MajorGeeks Support Forums IOBit Software

Go Back   MajorGeeks Support Forums > Majorgeeks.Com - Support Forums > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #81  
Old 02-29-12, 13:36
Larceny82 Larceny82 is offline
Private First Class
 
Join Date: Feb 2012
Location: Boca
Posts: 55
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Possible Failed Rootkit Removal

Oh. My. Word...I can't believe I had a brain-fart last that long. I created another Ubuntu live CD and reinstalled Ubuntu, so now I will have Internet access at will so it won't take me ages to get stuff uploaded to you. *facepalm* Anyway, here are the documents you requested from the scan over a week ago.
Attached Files
File Type: txt aswMBR.txt (2.0 KB, 4 views)
File Type: txt ComboFix.txt (34.3 KB, 7 views)
File Type: txt FSS.txt (3.2 KB, 2 views)
Reply With Quote
  #82  
Old 02-29-12, 13:48
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,143
Thanks: 263
Thanked 1,409 Times in 1,348 Posts
Default Re: Possible Failed Rootkit Removal

Quick question, are you running scans with SAS or MBAM on your own?
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #83  
Old 02-29-12, 14:34
Larceny82 Larceny82 is offline
Private First Class
 
Join Date: Feb 2012
Location: Boca
Posts: 55
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Possible Failed Rootkit Removal

Quote:
Originally Posted by thisisu View Post
Quick question, are you running scans with SAS or MBAM on your own?
The only thing I've run since that was a quick test to see if combo fix would get me connected.
Reply With Quote
  #84  
Old 02-29-12, 15:58
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,143
Thanks: 263
Thanked 1,409 Times in 1,348 Posts
Default Re: Possible Failed Rootkit Removal

Are you using the paid versions of SAS or MBAM?
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #85  
Old 02-29-12, 16:29
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,143
Thanks: 263
Thanked 1,409 Times in 1,348 Posts
Default Re: Possible Failed Rootkit Removal

Quote:
Originally Posted by Larceny82 View Post
In the super antispyware quarantine folder are all the afd.sys and afd registry entries. Is there a way to get them out cleanly?
I may have missed this earlier but you should not be running SAS on your own unless requested to.

Quote:
C:\Users\Larceny\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\SUPERAntiSpyware Scan Log - 02-18-2012 - 15-21-06.log
C:\Users\Larceny\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\SUPERAntiSpyware Scan Log - 02-18-2012 - 16-54-35.log
This may be what keeps quarantining afd.sys and other internet related drivers.

For good measure, please uninstall SAS, MBAM, and Spybot - Search & Destroy and leave them uninstalled for the remainder of malware removal.

Reboot your PC after you have uninstalled all 3 of these.

Now download a NEW ComboFix.exe from here. Place it on your desktop.

Fixing items using ComboFix
Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
Open Notepad and copy/paste the text in the below code box into Notepad:
Code:
KillAll::
ClearJavaCache::
Driver::
SASDIFSV
SASKUTIL
!SASCORE
File::
c:\windows\system32\dds_trash_log.cmd
Folder::
c:\program files\SUPERAntiSpyware
c:\windows\$NtUninstallKB41664$
MIA::
c:\Windows\system32\drivers\afd.sys
c:\Windows\system32\drivers\netbt.sys
c:\Windows\system32\drivers\tcpip.sys
c:\Windows\system32\drivers\tdx.sys
c:\Windows\system32\drivers\nsiproxy.sys
Save this file as CFScript.txt to your desktop. So now you should have both CFScript.txt and ComboFix.exe on your desktop.
Now use your mouse to drag CFScript.txt on top of ComboFix.exe and then release.

This will launch ComboFix.
Note: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Allow ComboFix to update itself if prompted.
When ComboFix finishes, a log will be produced at C:\ComboFix.txt
Attach this log to your next message. (How to attach)

Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
This updates all of the logs inside MGlogs.zip.
When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
Sponsored links
  #86  
Old 02-29-12, 19:19
Larceny82 Larceny82 is offline
Private First Class
 
Join Date: Feb 2012
Location: Boca
Posts: 55
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Possible Failed Rootkit Removal

Copy that. I'm at work now, but with a working edition of Ubuntu, you'll have these shortly after I get home tonight.
Reply With Quote
  #87  
Old 02-29-12, 19:38
Larceny82 Larceny82 is offline
Private First Class
 
Join Date: Feb 2012
Location: Boca
Posts: 55
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Possible Failed Rootkit Removal

Quote:
Originally Posted by thisisu View Post
For good measure, please uninstall SAS, MBAM, and Spybot - Search & Destroy and leave them uninstalled for the remainder of malware removal.
Do you recommend using standard Control Panel Add/Remove Programs? Because I've also used Revo Uninstaller in the past...
Reply With Quote
  #88  
Old 02-29-12, 19:46
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,143
Thanks: 263
Thanked 1,409 Times in 1,348 Posts
Default Re: Possible Failed Rootkit Removal

Quote:
Originally Posted by Larceny82 View Post
Do you recommend using standard Control Panel Add/Remove Programs? Because I've also used Revo Uninstaller in the past...
I typically just use the standard Control Panel for most applications. If I encounter any difficulties then I may use Revo Uninstaller.
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #89  
Old 02-29-12, 20:15
Larceny82 Larceny82 is offline
Private First Class
 
Join Date: Feb 2012
Location: Boca
Posts: 55
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Possible Failed Rootkit Removal

Quote:
Originally Posted by thisisu View Post
I typically just use the standard Control Panel for most applications. If I encounter any difficulties then I may use Revo Uninstaller.
Okay, I'll get those uninstalled and get the new logs up tonight.
Reply With Quote
  #90  
Old 03-01-12, 01:04
Larceny82 Larceny82 is offline
Private First Class
 
Join Date: Feb 2012
Location: Boca
Posts: 55
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Possible Failed Rootkit Removal

Newest Logs, definitely seemed to run smoother. Internet in general seems to be running smoother too.
Attached Files
File Type: zip MGlogs.zip (596.7 KB, 2 views)
File Type: txt ComboFix.txt (16.8 KB, 3 views)
Reply With Quote
Sponsored links
  #91  
Old 03-01-12, 11:54
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,143
Thanks: 263
Thanked 1,409 Times in 1,348 Posts
Default Re: Possible Failed Rootkit Removal

Quote:
Originally Posted by Larceny82 View Post
Newest Logs, definitely seemed to run smoother. Internet in general seems to be running smoother too.
Latest logs are clean.
I guess it was one of those 3 security applications after all.

If you are not having any other malware problems, it is time to do our final steps:
  1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
  2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    • "%userprofile%\Desktop\combofix" /uninstall
      • Notes: The space between the combofix" and the /uninstall, it must be there.
      • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
  3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
  4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
  5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
  6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
  7. Go to add/remove programs and uninstall HijackThis if it present
  8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
    related to MGtools and some other items from our cleaning procedures.
  9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
    • Refer to the cleaning procedures pointed to by step 7 of the READ ME
      for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
    • Then reboot and Enable System Restore to create a new clean Restore Point.
  10. After doing the above, you should work through the below link:
Be safe
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #92  
Old 03-01-12, 13:57
Larceny82 Larceny82 is offline
Private First Class
 
Join Date: Feb 2012
Location: Boca
Posts: 55
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Possible Failed Rootkit Removal

Quote:
Originally Posted by thisisu View Post
Latest logs are clean.
I guess it was one of those 3 security applications after all.
I can't thank you enough and I apologize for all the delays in the process!

Quote:
Originally Posted by thisisu View Post
Be safe!
Yes sir!
Reply With Quote
  #93  
Old 03-01-12, 14:14
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,143
Thanks: 263
Thanked 1,409 Times in 1,348 Posts
Default Re: Possible Failed Rootkit Removal

Quote:
Originally Posted by Larceny82 View Post
I can't thank you enough and I apologize for all the delays in the process!
You're welcome and no problem
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #94  
Old 03-02-12, 03:29
Larceny82 Larceny82 is offline
Private First Class
 
Join Date: Feb 2012
Location: Boca
Posts: 55
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Possible Failed Rootkit Removal

Didn't think I'd be back so soon...so since my last post, I went to work, came home played Portal, slept, played Portal, went to work, booted into Ubunto to watch TV, booted into windows, downloaded and installed Microsoft Security Essentials and a .NET framework as well as Avast!, rebooted and can't log in to Windows completely. As windows loads, the entire thing freezes. Safe mode loads fine however.
Reply With Quote
  #95  
Old 03-02-12, 15:52
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,143
Thanks: 263
Thanked 1,409 Times in 1,348 Posts
Default Re: Possible Failed Rootkit Removal

Hi,

It may be a problem with both MSE and Avast trying to load while in Normal Mode.

You should uninstall both for testing purposes and see if that helps.

By the way, you should only have one Antivirus installed, uninstall the rest. There are more details about why in the Read and Run Me First thread.
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
The Following User Says Thank You to thisisu For This Useful Post:
Larceny82 (03-03-12)
Sponsored links
  #96  
Old 03-03-12, 01:24
Larceny82 Larceny82 is offline
Private First Class
 
Join Date: Feb 2012
Location: Boca
Posts: 55
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Possible Failed Rootkit Removal

You were exactly correct. I loaded safe mode, uninstalled avast and the computer booted right up. Thanks again.!
Reply With Quote
  #97  
Old 03-03-12, 10:32
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,143
Thanks: 263
Thanked 1,409 Times in 1,348 Posts
Default Re: Possible Failed Rootkit Removal

Quote:
Originally Posted by Larceny82 View Post
You were exactly correct. I loaded safe mode, uninstalled avast and the computer booted right up. Thanks again.!
You're welcome.
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
Reply

Tags
malware, read me, rootkit, virus

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Q on Rootkit & Removal iamlee Malware Removal 1 02-09-09 16:08
Failed XP SP2 file removal kelnav Software 7 12-01-08 09:16
Norton detects trojan - removal failed? jjmb Malware Removal 3 02-12-08 12:24
about:blank - all removal methods failed! KateriTyre Malware Removal 7 06-21-04 23:57


All times are GMT -5. The time now is 09:39.


MajorGeeks.Com Home Page
| Admin Tools | All In One | Anti-Spyware | Anti-Virus | Appearance | Backup | Benchmarking | BIOS | Browsers | Covert Ops |
Data Recovery | Diagnostics | Drive Cleaners | Drive Utilities | Drivers | Driver Tools Ergonomics | Firewalls | Games | Game Tweaks | Graphics | Input Devices | Internet Tools | Macintosh | Mail Utilities | Memory | Messaging | Monitoring | Microsoft | Multimedia | Networking | Office Tools | Process Management | Processor | Registry | Security | System Info | Toys | Video | Miscellaneous
|

-->
Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger