Windows Removal Virus Problem

I’ve run 5 different virus deletion tools including avast, malwarebytes, avg, and kaspersky. None of which have fully worked. I’m able to do most everything I could before the virus. The pop up doesn’t appear anymore, but I still get random sound ads playing from no where, my background is still pure black(have used a hidden file finder and got everything but that back), I’m unable to open a few programs getting critical errors on them, and I’m getting random script messages(every 3 or so minutes) asking me if I want to stop running the script. I’ve been doing this for nearly 15 hours with minimal progress. I thought I would look for a professional to help me. I saw a post before this, but I was unable to reply on the topic. It contained information from Essexboy(also unable to send PM’s, but I believe this is the forums end). He said to download RougeKiller and OTS so I did just that and posted my reports as he said to do.

This was my RKreport:

RogueKiller V4.3.9 [04/16/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRKgmailcom
Feedback: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html

Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: Owner [Admin rights]
Mode: Remove – Date : 04/22/2011 18:17:11

Bad processes: 0

Registry Entries: 1
[APPDT/TMP/DESKTOP] setup_9.0.0.722_22.04.2011_10-59.lnk : C:\Users\Owner\Desktop\Virus Removal Tool\setup_9.0.0.722_22.04.2011_10-59\startup.exe → DELETED

HOSTS File:
127.0.0.1 localhost
::1 localhost

Finished : << RKreport[1].txt >>
RKreport[1].txt

10,000 character limit, more in reply.

The OTS was frankly way too long to post with the 10,000 character limit. If it’s absolutely needed I’ll post it, but I don’t want to fill this post with spam >.<

I’m hoping that you can help me out. I’m not much of a pro with computer issues, but this is the first virus that’s given me such a hard time. Also I was having a problem posting this so I had to reboot and run in safemode with networking, when I did, it ran a disk check and I got 2 “Desktop.ini” files on my desktop. Not quite sure what these are or if they offer any help to being able to solve my problem, so I’ll post them with some hope.

The first is:

[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21799

Second is:

[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21769
IconResource=%SystemRoot%\system32\imageres.dll,-183
[LocalizedFileNames]
Windows Movie Maker.lnk=@%ProgramFiles%\Movie Maker\MovieMk.dll,-61403

You can attach the file (Additional Options in the Reply window), which is easier for anyone familiar with analysing it and you don’t have to split it over lots of posts.

Thanks a lot David. (Edit): I actually had to swap computers to do this, so I had to change the file name and use copy and paste for the contents >.<

You’re welcome.

Hopefully someone who can analyse it can run with it, unfortunately essexboy who would normally do this will be tucked up in bed, it is a little after 4am in the UK right now, so hopefully he will be back later today.

Hi there this will take several long minutes to run as your temp files are very full

Start OTS. Copy/Paste the information in the quotebox below into the panel where it says “Paste fix here” and then click the Run Fix button.

[Unregister Dlls]
[Registry - Safe List]
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> 
YN -> HKEY_USERS\.DEFAULT\: "ProxyServer" -> http=127.0.0.1:5577
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> 
YN -> HKEY_USERS\S-1-5-18\: "ProxyServer" -> http=127.0.0.1:5577
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-2039977163-748715940-2778053649-1000\] > -> 
YN -> HKEY_USERS\S-1-5-21-2039977163-748715940-2778053649-1000\: Main\\"Secondary Start Pages" -> http://www.tinierme.com/tinierme/top.do [binary data]
YN -> HKEY_USERS\S-1-5-21-2039977163-748715940-2778053649-1000\: URLSearchHooks\\"{472734EA-242A-422b-ADF8-83D1E48CC825}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> HKEY_USERS\S-1-5-21-2039977163-748715940-2778053649-1000\: URLSearchHooks\\"{A3BC75A2-1F87-4686-AA43-5347D756017C}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-2039977163-748715940-2778053649-1000\] > -> HKEY_USERS\S-1-5-21-2039977163-748715940-2778053649-1000\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{0FEF2D2C-CDA6-45E4-B2ED-9DF7C50C95FF}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{472734EA-242A-422B-ADF8-83D1E48CC825}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{D4027C7F-154A-4066-A1AD-4243D8127440}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> "Adobe ARM" -> ["C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"]
[Files/Folders - Created Within 30 Days]
NY ->  WindowsUpdate -> C:\Users\Owner\AppData\Local\WindowsUpdate
[Files/Folders - Modified Within 30 Days]
NY ->  ~43114248 -> C:\ProgramData\~43114248
NY ->  ~43114248r -> C:\ProgramData\~43114248r
NY ->  43114248 -> C:\ProgramData\43114248
[Files - No Company Name]
NY ->  ~43114248 -> C:\ProgramData\~43114248
NY ->  ~43114248r -> C:\ProgramData\~43114248r
NY ->  43114248 -> C:\ProgramData\43114248
[Custom Items]
:Files
ipconfig /flushdns /c
:end
[Empty Temp Folders]
[EmptyFlash]
[CreateRestorePoint]
  

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here

I will review the information when it comes back in.

THEN

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

http://i1224.photobucket.com/albums/ee362/Essexboy3/aswmbrscan.gif

Click the “Scan” button to start scan

http://i1224.photobucket.com/albums/ee362/Essexboy3/aswmbrsavelog.gif

On completion of the scan click save log, save it to your desktop and post in your next reply

Not sure if this is significant, but after I ran the fix it restarted my computer then had the box popped up.

Total Files Cleaned = 6,972.00 mb lots of junk gone ;D On completion of this run can you let me know what problems you are having

http://img233.imageshack.us/img233/7729/mbamicontw5.gif
Please download Malwarebytes’ Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.

[*]Make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.
[*]If an update is found, it will download and install the latest version.
[*]Once the program has loaded, select “Perform Quick Scan”, then click Scan.
[*]The scan may take some time to finish,so please be patient.
[*]When the scan is complete, click OK, then Show Results to view the results.
[*]Make sure that everything is checked, and click Remove Selected.
[]When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
[
]The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
[*]Copy&Paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

Currently running the quick scan on the infected computer. All the issues are the same as before, the random sound ads that can’t be seen, my background is still pure black, and the same programs won’t run. Attached is 2 screenshots of error messages that I got just during typing this post out. (Edit): I just got a third error message, with more sound ads while scanning.

OK time for the big boy then as whatever it is, is hiding

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

[]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
[
]Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Gotta hate the new viruses lol. Attached is the log from mbam

I’ve just been looking at one of these I finished yesterday - it was a new variant of TDL4 that neither TDSSKiller nor ASWMbr caught - I am waiting for an mbr dump on that. CF killed it

None of the previous pop-ups since ComboFix was completed. Though now when I attempt to open ANY program including ComboFix or even something as simple as Paint. Attached is the ComboFix log. Also this is the error message I’m getting:

"C:\Program Files\Adobe\Adobe Photoshop CS3\Photoshop.exe

Illegal operation attempted on a registry key that has been marked for deletion."

Infected copy of c:\windows\system32\drivers\volsnap.sys was found and disinfected Restored copy from - Kitty had a snack :p
One culprit dead

OK reboot the system once more please - if you still get the error then uninstall Adobe (this is because adobe has corrupted the open with key)

Also could I have one final OTS scan please

No problem, I’ll get working on those right now for you and post as soon as the scan is done. (Edit): Also because just about everything is coming up with that error, does that mean I would have to uninstall everything on my computer petty much?

No just adobe - once it is uninstalled all should be back to normal - funnily enough I had one similar to this a few weeks ago and it took two days to figure out ;D

I’m just glad to have someone as professional as you helping me out, otherwise this would take me months to have figured out alone. :slight_smile:

If it helps I am happy

The new OTS

Alas that was unicode could you change it to ansi please - also what problems remain

http://i1224.photobucket.com/albums/ee362/Essexboy3/Untitled.gif