Malware-infected portable

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by CharlieSummers, Nov 21, 2007.

  1. CharlieSummers

    CharlieSummers Private E-2

    I got a call from my cousin asking if I could take a look at his Dell laptop, and...ugh. With the computer disconnected from the network, it slows within minutes after boot to such a crawl that it takes literally minutes to drop-down a menu. (Connected to the Net, or booted in Safe Mode, the machine is acceptable.) The major symptoms are pop-ups warning about Malware.

    I attempted to install various anti-malware tools, but I'm not certain any of them properly installed, and it won't allow me to update any of them anyway either with nameserver lockouts or registry warnings ("Contact your ssystem administrator..."); it's also locking me out of using various tools (regedit, Task Manager, etc.), although the registry entries can be temporarily removed in Safe Mode.

    I'm certain this seems worse to me than it does to the assemblage here, but it's clear I can't handle this with the usual tools (AVG, Spybot, etc., etc.), so I respectfully enclose a HiJackThis logfile (I think I renamed the executable incorrectly to analyZe.exe, but that should be ok, yes?), and thank you all in advance for any advice.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please download FixWareout by LonnyRJones from one of the two below links and save it to your desktop.

    http://downloads.subratam.org/Fixwareout.exe

    http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

    * Run Fixwareout.
    * Click Next,
    * then Install,
    * make sure Run fixit is checked
    * and click Finish.
    * The fix will begin; follow the prompts.
    * You will be asked to reboot your computer; please do so.
    * Your system may take longer than usual to load; this is normal.

    When you run fixwareout, just follow the prompts, you will need to restart when prompted.

    After rebooting (restart) back into normal boot mode, make sure you have all web browsers closed.

    * Go into Control Panel -->Network Connections.
    * Right click on your connection
    * and click Properties.
    * On the Properties page, highlight Internet Protocol(TCP/IP)
    * Click Properties. This will bring up another page.
    * Select Obtain DNS Server Automatically.
    * Click the ok button. The page will close.
    * Press ok on the page in front of you.
    * Restart the computer.
    * Reconnect to the Internet using Internet Explorer.
    * Now come back here and attach the log from fixwareout. It is located at c:\fixwareout\report.txt


    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now see if you can do the instructions here: READ & RUN ME FIRST. Malware Removal Guide

    Attach new logs for:
    ShowNew
    GetRunKeys
    HJT
    Avenger
    Wareout
     
  3. CharlieSummers

    CharlieSummers Private E-2

    I wouldn't dream of running a browser (or anything else) on that machine. I wouldn't connect it to the router if it weren't for the massive slowdown...so I can read this post on my desk machine while performing the steps on his laptop. Am using a thumb drive to transfer between the two. Should also note I created a copy of the Ultimate Boot Disk/Windows using his Dell XP startup disc, just in the event of a major emergency.

    Uh-oh...I can't find this one on this scan. Performed the other removals. After clicking Fix, I received five dialog boxes telling me Reg editing has been disabled by my admin, along with a boatload of Spybot TeaTimer dialog boxes. I turned off SPS&D, re-scanned, deleted the entries that still existed, then scanned again and they are, indeed, gone. (*whew*)

    Done.

    Copied to flash drive. (Yeah, too much information, but I want you to know anything I do outside the specific instructions just in case.) At reboot, an attempt was made to change the shell (that printer.exe deleted above)...denied in SS&D.

    Done; SS&D immediately requested a startup change, which I allowed. At restart, it tried to change the shell again, denied, and delete the Avenger .bat file startup entry, which I allowed.

    Will do. While I work on that, I'm attaching the log files from fixwareout and avenger here.

    EDIT: Control Panels, regedit, and I assume others are again being disallowed. (*sigh*) One step forward, two back...
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good....we request in the instructions to turn off Teatimer ....please do so.

    To Disable Spybot's TeaTimer

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Now please get me the logs from:
    ShowNew
    GetRunKeys
    and a new HJT log.
     
  5. CharlieSummers

    CharlieSummers Private E-2

    (*sigh*) Ran into a snag. To properly follow those directions, I wanted to remove all of the existing anti-malware apps and install only those mentioned with the exact settings listed (i.e. no TeaTimer). But I can't run Add/Remove programs - "contact your admin, policy violation, yadda yadda."

    I can use HiJackThis to get to RegEdit (clearly the malware is replacing the DisableRegedit entries, but I can keep working around that)...is there is registry setting I can manually edit to get Add/Remove Control Panel access back?

    Thank you for your help and patience.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run the HijackThis fix that Tim gave you in message # 2?
     
  7. CharlieSummers

    CharlieSummers Private E-2

    Yes, but I also mentioned every time I want to run RegEdit I need to re-scan and again delete the entries (the b*stard seems to be replacing it), and that fix does not seem to affect access to control panels, which I can't access (TIA, I can access some of them, but even something as simple as Sound seems to be on the "policy" list.)

    At any rate, after the holiday with a good night's sleep, I removed what I could through their own uninstallers, turned off/disabled what I couldn't, and followed through on the instructions listed on the READ & RUN ME FIRST page. I also want to note outside the testing routine I have noticed a process "Sample" that needs to be force-quit on reboot from Safe Mode - no idea if it means anything, just an observation.

    Followed procedures in the READ & RUN ME FIRST page as closely as possible, with the exception of using a "clean" computer to download the programs to a freshly-formatted flash drive and installing them to the infected machine from there...updates were performed as normal through an Internet connection. I did not get a CounterSpy log at the time, as the Safe Mode version doesn't have the "View" menu. I did not initially install the latest JRE, as in Safe Mode I was policy-denied (possibly the spyware or just Safe Mode, dunno) and the BitDefender online-scan failed; between running Spybot/Counterspy it was necessary to reboot into normal mode to install the latest JRE...when I did that, Windows installed some updates. Rebooted back to Safe Mode and attempted to run BitDefender online scan again, with no joy. Rebooted into normal mode and ran BitDefender online scan...the ActiveX control loaded, but it could not update the viral definitions. I tried a second time, with the same failure, then just told it to scan anyway. When finished, warned me the computer was still infected (also forgot to change Save As... type to text; apologies for the goof).

    Switch to Panda...I could not resolve pandasoftware.com on the infected machine, while I could on other machines on the network. I used pandasecurity.com to get there, then clicked for the free online scan, and...it failed to resolve. The problem here is clearly something in this machine (other machines using the same nameservers can easily get to pandasoftware.com, and the infected machine can get to pandasecurity.com - maybe hosts file, didn't check).

    So I went on to GetRunKey/ShowNew. (*sigh*) The thing clearly reset the RegEdit policy entries again (lots of policy dialogs), so I closed-out of GetRunKey and ran HiJackThis to remove those two d*mned policy entries, then immediately ran the two bat files. Ran HiJackThis to get a new log file, then copied the logs to the flash drive and immediately shut down the computer (Windows again installed updates, six of 'em this time. Really MS, or the malware?).

    Anyhow, this and next post(s) contain the log files, and I again thank everyone for their help and patience.



    NOTE: Something here (either Spybot or Counterspy) did something effective, at least; I'm no longer getting the "anti-spyware" dialog box and notification. I'll cheerfully accept any progress, you know?
     

    Attached Files:

  8. CharlieSummers

    CharlieSummers Private E-2

    Just more logs.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    Viewpoint Media Player
    Turn off all anti-virus and anti-spyware protection while you do the following:

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach new logs for:
    ShowNew
    GetRunKeys
    HJT
    Avenger
     
  10. CharlieSummers

    CharlieSummers Private E-2

    Well, that was fun. I might have mentioned I can't run most control panels...after manually deleting various entries in:

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System

    ...I was able to get to Add/Remove by the back-door ("Set Program Access"); I'm going to need to eventually figure out how to straighten that mess out. But anyway...

    Removed Viewpoint (Used: Frequently, I don't think I want to know). Fixed the entries in HiJackThis (keep killing the things, they keep coming back). Transfered fixme.reg via flash drive, merged. Transfered delete files, input into avenger.

    Logs requested attached, along with my continued thanks.
     

    Attached Files:

  11. CharlieSummers

    CharlieSummers Private E-2

    Final requested log.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean. You may uninstall any programs we had you download (including CounterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  13. CharlieSummers

    CharlieSummers Private E-2

    Will do; also uninstalling all anti-malware programs and reinstalling those suggested on the How to Protect yourself from malware! page.

    A note about cleaning up some residual problems:

    • HOSTS file
      When I looked at the C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS file, I could see why I had so much trouble with the anti-mal software; the malware clearly added most of the sites to the file keeping them from loading/installing/updating. Manually edited to allow the Spybot-added section while removing the other crud.
    • Dial-A-Fix
      This is cool, and you might consider adding it to your suggested toolbox. It solved a number of nagging problems, including not being able to use search ("A file that is required to run search companion cannot be found..."), not being able to view the Windows Update website, etc. It automagically unregisters and re-registers the components selected. Probably shouldn't be run by someone unfamiliar with the innards of Windows, but under the guidance of experts like yourselves, may be a solid tool for post-cleaning issues.

    I am not only going to place a shortcut to this page on his desktop (I considered making it his home page, but changing that would be rude), I am also going to print out a copy and include it in the computer case.

    Please accept my sincere gratitude for all of your help!
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem ...safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds