Windows Virus on 32 bit won't open exe files

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by superdan, Jun 22, 2011.

  1. superdan

    superdan Private E-2

    Hi
    Yesterday I got a malwar on my Sony Viao 32 bit. My computer is still running and my Windows virus check caught it, or what I now know to be most of it. Now I can not open any exe files without going into the browse list and even then some files are not opening at all.
    I am trying to run the Major Geeks Clean Up Process, but the Defogger won't run.
    So I can't even start the clean up process.
    Can you help get me to the first stage?
    Superdan
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.

    Now download and Run exeHelper from Raktor
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Now run this: Using Malwarebytes Anti-Malware

    Now run this: Using MGtools


    Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans
    • exeHelper log
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.
     
  3. superdan

    superdan Private E-2

    Thanks for this. I'm afraid that none of them are opening. I keep getting sent to the Open With box and when I go into the desktop (where they are saved) and open them, I am returned to the Open With box.
    I have tried to open them with a right click and via Windows Explorer.
    RKill.pif get me to a 404 Not Found page.
    Also none of the Open With boxes will shut, so now my screen is cluttered with tens of boxes.
    I feel there must be another way of opening the files.
    Can you help?
    Thanks again.
    Superdan
     
  4. superdan

    superdan Private E-2

    Also when I click on Rkill.exe, I get a box Winrar self extracting archive and a prompt comes up saying that it can not open the Rkill. exe file.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download RogueKiller.exe and save it to your desktop.
    • Now quit all running programs.
    • Double click RogueKiller.exe to run it.
    • When prompted, type 1 and hit Enter.
    • A RKreport.txt should appear on your desktop.
    • Note: If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe .
    • Please post the contents of the RKreport.txt in your next Reply.
     
  6. superdan

    superdan Private E-2

    Kestrel.
    Thanks so much for your help.
    Inbetween your replies I managed to do the following.
    I googled 'exe.files won't run on XP' and found a link to a programe called exefix.reg. I ran it thinking, 'in for a penny in for a new computer' and it seemed to get the exe files going again. The 'Open With' boxes all shut down and I was now able to run the programs you so kindly sent to me.
    I ran the other clean up programs.

    Find the first logs you asked for attached.

    Please can you tell me if I should run the Roguekiller.exe file and sent you the log?
    Also, shall I go through the orignal Run Me Read Me First process. My computer has been slow for a long time, so I think that it could do with a good clean!
    Best,
    Superdan
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome.

    Ahh, good.

    The avg antivirus you are using is out of date and ought to have really been uninstalled so that Combofix could have been run.

    Uninstall the below outdated Java.

    • J2SE Runtime Environment 5.0 Update 11
    • Java(TM) 6 Update 13
    • Java(TM) 6 Update 7
    • Java(TM) SE Runtime Environment 6 Update 1


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    After clicking Fix exit HJT.


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
    
    :files
    C:\Documents and Settings\sony\Local Settings\Application Data\3s0b02123f6r5tf0a0pgt1xhbnx42txruqu515byi350"
    C:\Documents and Settings\sony\Local Settings\Application Data\5nmo2vw136
    C:\Documents and Settings\All Users\Application Data\3s0b02123f6r5tf0a0pgt1xhbnx42txruqu515byi350"
    C:\Documents and Settings\All Users\Application Data\5nmo2vw136
    C:\Documents and Settings\sony\Templates\3s0b02123f6r5tf0a0pgt1xhbnx42txruqu515byi350"
    C:\Documents and Settings\sony\Templates\5nmo2vw136
    
    :Commands
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  8. superdan

    superdan Private E-2

    Thanks for this.

    I have followed what you said and here are the logs below.
    I also ran ComboFix, after uninstalling AVG, and you'll find that log here too.

    I think that I should clean my external hd and my flash drive, all of which were connected when the malware appeard. Do I need to? How do I do this?

    As for now, the computer is running well. It seems to be less noisy than before and the exe programs seem to be opening, though I have not tried to use the computer that much since the infection. An Rkill programe with 'system 32' in the black box keeps on popping up and then failing. Shall I uninstall all of the Rkill programs on the desktop?

    Thanks again.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is everything okay with your start up, Program Files, desktop and quicklaunch. Is anything like that hidden from you? Everything as it should be?

    I had left the " at the end of some of those files for deletion so they did not go last time. My apologies.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\sony\Local Settings\Application Data\3s0b02123f6r5tf0a0pgt1xhbnx42txruqu515byi350
    C:\Documents and Settings\sony\Local Settings\Application Data\5nmo2vw136
    C:\Documents and Settings\All Users\Application Data\3s0b02123f6r5tf0a0pgt1xhbnx42txruqu515byi350
    C:\Documents and Settings\All Users\Application Data\5nmo2vw136
    C:\Documents and Settings\sony\Templates\3s0b02123f6r5tf0a0pgt1xhbnx42txruqu515byi350
    C:\Documents and Settings\sony\Templates\5nmo2vw136
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  10. superdan

    superdan Private E-2

    Thanks again, Sir. The help and support you and your team offer is exceptional and also educational.:)

    My start up and general computer running seem fine. I've not surfed the net, as I'm running without virus checks etc at the moment, but general functions seem ok. The drive seems to be much quieter. I'll run some program files and let you know.

    Here are the logs attached.

    Do I need to clean my external hd and flash drives? I guess so.
    Best,
    Superdan.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I just so happen to be a Miss, not a sir. LOL

    You are most welcome. :) Safe surfing!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  12. superdan

    superdan Private E-2

    Apologies for the mistake.

    Thanks for your help.

    I am currently working through the 'How to Protect Yourself', can I ask your opinion about my protection choices?

    1. I have installed Comodo Personal Firewall with the Defense option, which I think is the anti-virus application. Am I correct in thinking that I will not need to upload another antivirus program?

    2. I am thinking of purchasing SUPERAntisypware Professional (the pay for one) and also

    3 Malwarebytes Pro (the pay for one)

    Just before I commit money, I should know wheter this will be too much or just the right amount? I know that you should only run one AV software programe on one computer, so will these three items cover me?

    Please advise.

    Thank you very much for all your fantastic help.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not to worry, people constantly assume I am a man on the internet :-D
    Most welcome.

    That sounds like it is just the firewall to me, but you may need to check in the software forum for further advice. What exactly appears in add/remove programs for its name?
    Only purchase one of these for they both have real time protection when you pay for them, using two will cause conflicts. Obviously you can use both of the free versions though as none of those offer real time protection.

    You will just need to check that you do indeed have antivirus included in the comodo software you are using. Use either SAS or MBAM paid for, only one.
     
    Last edited: Jun 27, 2011
  14. superdan

    superdan Private E-2

    Thanks for this. You were right my comido is just a wirewall. I'm finding it very nagging but will keep it for a week and see if it will settle or whether I can adjust it.

    I have one more question...I've chosen superanti spyware pro and am running a free trial before I buy. This is an anti virus program as well as an anti malware program? I'm a little unclear as there is so much jargon.

    So comodo firewall (no av) and superantispyware pro (paid for) are my choices.

    Thank you in advance

    Superdan
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Nope, you still need antivirus as SUPERantispyware is just anti-spyware. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds