Windows XP 2010 says PC infected

No cant open any exe files it seems,

Never managed to open malwarebytes after it download. I still have the setup application file but it wont open

If I go into control panel & double click anything in there a box comes up saying C:\Windows\system32\rundll32.exe Application not found.

Similarly if I go to Start - All programs & click any of the programs it either says application not found or “Open with” box opens.

You said to disable restore, but would it not be better to try to restore to a previous point if possible?

Thanks

Do NOT Restore your computer, it will restore back all the malwares you just clean up.

Click Start, Run. Type command and press Enter. Type notepad and press Enter.
Notepad opens. Copy all the text below into Notepad.

Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"

Save this as fix.reg to your Desktop (remember to select Save as file type: All files in Notepad.)
Double Click fix.reg and click YES for confirm.
Reboot your computer.

http://myantispyware.com/forum/rundll32-exe-application-not-found-t1761.html

Go http://www.dougknox.com/xp/file_assoc.htm and download and run the EXE file association fix.

Are you able to run programs ending in EXE now?

BINGO!!! downloaded & now just opened Malwarebytes setup wizard.

I presume I should continue to set up this & run a full scan straight away should I or should I re boot first?

Thanks again

Regards
Myles :slight_smile:

Install malwarebytes and update it then run full scan. If malwarebytes ask reboot in order to complete removal of malwares then you click “yes”.

Just running full scan now with malwarebytes. When that’s finished should I also do full scans with avast & superantispyware before I do anything else? (will post results shortly)

Will I also need to still go thru the procedure to remove the original problem of antivirus XP 2010?

Just out of interest, after I rebooted last time had a box come up:
RUNDLL: error loading nynw.wmo. The specified module could not be found.

What does this mean?

OK, So, finished scan with Malwarebytes, Here’s the log:

Malwarebytes’ Anti-Malware 1.44
Database version: 3823
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

04/03/2010 02:21:42
mbam-log-2010-03-04 (02-21-02).txt

Scan type: Full Scan (C:|D:|)
Objects scanned: 326435
Time elapsed: 1 hour(s), 13 minute(s), 7 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 10
Registry Values Infected: 1
Registry Data Items Infected: 4
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) → No action taken.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt&Search(default) (Adware.Hotbar) → No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) → Bad: (Explorer.exe rundll32.exe nynw.wmo mynleeq) Good: (Explorer.exe) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Administrator\My Documents\Application files\freezip.exe (Trojan.Agent) → No action taken.

Now here is log file from SAS:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 03/03/2010 at 05:36 PM

Application Version : 4.34.1000

Core Rules Database Version : 4634
Trace Rules Database Version: 2446

Scan type : Complete Scan
Total Scan Time : 02:32:14

Memory items scanned : 652
Memory threats detected : 2
Registry items scanned : 6990
Registry threats detected : 16
File items scanned : 122780
File threats detected : 5

Trojan.Agent/Gen-Frauder
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\3E.TMP
C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\3E.TMP
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\3E.TMP
C:\WINDOWS\SYSTEM32\NYNW.WMO

Trojan.Agent/Gen-Rogue[AV]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\AV.EXE
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\AV.EXE
C:\WINDOWS\Prefetch\AV.EXE-09240382.pf

Adware.MyWebSearch
HKU\S-1-5-21-2158612188-1835295398-4226529277-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{00A6FAF1-072E-44CF-8957-5838F569A31D}
HKU\S-1-5-21-2158612188-1835295398-4226529277-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{07B18EA1-A523-4961-B6BB-170DE4475CCA}

Trojan.Agent/Gen
HKCR\idid
HKCR\idid#url1
HKCR\idid#url2

Adware.MyWebSearch/FunWebProducts
HKCR\CLSID{147A976F-EEE1-4377-8EA7-4716E4CDD239}
HKCR\Interface{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
HKCR\Interface{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid
HKCR\Interface{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid32
HKCR\Interface{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib
HKCR\Interface{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib#Version
HKCR\Interface{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
HKCR\Interface{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid
HKCR\Interface{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid32
HKCR\Interface{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib
HKCR\Interface{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib#Version

would it be safe to restore any of these files?

Thanks[/color]

your Malwarebytes log says " No action taken. " you have to click the " REMOVE SELECTED " button after the scan to quarantine the infections

Hi Pondus,

Yes I see that now, not sure why it said that actually as I did remove, here’s log now;

Malwarebytes’ Anti-Malware 1.44
Database version: 3823
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

04/03/2010 02:23:17
mbam-log-2010-03-04 (02-23-16).txt

Scan type: Full Scan (C:|D:|)
Objects scanned: 326435
Time elapsed: 1 hour(s), 13 minute(s), 7 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 10
Registry Values Infected: 1
Registry Data Items Infected: 4
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) → Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt&Search(default) (Adware.Hotbar) → Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) → Bad: (Explorer.exe rundll32.exe nynw.wmo mynleeq) Good: (Explorer.exe) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Administrator\My Documents\Application files\freezip.exe (Trojan.Agent) → Quarantined and deleted successfully.

Is it safe to delete all these files from quarantine? or do I need to find replacements for any of them first?

Also It seems that XP antivirus has been uninstalled. but according to the manual removal link I was sent earlier in this topic, on opening taskmanager & processes tab, it says to delete image names svchost.exe . Do I still need to do this as it crops up in the process list 8 times.

It also said to delete the following REG keys:

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Cl ass{4D36E972-E325-11CE-BFC1-08002bE10318}\0012
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Cl ass{4D36E972-E325-11CE-BFC1-08002bE10318}\0013
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Cl ass{4D36E972-E325-11CE-BFC1-08002bE10318}\0014

Which are still in the registry, I just want to be certain it’s safe or necessary to do so first.

And Finally, here is scan result from Avast, there are a few items that it says it could not scan, are these potential threats?

avast! Virus Cleaner Tool - version 1.0.211 Ansi

Creating log file: C:\Program Files\Alwil Software\Avast4\DATA\log\cleaner.log

3/4/2010, 8:48:27 AM
Memory scanning started…
No virus body found in memory.
Memory scanning finished (28.1s).

Files scanning started…
C:\Documents and Settings\Administrator\Application Data\Skype\myles.brewer\dc.db-journal… file could not be scanned!
C:\Documents and Settings\Administrator\Application Data\Skype\myles.brewer\main.db-journal… file could not be scanned!
C:\Documents and Settings\Administrator\Local Settings\Temp\etilqs_bgMwdycJRxpWO7raO0v5… file could not be scanned!
C:\Documents and Settings\Administrator\Local Settings\Temp\etilqs_ijPApoaMpx4LgT99fUET… file could not be scanned!
C:\Documents and Settings\Administrator\Local Settings\Temp\tmp18.tmp… file could not be scanned!
C:\WINDOWS\system32\CatRoot2\edb.log… file could not be scanned!
C:\WINDOWS\system32\CatRoot2\tmp.edb… file could not be scanned!
No virus body found.
Files scanning finished (193816 files, 0 infected, 3315.3s).
Drives scanned: C: D:

Thanks very much
regards
Myles

If you follow this guide from Essexboy and post the OTL log HERE
he is the malware expert and can then see if there is moore that needs to be done

http://forum.avast.com/index.php?topic=53253.0

Hi Pondus,

OK did that & have attached files as requested.

Thanks

i usually see him in here after 20:00 norwegian time so be patient, he works in several forums

Hi I have a day off ;D That does not look to bad now - what other problems do you have ?

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

:OTL
O33 - MountPoints2\{9fa89f00-8950-11dd-8614-001d920d4861}\Shell\AutoRun\command - "" = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\stcvhost.exe -- File not found
O33 - MountPoints2\{9fa89f00-8950-11dd-8614-001d920d4861}\Shell\open\command - "" = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\stcvhost.exe -- File not found
:Files
C:\Documents and Settings\Administrator\Local Settings\Temp\tmp18.tmp

:Commands
[purity]
[emptytemp]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

OK Essexboy,

Here’s the log now after scan:

That was corrupted - you probably had notepad set to unicode as opposed to ansi

How is the computer now are you experiencing any problems ?

Your spot on, try this now, let me know if it looks ok.

Computer seems (I’m not saying this really) fine ssshhhh!!! :slight_smile:

Thanks everyone for your help on this, very much appreciated.

OK that looked good. At some stage you had connected an infected USB drive to your system, I would recommend that you always scan USB’s before running them
You have several out of date Java versions on your system

Please download JavaRa to your desktop and unzip it to its own folder

[*]Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
[*]Accept any prompts.
[*]Open JavaRa.exe again and select Search For Updates.
[*]Select Update Using Sun Java’s Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

.
.
Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself.

SPRING CLEAN

Download TFC to your desktop

[*]Open the file and close any other windows.
[*]It will close all programs itself when run, make sure to let it run uninterrupted.
[*]Click the Start button to begin the process. The program should not take long to finish its job
[*]Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean

.
THEN

Download Flush Flash from Here and follow the easy to use instructions on the same page

NEXT

Download and run Puran Disc Defragmenter

Thanks Essexboy,

Think that must be about it now, Just one final question, I have an external hard drive which I unplugged when I realised I was under attack!!

Haven’t plugged it back in since, so it’s had none of the scans etc, is it sufficient to just plug it in now & scan with SAS MBAM & avast before accessing it?

Thanks