Inundated XP Box. Cleaning Procedures Followed.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Drewbie, Apr 7, 2010.

  1. Drewbie

    Drewbie Private E-2

    Hello all. This is my first post, but I have relied heavily on MG.com in the past to help me clean up infected machines.

    The machine I am toiling with right now is one of the worst I have encountered, if it were for pure curiosity, I would have wiped it by now.

    Here is the run down of what is happening:

    1. XP Pro Box running Kaspersky. AV was fully updated, as was the Java and other plugins. Machine has all of the latest patches.

    2. User called to tell me he had some "virus popops". I went through the Kaspersky logs, and sure enough there were Trojans and Worms galore. BACKDOOR.WIN32.CETORP.P and VIRUS.WIN32.Sality.K are just some examples, there were a lot.

    3. I disconnected the machine, and began to do the Windows XP Cleaning prodecures. Here is the gist. I can run CCClean. Initially removed about 50mb of junk.

    4. I could run and clean the findings with SuperAntiSpyware. I attached that log. It found one Trojan, and about 100+ tracking cookies.

    5. Attempting to install MalwareBytes causes a BSOD. I changed the file name and installation locations, no joy.

    6. ComboFix will not run. I double-click the icon, and get the little green status bar go from right to left, and it disappears. No prompts after. Waited about four hours the first time, no joy.

    7. RootRepeal. I can start the program, but whatever is on the machine kills the process before I an initiate a scan.

    8. MGTools. I ran from the root, but during the scan process, the machine through a BSOD.

    9. I can not boot to Safe Mode. Only the standard mode. During boot into Safe Mode (any derivative) during the driver portion, it gets to TDI.SYS and reboots. Checked system32\drivers nothing that looks out of place, no files of 0kb, etc.

    10. I could run HiJackThis. I have attached the log.


    Is it time to wave the white flag on this one? I am beginning to think so. Thoughts? As always, any help is greatly appreciated.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then let's start with this.

    Run HJT and do a scan only, and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Now, download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now see if you can run the other scans.

    If not, rename HJT to analyse.exe and attach the new log.
     
  3. Drewbie

    Drewbie Private E-2

    Tim,
    Thanks for the reply.

    I attempted to follow the instructions, however whatever is on the box is now killing HJT before the scan can complete. Attempting a second time will throw a BSoD. It's very, very frustrating.

    I attempted to go on to the Avenger portion, and I was able to successfully accomplish it, upon reboot Avenger stated it was able to delete best.exe, but the other were not found. BEST.EXE has apparently rebuilt itself, as I can see it again in the recovery console.

    I ran the HJT as analyse.exe and nabbed the log before it went to a blue screen. It's attached.

    If you can help me pull this off Tim, you'll have to pass an address to where I can have a case of beer delivered to you. Thanks much.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Curious indeed.

    I really need you to retry running MGTools.exe.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.


    Let's do Avenger again, but you need to edit my fix and put in your user name where I have it underlined.

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip
     
  5. Drewbie

    Drewbie Private E-2


    Tim,
    I couldn't get any of the scans to run, it would just cause a BSOD repeatedly. I setup a laptop with a fully patched version of XP, and fully updated version of Symantec Endpoint, and MalwareBytes installed. I set the infected drive in a dock, and set it to read only. I ran scans against the drive, changed the write block to allow writes to the drive, and deleted tons of Trojans, worms and various malware. If you are interested to know what they were exactly, I can post the scan and deletion results here. My problem now is that drive now scans clean, but I still am dealing with the damage caused, the machine still will not boot into safe mode, it hangs at TDI.SYS and reboots, and I will still get a BSoD when trying to install a fresh copy of MalwareBytes. I'll keep plugging away at it this morning, and post a fresh HJT this log and the scan results in a bit. Thanks again for your help.

    EDIT: Scans are still being killed when I boot the drive. MB, RootRepeal, and HJT get their processes killed, and second attempts cause I BSoD. Because it happening slower, I was able to get another good scan out of HJT. It's attached.
     

    Attached Files:

    Last edited: Apr 12, 2010
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    A HJT log, esp. when it has not been renamed, is probably not going to help us at this point.

    Did you run any online scans with the hard drive in the external box? It would have been best to try to run the scans on the laptop with the dock attached. If you can do that, do so and attach the logs.
     
  7. Drewbie

    Drewbie Private E-2

    Tim,
    What do you mean by online scans? I ran the MalwareBytes and a Symantec scan on the drive in the dock. It now comes up clean. At the moment I have the drive back in the original machine, and got ComboFix to run with the recovery console by renaming the file to svchost.exe. At the moment, it's still going through the scan. I'm hoping it's an improvement. If you could give me a run down on the online scans you referred to, I'll jump in with both feet as soon as the ComboFix completes.

    Many thanks,
    -Drew
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's hope Combo runs and produces a log. As to online, try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log.
     
  9. Drewbie

    Drewbie Private E-2

    Tim,
    ComboFix did wonders. I ran RootRepeal, it found a file, and kicked out a log. I can also now run MalwareBytes, which is still in progress, it's already got nine hits. I'll go through the rest of the XP cleaning process now and post all of the logs up to make sure everything is running clean once I am done.


    Again, thanks for all the responses and helping me run this to ground!


    -Drew
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will be here when you have the logs. At least we are making progress!!
     
  11. Drewbie

    Drewbie Private E-2

    Hey Tim,
    Just an update. Time ran out on figuring out all of what went wrong on this machine. It was to the point were repeated scans with a variety of products yielded no results, but the damage that was wrought was considerable. Multiple services wouldn't start, corrupt and missing drivers, damaged registry, etc. The decision was made to simply pull off the user data and baseline the machine. It's back in service now, and I have the feeling of being defeated, but at least the user data was saved. Thanks for all of your help with this Tim, it was truly appreciated.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. Safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds