Please Help with Malware removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by quiltro, Jan 2, 2012.

  1. quiltro

    quiltro Private E-2

    Have run malware removal instructions

    The only one that failed was ComboFix. It has been a problem as it hangs up.
    The recovery module that ComboFix installs also hangs up. Computer freezes.

    I also still seem to have redirection by malware on my browser.

    Original source of problem was a file titled Facebook_Password.zip that came in an e-mail.

    I have attached the logs.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What malware issues are you having, as I am not seeing any malware in your logs.
     
  3. quiltro

    quiltro Private E-2

    Hi Tim:

    The two things I still notice are:

    My browser gets redirected to other webpages. Example, if I do a Bing Search on IE, for "ad-aware". I get the Bing results page, then when I click on the lavasoft link, the tab says "redirected" on it and I end up on a page called infomash.

    http//infomash.org/100/10653/search.php?etc...

    The other thing is that some programs are running much slower than before.
    It takes a long time to open the control panel and the security center. It also takes a really long time for the remove software list to display.

    Also, the internet is sluggish.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
     
  5. quiltro

    quiltro Private E-2

    Kestrel13

    It is not letting me run TDS Killer. I will try MBRCheck next.

    I renamed it as suggested in the how to you sent. I do get the "Open File - Security Warning" promt but when I say yes nothing happens

    Paul
     
  6. quiltro

    quiltro Private E-2

    Kestrel13!

    Please also download MBRCheck

    Bad news, here is the log...

    Paul
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do you have your XP boot CD?
     
  8. quiltro

    quiltro Private E-2

    Kestrel13!

    I have several, but I believe that my CD RW has been disabled.

    I do not think it boots anymore.

    Paul
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try going to device manager and deleting the CD/DVD drive. Reboot and see if it finds it and reinstalls it.
     
  10. quiltro

    quiltro Private E-2

    TimW:

    I am in windows setup from the boot disk. Deleting the driver worked.

    Paul
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    A small hidden partition is the problem. Also there is the issue of an infected MBR yet to address. Let's do this first.

    gparted-live-0.10.0-3.iso (114 MB)


    Create the bootable CD for Gparted. You can use ImgBurn do this.

    Now boot off of the newly created Gparted CD.

    [​IMG]
    You should be here...
    Press ENTER

    [​IMG]
    By default, "do not touch keymap" is highlighted. Leave this setting alone and just press ENTER.

    [​IMG]
    Choose your language and press ENTER. English is default [33]

    [​IMG]
    Once again, at this prompt, press ENTER

    You will now be taken to the main GUI screen below
    [​IMG]
    According to your logs, the partition that you want to delete is 10.33 MB
    Click the trash can icon to delete and then click Apply.

    You should now be here confirming your actions:
    [​IMG]

    Now you should be here:
    [​IMG]

    [​IMG]
    Is "boot" next to your OS drive? According to your logs, the Operating System (OS) drive is 111.78 GB

    If "boot" is not next to your OS drive under "Flags", right-mouse click the OS drive while in Gparted and select Manage Flags

    In the menu that pops up, place a checkmark in boot like the picture below:
    [​IMG]

    Now double-click the [​IMG] button.

    You should receive a small pop up like this:
    [​IMG]
    Choose reboot and then press OK.

    Boot back into Windows and let me know how things are running now.

    Re run MBRCheck and TDSSKiller

    Attach a new MBRcheck log from them both and describe if you had any trouble.
     
  12. quiltro

    quiltro Private E-2

    I cannot get g-parted to boot on this system. Even thought it boots on my laptop. I leave for work at 6 AM EST, so I will will have to call it quits for tonight.

    I also think that will call it quits for tonight and attempt it again tomorrow.

    Paul
     
  13. quiltro

    quiltro Private E-2

    TimW & Kestrel13!

    I cannot G-Parted. I tried two more times today and it does not boot on the infected PC. Same disk boots on my laptop.

    Not sure why, but after 4 tries I need to try something else.

    The XP CD does alow me to boot the recovery console

    Paul
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Create and try the new version:

    Preferably from a clean computer, I need you to download: gparted-live-0.11.0-7.iso (114 MB)

    Create a bootable CD for GParted. You can use ImgBurn to accomplish this.
    If you need help on how to use ImgBurn, please view this guide by dr.m -- Using ImageBurn to Burn an ISO image

    Now boot off of the newly created GParted CD.

    [​IMG]
    You should be here...
    Press ENTER
    [​IMG]
    By default, "do not touch keymap" is highlighted. Leave this setting alone and just press ENTER.
    [​IMG]
    Choose your language and press ENTER. English is default [33]
    [​IMG]
    Once again, at this prompt, press ENTER
    You will now be taken to the main GUI screen below
    [​IMG]
    According to your logs, the partition that you want to delete is 10.33 MB
    Click the trash can icon to delete and then click Apply.
    You should now be here confirming your actions:
    [​IMG]
    Now you should be here:
    [​IMG]
    [​IMG]
    Is "boot" next to your OS drive? According to your logs, your OS drive is the 140.85 GB sized partition.
    If "boot" is not next to your OS drive under "Flags", right-mouse click the OS drive while in Gparted and select Manage Flags
    In the menu that pops up, place a checkmark in boot like the picture below:
    [​IMG]
    Now double-click the [​IMG] button.
    You should receive a small pop up like this:
    [​IMG]
    Choose reboot and then press OK.

    Now reboot from the Windows XP Recovery Console CD and execute the following commands pressing ENTER after each:


    • fixmbr
    • fixboot
    • exit


    Once back in Windows...

    [​IMG] Re-run another scan with MBRCheck and attach its latest log. (How to attach)
     
  15. quiltro

    quiltro Private E-2

    G-parted

    Steps I have taken
    I have made 3 G-Parted disks:
    1) gparted-live-0.10.0-3.iso (@ Kestrel13!’s suggestion) burned on a laptop running Vista.
    Would not boot on the infected PC. Re-booted several times. Deleted driver of drive so that Windows XP would reinstall (Worked when booting the XP recovery disk. Would not work on G-Parted disk)

    2) gparted-live-0.11.0-7.iso (@TimW’s suggestion) burned on laptop running Vista.
    Would not boot on the infected PC. Re-booted several times. Deleted driver of drive so that Windows XP would reinstall (Worked when booting the XP recovery disk. Would not work on G-Parted disk)

    3) gparted-live-0.11.0-7.iso burned on a laptop running Windows7
    Would not boot on the infected PC. Re-booted several times. Deleted driver of drive so that Windows XP would reinstall (Worked when booting the XP recovery disk. Would not work on G-Parted disk)

    4) tried to burn gparted-live-0.11.0-7.iso from infected computer running Windows XP.
    Would not allow me to to burn the CD ImgBurn reported “Medium not present”. Inserted several different blank disks and re-booted several times. Deleted driver of drive so Windows XP would reinstall driver to no avail.

    What next? :-D
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you able to go into the control panel / admin tools and get into disc management? Can you then right click the partition and choose delete?

    If so, you will then have to reboot into the Recovery Console and run the fixboot/fixmbr commands.
     
  17. quiltro

    quiltro Private E-2

    TimW:

    I deleted it twice and go the following error message...

    An unexpected error has occurred. Check the System Event Log for more information on the error. Close the Disk Management console, then restart Disk Management or restart the computer.

    The system even log says:

    Type date Time Source Category Event User Computer
    Error 01/07/2012 3:31:57 PM LDM None 2 N/A LARISTONDO
    Error 01/07/2012 3:31:42 PM LDM None 2 N/A LARISTONDO
    Error 01/07/2012 3:30:39 PM disk None 11 N/A LARISTONDO
    Error 01/07/2012 3:30:38 PM disk None 11 N/A LARISTONDO
    Error 01/07/2012 3:30:38 PM disk None 11 N/A LARISTONDO
    Error 01/07/2012 3:30:37 PM disk None 11 N/A LARISTONDO
    Error 01/07/2012 3:30:57 PM disk None 11 N/A LARISTONDO

    Do you still want me to reboot into the Recovery Console?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Only if you were able to remove the fake partition.
     
  19. quiltro

    quiltro Private E-2

    I deleted the partition. Checked to see if it was gone, and it was gone.

    Then I rebooted into the Recovery Console and ran the fixboot/fixmbr commands.

    When I rebooted my computer I got the following message:

    "A disk read error occurred
    Press Ctrl+Alt+Del to restart"

    I did this twice and got the same error two more times...

    Paul
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now reboot from the Windows XP Recovery Console CD and execute the following commands:


    • fixmbr \Device\HardDisk0
    • fixboot c:
    • exit
     
  21. quiltro

    quiltro Private E-2

    Followed your instructions, still getting error.

    Paul
     
  22. thisisu

    thisisu Malware Consultant

    Hi quiltro,

    What happens if you go back into the Recovery Console and type in (and press ENTER after each command):
    • c:
    • dir
    What is listed (if anything)?
     
  23. quiltro

    quiltro Private E-2

    thisisu:

    I get a directory listing.

    When I load the Recovery Console, I am asked to pick windows installation.

    There is only one choice.

    1) C:\WINNT

    When I pick one, I get the C:\WINNT> prompt

    I can use the "DIR .." command to get back to root.

    All recovery console commands seem to work.

    Paul
     
  24. thisisu

    thisisu Malware Consultant

    Ok good.

    Go back into the Recovery Console and type out this command (and press ENTER):
    • bootcfg /rebuild

    When it's finished, it should say something like:
    Total Identified Windows Installs: [X]

    Let me how many Windows Installs were found here and list each one (if more than 1)
     
  25. quiltro

    quiltro Private E-2

    thisisu:

    Total identified Windows installs: 1
    [1]: C:\WINNT

    Add installation to boot list? (Yes/No/All):

    Paul
     
  26. thisisu

    thisisu Malware Consultant

    Let's try creating another boot entry.

    Note: The purple bold letters below are what you will be typing. The Black text is what will be presented to you.

    Type in Y (for yes)

    Enter Load Identifier: windows xp test
    Enter OS Load Options: /fastdetect

    exit

    Now reboot and try booting from windows xp test (the entry we just created)
     
  27. thisisu

    thisisu Malware Consultant

    If that does not work, verify that your OS partition (111.78 GB) is marked as Active in GParted.
     
  28. quiltro

    quiltro Private E-2

    When I rebooted my computer I got the following message:

    "A disk read error occurred
    Press Ctrl+Alt+Del to restart"

    I did this twice and got the same error two more times...


    > Now reboot and try booting from windows xp test

    How do you pick which installation to boot from?

    Paul
     
  29. thisisu

    thisisu Malware Consultant

    Sorry did notice you were getting that message before boot loader.

    At this point I would like you to verify that your OS is marked as active (has a checkmark in Managed flags) while in GParted.
     
  30. quiltro

    quiltro Private E-2

    I have not been able to get G-Parted to boot on my PC. I am going to try and make a copy at work, and see if I am able to boot.

    Thanks,

    Paul
     
  31. thisisu

    thisisu Malware Consultant

    Ah I did not realize you were unable to use GParted, but yes this is the problem. The TDL4 partition was marked active, and you deleted it. This is why we need to reassign the correct OS partition as Active/Boot. Once you do this, you should be able to boot properly again.

    Code:
    [B][COLOR="Indigo"]Bootable[/COLOR][/B]  Name                   Size          Type                     
              Disk #0, Partition #0  120023253504  Installable File System  [COLOR="DarkRed"]<-- OS partition[/COLOR]
    [B][COLOR="Red"]TRUE[/COLOR][/B]      Disk #0, Partition #1  10829824      Unknown  [COLOR="DarkRed"]<-- TDL4 partition[/COLOR]  
    There are some other tools that you can edit the partition table if GParted isn't working for you. I will try to gather some instructions on how to use them whenever I get a chance. ( still at work )
     
  32. quiltro

    quiltro Private E-2

    I am creating a USB G-Parted boot to see if it works... Should be done in a few minutes.
     
  33. quiltro

    quiltro Private E-2

    I got an error message that it needs an operating system to load when I booted G-Parted from a usb drive.

    I have a USB Ubuntu boot-able USB that loads on the PC.

    Can I run G-Parted from it?

    pL
     
  34. quiltro

    quiltro Private E-2

    While I waited,


    From a gnome-terminal in Ubuntu, I executed the sudo fdisk -l command

    The results were as follows

    Disk /dev/sda: 8074 MB, 8074035200 bytes
    39 heads, 31 sectors/track, 13043 cylinders, total 15769600 sectors
    Units = sectors of 1 * 512 = 512 bytes
    Sector size (logical/physical): 512 bytes / 512 bytes
    I/O size (minimum/optimal): 512 bytes /512 bytes
    Disk identifier: 0x04030201

    Device Boot Start End Blocks Id System
    /dev/sda1 * 2056 15769599 7883772 c W95 FAT32 (LBA)

    Disk /dev/sdb: 120.0 GB, 120034123776 bytes
    255 heads, 63 sectors/track, 14593 cylinders, total 234441648 sectors
    Units = sectors of 1 * 512 = 512 bytes
    Sector size (logical/physical): 512 bytes / 512 bytes
    I/O size (minimum/optimal): 512 bytes /512 bytes
    Disk identifier: 0x09100910

    Device Boot Start End Blocks Id System
    /dev/sdb1 63 2344020479 117210208+ 7 HPFS/NTFS/exFAT
    /dev/sdb2 * 23442048234441631 10576 17 Hidden HPFS/NTFS

    I thought this might be useful
    pL
     
  35. thisisu

    thisisu Malware Consultant

    Can you let me know if you are able to toggle "Active" on your OS partition using this boot CD (Super Fdisk)?

    See the attachment below:
     

    Attached Files:

  36. quiltro

    quiltro Private E-2

    thisisu

    I could not get the Super F disk to boot.

    I have to believe that there is something wrong with my CD ROM drive. The only disk that boots from it is the Windows XP recovery CD.

    All other CDs that I have burned on my other machines (all laptops) do not boot.

    If I burn something to a thumb drive, it seems to boot just fine.

    Paul
     
  37. quiltro

    quiltro Private E-2

    My booting options on the infected PC are:

    Hard Drive: PM-ST3120026A
    Not booting at the moment

    SS-SONY CD-RW CRX215E5
    Boots Windows XP recovery, but does not boot disks burned on my other machines

    Kingston DataTr (Or other USB thumb drives I own)
    Boots Ubuntu Linux and seems to boot other software I write to it as long as I have an operating system loading.

    SM-IDE-DVD ROM
    I am not able to open this drive

    1st Floppy drive
    Only floppy drive in the house

    I have 3 laptops.
    1 runs Ubuntu Linux
    1 runs Windows 7
    1 runs Windows Vista Home Premium
     
    Last edited: Jan 11, 2012
  38. thisisu

    thisisu Malware Consultant

    I was afraid of that.

    What software are you using to burn the .ISO files. And what speed are you burning at (4x, 8x, 48x, etc) ??
     
  39. quiltro

    quiltro Private E-2

    I am using ImgBurn. I used the slowest setting. Can't remember what it was.

    Super F Disk was an .exe file that burned the image that I downloaded. It did not give me an option to burn to USB thumb drive.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds