XP Security Center gone...but...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by axnxn, Jun 16, 2011.

  1. axnxn

    axnxn Private E-2

    Hi there,
    I have successfully eliminated the XP Security Center malware that was disabling my computer, but I ran all of the scans as "Administrator," and now when I log back on to my account, all of my Quick Launch shortcuts are broken. There may be other issues, but that's as far as I got.

    These logs are attached:
    SASlog.txt log from SuperAntiSpyware.
    Malwarebytes Anti-Malware log
    ComboFix.txt (normally C:\ComboFix.txt)
    RRlog.txt (from RootRepeal)

    MGtools coming in the next post.

    Thanks in advance for your help.
    ann
     

    Attached Files:

  2. axnxn

    axnxn Private E-2

    MG log attached. Thanks.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  4. axnxn

    axnxn Private E-2

    Thanks very much for the quick reply, but unfortunately that didn't fix it.

    I can see my desktop, can see the start menu, task bar, etc., but when I click on an application I either get "application not found" or the option to choose which application to open. I was hoping that after choosing the application the first time that might reset the link, but no luck. And I can't, for example, run msconfig from the run command, either.

    I can, of course, just recreate the quick launch items, but I'm afraid this might be a symptom of something bigger.

    I also just noticed that my autorun items aren't loading (avira, hp tool box, etc.)

    thanks again for your help
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes I think that would be the best way to go.

    It is showing up in your logs anyway. Are you able to run anything else from the run box?

    • C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe

    What do you mean by this? I see HP items and Avira running at start-up.
    Please make sure you are in normal mode now not safe mode.

    Java(TM) 6 Update 22 <--- Uninstall outdated Java.

    Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Folder::
    C:\$AVG8.VAULT$
    c:\program files\AskBarDis
    File::
    C:\windows\Elahi.dat
    C:\windows\Tsacikodurexuri.bin
    C:\Documents and Settings\All Users\Application Data\g5m6ob75g5s1l11u55n4i
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"=-
    [-HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
    [-HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
    Last edited: Jun 18, 2011
  6. axnxn

    axnxn Private E-2

    Thanks again for your quick response.

    My computer automatically ran SpyBot last night, found a bunch of problems and fixed them -- which seemed to fix the broken Quick Launch, "Run," etc.

    I've followed your instructions and am attaching the following logs:
    Super Anti Spyware
    ComboFix
    MGTools

    as well as the SpyBot log in case you want to see it.

    But everything seems to be back to normal now. I'm very grateful.

    Is it safe to run Defogger and re-enable?
    thanks again
    ann
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not quite ready for wrapping up just yet.

    C:\Documents and Settings\All Users\Application Data\cfg <---What is this file?

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    FireFox::
    FireFox-: ProfilePath - c:\documents and settings\ann\Application Data\Mozilla\Firefox\Profiles\gupan3m0.default\
    FireFox-: prefs.js: keyword.URL - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={59147294-310A-EBCC-C42C-0CC82B1157EA}&q=
    File::
    C:\Documents and Settings\ann\Templates\g5m6ob75g5s1l11u55n4i
    C:\Documents and Settings\ann\Local Settings\Application Data\g5m6ob75g5s1l11u55n4i
    C:\windows\system32\REN35.tmp
    C:\windows\system32\REN36.tmp
    C:\windows\system32\REN37.tmp
    C:\Documents and Settings\ann\Local Settings\temp\upromise_metaconfig_FF.dat
    C:\Documents and Settings\ann\Local Settings\temp\upromise_redir_rules_FF.dat
    C:\Documents and Settings\ann\Local Settings\temp\upromise_restaurant_schema_FF.dat
    C:\Documents and Settings\ann\Local Settings\temp\upromise_searchoverlay_FF.dat
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  8. axnxn

    axnxn Private E-2

    C:\Documents and Settings\All Users\Application Data\cfg <---What is this file?

    I don't know what this file is...nothing helpful in properties...

    New logs attached.
    For some reason my computer was running verrryyy slowwwlllyy -- taking about 30 seconds to a minute to launch a Firefox window, for example. I rebooted, and things are picking up a bit, but I thought I would mention it.

    thanks again!
    ann
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Click Start, Run, and copy and paste the below into the Run box and click OK.

    This should bring up your preferences file for FireFox in a notepad window. Look for lines containing the below information and delete the whole line where it appears.

    • After deleting those lines, click File, and select Save. If you cannot save the file, close all browsers first before saving.
    • Now close ALL browsers and then reopen one and see how things are working.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    After clicking Fix exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  10. axnxn

    axnxn Private E-2

    Thanks again!
    MGtools log attached.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry, I meant to ask you to run Combofix again, could you do so by double clicking it (right click and run as admin if using Win 7/Vista) then attach the C:\combofix.txt. :)
     
  12. axnxn

    axnxn Private E-2

    here's the combofix, thanks!
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Back up any bookmarks that you have before uninstalling Mozilla Firefox using the below software as it's standard uninstaller does not do a good enough job.


    Try Revo Uninstaller.

    Choose the option on the bottom of the list (#4). Be very careful while deleting the bolded registry items ONLY!! This software will create a system restore point for you as well prior to uninstalling a software program.

    Now reboot the machine, reinstall Firefox, and then run Combofix again and attach the log. :)
     
  14. axnxn

    axnxn Private E-2

    Firefox uninstalled and reinstalled.

    ComboFix attached.

    thanks again!
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  16. axnxn

    axnxn Private E-2

    Awesome. Thanks so much.
    You were so thorough and so very helpful, and I appreciate your time.

    best
    ann
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome Ann! Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds