1.

Solve : Help please! Malwarebytes won't run. SAS and HJT Logs included...?

Answer»

Hi there,
So I managed to catch myself a lovely virus (Vundo among others, it would appear).  I first noticed it when I started getting various fake "security" warnings, and then discovered that it has disabled Malwarebytes.  I tried various methods recommended by the folks at Malwarebytes to get it running again but to no avail.  Since then, I have followed all of the procedures listed in the "Read this before requesting malware removal help".  I was, of course, unable to run Malwarebytes but I did everything else (properly I hope!).  Everytime I try to do anything with mbam, I get an error code 2 message and the prgoram won't open.  I'm fresh out of ideas so I'm hoping and praying that you guys might be able to help.  If you would please give me a hand I'd be much obliged.  My logs are attached so please let me know if I can provide any further info.  Thanks in advance!
- Cayti     

[Saving space, attachment deleted by admin]you do not seem to have any anti-virus installed or other security can you NAME what you have Hello.  I have Symantec Anti Virus/Anti spyware, but even though it is updated it didn't find anything yesterday during its weekly full scan.  Even now it is saying "Your computer is protected, no problems detected".  Beats me!  Any ideas?  sorry i'm not an expert , but can you start malware in safe mode , or did you try to rename it


sorry i miss that symantec  No problem!  I have already tried the renaming thing, but that definitely doesn't work.  I will try to run it in safe mode and update with results ASAP. No luck in safe mode unfortunately.  It doesn't seem to even register that I opened it.  No error this time, just nothing!<Removed>

Please don't send users away. EFHello caytidid.

Please DOWNLOAD and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
 
There are 4 different versions. If ONE of them won't run then download and try to run the other one.
 
Vista and Win7 users need to right click Rkill and choose Run as Administrator

You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

* Rkill.com
* Rkill.scr
* Rkill.pif
* Rkill.exe

* Double-click on the Rkill desktop icon to run the tool.
* If using Vista or Windows 7 right-click on it and choose Run As Administrator.
* A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
* If not, delete the file, then download and use the one provided in Link 2.
* If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
* Do not reboot until instructed.
* If the tool does not run from any of the links provided, please let me know.

Once you've gotten one of them to run then try to immediately run the following.
 
Now download and Run exeHelper.

* Please download exeHelper from Raktor to your desktop.
* Double-click on exeHelper.com to run the fix.
* A black window should pop up, press any key to close once the fix is completed.
* A log file named log.txt will be created in the directory where you ran exeHelper.com
* Attach the log.txt file to your next message.[/list]

Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).



If you already have ComboFix be sure to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note:  It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
 
Double click combofix.exe & follow the prompts.
Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFix

----------

Next post please add:

  • exeHelper log
  • ComboFix log
Hi evilfantasy,
Thanks for the reply and sorry for the delay, I had some trouble disabling all aspects of my antivirus software.  Everything seemed to run fine after that.  I have attached both of the requested logs.  I don't know if this is worth noting or not, but after I ran Combofix and the computer restarted, I got the RUNDLL errors for both hafimiw.dll and c:\windows\system32\rosogobu11.  I'm guessing those are remnants of malware that have been deleted.  Didn't know if it was relevant but I figured full disclosure was best.  Thanks for you help on this!

[Saving space, attachment deleted by admin] Quote from: caytidid on November 07, 2009, 05:29:20 PM
Thanks for you help on this!

Your welcome.

Quote from: caytidid on November 07, 2009, 05:29:20 PM
after I ran Combofix and the computer restarted, I got the RUNDLL errors for both hafimiw.dll and c:\windows\system32\rosogobu11.  I'm guessing those are remnants of malware that have been deleted.  Didn't know if it was relevant but I figured full disclosure was best.

Yes and we will take care of that.


Did you create these folders and files?

Quote
2009-11-07 21:24 . 2009-11-07 21:30   --------   d-----w-   c:\program files\Attempt 6 SM
2009-11-07 18:52 . 2009-11-07 18:53   --------   d-----w-   c:\program files\Attempt 5
2009-11-07 18:24 . 2009-11-07 18:28   --------   d-----w-   c:\program files\Attempt 4
2009-11-07 18:20 . 2009-11-07 18:20   --------   d-----w-   c:\program files\Attempt 3
2009-11-07 14:33 . 2009-11-07 14:33   --------   d-----w-   c:\program files\please work
2009-11-07 05:20 . 2009-11-07 05:20   4045528   ----a-w-   c:\program files\xxxx.exe
2009-11-07 05:12 . 2009-11-07 14:41   --------   d-----w-   c:\program files\MF
2009-11-07 05:07 . 2009-11-07 05:10   --------   d-----w-   c:\program files\MW-upfucker
2009-11-07 05:06 . 2009-11-07 05:06   4045528   ----a-w-   c:\program files\mw-upfucker.exe
2009-10-22 18:12 . 2009-10-22 19:04   --------   d-----w-   c:\program files\lmxiyi
I created all of them while attempting to re-download mbam, except for the last one "lmxiyi".  I don't recognize that one at all and noticed it was created on a different day than the rest.  My apologies for the, ummm, colorful file names.  It was a frustrating day. *blushing*  I can delete them now if you would like me to since they didn't work anyway.    Quote
My apologies for the, ummm, colorful file names.

I'V eseen worse... 

Quote
I can delete them now if you would like me to since they didn't work anyway.

We can do it with ComboFix since we need to run it again anyway.

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

File::
c:\program files\xxxx.exe
c:\program files\mw-upfucker.exe

Folder::
c:\program files\Attempt 6 SM
c:\program files\Attempt 5
c:\program files\Attempt 4
c:\program files\Attempt 3
c:\program files\please work
c:\program files\MF
c:\program files\MW-upfucker
c:\program files\lmxiyi

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=-


3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

----------

Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.

1) DDS.txt
2) Attach.txt

* Save both logs to your desktop.
* Please copy and paste the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copy and pasting it into the reply.

----------

Next post please add:

ComboFix log
Both DDS logs
Done and done!  I attached the Combofix, DDS, and Attach logs rather than copy and pasting them since they are apparently too large to add to the message body.  I hope that's alright.   



[Saving space, attachment deleted by admin]Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

Exit out of MessengerDisable then delete the two files that were put on the desktop.

----------

Download JavaRa
* Unzip the file and open the JavaRa.exe
* Click Remove Older Versions
* JavaRa will search for and remove any outdated version of Java and remove any that are found.
* Click Additional Tasks
* Place a check next to Remove Useless JRE Files and click Go
* Exit JavaRa
* Delete the JavaRa files from the desktop

----------

Go to Add or Remove Programs and uninstall:

- Viewpoint Manager (Remove Only)
- Viewpoint Media Player


----------

We need to use ComboFix again.

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

DDS::
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -

Folder::
C:\Program Files\Viewpoint
c:\program files\Malwarebytes' Anti-Malware Attempt 2

3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

----------

I think we deleted Malwarebytes in that last fix. If it is still installed then update it and run a scan.

Post the log it creates.

If you need to download it again be sure to update it before the scan. Malwarebytes' Anti-Malware (MBAM)



Also let me know how the computer is running now.Good Morning!

I have attached the most recent combofix log as well as the mbam log.  While I was running combofix, i got the following notification "PEV.cfxxe has encountered a problem and needs to close...".  I left it alone because combofix seemed to be running ok.  As far as I can tell, everything seems to be running normally now    Yay! (hopefully that's not a premature celebration)  Let me know if you need anything else and thanks!

 - Cayti

[Saving space, attachment deleted by admin]


Discussion

No Comment Found