Malware Removal Help Needed After READ&RUN ME's

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by LittleNooch, Sep 20, 2011.

  1. LittleNooch

    LittleNooch Private E-2

    I'm helping a friend with her computer, so I cannot directly answer what she was doing at the time of infection. What I can tell you is that I've been working through the list of "Read & Run Me First" and am still having problems.

    Some information:

    Windows XP 32-bit SP3

    I started by removing all AV programs that she had installed to start with a clean slate. I cannot, however, remove SPAMFighter. It will not launch, it will not remove from Add/Remove. It will not even respond when hovering over the icon in the sys tray.

    I downloaded and attempted to run SAS, but it will start scanning and close out. I rebooted and tried again...same thing.

    I downloaded and attempted to run Malware Bytes. It too will start scanning and then close out after about 15 seconds. After a reboot, same thing.

    I will often get the error that the path is not accessible and that I might not have administrative rights, etc. etc.

    I was able to get ComboFix to run and during the scan process, the following message popped up:

    "You are infected with Rootkit.ZeroAccess! It has inserted itself into the tcp/ip stack. This is a particularly difficult infection."

    It then indicated that it the system needed to reboot to continue. I was given no other option than "OK". After a reboot, the scan continued.

    I also continued with the rest of the instructions provided, and the other scans did complete.

    Three log files are attached.

    Thanks for your help!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download and run Win32kDiag per the below instructions:

    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log

    C:\win32kdiag.exe -f -r



    Now download Junction,zip to your Windows folder

    • Please download Junction.zip and save it to your Windows folder (i.e, C:\Windows\Junction.zip This assumes C:\ is your Windows boot drive.)
    • Now unzip it and put junction.exeinto the Windows folder (i.e., C:\Windows\junction.exe)
    • Do not try to run it right now. We will run something that uses it later.

    Now we need to reset the permissions altered by the malware on some files.

    • Download and save inhertit.exe to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!

    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.

    And one more scanning tool I want to use to collect more information is OTL per the below.

    Please download OTL by Old Timer to your desktop.
    See the download links under this icon: [​IMG]

    1. Double-click OTL.exe to run (Vista and Win7 right click and select Run as Administrator)
    2. When OTL opens, change the Output (at the top-right portion of the program) to Minimal Output.
    3. Put check-marks in LOP Check and Purity Check.
    4. Now click the [​IMG] button.



    • When the scan is complete, two logs entitled OTL.txt and Extras.txt will be created on your desktop.
    • Attach both of these logs to your next message.
     
  3. LittleNooch

    LittleNooch Private E-2

    Attached are the three requested log files.

    Had some problems downloading the programs...pages were opening up <blank>, but was able to transfer them from a good computer to the file locations you specified. Programs ran with no problems.

    Thanks for the help!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Uninstall both SAS and MBAM, reboot and download new copies of each. Can you now run them?
     
  5. LittleNooch

    LittleNooch Private E-2

    Hi Tim,

    Yes, I was finally able to get them to run after doing what you said. Attached are the log files.

    Thanks!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good, they didn't find anything. And Combo seems to have removed most of it, so just re-run Combo and let me know how it goes. Attach the new log. And be sure to tell me how things are running. ;)
     
  7. LittleNooch

    LittleNooch Private E-2

    Will do, thanks! Just waiting for Combo to finish up now and I'll post the log. Just curious as to what the SPAMFighter is and why I can't get it to budge. Can't start it, can't end it, can't remove it. Is it anything I should be worried about? Also, I keep getting a pop-up that AVG Firewall is turned off. I removed that before I started any of the other clean-up. What's going on with that? Thanks again for all the help today!
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can try using Revo to uninstall it.
     
  9. LittleNooch

    LittleNooch Private E-2

    Thanks, I'll give Revo a try.

    Here's the ComboFix log....
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Tell me how things are running. If Revo doesn't work, try CCleaner. If neither work, we can remove it manually. ;)
     
  11. LittleNooch

    LittleNooch Private E-2

    Oh no, Revo's found lots to remove. I'm just afraid I'm going to remove too much and really screw things up...now that we seem to be mostly back to normal! :)
     
  12. LittleNooch

    LittleNooch Private E-2

    Oh yeah, and one other question.. Your thoughts on what to leave on here or put back on here for AV to keep her from getting back to the way it was this morning?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0


    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    SUPERantispyware and Malware Bytes.

    I use Avast! Free version and am very happy with it. I believe TimW uses Microsoft Security Essentials, and is happy with that. Your preference. :)
     
  15. LittleNooch

    LittleNooch Private E-2

    Thanks for all of the help and suggestions, guys! I'm going to finish it up today but getting an AV on here. Looks like everything is running well. The only remaining thing would be manually removing SPAMFighter. Do you want me to start a new thread for that? I can see thru Revo that it will remove A LOT. I'm just afraid to remove too much.

    Thanks again,
    Denise
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are worried about using Revo, we can do it manually. However, I am about to go out for a while and it will be later this afternoon when I can get back to you with the fix.
     
  17. LittleNooch

    LittleNooch Private E-2

    Sure, later today is not a problem. I'll be here all day! I'm just not that comfortable with Revo and if I delete too much, this will wind up being a much longer thread to get things running again. LOL :)
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have already removed MGTools, please download it again.

    Now download The Avenger by Swandog46 to your Desktop.

    See the download links under this icon [​IMG]
    Extract avenger.exe from the Zip file and save it to your desktop.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.


    1. Run avenger.exe by double-clicking on it.
    2. Click OK at the warning to continue to use The Avenger
    3. Do not change any of the check box options!
    4. Shut down your protection software now to avoid possible conflicts.
    5. Copy everything in the Quote box below, and paste it into the Input script here: part of The Avenger
    6. Now click the [​IMG] button
    7. Click Yes to the prompt to confirm you want to execute.
    8. Click Yes to the Reboot now? question that will appear when The Avenger finishes running.
    9. Your PC should reboot, if not, reboot it yourself.
    10. A log file from The Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
    11. Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Now run Ccleaner to clean out only temp files. Then do the registry cleaning and make sure you do the backup when prompted.

    Let me know how that all went.
     
  19. LittleNooch

    LittleNooch Private E-2

    Here's the Avenger log.

    Thanks!
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good. Are you having any other issues? ;)
     
  21. LittleNooch

    LittleNooch Private E-2

    No, things are looking pretty darn good now! The final question I have is on firewall. I decided to go with Avast for AV, I've kept MWB and SAS. I put COMODO on for her firewall. Just concerned that it'll be too cumbersome for a novice user and she'll be calling me all the time saying that "weird things are popping up". Is there anything I can do to make it a little more "behind the scenes"? Thanks for everything!!
     
  22. LittleNooch

    LittleNooch Private E-2

    SPAMFighter is still in my Add/Remove BTW...just noticed that. This thing is PITA!
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    See if CCleaner will remove it.
     
  24. LittleNooch

    LittleNooch Private E-2

    Finally Gone! Thank God! Any tips on COMODO? Thanks again!
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Questions about Comodo should be addressed in the software forum. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds