{HELP} I think this is beyond my expertise.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by chromegsx, May 13, 2010.

  1. chromegsx

    chromegsx Private E-2

    I've removed malware and viruses before but I think this one is a bit deeper than I've ever experienced. I've read and followed all the instructions on the sticky page and attached are the results. Let me know if I missed anything. Thanks.

    After running all those scans I am still unable to access windowsupdate.microsoft.com and I got one pop window about winning somthing when I opened internet explorer... which tells me I still have some things to fix.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use windows explorer to find and delete:
    C:\Documents and Settings\Justin Martin\Local Settings\Application Data\bhcohtglu
    C:\Documents and Settings\Justin Martin\Local Settings\Application Data\bsdpgjsay

    Please run this: GMER - running with a random name and attach the log from GMER
     
  3. chromegsx

    chromegsx Private E-2

    See Attached.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay the GMER log did not provide the answer TimW was looking for. So please follow the instructions in the below procedure and attach the requested log:

    MaxLook - XP
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    One other thing to try, since GMER failed us, is to do this:
    Download Rootkit Unhooker from here: http://www.rootkit.com/vault/DiabloNova/RKUnhookerLE.EXE
    Save it to your desktop.
    Now double-click to run RootkitUnhooker.
    Click the Report tab, then click Scan.
    Select the pages Drivers, Stealth, Files, Code Hooks. Uncheck the rest. Click OK.
    Wait till the scanner has finished and then click File, Save Report.
    Save the report somewhere where you can find it. Click Close.
    Attach the report to your next reply.
     
  6. chromegsx

    chromegsx Private E-2

    Shall I do both right away or just one then post and wait for reply to proceed to the other? I will be able to do this about 6 hours from now. Thanks.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do what Chaslang suggested first and post that log. Then do the other and post that log. One of them should show us what we are looking for. :)
     
  8. chromegsx

    chromegsx Private E-2

    Ok. Got maxlook to run... and after doing the sig command I got this error, don't know if it's related. Also attached looklog.txt. Off to do unhooker now.
     

    Attached Files:

  9. chromegsx

    chromegsx Private E-2

    Just ran unhooker and it said it detected a parasite in itself.:confused I've attached a pic of the error dialog. Everything else I've done has followed the instructions to a T so far and this isn't in the instructions, so I'll wait to hear back from you guys. Thanks.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. chromegsx

    chromegsx Private E-2

    after attempting combofix with script file... the pc is now stuck in a constant reboot loop in safe mode or normal mode. I can still log into recovery console. And I have not tried last known good configuration yet.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boot to the recover console and at the C:\Windows> prompt, enter the below command. Note the space before each c:

    copy c:\windows\maxdriver\kbdhid.sys c:\windows\system32\drivers\kbdhid.sys


    Then reboot and see if your PC boots.
     
  13. chromegsx

    chromegsx Private E-2

    file copied successfully but didn't help. still have the reboot loop. I can see a quick flash of BSOD after the windows XP progress bar animation, but it's too fast to read the stop error.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then it may not be related to ComboFix since we just restored the only thing it was trying to fix and the copy we restored is actually the infected one. I was guessing that possibly the original infection was looking for the missing file and this was the reason you could not reboot.

    Try last know good and see what happens. Next step would be to try the below to restore to an older restore point to see if registry corruption is the problem.

    http://support.microsoft.com/default.aspx?scid=kb;en-us;307545&sd=tech
     
  15. chromegsx

    chromegsx Private E-2

    Last known good does not work either. :(Combofix kept warning me about AVG. There didn't seem to be a way to shut AVG down so I used the system configuration utility to shut off the 3 services that I saw. rebooted and tried combofix. gave me a warning about avg. checked the avg UI and nothing was loaded nor did I see anything in the task manager. so I just continued. but then I remembered I forgot to drag the script file to start combofix. So I exited out of the combofix dos window and proceeded with the correct method of dragging the txt file onto combofix. It did it's thing and said it detect rootkit activity and needed to restart. After restart it was all over and never came back up. I have an additional hard drive in this box that I can install another windows xp on if it might help. Normally at this point I'd have given up but this media center stuff takes a lot of configuration time which is a pain.
     
  16. chromegsx

    chromegsx Private E-2

    oh and the unhooker program was still warning me about self infection prior to system configuration utitility change for AVG. I just cancelled
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Chaslang will be away for a few days, so please update your situation for me.
     
  18. chromegsx

    chromegsx Private E-2

    I'm still stuck in a reboot loop. I attempted a repair install last night only to have the same outcome. Reboot loop starts right after the windows xp logo screen. I see a stop error BSOD flash (but too quick to read) and then reboots. This happens in safe mode, last known good configuration, and normal mode. My next step when I get a chance (maybe tonight) was to see if I had a coincidental hardware failure/conflict of sorts by removing all hardware except hard drive, video card & 1 stick of memory... unless there's a better idea to try first.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you try to run the link that Chaslang gave you for repairing a corrupt registry?
     
  20. chromegsx

    chromegsx Private E-2

    My bad. I misunderstood chaslangs instructions there... brain dump I guess. I noticed in that link something about oem not applicable and must of just dismissed it. I should have asked...

    This system is built from a system builders disk set, does the article still apply in that case?

    It states "Warning Do not use the procedure that is described in this article if your computer has an OEM-installed operating system."

    I'm thinking I'm still ok to try it, and that the warning is for systems like dell, gateway, etc., but wanted to make sure.
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    At this point, you may as well try it all since your only other option would probably involve reinstallation.
     
  22. chromegsx

    chromegsx Private E-2

    Well I tried the repair registry and failed. :cry did the whole replace file thing but when I tried to boot to safe mode per instructions it just goes to stop error and reboots like I achieved nothing. I did a chkdsk while in the console and it did find some errors on the drive, but it doesn't indicate that it fixes anything.

    I also did some looking around as something seemed odd to me... that when I boot to my other hard drive it acts exactly the same way. Whether the other drive has a coherent installation or not, I'm not sure, I'm thinking not. So I was looking at the boot.ini file on both drives and both drives have it pointing to multi(0)disk(0)rdisk(0)partition(1). Now this was not a dual boot setup, but each drive has it's own boot.ini, so I'm not sure if this is normal or one of these should really be multi(0)disk(1)rdisk(0)partition(1). Just thinking out loud here. If this is the case, I think it would explain the current behavior. Any thoughts?
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you saying you have two separate drives? Not one drive that is partitioned? If it is two separate drives, then the boot.ini is correct. Do you have them set as master and slave or what?
     
  24. chromegsx

    chromegsx Private E-2

    Guess that isn't it then. Yeah I have two drives not partitions. one is on a sata cable and the other on ide ribbon.
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Booting to either drives gives you the same loop or BSOD?
     
  26. chromegsx

    chromegsx Private E-2

    That's correct. I select which drive I want to boot to through the BIOS (MSI motherboard) boot menu and it'll go through the same loop.
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then this is sounding like a hardware issue. Perhaps related to your RAM. I would suggest you post in the software forum for now to get some other feedback with this issue. Did you already do what you were thinking of doing i.e. removing hardware and RAM to try to diagnose the problem?
     
  28. chromegsx

    chromegsx Private E-2

    Malware/rootkit issue morphed into hardware problem, can it get any worse? rolleyes don't answer that. Post in software for hardware issue? you sure? just checking.

    Yes. I tried eliminating all hardware I could including the second ide hard drive. didn't help. even swapped single pieces of ram and made no difference. I did not try yet booting with only ide hard drive and disconnecting sata drive.
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, try doing that. If that doesn't work, then you could post in software as you may have eliminated the hardware side of it.
     
  30. chromegsx

    chromegsx Private E-2

    Well, after unhooking my sata drive. I could get into safe mode on the ide drive. but I still get the reboot loop in normal mode. Hooking the drives back up like they were I can still get into safe mode but loop on normal. I think that drive is riddled with malware too as there were a few things in the msconfig startup that I didn't recognize. I'm going to try a few things first, but I think I'm going to reinstall the OS from scratch on the ide drive after I move my tv shows off on to the sata drive... since this drive was serving as extra storage only for me. Then I will hopefully have a clean install in which can serve as a back up once I get the sata drive issues worked out. Once I've done that and am functional on the ide drive I will post to the software forum look for help in getting past the loop. If I end up with a reboot loop after a clean format and install or during it... I'm guessing I have a hardware issue somewhere.
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sounds like a good plan, though you may want to redo as many of the scans in safe mode as you can so that maybe we can clean it up and get normal mode working again.
     
  32. chromegsx

    chromegsx Private E-2

    Well I now have one hard drive with a clean install (SP2) that boots in all modes without error. I also did memtest for 23 passes (left it run overnight) with no errors. I haven't configured anything like internet, tv tuner cards, windows updates, antivirus, etc.

    My main hard drive is still not able to boot except to recovery console. Can the main drive boot problems be diagnosed from another drive? Shall I take this to the software forum at this point now? Thanks.
     
  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now that you can boot to a clean install, you should be able to get some help for the other drive in the software forum. Or at worst, save your data and files from the other drive and then reformat and reinstall on that drive as well. You won't be able to boot both drives, but you should be able to clean up the other.
     
  34. chromegsx

    chromegsx Private E-2

    Well now that I've rebuilt the smaller storage drive partially, I managed to get the malware again. Now I know what action is causing it and where it is coming from. Antivirus Soft is the fake scanner that pops up while disabling a bunch of stuff like task manager and such. Luckily I could boot into safe mode yet and run a system restore. I've now switched to Google Chrome with an advertising disable extension, but haven't been brave enough to go back to the computer killing web pages to see if the switch will protect me any better. 'Tis a shame as it was a great place to catch shows that my antenna missed. So anyway...

    I have one more thing I think I want to try on the original problem drive to be able to boot into safe mode, but it's looking strong like I'm going to have to go through the pain of reformat/reinstalling everything. :major:crap I'll be on vacation for a bit, but will try it when I get back.
     
  35. chromegsx

    chromegsx Private E-2

    I've made some progress... if you can call it that. Somehow I got it to boot now to safe mode. After doing a repair install. I now get stop error 0x7e, instead of 7b. I'm going to put this in my thread in Software, but wanted to check here if there's anything we can do in safe mode at this point for malware, rootkits, etc.? Thanks.
     
  36. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should be able to run the requested scans in safe mode. Attach what logs you can run. I would like to see:
    SAS
    MBAM
    ComboFix
    C:\MGLogs.zip
     
  37. chromegsx

    chromegsx Private E-2

    Logs attached.
     

    Attached Files:

  38. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The good news is that this is not a malware issue as your logs are clean. I suggest you continue with your thread in software to try to figure out what is wrong.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  39. chromegsx

    chromegsx Private E-2

    Well just wanted to follow up on this. Even though I managed to get the thing to boot and even after a repair install... there were so many things broken, I finally just bit the bullet and reformated. I'm now back in business with everything updated and configured better than before, and I'm dropping Internet explorer except for windows update, in favor of chrome and using some extensions. Still haven't been brave enough to go back to the web page that caused all this mess. I'll probably find any other way I can to get our Lost episodes we missed so that I can avoid that page.

    Thanks so much for the help from everyone. I learned a lot about malware & how some things work in windows.
     
  40. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds