This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Desktop infected with multiple virus-most apps dont work

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, My desktop is infected with multiple virus. The virus took administrator ownership of my pc. I am not able to start the PC under safe mode. Most of the applications are not working. When i click an .exe file, i always get the option "Choose the program you want to use to open this file" Some of the applications I am able to start from DOS prompt. Other than AVG, it is not letting me run other antivirus or malware programs. AVG finds 5000 virus but it was only able to remove 100 of the findings. I need you help to get my PC fixed. I have windows XP, SP2 installed. Thanks, glitter
[external image: Posted Image]

Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:

  • Absence of symptoms does not always mean the computer is clean
  • Please do not run any scans or fixes without my direction.
  • Finally, stay with this topic until I give you the final 'All clear' post.

1) numberCruncher
Please download numberCruncher by Raktor to your desktop. Make sure you save it with its current filename of explorer.exe.
  • Double-click on explorer.exe to start the tool
  • A black box will open, and run the fix.
  • At the end, be sure to record the information in the window and post it here. No logfile will be saved
  • Press any key to close the window
  • Note: If the program will not execute, download explorer.com, and follow the above instructions again (but ensure that it is named explorer.com).

2) DDS
[external image: Posted Image]
Please download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop.

3) RR
Please download RootRepeal.zip.
Save it to your Desktop. Alternate download links here or here.
Please print these instructions, you will not have an Internet connection!
If you have a 3rd party "unzipping" program…use it to open the zipped file…then skip to Step 5. Otherwise…
  • Right click on RootRepeal.zip and select "Extract All"….
  • Click Next on the "Welcome to the Compressed (zipped) Folders Extraction Wizard."
  • Click on the Browse…button, then click on Desktop, then click OK.
  • Once done, check (tick) the Show extracted files box and click Finish.
  • Before running RootRepeal:
    • Disconnect from the Internet as your system will be unprotected while using this tool.
      Close all programs and temporarily disable your anti-virus, Firewall and any anti-malware real-time protection before performing a scan.
  • Open the RootRepeal folder and double-click on RootRepeal.exe to launch it.
  • When the program opens, click the Report tab at the bottom, then click the Scan button.
  • In the Select Scan, dialog which asks What do you want to include in the scan?, check ALL the boxes.
    🖼Click to load external image (Posted Image)
  • Click OK.
  • In the Select Drives, dialog Please select drives to scan: select all drives showing, then click OK.
    The scan can take some time to finish. Do not use the computer while the scan is running.
    When the scan has completed, a list of files will be generated in the RootRepeal window.
  • Click on the Save Report button and save it as "rootrepeal.txt" to your desktop.
  • Close and exit RootRepeal
  • Double-click on the file rootrepeal.txt… Notepad will open… copy/paste the file contents in your next reply.

Make sure to enable your anti-virus, Firewall and any other security programs you disabled.
Note: If RootRepeal cannot complete a scan and results in a crash report, try repeating the scan in "safe mode".

4) What You Will Need To Post:
  • Information from numberCruncher
  • DDS log
  • RR log
Hello Raktor, Thank you for helping me out. Appreciate your time and effort. I have uploaded the zip file of all the logs as requested by you. Thanks, glitter

Attachments:

  • [attachment removed: NC_RR_DDS.zip]
I hate to the bearer of bad news but, your logs show very dangerous trojans and rootkits are residing on your PC.

They attempt to steal passwords, as well as logging key presses and open window titles to text files and periodically send the collected information to a remote user via HTTP. They download and execute additional files from a remote site. Configuration files may also be downloaded which define further behaviors.

As you can see, it not only includes a key logger, but back door functionality.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or it if it contains any other sensitive information, please get to a known clean computer and change all passwords where applicable and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the trojans and rootkits have been identified and can be killed, because of their back door functionality your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with these types of infections, the best course of action would be a reformat and reinstall of the OS. If it were on my PC I would not hesitate for a moment to do so. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall

Should you decide not to follow that advice, we will of course do our best to clean the computer of any infections that we can see but, as I already stated, we can in no way guarantee it to be trustworthy.

Should you have any questions, please feel free to ask.

Please let us know what you have decided to do.

If you choose to continue instead of format, follow the below instructions.

======================================================

Please read through the instructions to familiarize yourself with what to expect when the tool runs.

Please download Combofix from either of the links below, and save it to your desktop.
You must rename it before saving it. Save it as iexplore.exe.

[external image: Posted Image]

Link 1
Link 2

The images above say how to save it as Combo-fix.exe, but in this case it is crucial that it is saved as iexplore.exe

**Note: It is important that it is saved directly to your desktop**

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link:How to Disable your Security Programs
  • Double click on iexplore.exe & follow the prompts. Close all browsers/windows first.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi Raktor, I wanted to clean my PC and remove the major threats before I format my computer. Ever since it was hijacked, I havent used this PC for a month now. I also disabled the network. I ran combofix as you requested. Attaching the log.

Attachments:

Please redownload Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    http://forums.whatthetech.com/Desktop_infected_multiple_virus_most_apps_dont_work_t106711.html
    
    Collect::
    c:\windows\waw32.exe
    c:\windows\system32\riwakabe.exe
    c:\windows\system32\yikujode.dll
    c:\windows\system32\gazeyuha.dll
    c:\windows\system32\pimenuda.dll
    c:\windows\system32\bavovayo.dll.tmp
    c:\windows\system32\jutepeso.dll
    c:\windows\system32\regoyivu.dll.tmp
    c:\windows\system32\sapahore.dll
    c:\docume~1\LOCALS~1\protect.dll
    c:\windows\system32\drivers\21c37e9b.sys
    
    File:: 
    C:\cleanup.bat
    C:\zip.exe
    
    Folder::
    c:\documents and settings\Compaq_Owner\Application Data\fhqtmysk
    c:\documents and settings\All Users\Application Data\93268746
    c:\documents and settings\All Users\Application Data\13258754
    c:\program files\Yahoo!\Messenger\bak
    c:\program files\QuickTime\bak
    c:\program files\Musicmatch\Musicmatch Jukebox\bak
    c:\program files\Java\jre1.5.0_09\bin\bak
    c:\program files\iTunes\bak
    c:\program files\Common Files\Real\Update_OB\bak
    
    AWF::
    c:\program files\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe
    c:\program files\Common Files\InstallShield\UpdateService\bak\ISUSPM.exe
    c:\program files\Common Files\InstallShield\UpdateService\bak\issch.exe
    
    FixCSet::
    
    Registry:: 
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CPM6f81eeda"=-
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "autochk"=-
    [-HKEY_LOCAL_MACHINE\System\controlset002\Services\21c37e9b]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    Driver::
    ghe3uydrt57iw54wuaehaamg80
    
    File::
    c:\windows\ghe3uydrt57iw54wuaehaamg81.exe
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

That will finish the removal of the major infection, if you want to proceed cleaning and get the other bits - let me know, otherwise now would be a good enough time to format. :) Let me know which way you're going to go.
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    Rootkit::
    c:\windows\ghe3uydrt57iw54wuaehaamg81.exe
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

That will finish the removal of the major infection, if you want to proceed cleaning and get the other bits - let me know, otherwise now would be a good enough time to format. :) Let me know which way you're going to go.
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    Rootkit::
    c:\windows\ghe3uydrt57iw54wuaehaamg81.exe
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

That will finish the removal of the major infection, if you want to proceed cleaning and get the other bits - let me know, otherwise now would be a good enough time to format. :) Let me know which way you're going to go.
Hi Raktor, Appreciate your help and time. I am attaching the log from my last combfix run. Is it now safe to backup my files from this desktop to a external hard drive? Is it safe to connect this PC on the network? If you certify, then I would like to backup stuff and format the PC. Thank You, glitter

Attachments:

Go for it. :thumbup: I'd prefer you used an external hard drive rather than connecting it to a network, but it appears that all the major infections are gone. :) Reply and let me know how you go.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI