Infected with catchme.sys based worm/trojan whatever... Help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Opt1mus, Apr 17, 2010.

  1. Opt1mus

    Opt1mus Private E-2

    So recently I was trying to find a UFC fight video searching through Google and my computer was infected with Animalware Doctor after I clicked on a link... SIGH..

    Being experienced in clean Windows installs, I backed up some data quickly to a flash drive and then did a re-install of windows. I cleared my partitions and deleted all data through the Windows Setup console on my Windows XP CD and then installed windows again. So I get through the install get to the desktop and immediately notice that something is not right...

    Msconfig is not even on the system and/or the system cannot find it. Also most of the automatic windows services that start up after a boot do not start at all and have to be manually started. Once I do this, I can finally get on the internet through windows explorer... for some reason IE is not even recognized after the new install as well. My version of windows is pretty old.. I am running XP 2005 MCE with only SP1 on the disk, but I have done a clean install 3 or 4 times on this PC and every time prior to this happening it worked like a charm to 'start over'.

    I have also used killdisk to completely re-write the data in the hard drive to 000s and when that also didnt work I broke down and bought a new HD, only to install windows again and see the same problem...

    This leads me to this forum and others seeking help as I believe this catchme.sys is some type of gateway or something to a worm/trojan/virus that is still residing somewhere other than the HD (maybe memory or bios???) and I am worried that I could experience the identity theft issues or other bad news that happens to others...

    I have been trying to fix this on my own and have ran these programs looking for problems: Combofix, Smitfraud fix, HiJack This, UnHackme, GMER, Malware Bytes Anti-Malware, Trend Micro RootBuster, RegRun Reanimator and a couple others and found instances of catchme.sys in the registry and in the C:/documents and settings/ 'area'

    When I run the programs now it doesn't find 'as much' entries as before as I have deleted some, but I have no idea if the problem is actually gone or not. Should I re-install windows again and start over to check? If you can give me a starting place I can definately submit any logs needed and perform whatever checks you require to help troubleshoot!

    Thank you in advance!
    Opt1mus
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Before wasting any time trying to perform malware removal steps, let's first clear something up.

    catchme.sys is not malware. It is a driver loaded by GMER and other tools from GMER.

    If that is your only issue, than you don't have an issue. ;)

    As for msconfig.exe not existing, you will just have to restore it from your CD if there are no backup copies. Or you can use sfc /scannow

    In what folder are you looking for it? It is not in the system32 folder. This is aso not a malware problem.

    If you have just reinstalled the PC from scratch from clean, original, uninfected media (not backups that could be infected) then you are not having malware problems. If you installed anything else from backup type files after you installed Windows then you could possibly be installing an infection from your backups. Did you delete partitions and repartition before reinstalling? This is highly recommended so that any boot record infections would be removed.

    If you still would like us to check the current installation for malware, then work thru the below and attach the 5 requested logs:

    READ & RUN ME FIRST. Malware Removal Guide
     
    Last edited: Apr 17, 2010
  3. Opt1mus

    Opt1mus Private E-2

    I am pretty sure that I saw some kind of catchme references before I even did anything with GMER. GMER was something I tried after already running primarily Combofix and MalwareByte's Anti-Malware programs since I could not get windows to act normally still. The first thing I did was run Combofix, and the log indicated that the scsvc.dll file was infected. I found a new scsvc.dll file from dlldump.com and put it in the system32 folder and then ran Combofix again and the alert about the file being infected was not reported in the log. Maybe I am just masking it now though...

    The new hard disk showed free unpartitioned space the first time I used it and I created the 2 normal partitions I use with my PC, thinking well hey now I know I will be fine.. only to find that I was in the same boat.

    I have ran sfc /scannow as well and I constantly have to keep 'skipping' the files that it looks for from the Windows XP Pro CD that I do not have because I am using the XP 2005 MCE edition.. not sure why it would be asking for files from the PRO CD. I spent an hour trying to get through all of these alerts so at least some of the files could be re-copied.

    Msconfig I know is stored in the windows/pchealth/helpcntr/binaries folder, and when I try to run it immediately after installing windows I get the 'msconfig.exe not found' message. That is super strange to me... never ran into that before. If I download msconfig.exe from the net and install it in the folder it should be in it works without issue, but I still can't do anything to get the automated windows services to start on start up.

    When I did install windows to the new hard drive I was careful to not have my flash drive connected to the PC so nothing could get 're-infected' but like I said right when it was finished it was as if I was using the same exact hard drive with the same problem after I clean installed the original one and Windows booted the first time again.

    Should I possibly just start over again and repartition the drive, re-install windows and then start the troubleshooting over to see what is found immediately before I change or do anything?

    I appreciate the second reply since I have tried some things already... I thought maybe the new and clean media info could raise some eyebrows ;) is it possible that the problem could be lying in memory or in the bios??
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    GMER's catchme program is used by many tools including ComboFix and SDfix.

    Then you have files missing or corrupted that are not getting fixed and this can lead to many problems within Windows.

    Is the file there right after installation and was it the correct file? Right click on it and select Properties and check Version info ( I guess it would be too late for this now if you already downloaded and put one there).

    If you have missing/corrupted Windows system files this could be the problem.


    I suggest that you run the READ & RUN ME so that we can see if we can rule out malware.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds