The most difficult malware removal I've ever experienced...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by quantumburnz, Oct 24, 2010.

  1. quantumburnz

    quantumburnz Private E-2

    Hello, I've run into a system that has me totally stumped. I'm trying to fix it for someone I work with so I'm not totally sure how it got so infected. I previously installed Symantec Endpoint Protection (SEP) on the system and it was working fine. However, the person I work with brought it back to me about a week later saying something about receiving pop-ups in email. I can confirm a fake anti-virus program managed to install on the system. I've attempted to run a majority of the Antivirus tools on Hiren's Boot CD with little success. I'm unable to boot into safe mode and logging into accounts in normal mode doesn't always work. Sometimes it will just get stuck and hang at the Welcome screen with the little circle going round and round. What really odd is sometime when it’s stuck, as soon as I press the power button, the Welcome screen goes away and a black screen with the mouse cursor appears, nothing else. Unfortunately, even at this black screen, I can’t Ctrl+Alt+Del or anything to help it load further. The same things happens when you try to shut down, it says “Logging off…” but just sits there, I have to hold the power to turn it off and back on. Finally, it's very difficult to run anything on the machine. I can't get to msconfig, event viewer or many other tools, they just don't show up, but I see their process running in task manager. Finally, it should be noted, when the computer boots up, I get an error saying the “Services and Controller app stopped working and was closed.”

    SUPERAntiSpyware Results (Hiren’s Boot CD)
    System.BrokenFileAssociation
    Rootki.Unclassified/USBHubB
    Security.HiJack[ImageFileExecutionOptions]
    After running and cleaning these, I can usually get past the stuck Welcome screen on bootup. However, these continue to come back even after I clean them.

    READ & RUN ME FIRST Results
    1. 32-bit Vista SP2 w/ 2GB RAM
    2. Symantec Endpoint Protection (SEP) Installed
    3. House Cleaning
      • Add/remove programs -- I'm unable to load the control panel. However, I can run add/remove programs from the run box and it will populate. However, I tried to uninstall a toolbar and it stopped responding up "Initializing Wise Uninstall Wizard..."
      • Unable to launch SEP
      • Unable to complete CCleaner, it gets to 7%, cleaning the Internet Explorer History, C:\Users\Test\App…\index.dat and just sits there. However, I was able to deselect History and clean everything else.
    4. Unable to run msconfig but I’m pretty sure it’s in normal mode.
    5. I don’t see anything suspicious in Add/Remove programs.
    6. N/A
    7. Installing Tools & Running Scans
      1. SAS – Unable to install. I tried the portable launcher, it opened, I clicked “Click here to start” but it doesn’t launch. PROGRAM.COM just sits in the processes tab of task manager but it doesn’t appear to be doing anything.
      2. I was able to install Malwarebytes’ Anti-Malware. However, when I ran the quick scan, it froze at an elapsed time of 4 seconds.
      3. Upon running ComboFix, a window with a blue background opens. The window is titled “Administrator: .” and there is a blinking cursor in the box. Nothing else appears in the box like “Please wait.” or “ComboFix is preparing to run.” as shown in the tutorial.
      4. RootRepeal was a success and the logs are attached. It looks as though there’s a lot of suspicious items to me.
      5. MGtools would not complete and the command prompt just did nothing after displaying the warning message about not clicking the cancel button on the WhoAmI application. Of note,
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now download and Run exeHelper from Raktor
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Try running this:
    Using ESET's Online Scanner

    and this... GMER - running with a random name

    Failing that try this:

    Scan With RKUnHooker
    • Please Download Rootkit Unhooker Save it to your desktop.
    • Now double-click on RKUnhookerLE.exe to run it.
    • Click the Report tab, then click Scan.
    • Check (Tick) Drivers, Stealth, Files, Code Hooks. Uncheck the rest. then Click OK.
    • Wait till the scanner has finished and then click File, Save Report.
    • Save the report somewhere where you can find it. Click Close.
    • Attach the entire contents of the report in a reply here
    .

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see. If successful, attach logs.

    If you really cannot run anything to provide us information that we need to perform a proper diagnosis, your option would be to use another PC to try create one or more of the below CDs to boot from that allow you to run scans and perform many other tasks without Windows even being loaded. Sometimes this can help to get you started when all else fails. They can even help in cases where a previous scan may have removed something that resulted in your PC being unbootable.
     
    Last edited: Oct 24, 2010
  3. quantumburnz

    quantumburnz Private E-2

    exeHelper ran without a problem.

    Unable to run ESET as the network adapter does not appear to be enabled and I can’t run netsh from the command line to enable them.

    I’m unable to run GMER from the desktop so I tried it via Hiren’s BootCD and it loaded; however, it died at \Device\HarddiskVolumeShadowCopy1. I booted Hiren’s BootCD and attempted to run GMER from MiniXP and I’m actually getting an error “X:\i386\system32\config\system: The system cannot find the file specified.” Kind of strange…

    I couldn’t run everything you requested from RKUnhooker because it froze when I included scanning of Stealth and Files but I included the logs for Drivers and Code Hooks.

    Why I do ShowNew, I’m still getting the same thing; the command window just sits there with a blinking cursor after the warning about the WhoAmI application. As for GetRunKey, it tells me
    The system cannot find the file specified.
    updating: runkeys.txt (160 bytes security) (deflated 80%)

    As I mentioned, I’m using Hiren’s Boot CD, are there any utilities or tools you’d like me to run from there? I can download one or more of the others if you wish. Thank you for the assistance!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete these if you are able to manually using windows explorer.
    • C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\lado.exe
    • C:\Users\Test\AppData\Roaming\juzjf.exe

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    You need to make sure that combofix is on your desktop and not inside of any folders, rename it to 123abc.com and try and run it again, if not in normal mode then try safe mode!

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
     
  5. quantumburnz

    quantumburnz Private E-2

    Thank you for all the help Kestrel13!!

    I deleted the two files you found to be suspicious.

    I then ran TDSSKiller and it found a file called rrumcsrt.sys that looked suspicious. I couldn't quarantine it but I booted into MiniXP and moved the file to the desktop. Problem solved!

    I'm currently running ESET's online scanner on the machine. SEP is working again as well so I'll run a scan with that as well.

    I think I have things from here though. Thank you again!

    P.S. Out of curiosity, what tipped you off to those two files you found? Also, what gave you the idea to run TDSSKiller? I've never heard of TDSSKiller but I won't forget it!
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome.

    Are you sure?

    It was easy...they were just screaming malware. Blatantly odd file names.

    Let me know if you still need me or not.
     
  7. quantumburnz

    quantumburnz Private E-2

    Hi Kestrel13!,
    I think I have the system cleaned up but there are a few things that still look funny in the logs to me, such as the following in my ComboFix log:

    --- Other Services/Drivers In Memory ---

    *Deregistered* - klmd25

    Would you mind giving the attached logs a look over for me and tell me what you think? Thanks!
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode, if you haven't done so already.

    What's inside of this folder?
    C:\ProgramData\14396

    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    How're things running?
     
  9. quantumburnz

    quantumburnz Private E-2

    Hi Kestrel13!,
    Thanks for the reply. There's a Shockwave Flash file in each of those strange folders. C:\ProgramData\14396 has a file called {8EE52021-79D1-495C-8B5D-7EE37B3FCCD5}.swf and C:\ProgramData\25362 has a file called {81797D50-D762-4BBB-A31B-894FA4D1E38D}.swf.

    Doing the Avenger thing momentarily.
     
  10. quantumburnz

    quantumburnz Private E-2

    Hi Kestrel13!
    System is running in normal start up mode and it appears to be running fine. MGLogs attached. Hopefully everything looks good!
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, all looks good now. :)

    Let's just do this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    • O15 - Trusted Zone: *.realpage.com

    After clicking Fix exit HJT.

    C:\Windows\system32\tmp.txt <--- delete this.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  12. quantumburnz

    quantumburnz Private E-2

    Looks like the machine is clean and running well! Thanks again for all your help!
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome. :) Safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds