The problems still persist even after completion of READ & RUN ME FIRST.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sejin8642, Jun 15, 2010.

  1. sejin8642

    sejin8642 Private E-2

    I did everything I could to remove the virus. My OS is windows XP professional and I am running the OS using Mac Boot camp. And I know why I got infected by the virus (I ran a hacking file from dubious internet user...yeah I know it was stupid). So after the clean up, everything is fine but later the virus appears again. Basically it disables task manager and registry edit. I don't know what else it does but I am pretty sure it does a lot of bad things that I do not notice. One thing I noticed was that .exe file keeps appearing in my local settings folder with bunch of folders and files that contains a word tmp. Since I cannot remove them directly I removed those files using virus programs and even in Mac mode. But it appears again and again and again. I don't know what else I can do. I am attaching Log files. Please help me. It just annoys me to the point of insanity.
     

    Attached Files:

  2. sejin8642

    sejin8642 Private E-2

    Here's the last log attachment.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do the following from the Read and Run First instructions:
    Not disabling your dameon tools may be giving a false positive for an MBR infection.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  4. sejin8642

    sejin8642 Private E-2

    This time I uninstalled Demon and ran MGtools again. Here's the file.

     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Please download TDSSKiller to your Desktop
    * Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    * Click Start > Run and copy/paste the following bold command into Run box and hit Enter.

    "%userprofile%\Desktop\TDSSKiller.exe" -v

    * Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    * When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.
     
  6. sejin8642

    sejin8642 Private E-2

    Thank you for your help. Here's the TDSSKiller log file.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Thats the shortest log I have ever seen. Something is reporting an MBR infection. Let's try one other thing before we go about it the old way.

    Please run this: GMER - running with a random name and attach the log from GMER.
     
  8. sejin8642

    sejin8642 Private E-2

    Here's GMER log file. Thank you again. In case you didn't know there seems to be no problem at this moment. But I am afraid how long the peace will stay.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will need to boot to the Recovery Console to remove this infection.

    Now boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    Then boot back into normal mode.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me ask you one more time; did you disable your disc emulation software?
     
  11. sejin8642

    sejin8642 Private E-2

    When I ran ComboFix, I think it disabled it. Anyway I uninstalled Demon Tool so there should be no CD emulation. Anyway I'll try console recovery this time. Hope everything goes well ^^
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have removed Dameon, just re-run the C:\MGtools\GetLogs.bat and attach the new log. It will show if the MBR report was a FP due to the Dameon tools.
     
  13. sejin8642

    sejin8642 Private E-2

    At first try I couldn't run MGlogs because the virus again disabled registry edit so I ran SAS again to remove the harmful infections. Anyway here's MGlogs.zip file. Just in case it is helpful to have a virus file (to analyze it or something) I can download the virus file again if you want to analyze it or something. Thank you for your support.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Nope, it is still showing an MBR infection. Please go ahead and boot into the recovery console and run the fixmbr.

    Let me know if you have any problems with that.
     
  15. sejin8642

    sejin8642 Private E-2

    I thought I did that. But I'll do it again and be back soon.
     
  16. sejin8642

    sejin8642 Private E-2

    There appears to be another problem. When starting recovery console, a blue screen comes out with the following message:

    A problem has been detected and windows has been shut down to prevent damage to your computer.

    UNMOUNTABLE_BOOT_VOLUME

    If this is the first time you've seen this stop error screen, restart your computer. If this screen appears again, follow these steps:

    Check to make sure any new hardware or software is properly installed. If this is a new installation, ask your hardware or software manufacturer for any windows updates you might need.

    If problems continue, disable or remove any newly installed hardware or software. Disable BIOS memory options such as caching or shadowing. If you need to use Safe Mode to remove or disable components, restart your computer, press F8 to select Advanced Startup options, and then select Safe Mode.

    Technical information:

    *** STOP: 0x000000ED (0x89EB4E30, 0xc000014F, 0x00000000, 0x00000000)



    I am not sure what steps I have to take from here.
     
  17. sejin8642

    sejin8642 Private E-2

    This time I think I did everything correctly. After Fixmbr command I got a message that looks something like this:

    A new master boot record has been written on the following directories
    \Device\Harddisk0\Partition0

    Now I am again attaching MGlogs.zip file. Thank you for your support always.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't think you have an MBR infection. I believe that Daemon Tools did not uninstall all the junk it puts on your system and this is the cause of the false indications. You just have a couple of minor registry keys to fix up and let's get a new scan from a new version of MGtools.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell us how things are working now! Are you having any malware problems now? Any Google redirects?
     
  19. sejin8642

    sejin8642 Private E-2

    Here are the files. After the clean up, the task manager is disabled again...

     

    Attached Files:

  20. sejin8642

    sejin8642 Private E-2

    And after SAS virus scanning, usually five kinds of threats are detected;Disabled.RegistryEditor, Disabled.TaskManager, Disabled.SecurityCenterOption, Trojan.Unknown Origin, and occasionally Ad.ware. They are gone after clean up but later on they appear again.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I went back thru your logs and I see the reason for this. You have a W32/Sality infection which you can read more about in the below links:

    http://vil.nai.com/vil/content/v_149269.htm

    http://www.bitdefender.com/VIRUS-1000406-en--Win32.Sality.OG.html


    This may not be fixable! Do you have all important data backed up before we try to continue?
     
  22. sejin8642

    sejin8642 Private E-2

    I see. My old antivirus program detected this virus as well but they appear again. So what steps should I take? I have all important data backed up in my USB already.

     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note that your USB drive and and system it was plugged into, is likely infected.

    Put the below two files into a ZIP file and attach it to your next message:
    Code:
    C:\Qoobox\Quarantine\Registry_backups\
    legacy~1.dat 2010-06-15 1220 "Legacy_ABP470N5.reg.dat"
    servic~1.dat 2010-06-15 2548 "Service_abp470n5.reg.dat"

    Download the below files and save them to the C:\MGtools folder:

    http://forums.majorgeeks.com/chaslang/files/Sality/SalityFix.reg

    http://forums.majorgeeks.com/chaslang/files/Sality/system.ini


    Now double click the C:\MGtools\SalityFix.reg file and allow it to be added into the registry. Make sure you receive a success message. Tell me whether you do or not.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).




    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  24. sejin8642

    sejin8642 Private E-2

    Here are the files. I successfully added the registry. Thank you for your support. And it seems that after ComboFix run, the virus comes back again. So I am not sure if the core file that's creating all the viruses can be killed using ComboFix.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I had a typo in the system.ini file I had you download.

    Manually edit your C:\Windows\system.ini file and you will see the below. I want you delete the text that is shown in RED and then save the file.
    Tell me if edit and save works. Reload the file and make sure that text is gone.


    As a note to you and TimW, you will see that the MBR infection no longer shows since I deleted the driver for Daemon Tools. ;)
     
    Last edited: Jun 16, 2010
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is the below?

    "GAZ"="c:\program files\Gaz\Startup" [X]
     
  27. sejin8642

    sejin8642 Private E-2

    Edit and save works. And the text is gone after reloading the file. is it gonna cease the viruses popping up again?

    Tell me if edit and save works. Reload the file and make sure that text is gone.


    As a note to you and TimW, you will see that the MBR infection no longer shows since I deleted the driver for Daemon Tools. ;)[/QUOTE]
     
  28. sejin8642

    sejin8642 Private E-2

    I have no what "GAZ"="c:\program files\Gaz\Startup" [X] is. Is it in my program files folder? I don't see it.

     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps after another reboot if we don't find all the roots of the infection.


    Okay those files I had you attach, showed me the name of a driver file used by the infection. Let's see if we can delete this in the next fix. Also you need to keep checking your C:\Windows\system.ini file to make sure that the below do not come back. They are part of the infection.
    So you will have to check after the reboot cause by ComboFix.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).




    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  30. sejin8642

    sejin8642 Private E-2

    DEVICEMB=21803154243 texts re-appeared after reboot by ComboFix.
     
  31. sejin8642

    sejin8642 Private E-2

    And here are the log files
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes because the driver file is changing at each reboot. The C:\WINDOWS\system32\drivers\fqkrnl.sys we deleted in the last fix was already renamed to something else before you ran the last fix.

    Let's try a automatic tool from Kaspersky to see if it can help before we try to continue manually. In many cases, the only cure is a reinstall. Please download the below file to your Desktop:

    http://support.kaspersky.ru/downloads/utils/sality_off.zip

    Then extract the sality_off.exe file from the ZIP to your Desktop. Now run the sality_off.exe file by double clicking on it. Reboot and see where things stand. If still having a problem, run the below procedure also from Kaspersky:

    http://support.kaspersky.com/viruses/solutions?print=true&qid=208279889
     
  33. sejin8642

    sejin8642 Private E-2

    After Sality_off.exe, Disabled.RegistryEditor, Disabled.TaskManager, Disabled.SecurityCenterOption came back so I needed to remove them using SAS. But DEVICEMB=21803154243 is gone by reboot after Sality_off.exe. But is this all gone or there's possibility that virus might come back?
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try rebooting a couple of times to see if any of it returns.

    After a couple reboots, run C:\MGtools\GetLogs.bat again and attach the new MGlogs.zip log.
     
  35. sejin8642

    sejin8642 Private E-2

    I think the virus came back again. Here's MGlog.zip file.
     

    Attached Files:

  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it did. This infection is rarely fixable which is why back in message # 21 I said "It may not be fixable". ;) I'm sorry, but your course is clear now. You will have to reinstall to be able guarantee that you can remove all aspects of this infection. During the reinstall, make sure that this time you properly protect this PC. You had no protection installed when you first came here. Refer to the below:

    How to Protect yourself from malware!
     
  37. sejin8642

    sejin8642 Private E-2

    Thank you for your support. But I have one more question. You said that my USB and external hard drive might be infected by the same virus as well. Is there a way to check that those devices are virus-free? I re-installed Windows XP but I am afraid that the virus might come back upon plugging those devices. And is it common to have RECYCLER and System Volume Information folders in external hard drive?
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not just them!!!! Any other PC they were plugged into and any PC networked to the infected PC could be infected. You could try using a fully protected clean PC that has autoruns disabled doing a full scan with an antivirus program on these removable devices and hope that it is able to detect and remove any pieces of the infection if present.

    Yes.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds