Malware completely denied all atempt (MGlog attached)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jozeft, Oct 19, 2010.

  1. jozeft

    jozeft Private E-2

    I have a malware which I figured out when my google chrome keeps crashing everytime I want to search. I cant update by bitdefender, or any antivirus or antimalware program.

    I have been facing with this problem jumping to forum to forum,

    So far,
    Super anti spyware, Malwarebytes wouldn't run..
    It would start, but then immediately close itself (Malware)
    It didnt detect anything (Superspyware)

    Even though I use Safe mode too..

    Luckily your program seems to go with no problem

    However, I can't upload anything since it blocks all antivirus website, and anything with the word 'upload' in it. so I used Megaupload http://www.megaupload.com/?d=BQGZRWIR

    Hope you can help me..

    thanks
     

    Attached Files:

    Last edited by a moderator: Oct 19, 2010
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Currently reviewing your logs and will get back to you with a set of instructions as soon as possible.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue you need to use MSConfig to put this machine back into normal start up mode.

    Tencent QQ <--- uninstall this garbage.

    Uninstall this out of date Java also:

    • Java 2 Runtime Environment, SE v1.4.2_05
    • Java Auto Updater
    • Java(TM) 6 Update 21
    • Java(TM) 6 Update 5
    • Java(TM) 6 Update 7

    Running from: c:\documents and settings\JJ\Desktop\New Folder\iexplorer.exe <--- You should not have combofix inside of a folder, it needs to be directly on your desktop. Also I would suggest you rename it to something else for now such as 123.com. Later on we can rename it back to combofix.exe so that final steps go without hitch.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\aspdict-en.dat
    c:\windows\system32\asdict.dat
    Folder::
    C:\WINDOWS\temp\tmp000001c7
    C:\WINDOWS\temp\tmp00000332
    C:\WINDOWS\temp\tmp00003557
    DirLook::
    c:\program files\gagaawe
    c:\program files\testes
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).

    Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Try SUPERAntiSpyware Portable

    If that works, try running Malware Bytes again. Attach a log if successful.

    Then give this a run:
    Running Kaspersky Online Scanner

    Let me know how you get on with that and attach the requested logs when ready. Let me know how things are running.
     
  4. jozeft

    jozeft Private E-2

    Thank you Kestrel! I followed your instruction on the uninstallation and deleted folders,
    several files couldn't be deleted and Java autoupdater

    I moved the combofix to desktop and renamed it and click and drag the CFscript onto the icon; It shows sign of functioning until it gets to the scanning bit, it suddenly blinked and no sign of hard disk activity was heared. It just stayed like that till 10 minutes and I just closed it.

    I did another scan, for you to look at

    Thanks man,
     

    Attached Files:

    Last edited by a moderator: Oct 21, 2010
  5. jozeft

    jozeft Private E-2

    Kestrel, btw, a few days ago I did managed to run combofix.. I'll just post it here to see if it shed any light.


    ComboFix log
     

    Attached Files:

    Last edited by a moderator: Oct 21, 2010
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What can you tell me about these two folders?

    • c:\program files\gagaawe
    • c:\program files\testes

    What happened with SUPERantispyware Portable??

    What happened to the Kaspersky Online scanner?

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :dir
      gagaawe
      testes
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Download a fresh version of combofix and overwrite the old version.

    If necessary reboot into safe mode to try and get it to run! But do try NORMAL mode first, then you can try the rename again too if needed.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    This time include the SAS and the Kaspersky scan results too.
     
  7. jozeft

    jozeft Private E-2

    The folder that you asked are Malwarebytes folder which I renamed

    Avenger:
    Could not set driver ImagePath

    Kasperkey:
    405 Not Allowed

    nginx/0.8.27

    SAS:
    Stalled at HKLM\System\Controlset002\SErvices\61883

    Combofix:
    Still stalled in Windows normal mode.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I asked about TWO folders. Please explain about the remaining one.

    So what about in safe mode, and did you even try the rename?

    Delete these manually.

    Files to delete:
    • c:\windows\system32\aspdict-en.dat
    • c:\windows\system32\asdict.dat
    Folders to delete:
    • C:\WINDOWS\temp\tmp000001c7
    • C:\WINDOWS\temp\tmp00000332
    • C:\WINDOWS\temp\tmp00003557

    Try looking at this and let me know how you get on with it.

    SUPERAntiSpyware will not run when my computer starts or when I double-click it.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  9. jozeft

    jozeft Private E-2

    Both folder are Malwarebytes that I installed with those names

    SAS ran, found 21 adware and deleted those. Got log

    Folders already disappeared, files already deleted.

    Ran combofix on safe mode, renamed, and ran CFscript
    It found rootkit and restarted
    It starts and proceed with stages
    I didn't know till what stages it went through
    Because when I came back
    I find a black screen with only the mouse cursor
    Both normal and safe mode
    Couldn't access task manager
    Only a black screen with mouse cursor.
    Therefore I couldn't post any logs..
    Any idea what happened?
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So what's the status of the computer today? (No, I have no idea what could have happened)

    If you can log in okay do this:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds