6-10-11 Hijack/scareware win7-64bit

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by theHollyWood, Jun 10, 2011.

  1. theHollyWood

    theHollyWood Private E-2

    Mid-month of June 2011, I got my first virus in my history of computing that started in the early 90s on my Window 7 64-bit Ultimate laptop.
    This was the nastiest virus I have ever seen, because I do virus removal on occasion for friends.

    The most probable reason why I was hit by this Hijack/Scareware virus is that my Windows Update,
    had failed to complete in over a month and I choose to ignore fixing the update process.

    This virus Modified the OS to make it look like all my programs and files were deleted.
    All of my files are still intact and are on my SSD but I have no way to access them in Windows.

    I had already removed the virus by taking the infected drive and running a scan by a different system.
    When I did this the infected SSD tried to attack that system, but all my updates and scans were current on the desktop computer and it remained protected.

    Now that the SSD is clean of the virus, Windows 7 is still modified where I can do next to nothing and cannot access the files or .exe on the drive.

    After seeing this I booted Ubuntu Linux and did a file extraction of any thing that I thought was important.
    At this point I could nuke the SDD and start over, but I really want to try to preform a fix so I can gain knowledge on how to deal virus like this in the future.

    I have a few friends that work in IT that directed me to this website for help. They said that I needed to fix .exe extensions and other things in Windows.
    If you need any log files, just tell me how to retrieve them.

    Thanks,
    -the wood
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. theHollyWood

    theHollyWood Private E-2

    Thanks that did help a lot, now I can see and run the programs on the hard drive.
    But the Windows setting are still messed up, I can't run Task Manager, and the Start Menu Pin list is not populated.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then it is time for you to move on to the below.

    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:


    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  5. theHollyWood

    theHollyWood Private E-2

    logs 1
     

    Attached Files:

  6. theHollyWood

    theHollyWood Private E-2

    logs 2

    let me know if you want to have the logs of the trojan from my other computer
     
  7. theHollyWood

    theHollyWood Private E-2

    logs

    I am having trouble with posting the MGtools.zip
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The log file is named MGlogs.zip. Do not attempt to attach the MGTools.exe program that you downloaded.
     
  9. theHollyWood

    theHollyWood Private E-2

    mglogs
     

    Attached Files:

  10. theHollyWood

    theHollyWood Private E-2

    Here are the logs of the Trojan taken last month
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Running from: c:\tools 2011\ComboFix.exe <--- Combofix needs to be run from your dekstop, please move it there now before we continue. Also MGTools should be on the root folder of your Windows Boot drive, usually C:\

    What are you currently using for antivirus?? I am seeing two different anti virus which has not been completely uninstalled.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "DisableCAD"=-
    File::
    C:\ProgramData\~45604600
    C:\ProgramData\~45604600r
    C:\ProgramData\45604600
    Folder::
    C:\ProgramData\mO00000McMmO00000
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  12. theHollyWood

    theHollyWood Private E-2

    There are bits and pieces of Microsoft Security Essentials left over and I am unable to delete them. My system is currently running ESET 4.

    I followed the instructions but it doesn't look like anymore changes to my system occurred.
     

    Attached Files:

  13. theHollyWood

    theHollyWood Private E-2

    It looks like all Microsoft programs have been affected by the Trojan.

    I can't find paint, Microsoft Office is gone and shortcuts/extensions like to the download folder are still broken.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      mspaint.exe
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt


    Are you able to reinstall this from the disk which would be easy enough to sort out? However all the below still appears in add/remove progs:

    What other shortcuts are broken exactly?

    See if this works for you.

    Empty Temp Folders 2.8.3

    Let's see if it's any help to you and your situation.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Be careful with this. You DO NOT WANT to empty temp folders. The infection you had stores backups in temp folders. Running this could delete them if you choose to empty/cleanup temp folders. This is not recommended. Fixing links is one thing, emptying temps is another.;)
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I only wanted to try and fix the links, use that side of the software, but you are right, too risky I will find a better alternative. I'll edit the post or delete it. :) Holly wood, you have not followed those instructions, no?
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What other shortcuts are broken exactly? Let me know.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Rerunning unhide may be worth a try. If it is not restoring links to program files then they may not exist any more and manual rstoration may be the only option other than trying a System Restore to before the infection. But then you would have to rescan to make sure no infected items are restored.
     
  19. theHollyWood

    theHollyWood Private E-2

    Well now that you helped me find paint I can post screenshots of my problems :)

    The first is the unpopulated start menu
    The second is the bad link to the download folder

    *Oh I was able to uninstall Microsoft Office and now I am in the process of reinstalling it.
     

    Attached Files:

  20. theHollyWood

    theHollyWood Private E-2

    Can't do that all the restore points were deleted by the Trojan, it would have to be a manual restore.

     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So this probably will not work for your start menu but I shall try and think of something else, but give it a go anyway.

    Open Notepad.

    Copy all text from the following code box and paste it into Notepad window:

    Code:
    @echo off
    xcopy "C:\Users\hollywood\AppData\Local\Temp\smtmp\1\*" "C:\Program Data\Start Menu\" /s
    
    Save the file as fix.bat

    • Double click fix.bat to run it.
    • A pop-up window will open and you will see information regarding the number of files being copied.
    • The window will now close.

    Did that help?
     
  22. theHollyWood

    theHollyWood Private E-2

    Oh and I need to figure out how to delete Microsoft Security Essentials completely off of the computer.

    see screenshot

    combofix log attached
     

    Attached Files:

  23. theHollyWood

    theHollyWood Private E-2

    The window popped up for a split second and then closed, I couldn't see anything. Start Menu is the same.


     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you able to then drag and drop programs onto the start menu? :confused
     
  25. theHollyWood

    theHollyWood Private E-2

    I right-clicked properties and restored default settings for the start menu.

    As for the other stuff, I guess it doesn't need to get fixed or I will play with it in the future.

    Thanks for the help Kestrel13!
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    One more look through the logs

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  27. theHollyWood

    theHollyWood Private E-2

    mgtools log
     

    Attached Files:

  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Everything okay? The logs look good. Just delete this folder:
    • C:\Windows\8A809006C25A4A3A9DAB94659BCDB107.TMP

    AVG Free 9.0 <--- Also note that this is out of date and you should upgrade to the current version or pick another antivirus.
     
  29. theHollyWood

    theHollyWood Private E-2

    K thanks, I am currently running ESET 4 on that machine.
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds