rogue AV tool infection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rtxx, Apr 2, 2011.

  1. rtxx

    rtxx Private E-2

    I'm helping friends with their Vista Home Premium SP2 32 bit computer. It had something that sounds similar to a MS Removal tool infection (apparently they didn't feel a need to renew their AV subscription when it expired). An interface came up at startup claiming infection, there were tons of browser popups, and the computer was very slow. I got rid of several copies of malware in the temp/Low directories before starting your procedure, so there used to be more than the logs will show. I was told the symptoms started around 3/26, so did a system restore to 3/18. Then I found cookies belonging to 69.50.209.220 as early as 3/17. So did another system restore to 3/8, then more rounds of scanning. Clearly the tools I used (MBAM, SAS, HitmanPro, Kaspersky, Avast) didn't finish the job. Then I started your steps.

    Even after finishing your steps I am not able to unlock the taskbar or unhide file extensions etc. Also, some context menu items are missing (new folder, new text doc, etc), which I was unable to fix by using these tools
    http://www.vistax64.com/tutorials/154554-new-context-menu-restore-default-menu-items.html
    (There may be more such issues I just haven't found yet, since this isn't my computer.) I don't know if these are all due to changes by the malware, or if they are totally separate issues. This is my first experience with Vista so I'm especially ignorant of tips, tricks, & differences from XP.

    At one point I ran the System File Checker tool as in KB929833, found corrupt files, unable to fix some. I couldn't open c:\windows\logs\CBS\ logs -access was denied at the time. Now I see that I can access the logs, but I'll wait till later to try fixing the listed files.

    Old SpySweeper & trend micro installations interfered with a Panda AV install, so I installed Avast instead. I had difficulty getting rid of Spysweeper & TM, but finally did -so now Panda keeps trying to install on bootup. I haven't dealt with that yet, just letting you know in case you wonder what's going on there.

    There is only one user account, which is an admin.

    I'll omit the MBAM log for now,so the post will show as having 0 replies. There was NOTHING detected in the MBAM log. Will attach later if you want.

    Thanks!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry for the delay in getting back with you. I am not seeing much in the way of malware on your system.
    However, let's clean up a few things:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    SecCenter::
    {48929DFC-7A52-A34F-8351-C4DBEDBD9C50}
    
    Driver::
    PavProc
    
    File::
    c:\windows\system32\DRIVERS\PavProc.sys
    
    Folder::
    c:\program files\Common Files\Panda Security
    c:\programdata\gObOcDmLjNp06511
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\MRI_DISABLED]
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\MRI_DISABLED\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\MRI_DISABLED\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\MRI_DISABLED\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. rtxx

    rtxx Private E-2

    You're working at this on a Sunday! I appreciate that! There was no delay.

    Sorry, I didn't realize Windows Defender was still running until I read the combofix log. Hope it's not a problem, it's not obvious how to disable that.

    There have been no popups or other overt signs of malware since before I started this thread.
    I am still not able to unlock the taskbar or unhide file extensions etc. Context menu items are still missing (new folder, new text doc, etc).
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer to find and delete:
    C:\Windows\temp\TMP0000001E4C2282A73A06A9AB
    C:\Windows\temp\TMP0000001E4C2282A73A06A9AB

    Yes, there are two in your logs.

    I am not seeing any other malware in your logs. Your issue with the taskbar should be address in the software forum, but these final steps should hide your files again:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  5. rtxx

    rtxx Private E-2

    (OK, I see how to disable Windows Defender. I hadn't scrolled down far enough under Tools /Options)
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem at this point. :)
     
  7. rtxx

    rtxx Private E-2

    C:\Windows\temp\TMP0000001E4C2282A73A06A9AB (you listed the same thing twice) was not in the temp directory. Could it have disappeared when I rebooted? OR is it a hidden file? I STILL can't unhide files and file extensions, even after uninstalling Combofix. irritating.

    If deleting the above file is not an issue, I'll ask about unhiding files in the software forum, after running System File Checker again.

    THANKS, Tim!
     
  8. rtxx

    rtxx Private E-2

    I can delete that file, if it's still there but hidden, by runnning CCleaner, right?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It may have disappeared after a reboot. Just run CCleaner to clear out your temp files.

    Yes, I suggest you post in the software forum.

    Try doing this first:

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot and go to the control panel, click on folders / view and see if you can hide them again.
     
  10. rtxx

    rtxx Private E-2

    On running fixme.reg I get "Cannot import fixme.reg: error accessing the registry." Both Avast & Win Defender are disabled. Using Windows Firewall now, which is on.

    One other funny thing, probably unrelated: Every time I restart Internet Explorer 8 (which I just updated to), it says it is not my default browser, do I want to set it as default, & check every time? I always say yes, although I don't think there is another brower on this machine. If that's unrelated I'll deal with it later (planning to go to MSIE 9 & FF4)
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you: Be sure the "Save as" type is set to "all files"?

    The issues with IE are also something to address in the software forum. ;)
     
  12. rtxx

    rtxx Private E-2

    Yes I did. Although I can't se the extension, it's clearly .reg and shows the proper icon on the desktop.

    Another funny thing. Running CCleaner with only System/Temporary files checked, CCleaner doesn't see anything to clean and doesn't delete the Windows\Temp files. However i can manually delete the ones I see there. There are several files and one folder in there aside from the Low folder.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sounds like system issues. Have you got your install CD? If so, go to start / run and type:
    sfc /scannow. Run it at least twice.

    Is there anything left in the Low folder? If there is, delete them and then the folder.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just to be on the safe side, let's have you do an online scan:

    eSet Online Scan.
     
  15. rtxx

    rtxx Private E-2

    ...AND, when I delete a file from the desktop it does NOT show up in the recycle bin. Then when I tell CCleaner to analyze only what's in the recycle bin before cleaning, it reports nothing there. So does that mean now when I manually delete something it just gets hidden, not really deleted? I doubt it, just being paranoid here. That behavior sounds like something a rootkit would want to do.

    The windows\temp\low folder definitely showed "this folder is empty". Now it's deleted.

    ESET found nothing other than the MGTools process.exe.

    I did the SFC scan 3 times. The only items that could not be repaired, mentioned in the last sfc scan, are shown in the attachment. Doesn't seem to account for the wierd behavior. (I don't have an install CD, will try to get the owners to request one from Dell. There is a recovery partition)
     

    Attached Files:

    Last edited: Apr 4, 2011
  16. rtxx

    rtxx Private E-2

    Oh, I see, CCleaner has advanced Options, where the default is to NOT delete anything in windows\temp newer than 24 hours old. whew.

    But why aren't manually deleted files appearing in recycle bin? one more thing to address in the software forum, I guess
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, there are multiple issues that you need to address in the software forums.
     
  18. rtxx

    rtxx Private E-2

    Thanks very much for your help, Tim!
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are quite welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds