Help with removing malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jlachey, Aug 12, 2012.

  1. jlachey

    jlachey Private First Class

    I went through the READ & RUN ME FIRST thread, and I need help removing the malware that has been detected. I have attached the logs for RogueKiller, Malwarebytes, and and HitmanPro. I have been unable to run MGTools. I downloaded it to the folder C:\MGtools, but I cannot find it when I search for it. I also tried saving it to F:\MGtools, and had the same problem (I have two hard drives installed on my computer). What should I do?
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  3. jlachey

    jlachey Private First Class

    I attached the logs to this reply- what should I do next?
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What detected what?
     
  5. jlachey

    jlachey Private First Class

    I thought one of the programs I ran scans with detected four threats- was I wrong about that? One of my programs (I believe it was Malwarebytes) originally detected and hopefully removed two trojans, which is the main reason for this thread. I'm not sure if I would have the log for it though, since I uninstalled and reinstalled it. Have you seen any threats detected in the logs I posted? Do I need to do anything more?
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No malware. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  7. jlachey

    jlachey Private First Class

    Sounds good! I do have one more question. Is it still possible to use Sandboxie with Google Chrome? I was able to use them together for a while, but it doesn't work now When I try to run Chrome sandboxed, it won't connect to the internet. I think I got the trojans I mentioned when I started using Chrome by itself. Are there certain settings I should adjust in Chrome to make it safer to use, or is there a way to use it with Sandboxie?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It would be best if you asked the guys and gals in software forum as I have no experience with either. Sorry.
     
  9. jlachey

    jlachey Private First Class

    Okay thanks. And I ran into a problem while trying to flush system restore points. Now when I try to access system restore, it says it is unable to protect my computer and I should restart my computer. Restarting does not help. What could be causing this problem?
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Again, something to ask about in the software forum. :)
     
  11. jlachey

    jlachey Private First Class

    Okay- thank you for your help. Hopefully you won't be hearing from me again any time soon! ;)
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. Safe surfing! :)
     
  13. jlachey

    jlachey Private First Class

    Well, I'm back. I was still having problems with system restore and windows updates, so I did several malware scans. Emsisoft Anti-malware seems to come up with something every time I scan, so I don't know if it is properly getting rid of malware. What should I do?
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you run MGTools.exe please (Following the instructions in the R&R - READ & RUN ME FIRST. Malware Removal Guide)

    and attach the MGlogs.zip.
     
  15. jlachey

    jlachey Private First Class

    I can't seem to get it to cooperate. I download it to C:/MGtools, but when I try to find it, it isn't there. However, if I try to download it again in the same place, it will show up as if I am trying to replace it. Am I doing something wrong or does that tell you something about my system?
     
  16. jlachey

    jlachey Private First Class

    I did eventually find it, but when I try to run it, I get an error message saying 'Failed to set current dir: \MGtools. What does this mean?
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Press start > run > and type in services.msc

    Is the Background Intelligent Transfer Service listed? If so what is it's status and start up type?
     
  18. jlachey

    jlachey Private First Class

    It is listed- Its startup type is 'manual' and there is nothing listed under status. Do I need to start it?
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes. let me know what happens when you try please?
     
  20. jlachey

    jlachey Private First Class

    I was able to start it- should I try running MGtools again?
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can try. Does Windows Update work?
     
  22. jlachey

    jlachey Private First Class

    Windows Update still won't work. It hangs while installing the first update (I let it run for nearly a half hour), as well as when I try to cancel the updates. I have to shut the computer down to get out of it. I'm still getting the same error message with MGtools.
     
  23. jlachey

    jlachey Private First Class

    I managed to get the updates to install again, but then the yellow shield immediately came up and listed the same updates. They are listed as successful multiple times in my update history, but they keep reappearing. Could malware be causing this problem or is it a software issue?
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I think all the malware is gone, not sure what EMIsoft is finding, you would have to let me know. Let's use Combofix to try and get BITS back in place.

    Download Combofix to your desktop. DO NOT run it yet!! You must first ensure all antivirus/antispyware is disabled.


    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    ClearJavaCache::
    KILLALL::
    Registry::
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS]
    "Type"=dword:00000020
    "Start"=dword:00000003
    "ErrorControl"=dword:00000001
    "ImagePath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,\
    32,5c,73,76,63,68,6f,73,74,2e,65,78,65,20,2d,6b,20,6e,65,74,73,76,63,73,00
    "DisplayName"="Background Intelligent Transfer Service"
    "DependOnService"=hex(7):52,70,63,53,73,00,00
    "DependOnGroup"=hex(7):00
    "ObjectName"="LocalSystem"
    "Description"="Transfers data between clients and servers in the background. If BITS is disabled, features such as Windows Update will not work correctly."
    "FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,03,00,00,00,68,e3,0c,\
    00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters]
    "ServiceDll"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,73,79,73,74,65,6d,33,32,\
    5c,71,6d,67,72,2e,64,6c,6c,00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security]
    "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
    00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
    00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
    05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
    20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
    00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
    00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum]
    "0"="Root\\LEGACY_BITS\\0000"
    "Count"=dword:00000001
    "NextInstance"=dword:00000001 
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Reboot, is Windows Update now working, and what is the start up type of Back ground Intelligent Transfer Service now?
     
  25. jlachey

    jlachey Private First Class

    Combofix has been running at Stage 50 for at least 20 minutes- should I let it continue to run?
     
  26. jlachey

    jlachey Private First Class

    Actually, it's working now- it's currently preparing the log report.
     
  27. jlachey

    jlachey Private First Class

    I have attached both the combo fix log and a list of quarantined files from Emsisoft (I also deleted some files from there, so they won't show up). Could some of them be false positives? No other scanner detected them. Windows Update still won't work. Background Intelligent Transfer Service is still set to manual and nothing is listed under status. It would most likely start if I manually started it, but it would go back to the current settings if I restarted my computer.
     
  28. jlachey

    jlachey Private First Class

    Ok- now these should be attached.
     

    Attached Files:

  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Seeking advice, hang in there. :)
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's try this for now - (Do you still have MGTools.exe?)

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    • cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    • nwktst<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    • analyse <-- this attempts to run HijackThis. Be sure to click the Accept button twice in the license agreement popup or it will just sit there and wait.
    Now look for the C:\MGlogs.zip file and attach it no matter what happened while doing the above.

    If that does not work, I have some more we can try. My aim is to get BITS service straightened out again, and eventually any other messed up services too.
     
    Last edited: Aug 27, 2012
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The log file should be F:\MGlogs.zip.

    The drive Windows is installed on is F and that is the drive where MGtools should be run from.
     
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall the below please if still installed:
    • Emsisoft Anti-Malware
    • Spyware Terminator
     
  33. jlachey

    jlachey Private First Class

    cd \MGtools gave the error message 'the system could not find the file specified'. I didn't delete it, so it should still be in my system.

    The rest of the commands gave the error message 'command name' is not recognized as an internal or external command, operable program or batch file. Should there still be a zip file if MGtools didn't actually scan anything? I couldn't locate this file.

    I just uninstalled Emsisoft Anti-Malware, and Spyware Terminator was not installed.
     
  34. jlachey

    jlachey Private First Class

    I finally managed to get MGtools to cooperate- the log is attached. :)
     

    Attached Files:

  35. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Click Start, click Run, type services.msc, and then click OK.
    • In the list of services, right-click Automatic Updates, and then click Properties.
    • In the Startup type list, click Automatic (if it is not already), and then click Apply.
    • If Service status is set to Stopped, click Start, and then click OK.
    • Right-click Background Intelligent Transfer Service, and then click Properties.
    • In the Startup type list, click Manual, and then click Apply.
    • If Service status is set to Stopped, click Start, and then click OK.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  36. jlachey

    jlachey Private First Class

    I have attached the new file.
     

    Attached Files:

  37. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Right, BITS is back....so, let's get the rest sorted.

    Download this file to your desktop.
    Dhcp.reg


    • Now please click Start, and type regedit into the search box.
    • You should see a regedit.exe and icon appear in the Programs area of the Start Menu.
    • Right click on regedit.exe and select Run As Administrator
    • Then in the Registry Editor menu click File and select Import.
    • Navigate to the Dhcp.reg file saved to your Desktop and double click it. Allow it to be added to the registry.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    After reboot, check to see if your firewall is working.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  38. jlachey

    jlachey Private First Class

    When I tried the first set of steps, I got the error message 'The My Documents folder could not be found. Right-click the My Documents icon, click properties, and then check that the path to your target folder location is correct.' I click ok to exit the box, and I get another message saying 'F:\Documents and Settings\UserName\Desktop is not accessible. Access is denied.' What could be causing this problem and what should I do?
     
  39. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try in safe mode please.
     
  40. jlachey

    jlachey Private First Class

    I really only had two minor problems- I had to double click on regedit.exe instead of selecting run as administrator, and I had to manually restart my computer after Windows Repair finished. My firewall seems to be working. Should I see if System Restore and Windows Update are working?
     

    Attached Files:

  41. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Dynamic Host Control Protocol -DHCP- is NOT running
    • Windows Firewall Service is NOT running
    • and I no longer see BITS listed. (Back ground Intelligent Transfer Service)

    Check in services again and let me know the status of each please and start up type?
     
  42. jlachey

    jlachey Private First Class

    DHCP doesn't have a status, but is listed as automatic startup. Windows firewall also has no status and automatic startup. BITS does not have a status, and has a manual startup.

    I use Zone Alarm as a firewall, and it is working. Does that make a difference with Windows Firewall Service?
     
  43. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, you are precisely right, so that's that problem ended. ;)

    Not good, I need to keep trying to get that solved!

    What happens when you go into services again and try to restart each of the two?
     
  44. jlachey

    jlachey Private First Class

    They both start up successfully.
     
  45. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Forgive the fact this is taking so long, removing the malware is simple in comparison to mending all the chaos the malware caused. Again, my apologies that there is no instant quick fix.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  46. jlachey

    jlachey Private First Class

    It's okay- there is no hurry. :)
     

    Attached Files:

  47. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, everything looks great now!! :) Ready for final steps?
     
  48. jlachey

    jlachey Private First Class

    Absolutely! :)
     
  49. jlachey

    jlachey Private First Class

    I am getting the error message 'Windows Firewall settings cannot be displayed because the associated service is not running. Do you want to start the Windows Firewall/Internet Connection Sharing (ICS) Service?' What should I do? As I said before, I am using Zone Alarm as my firewall. Do I need this service?
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See the below from miscinfo.txt

    Code:
    SERVICE_NAME: Netman
    DISPLAY_NAME: Network Connections
            TYPE               : 120  WIN32_SHARE_PROCESS (interactive)
            [B][COLOR=red]STATE              : 1  STOPPED 
    [/COLOR][/B]                                (NOT_STOPPABLE,NOT_PAUSABLE,IGNORES_SHUTDOWN)
            WIN32_EXIT_CODE    : 1067 (0x42b)
            SERVICE_EXIT_CODE  : 0 (0x0)
            CHECKPOINT         : 0x0
            WAIT_HINT          : 0x0
     
    SERVICE_NAME: SharedAccess
    DISPLAY_NAME: Windows Firewall/Internet Connection Sharing (ICS)
            TYPE               : 20  WIN32_SHARE_PROCESS 
    [COLOR=red][B]        STATE              : 1  STOPPED[/B][/COLOR] 
                                    (NOT_STOPPABLE,NOT_PAUSABLE,IGNORES_SHUTDOWN)
            WIN32_EXIT_CODE    : 1067 (0x42b)
            SERVICE_EXIT_CODE  : 0 (0x0)
            CHECKPOINT         : 0x0
            WAIT_HINT          : 0x0
    
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds