Bypassing Malware which stops applications with Remote Desktop Connetion

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by chris007, Jan 30, 2010.

  1. chris007

    chris007 Private E-2

    I was trying to help my client remove some malware of his website and got myself infected. My #1 sympton is that the possible malware is blocking most applications from executing when logged in with default Admin login.

    Applications which are being blocked right now are most of the popular anti malware applications including spybot, sas but also other applications such as Adobe apps and it's also blocking newly installed software from executing.

    Another sympton I have is that the desktop constantly refreshes (blinking) immediately upon login. I checked the event viewer which basically says that the winlogon.exe is crashing explorer.exe. The only way I am able to stop this constant refreshing is by running combofix.exe via task manager right upon login.

    I found this very interesting as comobofix isn't really supposed to run on my system which is WIN2k Advanced Server SP4. But it seems to be the only tool I found that stops the desktop refresh and I am actually very very happy about that, as my symptoms when logged into safe mode are almost identical.

    I found a workaround by connecting to the machine via Remote Desktop Connection (RDC). When connected with RDC everything works fine. I am able to run all programs.

    Hopefully this will help someone who is in the same situation and unable to run Anti Virus programs even in safe mode. In order to establish a successful RDC connection, make sure that all required services are started such as Terminal Services and others.

    Unfortunately, the scanners that I ran including the ones mentioned above + Malwarebytes, even Kaspersky and Panda online scans did NOT pick it up and I still have both symptons.

    Does anybody know if there is a way to overwrite the current admin profile with the same profile that's created when a RDC connection is established?
    Or should I approach this a different way?

    Any advice, comments or assistance you may be able to provide is highly appreciated.


    Thank you all in advance,
    Chris
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Combofix is indeed compatible with windows 2000m machines. And so is MGTools.
    Can you then run all of the requested scans by that method?
     
  3. chris007

    chris007 Private E-2

    No, all I am getting is the combofix progress bar - even in safe mode. But the process of the combofix progress bar loading seems to put a stop on the desktop refresh (explorer.exe crash by winlogon.exe). 1 out of 100 attempts, I got a windows screen saying that combofix is not supported on my OS and runs on XP and Vista or something.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So what happens with MGTools? In order to give you a fix I must see at least logs from running MGTools.exe.
     
  5. chris007

    chris007 Private E-2

    here ya go ...thx in advance 4 ur help
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Do not keep randomly running combofix now. It obviously isn't working properly for you at the moment so we will need to use another tool until we make some progress.

    2. Also before we continue I need you to ensure that you do indeed have MGTools.exe directly on your C Drive and not any other location like the desktop.

    3. Tidy this desktop for your benefit:

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here.

    You need to also tidy up the C Drive, files and folders you createed and have scattered there could be in another more suitable location such as in your My Documents folder for instance.

    4. Did you download the contents of the following directory?

    • C:\temp\exotic images

    5. Please go to add/remove programs and uninstall the following outdated software:

    • Java(TM) SE Runtime Environment 6 Update 1

    6. Teatimer is running which could well interfere with my fix. Please see the below link for how to disable before we move on any further.

    How to disable Spybot's TeaTimer

    7. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    ________________________________

    8. Please do the following:

    1. Click on the Start button, then click on Run...

    2. In the empty "Open:" box provided, type cmdand press Enter
    • This will launch a Command Prompt window (looks like DOS).
    3. Copy the entire bold text below to the clipboard by highlighting all of it and pressing Ctrl+C (or after highlighting, right-click and select Copy).

    copy C:\WINNT\$NtServicePackUninstall$\atapi.sys %systemdrive%\ /y

    4. In the Command Prompt window, paste the copied text by right-clicking and selecting Paste.

    5. Press Enter.

    6. When successful, you should get the below message within the Command Prompt:
    • "1 file(s) copied"
    7. NOTE: If you didn't get this message, stop and tell me first. Executing any following instructions with avenger are dependent upon this file being successfully copied.

    8. Exit the Command Prompt window.

    ___________________________________

    9. Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    10. See if you are now able to run combofix. But let us download a fresh version to overwrite the old first.

    Combofix


    11. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    12. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    C:\Documents and Settings\Administrator.OK2-UUW85Z21GX6\Local Settings\TEMP
    C:\TEMP

    13. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix if you were successful. & the log from avenger.

    14. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  7. chris007

    chris007 Private E-2

    thx a lot for these instructions ...I am going to work through this tasklist shortly an report back. thanks again
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome, take your time and complete what you can of the above. Let me know how you got on. :)
     
  9. chris007

    chris007 Private E-2


    Hi again, I am stuck at your point #8. It says:

    Access denied
    (0) files copied
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then let's do this instead:

    1. Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    2. Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.


    3. See if you are now able to run combofix. But let us download a fresh version to overwrite the old first.

    Combofix


    4. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    5. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    C:\Documents and Settings\Administrator.OK2-UUW85Z21GX6\Local Settings\TEMP
    C:\TEMP

    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this. Also attach the log from Combofix if you were successful.The log from avenger and TDSSKiller.

    7. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  11. chris007

    chris007 Private E-2

    gr8t thx I am on it
     
  12. chris007

    chris007 Private E-2

    I am getting the following error:

    Error: Invalid registry syntax in command
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | Inxset
    Only registry keys under the HKEY_LOCAL_MACHINE hive are accessible to this program. Skipping line. (Registry value deletion mode)
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just continue on with the steps please. Report all errors later.
     
  14. chris007

    chris007 Private E-2

    Yay, this is the 1st time after a week of me not having to start combofix upon boot :)

    I had to go through regedit and get rid of this piece of s%#t manually. Upon restart everything seems back to normal.

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | Inxset

    *bangs head on keyboard for not checking HKEY_CURRENT_USER but only HKEY_LOCAL_MACHINE*

    Anyhow, you did it man!! I bow to you. Thanks a mil.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So, rewind back to some of your original complaints:
    Are you now able to use and update the applications you mentioned? If so run scans with both MBAM and SAS and attach the logs that they each create into your next reply as well as the other requested logs from my post # 10.
     
  16. chris007

    chris007 Private E-2

    yes, all apps are working again, no more crashes. It's back to the way it was. I'll do some scanning overnight and report back, but sofar everything looks nice and clean again ...thx again
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes the MBAM and SAS scan can be done overnight and logs attached in the morning. However what about the other logs? Are you going to attach those for me tonight?
     
  18. chris007

    chris007 Private E-2

    combofix gives that error win32 only, so no logs from that ...
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you aware that these entries are now showing up in your hosts file? If not then please opt to fix these.

    1. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.


    2. What do you know about the contents of the following directory?

    • C:\temp\exotic images

    3. You need to tidy up your C Drive, you have many many files and folders scattered all over it, alot of which are jpegs which should not be here anyway, they would be better off organised and placed into a folder you create for them in "My Documents" or such as.

    4. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    5. Install some anti virus now at this point I think, and also be aware that sygate firewall is outdated and unsupported for many years now. You could install a firewall from the list of recommended that we have, which a link will be included for in my final steps.

    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    7. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  20. chris007

    chris007 Private E-2

    I am aware of point #1 and #2, but thanks!
    #3 ... this is gonna take a while as I need to backup stuff externally, same with c:/temp

    #4 ok thx, I deleted everything in \Local Settings\Temp

    #5 Any recommendations for a free anti virus other than AVG? ...possibly something thats free for win2k server also?

    #6 haven't done this yet due to point #3

    #7 things are running well, thx again
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't worry about completing the tidy up now, it's not urgent, however it will benefit you to keep the C Drive in a nice organised state.

    Just attach the last log I requested and then I will be giving you final steps as long as all is well, which it does indeed sound it!


    You can discuss this in the software forum :)
     
  22. chris007

    chris007 Private E-2

    ok moment
     
  23. chris007

    chris007 Private E-2

    attached...
     

    Attached Files:

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your firewall (sygate) is outdated and unsupported. I suggest you ditch it and opt for something else.

    Don't forget to install some anti virus too, you can see recommendations for this and firewalls in our how to protect yourself from malware link which will be included in my final steps.

    Delete the following bold folder, leftover from avg:
    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds