BSoD whilst installing XP Malicious Tool update

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by haagden, Dec 16, 2006.

  1. haagden

    haagden Private E-2

    Hi,
    This saga started whenthe young owner of this laptop requested help after opening a suspicious file received on MSN Messenger.

    I installed and ran AVG anti-spyware and AVG anti-virus which found several Trojans and downloaders. However the laptop continued to get infested and it appeared that Trojans were regularly being reinstalled. I then installed and ran Spyhunter. This also found and cleaned Trojans and Downloaders. I then (perhaps unwisely) attempted a repair on the Windows XP OS for which I had the original disk (not SP2). Several doozen updates later it installed SP2 however since then when attempting to install the MS "Malicious Software Removal Tool" the update has always resulted in a BSoD.

    I have now followed the procedures in the READ ME PROCESS and will attach the files for analysis and comment. I fear that there is a ROOTKIT infection.

    Your assistance will be much appreciated.
     

    Attached Files:

  2. haagden

    haagden Private E-2

    Herewith the remaining files. By the way when I ran Bit Defender I accidently lost the text file report (it showed some items infected and removed) so I ran it again. Consequently the atttached BD Report shows no infections. Sorry about that, hope it doesn't hinder the investigaion
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    None malware observation: I recommend that you either cleanup (remove) a lot of stuff from your hard disk or get a larger hard disk. You show only 760,823,808 bytes free. I know this looks like a lot but it is not even 3/4 of a Gigabyte and in todays Windows XP environment, this is really to little to have free. A lot of disk is required for the OS to run smoothy and for backups and System Restore points to be created....etc.

    We don't recommend using SpyHunter and infact recommend uninstalling it. Bad track record/history! This is up to you though. But if it was just the trial download it is of no use to you anyway.

    Now Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 3
    J2SE Runtime Environment 5.0 Update 6

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Now you need to re-run CounterSpy and have it fix everything it found. You had it ignore all of the MyWebSearch and Fun Web Products junk.

    Okay now let's remova a malware service!
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Microsoft authenticate service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteMsaSvc into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when if it tells you it needs to.
    After reboot delete the below folders if found:
    C:\Program Files\MyWebSearch
    C:\Program Files\Common Files\{806D4CF1-018F-1033-1231-993199002c}
    C:\Program Files\Common Files\{306D4CF1-018F-1033-1231-993199002c}

    Additional step to delete files in the Downloaded Program Files folder :
    - Click Start, Run, and enter cmd in the box and click OK. This opens a command prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s f3initialsetup1.0.0.15.inf
    del f3initialsetup1.0.0.15.inf
    exit



    Now attach a new HJT log and tell me how things are working!
     
  4. haagden

    haagden Private E-2

    Thanks for your time. It is much appreciated.

    Regarding your observation on lack of free disk space, I wholeheartedly agree. Believe it or not I have had to move some data files (photos and word documents) to a memory stick to get even the space there is at present. Don't know what's hogging all the space as there is little in the add/remove programs that looks that significant. I'll advise the laptop owner to purchase a larger disk.

    Back to the malware. I uninstalled Spyhunter, it wasn't the trial version but I felt it best to purge it. I uninstalled the old Java Runtime and installed the later version.

    I then ran Counterspy but unfortunately I got a BSoD whilst it was checking Registry entries. I rebooted and tried again in Safe Mode. This time it again found the MyWebSearch and Fun Web Products junk (nor sure how I came to not delete it first time round) as well as Trojan Downloader Matcash. This time all were deleted.

    I then implemented the remaining actions you suggested until the attribrute change to the file f3initialsetup1.0.0.15.inf which was unsuccessful. I checked the directory but this particular .inf file is not present.

    Attached is the HJT file you requested.

    Since these actions I have successfully installed the MS Malicious Software Removal Tool and IE7. The system is much, much better.

    Hope I have done all the right things.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What size hard disk is it?

    Try running this to help you see where space is being used:

    http://users.forthnet.gr/pat/efotinis/programs/overdisk.html

    Good!

    That's okay! Rerunning CounterSpy and having it fix the malware it detected probably deleted it already.
     
  6. haagden

    haagden Private E-2

    The disk size is only 6 Gbyte, it's an old Toshiba Tecra 8000 upgraded to XP.

    I'll try the program you recommend to see what's taking up the space.

    Do I need to take any other clean-up action such as toggling System Restore?

    You certainly work hard for the benefit of others!
     
  7. haagden

    haagden Private E-2

    Looked at disk analysis. Larger disk certainly required. Surprising how much space is taken by Windows and all it's backtrack and recovery files/mechanisms
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that was the first mistake. This PC does not fit what I would define as the minimum requirements for effectively using Windows XP. The harddisk is way to small, the processor speed is too slow, and it probably does not have enought RAM either. I believe it was a 333Mhz system with only 64 MB by default. I don't even recommend using Windows 98 on a system with only 64MB of RAM. However, I don't know how much RAM is in your system. I don't recommend less than 512 MB with Windows XP; however I would not installed Windows XP on a system with less then a 1 Ghz Processor. While it may work (based on Microsofts minimum recommendations) there is a difference between working and working well.

    Yes! If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
    Last edited: Dec 17, 2006
  9. haagden

    haagden Private E-2

    Completed the cleanup. However this morning I ran Counterspy again just as a final check. It found a new Trojan PWS-Banker. I quarantined this and then did a further scan that proved clean.

    Incidently I can only complete Counterspy in Safe Mode. Running it in Normal Mode always results in a BSoD. This may be due to the lack of free disk space on this machine. I have noted your comments on iits limitations for running XP. It is not quite as bad as you assumed, having a 400MHz PIII and 256Mbytes RAM. Unfortunhately it's all my young student friend can afford . XP was installed as Microsoft no longer support Win'98.

    I will attach a final HJT log just so you can confirm that it is clean.

    Many, many thanks for your help.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not as bad as I thought but still rather inadequate especially with the hard disk size. MS does not support Win98 anymore but they do support Windows 2000 which could run better on this PC. However even with Win 2000 a 6 Gb hard disk is a little too small. And if you are cgoing to use programs like LimeWire to download stuff (like MP3s...etc) it is way too small.


    Your log is clean.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds