Malware blocks Malewarebytes

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kmaccoy, Oct 6, 2011.

  1. kmaccoy

    kmaccoy Private E-2

    I am having an issue with a piece of malware. I am constantly getting messages from my anti-virus (Symantec) that websites, which appear to be nothing more than random character strings, have been blocked. This occurs whether I am actively using the internet or not.

    I have tried performing scans with the antivirus but it will not perform the scan. Instead it locks up at about 1%.

    I tried to run malwarebytes but it crashes after about 13 seconds. When I try to re-run malwarebytes I am told that I do not have permission to access the file.

    The task manager shows a process running consisting with a name "#########:#########.exe" where the #'s are random integers. This process will not terminate. I have tried forcing it to end using TASKKILL in the command prompt but it does not terminate even though TASKKILL says it successfully terminated.

    In addition I cannot load in safe mode. The system loads the drivers when I select safe mode but then reboots and attempts to enter normal mode.

    I have tried restoring the system to a previous date twice with no success.

    Thanks
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Then continue on with these instructions appropriate for your operating system READ & RUN ME FIRST. Malware Removal Guide
     
  3. kmaccoy

    kmaccoy Private E-2

    Kestrel,

    I followed your directions the associated log files are attached.

    Thanks for your help. Hopefully we'll be able to fix this.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  5. kmaccoy

    kmaccoy Private E-2

    I ran SUPERAntiSpyware and Malware bytes. Both the log files are attached. I tried to run Combofix but it just stuck at a blue prompt screen with no text. As the directions recommended I skipped it and Ran RootRepeal and MGtools the log filse are also attached.

    Everything seems to be running fine now and the system seems stable. I will give it a few days and then toggle the system restore per your advice.

    Thansk again!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why am I not seeing any AV protection on this system?

    Do you have your XP CD?

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.1_02
    Java(TM) 6 Update 2
    Java(TM) 6 Update 26
    Java(TM) SE Runtime Environment 6 Update 1

    Use windows explorer to find and delete:
    C:\Program Files\AntivirusPro_2010

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now, if you don't have your XP CD, you can make a recovery console disc here:
    This is a download of an .iso file of just the Recovery Console for XP.
    Burn to CD with Nero or other 'disc image' capable tool and boot.

    XP Recovery Console.

    You can use ImageBurn to create the disc.

    Boot into your bios and change the boot order to CD/DVD as first boot device. Insert the disc and reboot. Once in the Recovery Console, type this:
    fixmbr

    Exit out and reboot to normal mode.

    Download OTL to your desktop.
    Double-click OTL.exe to start the program.

    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code

    Code:
    :processes
    :otl
    :files
    C:\WINDOWS\3057707195
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.


    Now download and install:
    Java Runtime 7

    Re-run MBRCheck and attach the new log. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:
    * OTL log
    * MBRCheck log
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
    Last edited: Oct 8, 2011
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    @TimW and Kestrel13!, Don't forget the rest of the Zero Access infection. Like the below still exists
    Code:
    "C:\WINDOWS\"
    305770~1      Oct  5 2011           0  "3057707195"
    Which means you likely have more.
     
  8. kmaccoy

    kmaccoy Private E-2

    Tim,

    I do not have an XP CD. I did remove all of the Java Applications as you instructed, however C:\Program Files\AntivirusPro_2010 is not present on my system.

    Should I continue with the Registry Repair?

    (By the way I am running TrendMicro OfficeScan as my AV)

    Thanks for your help.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, carry on with the instructions I gave you. You can also make a Recovery Console disc by doing as I instructed to fix your MBR. Attach the requested logs once you are done.
     
  10. kmaccoy

    kmaccoy Private E-2

    TimW,

    I was able to successfully merge the registry file but when I went to run FixMBR i got the following warning:

    My system seems to be fairly stable so I was weary of potentially loosing access to the data I currently have stored on my drive.

    Please advice if you think further action is necessary.

    Thanks again.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is just a standard warning when ever one tries to re-write the MBR. Unless you are on a Dell computer, you can safely go ahead and re-write it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds