avg rootkit scan causes bsod?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by John67, Feb 13, 2011.

  1. John67

    John67 Private E-2

    I am trying the sophos but everything it says is unknown hidden files,
    this is an Xp sp3 system with 2ghz, 1gb ram, emachines i think
    I recently tried to download new Internet explorer and am using it, but this thing will reboot itself in the middle of the night without running sched avg scans , that's the main symptoms, but the avg did find some malware,
    is this a rootkit virus? that it would make avg rootkit scan reboot and with bsod?

    please help
    thanks
    John K
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    There can be many reasons for a PC to be rebooting. Most of them are not malware. They are more likely system or application crashes. However if you wish to properly check your PC for infections, please run the below.


    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:
    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. John67

    John67 Private E-2

    thank you i will read all this and try the steps..
    John
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Be sure to attach the requested logs when you finish.
     
  5. John67

    John67 Private E-2

    I will, it is still scanning with superscan..so i got up to #7 step and have the 4 more scan categories to go thru, but i tried to rootkit scan with avg at step 6 and it did not cause the bsod..yippee, so should i continue?
    thanks again..
    john
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not run anything except what we asked you to run and complete all steps in the order given. Since AVG is quite problematic for tools like ComboFix and also sometimes for MGtools, you may need to uninstall AVG inorder to complete the scans.

    Yes!
     
  7. John67

    John67 Private E-2

    ok sorry i knew I prob shouldn't have ran it, the superscan still going ..has found a trojan .agent/gen-iefake..amongst adware tracking cookies and browser hijacker-favorites, is it normal for superscan to take so long up to 3 1/2 hrs now..
    thanks for your help I appreciate it!
    ..john
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it can take a long time for scans to run depending on hard disk size, number of files on the disk, and the speed of your computer. Just wait for all scans to finish before posting back unless you have a real problem.

    NOTE: Cookies are not problems and you were supposed to disable scanning for them when you setup SUPERAntiSpyware per the instructions.
     
  9. John67

    John67 Private E-2

    Hi i finished the steps, couldn't run combofix unless avg uninstall, but here is the mgtools log, it did fix the bsod problem, thank you sooo much,
    i see the mgtools was by you? that's cool as hell, very nice..
    i didn't see the superantispyware option for no cookies:-o,
    it gets confusing for a greenhorn like me;) , well thank you i guess you'll let me know about the log?,
    how do i send the rootrepeal log?
    best wishes ..john k
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that was explained and if you really wish to complete your check for malware, you will need to do this.

    It is in the procedure explaining how to run it.

    You attach it just like MGlogs.zip. You also need to attach the logs from SUPERAntiSpyware and Malwarebytes.
    Code:
     
    "C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    Apr 17 2010  2322 "SUPERAntiSpyware Scan Log - 04-17-2010 - 14-30-19.log"
     
    "C:\Documents and Settings\Owner\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\"
    Feb 14 2011   953 "mbam-log-2011-02-14 (13-19-37).txt"
    
    Do you have any idea what the below startup process is? Looks like malware to me.
    O4 - HKCU\..\Run: [qK11n4n5QpCnn] control.exe "C:\Program Files\dsZA5\qK11n4n5QpCnn.cpl",0,1


    Uninstall the below extremely old version of software:
    Spybot - Search & Destroy 1.2

    Also the below are not recommended
    BearShare Test
    BearShare
     
  11. John67

    John67 Private E-2

    Ok i think the dsza5 is easy duplicate file finder..webminds inc ,it sure didn't work..,
    the folder it made though is empty, ok think i got the files for you,
    gonna uninst avg now..
    thanks
    John K
     

    Attached Files:

  12. John67

    John67 Private E-2

    Hi chaslang,
    here is the combofix log,
    do you have a better suggestion for antivirus other than avg?
    thanks
    john k
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Avira or Avast as show in the below sticky thread.

    How to Protect yourself from malware!


    You need to stop downloading and saving files into your Progam Files folder like below ( and you have many more there too ):
    Code:
    2011-02-13 22:31 . 2011-02-13 22:31 13564184 ----a-w- c:\program files\SAS_757C8785.COM
    2011-02-13 22:23 . 2011-02-13 22:24 7734240 ----a-w- c:\program files\mb.exe
    2011-02-13 20:45 . 2011-02-13 20:46 883488 ----a-w- c:\program files\JavaSetup6u23.exe
    2011-02-13 05:53 . 2011-02-13 05:53 1376832 ----a-w- c:\program files\sar_15_sfx.exe
    2011-01-28 06:24 . 2011-01-28 06:24 14709624 ----a-w- c:\program files\IPx86_1033_8.0.225.0.exe
    
    This is a bad practice. Only installed programs should be here. Save your downloads elsewhere like a C:\Downloads folder with appropriate sub-folders showing the correct full program name and version so you know exactly what a file is for.... even many months after downloading it.





    You are way out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.
    Now run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O3 - Toolbar: Tracker Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O4 - HKCU\..\Run: [qK11n4n5QpCnn] control.exe "C:\Program Files\dsZA5\qK11n4n5QpCnn.cpl",0,1
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Owner\Local Settings\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the new SUPERAntiSpyware log
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Feb 16, 2011
  14. John67

    John67 Private E-2

    ok i did the new scan here is the log
    ..thank you for the heads up on the dl of program inst to program files,
    I didn't know where to really dl i thought that would be the place ..
    John k
    now to get rid of bs
     

    Attached Files:

    Last edited: Feb 17, 2011
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to finish the rest of my previous instructions.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds