that is just starting to show up and this infection is very nasty and blocks many malware tools from running. Which is also propbably why you are not seeing a license agreement for HijackThis. I will have to give you a new version of MGtools to run and also will have to think for a bit about some other tools to possibly use to collect more info so we can locate the source of the problem.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I can see from your last logs that I was correct about you having a new type of infections that is going around. Here is what I want you to try doing. Since you cannot boot in safe mode, this may be more difficult and may not even work.

    Right click Start and select Explore to run Windows Explorer. Navigate into the C:\Windows\system32 folder and you will see many files but the ones we want to focus on are list below:
    Code:
    174,592 2002-08-29 10:41:12  C:\WINDOWS\system32\scecli(2).dll
    174,592 2002-08-29 10:41:12  C:\WINDOWS\system32\scecli(3).dll
    174,592 2002-08-29 10:41:12  C:\WINDOWS\system32\scecli(4)(2).dll
    180,224 2004-08-04 07:56:44  C:\WINDOWS\system32\scecli(5).dll
     60,928 2008-04-14 00:12:05  C:\WINDOWS\system32\scecli.dll


    The very last one is the problem file. This is not a valid copy of the scecli.dll file which is the Windows Security Configuration Editor Client file and a required system file.
    • Right click on the scecli.dll file and select Rename. Rename the file to scecli.dll.vir
    • if the above rename is accepted, then continue with the below. Otherwise stop and tell me.
    • Then right click on the file name scecli(5).dll and rename it back to scecli.dll
    • Then immediately reboot.
    • After reboot, see if you can run the tools that would not run.
    • Either way, download the current version of MGtools (yes another new version due to these infections) and save it to your root folder. Overwrite your previous MGtools.exe file with this one.
    • Run MGtools.exe and attach the new C:\MGlogs.zip file.
     
  6. timmay

    timmay Private E-2

    Hello Chaslang,

    I did not see any log or txt files in the Program Files\SUPERAntiSpyware folder. There are exe, dll, db, sys, stg and chm files (nothing that resembles a log file though). There are also 2 folders (Language and Plugins) but neither contain log files.

    I attempted to rename the scecli.dll file nut was rebuffed so I stopped and am posting this response. The error message that I received when I tried to rename scecli.dll is as follows: "Cannot rename scecli: It is being used by another person or program. Close any programs that might be using the file and try again." I did not have any other programs open at the time.

    Thank you again for your assistance!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They are not stored there. There are stored as show below:
    Code:
    "C:\Documents and Settings\tim\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    Aug  8 2009       25491  "SUPERAntiSpyware Scan Log - 08-08-2009 - 13-27-42.log"
    Aug  8 2009         856  "SUPERAntiSpyware Scan Log - 08-08-2009 - 18-26-06.log"
    Aug 10 2009         465  "SUPERAntiSpyware Scan Log - 08-10-2009 - 20-38-43.log"
    As you can see, there are three logs there. The most important one is the largest one which is 25491 bytes in size.

    Windows itself is running many programs and has the file in use. I will see if I can figure out another way to overwrite the bad file. Our choices are limited since you cannot run any of the special tools and also cannot boot in safe mode.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you were previously able to run Avenger without it being blocked by the malware, let's see if we can use it again.
    We will see if it can rename the bad file and replace it with a valid file. Also we will attempt to have Avenger run ComboFix automatically at reboot time. Not sure if this will actually will work but be prepare to see ComboFix and allow it to run if you see it pop up.


    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. timmay

    timmay Private E-2

    avenger and MGTools both ran successfully. Here are the requested logs. Thanks!
     

    Attached Files:

  10. timmay

    timmay Private E-2

    Attached is the actual avenger.txt. I renamed combofix.txt to avenger.txt inadvertantly.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please try to run C:\MGtools\analyse.exe by double clicking on it. This is actually HijackThis. Tell me what happens. If you get a popup license agreement, make sure to click the Accept button twice.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now download yet another new version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    See if you can run SUPERAntiSpyware and Malwarebytes now.
     
  12. timmay

    timmay Private E-2

    Hello Chaslang,

    I did try to run C:\MGtools\analyse.exe by double clicking on it but received the following error:

    "Windows can not access the specified device, path or file. You may not have the appropriate permissions to access the item."

    I was able to drag CFscript.txt on top of ComboFix.exe and it completed (it rebooted my PC then create the log file). I ran the newly downloaded MGTools.exe but again there were no pop-ups to acknowledge.

    Logs attached. Thank you!
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now download and save this XPsp3bu.exe to your C:\ root folder. You must do this properly. Now run the XPsp2bu.exe program by double clicking on it. You may or may not notice a quick flash of a black window. This is normal. The program runs quickly and just extracts some files we need.

    We will now run Avenger again to remove some malware and also to replace some files that are missing that you need. Also we will attempt to have Avenger run RootRepeal and HijackThis (analyse.exe) automatically at reboot time. Hopefully this works like it did with ComboFix. Make sure you allow RootRepeal to run if it loads up. You need to run it like instructed here: Running RootRepeal

    Also if HijackThis runs, accept the license agreement by clicking Accept twice.


    Now run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Sean Walsh\Local Settings\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )



    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Aug 21, 2009
  14. timmay

    timmay Private E-2

    Hello Chaslang,

    I successfully ran fixme.reg and did receive a success message. I also ran the XP executable and saw the brief flash of a black dos window.

    I attempted to execute avenger with the provided script but received the following error: "Error: Invalid script. A valid script must begin with a command directive. Aborting execution!"

    I manually removed the .vir file and the Windows Antivirus Pro folder. I manually copied the three MGTools/temp files to WINDOWS/system 32. I then ran avenger with just the last 2 startup lines and rebooted. I was greeted with avenger.txt and 2 pop-up errors: "Windows can not access the specified device, path or file. You may not have the appropriate permissions to access the item".

    I downloaded a new version of RootRepeal to a different location and was able to execute it. I can not execute analyse.exe.

    I ran the CCleaner and the current version of MGTools. Logs attached. Thank you!
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that. I had a couple of typos in the fix where I was using the syntax for ComboFix rather than Avenger. Please run the last fix starting from the point with Avenger again but after the reboot from Avenger, continue with the fix in this message rather than the previous message.

    First please uninstall both Malwarebytes and SUPERAntiSpyware and delete any previous copies of their installers that you may have downloaded.

    Now delete all files and subfolder in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\temp


    Now download, install, update and try to run scans using the below links for SUPERAntiSpyware and Malwarebytes:
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Then attach the below logs:
    • C:\avenger.txt
    • the SAS and MBAM logs if they ran
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  16. timmay

    timmay Private E-2

    Hello Chaslang,

    I re-ran avenger successfully with updated script but the programs did not launch at reboot (log file said it could not find them, but they did exist in the locations specified). I manually ran RootRepeal from my C:\ location. Was unable to run analyse.exe though.

    Uninstalled both Malwarebytes and SUPERAntiSpyware. No files to clean in C:\WINDOWS\temp.

    Reinstalled both Malwarebytes and SUPERAntiSpyware and ran them successfully.

    I ran the CCleaner and the current version of MGTools. I still did not receive any pop-ups for HijackThis but the analyse.exe file is now showing a logo (the icon was just a White box before). Logs attached (I can not locate my avenger.txt file, it is not in C:\ where it used to be). Thank you!
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Not sure what problem you are having but it runs just fine now as you can see he log from it is inside of MGlogs.zip. Thus analyse.exe (HijackThis) runs okay.

    That's okay. Based on the other logs, it appears to have done what I wanted it to do.

    Your logs are clean now. Are you having any malware problems?
     
  18. timmay

    timmay Private E-2

    Hello Chaslang,

    Thank you very much for your assistance. It appears there are still issues with my PC as I am still unable to startup in Safe mode and I cannot delete some files from my PC (saying I do not have permission to (for example: Cannot delete RootRepeal: Access is denied. Make sure the disk is not full or write-protected and that the file is not currently in use.). It appears that whatever infected me is still not giving me full admin power over my PC. In addition, startup takes longer and the User Account screen with my account is not displayed.

    Any advice?

    Thank you!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    This could be a problme with Windows itself. You could try running SUPERAntiSpyware and select Preferences and then select the Repairs tab. Scroll down to the Repair broken SafeBoot key option and select it. Then click the Perform Repair... button see if this helps.

    Are you referring to a folder name or a file. If a folder, delete all the files in the folder first and see what happens.

    Why are you trying to delete this right now anyway. I have not asked you to do this.

    Not sure what you mean. Do you mean the Welcome Center screen does not show your user account on it? If so, what user account are you now using?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds