VICIOUS, EVIL malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jenandlaw, Oct 3, 2010.

  1. jenandlaw

    jenandlaw Private E-2

    So glad you guys know this stuff and so glad you're willing to help us ignoramuses.

    OK, the problem:

    My mom's AV expired. Eset. I renewed it, downloaded it. The problems began. It was one of those "Fake Antivirus" trojans that kept popping up. I downloaded Malwarebytes and couldn't get it to run. I downloaded it, renamed it, it would start then shut down. I tried to restart in safe mode, and it wouldn't let me have that option. My options were "repair" or "start normally". If I choose repair, it goes to a blue screen where the only option is "Other User". If I click on it, it asks for a username and password. I have no idea what it might be.

    If I click "start normally" it goes into an endless boot cycle. I have not been able to get back to where I could run anything at all.

    I downloaded an Unbuntu Live Cd. Booted it up in the computer and was able to see everything. Can't run Malwarebytes in Ubuntu. Was able to copy some files over to an external hard drive, but I'm afraid to use it because I'm afraid the trojan is in it somewhere.

    I downloaded a Kaspersky Rescue CD. Scanned whole computer. The only thing it "found" was MGTools. Told me it was trojan-dropper.win32.agent.bsvq It was unable to update it to the most recent database.

    Can't find my windows cds to save my life. Just to reiterate, I can't get it to boot in windows at all to the desktop.

    I'm on Windows Vista.

    Tell me what to do and I'll do it. I'm not an expert but I can follow directions.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have access to a different computer, you can download and create this disc. You can use it to do a repair in the vista recovery environment:

    Vista and Win7 Recovery disc
     
  3. jenandlaw

    jenandlaw Private E-2

    Ok that worked. I can now boot to the desktop. I'm getting the "your system is infected" wallpaper and "Windows Security Alert" window now. It says "Your computer is making unauthorized copies of your system and Internet files. You should imideatly run full scan your system to prevent any unauthorized access to your data. Click YES to run Antivirus scaner right now." (terrible misspellings are verbatim, and thank goodness for them because they're a huge indication it isn't legit).

    Do I begin trying the removal protocol again? Just to refresh, it wouldn't let me run Malwarebytes' before.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you now need to try to run all the required scans:
    SAS
    MBAM
    ComboFix
    C:\MGTools.exe --> and attach the C:\MGLogs.zip
     
  5. jenandlaw

    jenandlaw Private E-2

    Ok. Wouldn't let me get through SAS. It would freeze on this file:

    HKLM\System\ControlSet001\bcm4sbxp

    Wouldn't run MB for more than 5 seconds and would shut down.

    Attached are logs. I think one of them says I didn't disable my spyware but I did and I completely uninstalled the AdWatch that it said was running. But maybe I misunderstood the log.

    Thank you so much!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it.
    • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message
     
  7. jenandlaw

    jenandlaw Private E-2

    Logs attached... don't know how I ended up with 2. Can I run MB now?
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That looks like it took care of your MBR infection. Let's have you run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Yes, you can re-run MBAM and attach that log as well.
     
  9. jenandlaw

    jenandlaw Private E-2

    Does it matter in which order I do it? First, MBAM then C:\MGtools\GetLogs.bat ? or the other way around?
     
    Last edited: Oct 6, 2010
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MBAM first.
     
  11. jenandlaw

    jenandlaw Private E-2

    Still can't run MB.

    Log attached.

    Thank you so much, Tim for helping me. This is my mom's computer and she is in college and she really needs it back. I am so incredibly grateful for your help. You have no idea. (Bet you get that all the time.)
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's see if this helps:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    gbaehybc
    
    File::
    c:\windows\system32\gbaehybc.dll
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  13. jenandlaw

    jenandlaw Private E-2

    Now it won't let me run C:\MGtools\GetLogs.bat
    See attached Combofix logs. I attached both because the one displayed at the very end wasn't named the same thing.

    Also, now anytime I click on anything it says "Illegal operation on a registry key that is marked for deletion." I know some of the file associations are gone too because I can't open any .exe file.

    Do I need to start all over?
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How rude!! Go HERE and click on the exe to get the zip registry fix.

    Tell me if that works.
     
  15. jenandlaw

    jenandlaw Private E-2

    Very rude... those darn ruskies.

    Ok, I get the "illegal operation attempt on a registry key marked for deletion" message.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try rebooting.
     
  17. jenandlaw

    jenandlaw Private E-2

    Rebooting worked. See attached.
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Still not seeing any malware in your logs. Please do an online scan and attach the log when done:

    eSet Online Scan.
     
  19. jenandlaw

    jenandlaw Private E-2

    When I click on "I agree" all I get is a light blue window that doesn't do anything. Would the Eset online scanner be able to find something that my Eset resident on my computer can't? Here's what's weird... the "Antivirus 2010" program that I uninstalled as part of the "Read Me" procedures said it was downloaded the same day I updated my Mom's Eset. What are the odds?

    Maybe there isn't any malware left, but I still can't run MalwareBytes, and I can't boot into Safe Mode. Maybe there's some other reason for that?

    Also, I hate to mention it now cuz I'm afraid you'll kill me, but I get this DOS looking notification when I first turn on the laptop before the Dell or Windows logos come up, that says "battery not recognized, press any key to continue". I was just going to get her a new battery, but I mention it now in case it's important.


    Some more questions:
    Should I just go ahead and buy a new hard drive and OS and start from scratch?
    If I had purchased Malwarebyte's, would it have caught this?
    I have been transferring these logs to post on Majorgeeks back and forth from the laptop to my work computer with a flash drive. Are trojans smart enough to copy themselves onto removable drives, and then copy to another computer?
    I copied some of the documents from Mom's user account onto an external hard drive in case all this went to heck. Are they safe or is the trojan smart enough to know that?

    I'm sure some of these questions are really stupid, but I just don't know enough about malware and computers to know its limits.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't think we are at that point yet.
    Hard to say, but it might have.
    That is a chance you take when using a flash drive instead of using a cd.
    The virus's rarely attach themselves to documents.

    If your eSet online scan failed, then lets try doing this:
    Using BitDefender Online Scan.
     
  21. jenandlaw

    jenandlaw Private E-2

    I've been running everything I can without being connected to the internet. I'm at work right now and brought my mom's computer with me. We don't have wireless. If I plug her computer in to my ethernet connection, can I spread this virus/trojan to our servers?
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I think you will be safe. Your logs have been indicating that you are malware free, but the online scan may find something I am missing. If you are worried about connecting at work, I would wait until you return home and connect there. Just to be on the safe side.

    The other thing that I have been considering is to have you try to do a system restore to before this all occurred. Even if you go back to a point that still has malware, then we can re-run the scans. You risk losing anything you downloaded since then. But it may be a better choice.
     
  23. jenandlaw

    jenandlaw Private E-2

    Ok, I tried. My computer wouldn't go to the site at all for a while, but somehow I googled it and got to it through another page. The computer was running SOOOO SLOOOOWWWW it took forever to download Java, and then when I got to bitdefender, it tried to update the definitions and took so long and kept restarting that I eventually told it to scan without updates. Then it took soooo long to start the scan and it scanned so slow, that I gave up. I have to have my internet connection to work. I finally got to task manager to see if something was eating up the resources and I didn't see anything, but there were 12 instances of svchost.exe

    Is that normal? So I'll try again later tonight when I can get to the internet at home. Also, again, Tim, I can't thank you enough for your help, but let me tell you this information before we continue: I'm going back to my mom's Saturday, so if you don't think we'll be able to get it clean (or maybe it is already?) and I need to get a new hard drive and OS, I'll need time to do that after the point we've given up. Did that make sense? Usually I'm more articulate.
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have a restore point before this all started happening?
     
  25. jenandlaw

    jenandlaw Private E-2

    I don't know. I don't really know how that works. If it's something I would have to manually do, then probably not, cuz if I don't know to do it, my Mom SURE doesn't. Is there a way for me to check?
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, just go to start / programs / accessories / system tools / system restore. Once that opens, you can click back to last month and choose a restore point.
     
  27. jenandlaw

    jenandlaw Private E-2

    Earliest system restore point I can see is 10/05/2010. Didn't see an option to go to a previous month.

    I had shut the laptop down after the last attempt at Bitdefender. When I booted it up to look at system restore, CHKDSK did a CRAPload of stuff. It hasn't done that before. Is there a way to get you the log from that and would it help?
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Usually on the calender that comes up on a system restore, you have the option to click forward or backward on the months. Top left corner to go back a month. The restore point of the 5th would not do us any good.

    When CheckDisc ran, did you happen to see any errors ..... bad sectors? That would indicate a problem with the Hard Drive.

    Can you run the getlogs.bat now or is it still not working?
     
  29. jenandlaw

    jenandlaw Private E-2

    I looked again just to make sure, and I really don't see anything anywhere.


    Unfortunately, I wasn't looking when it did it. I had turned it on and turned away and when I looked back all this stuff was scrolling up. Then it just continued booting up and I didn't see if there was a summary or anything.

    See logs attached.
     

    Attached Files:

  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    While I look over your logs, please go to C:\MGTools\analyse.exe and run it. Then attach the HJT log that will be produced.

    Also, tell me what issues still exist.
     
  31. jenandlaw

    jenandlaw Private E-2

    It says "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item." Should I delete and re-download MGTools?

    The popups and "antivirus wallpaper" are gone, so I don't know what other issues I have. I feel antsy because I can't run Malwarebytes and boot in safe mode, but maybe that is unrelated. Maybe I'm giving the trojan too much credit.
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You currently have the Administrator account disabled. I would like you to enable it. Then you can log into that account and see if you can run MBAM.

    First you need to go to start / accessories / right click command prompt and choose run as administrator.

    * Now type the following command:
    net user administrator /active:yes

    Reboot and you will have the choice for the Administrator account. Log in ( you won't need a password thought you should create a password at some point ). Download and install MBAM and see if it will run.
     
  33. jenandlaw

    jenandlaw Private E-2

    That worked! I changed it's name from MB to "Thursday" and ran it. No malicious items detected. Then, I uninstalled it, and reinstalled it and DIDN'T change its name (in case I had done it the wrong way all the other times and this might help). It still ran and still no malicious items. WHOO HOO!

    Should I now go back to the beginning of the READ AND RUN ME procedure in this administrator account?
     
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What I am thinking is that there is some corruption in the other user account. Since you have backed up all the data and files from that account, maybe what you should do is to create a new user account ( with admin. privileges ) and then transfer the data back over to the new account. Then you could delete the old account.

    I am thinking that the old account was compromised by the infection. Which I believe is now taken care of.

    This would be a lot simpler than trying to fix the corrupt account, esp. if you have things backed up.

    ( Do not forget to add a password to the new account as well as the Administrator account ).
     
  35. jenandlaw

    jenandlaw Private E-2

    Is there any chance I could move a hiding infection over to the new account?

    Can I "see" the documents from the old account in the new account? Also, can I perform the Read and Run Me procedures on that external hard drive that I have the data on and the thumb drive I've been using to move back and forth to make sure I don't have it on those?
     
  36. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The infection is gone. And you should be able to use windows explorer to "see" any files / program / data that you want to move to the new user account. If you have problems with that, you can post in the software forum. ( I am not trying to brush you off, just want to make sure you get answers that may come up for you. ) You can be confident that the system is clean now.

    I don't recall what programs you have, but it should be no problem to redownload them. Plus the backups can be re-installed to the new user account without issue.

    I will give you the final cleanup instructions for you to do when you feel confident ( though if you delete the old account, there is no reason to do them other than creating a new system restore point ).

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  37. jenandlaw

    jenandlaw Private E-2

    I know you're not trying to brush me off. ;)

    I'm going to run through the Read and Run Me again under this new account and make sure the external hard drive is hooked up to check to see if IT has it and just to make me feel better.

    Again, you are the absolute BEST!!!!
     
  38. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome. Do scan the backup drive with both SAS and MBAM. Once you are confident that all is well, create the new user account and transfer to that account. Then, let me know if there is a problem. I am mainly concerned about your time deadline for returning the computer. I just want to know that all things are straightened out before you give it back. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds