MAJOR Malware problem -- Unfixable outside of reformatting (it would seem.)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by RottenRice, Jul 8, 2011.

  1. RottenRice

    RottenRice Private E-2

    I would first off like to say that I really think you guys are doing a great job here, and I hope that you can help me with this issue I've had since late yesterday.

    I was in the middle of a gaming session on Steam, and it suddenly crashed without warning. Curiously, I tried to start it up again only to receive an error: "Windows cannot the specified device, path or file. You may not have the appropriate permissions to access the item."

    I found this odd because

    1. I'm an Administrator, and the permissions on the file are full access open to "everyone"

    2. Even after replacing Steam, the error occurred (not ending the process on startup, but in mid-game).

    3. This problem soon extended to Malwarebytes, SuperAntiSpyware, Kepersky, Spyhunter4, MGtools and avast, the processes abruptly a minute into starting. Even a boot-time scan with avast wouldn't pick up on anything.

    I tried everything on the Readme page to no avail, including reinstalling every listed anti-malware. The only thing that lasted more than a minute was Combofix, and it didn't even do anything for about an hour past the "scanning infected files" segment.

    And, this morning, I learned that my archival programs (WinZip, WinRar, 7Zip) are now being blocked as well.

    I really hope that I can get a fix soon. A few of my things are irreplaceable, and I simply hope that there might be some way to preserve those things, at the very least.

    Thanks.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Might be a silly question but have you tried rebooting at all?

    If that does not solve anything then please do this:

    Get this EXE file fix onto the affected machine and run it to see if it helps. (Ninth fix in the list)

    Or this may help.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.


    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post )


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).
     
  3. RottenRice

    RottenRice Private E-2

    Thank you very much for the reply, but sadly, nothing has seemed to work. Whatever's doing this impossibly elusive.

    Firstly, the EXE File fix was usuable, but I was greeted to an error:
    "Cannot Import C:\Users\(Username)\Desktop\xp_exe_fix.reg: Not all data was successfully written to the registry. Some keys are open by the system or other processes"

    I looked up this error in question and it suggested that I should try running it in safe mode, but I discovered that, even when pressing and holding F8, I could not enter the "advanced options" menu on startup and was unable to select any safe mode option.

    My homepage was also replaced by "http://www.startnow.com/", which is also a bad sign, but I digress.

    Rkill.exe came back with absolutely nothing of note within its scan, while AVPFind.bat either abruptly stopped; whether it was its own accord, or by the malware's, I can't tell, but it did leave a log, which I will attach in addition to that of Rkill and exehelper.

    Speaking of the latter, I ran it and it seemed to change nothing; I still recieve the same error message whenever I attempt to start up a "blocked" program.

    Combofix also refuses to work, for whatever that may be worth, even after a restart and fresh install/update.

    So, is there anything else I could use, or should I start saying my farewells? Thanks for your help at any rate.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  5. RottenRice

    RottenRice Private E-2

    As before, SuperAntiSpyware ended out of the blue, but the portable version did pick up at least four instances of "Trojan.dropper/svchost-fake" before cutting off after three minutes.

    And, the ESET ran a scan, and got rid of a few "Win32/Patched.HN trojan"s, but one persisted, for reasons unknown.

    As a sidenote, I looked up the former bit of malware over Google and used OTS; just stating ahead of time that it did not work. I started up the utility and attempted to use the method here (http://www.help2go.com/forum/spyware-help/106163-trojan-dropper-svchost-fake-virus-malware.html) before, when I tried to run it, the process instantly ended as soon as I clicked "Run Scan".

    (Edit:) Also ran GMER from said method, only to have it face the same fate as OTS after it gave an initial scan. Details are now attached.
     

    Attached Files:

    Last edited: Jul 10, 2011
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You should not ever follow a fix tailored for someone else!!

    GMER found a rootkit.

    The ESET scan did not find malware, they were false positives.

    Please download RogueKiller.exe and save it to your desktop.
    • Now quit all running programs.
    • Double click RogueKiller.exe to run it.
    • When prompted, type 1 and hit Enter.
    • A RKreport.txt should appear on your desktop.
    • Note: If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe .
    • Please post the contents of the RKreport.txt in your next Reply.

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run
     
  7. RottenRice

    RottenRice Private E-2

    Yeah, I noticed that it cautioned against it, and I realize it didn't do me very much good, but I'm just kind of desperate not to let my system.

    Now, the tricky part about TDSSKiller is that it apparently cures most of these afflicted programs at a time, but usually a small percent have "processing errors". It might show up in the log.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      msiscsi*
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    Also, after running TDSSKiller and having it find and fix a couple items, are you now able to run Combofix and MGTools?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds