Infected with Cidox-E Rootkit

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by BlackJaguar, Feb 9, 2015.

  1. BlackJaguar

    BlackJaguar Private E-2

    Avast detects a Cidox-E rootkit but unable to remove it. I am also experiencing Internet Explorer redirect problems.

    I did the READ & RUN ME FIRST. However, I could not get MGTools to run from the C drive or the Desktop. Its telling me its not a valid Win32 application.

    Attached are the resulting logs requested...
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please try running MGTools in safe mode.
     
  3. BlackJaguar

    BlackJaguar Private E-2

    I tried running MGtools in safe mode and I am still getting MGtools.exe is not a valid Win32 application message.


    Thank you so much for your time!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now please download OTL by OldTimer.
    • Save it to your desktop.
    • Double-click on the OTL icon on your desktopto run it. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the [​IMG] text-field.
      Code:
      activex
      netsvcs
      drives
      
    • Now click the [​IMG] button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
     
  5. BlackJaguar

    BlackJaguar Private E-2

    Here is the report generated for the OTL by OldTimer.

    See OTL.txt Attachment...

    Thank you!
     

    Attached Files:

    • OTL.Txt
      File size:
      210.8 KB
      Views:
      4
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm very sorry. I've had a very hectic 24 hours. Reviewing the log now!
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman Pro and have it remove everything under the heading Potential Unwanted Programs.

    Now rerun Malware Bytes and have it fix anything it may find, attach log so I can see what was removed.

    Re run TDSSKiller (just a scan!) and attach log.

    Now see if you can run MGTools. If NOT then re run OTL same as before and attach log.
     
  8. BlackJaguar

    BlackJaguar Private E-2

    Attached are the logs generated by the scans you instructed me to run. I tried running MGTools but I'm still getting MGTools.exe is not a valid Win32 application message...

    Thanks again for all your help!
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hitman is *still* showing Potentially Unwanted Programs, look at the latest log you attached. That is all that needs to be fixed. (Under heading PUP's) It should deal with these items as your trial has not expired...

    Once done, rescan again with Hitman and attach the new log please.
     
  10. BlackJaguar

    BlackJaguar Private E-2

    I ran Hitman Pro but when I tried to delete the items found its asking me to register or activate a free trial. Its not allowing me to delete the items found.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ok, no problem, we'll try another way. :)

    Uninstall Ask Toolbar if you see it.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Delete these if you can see them:

    C:\Program Files\Ask.com
    C:\ProgramData\Anti-phishing Domain Advisor
    C:\ProgramData\PC Optimizer Pro
    C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
    C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar
    C:\Windows\Tasks\PC Optimizer Pro startups.job


    Reboot the machine and now rescan with Hitman and attach log please. :)
     
  12. BlackJaguar

    BlackJaguar Private E-2

    I uninstalled Ask Toolbar. I was successful in merging the fixMe.reg file. I was able to delete 4 of the 6 items requested.

    Could not see these 2:

    C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
    C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar

    I rebooted and rescanned with HitmanPro and when I tried to delete the items found its asking me to register or activate a free trial. Its not allowing me to delete the items found. :confused

    Thanks again and enjoy your long weekend...
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I understand the trial has expired, I just wanted you to do a rescan with it , attach log, so I can see what remains. ;) Thanks
     
  14. BlackJaguar

    BlackJaguar Private E-2

    I am so sorry...:-o I apologize for having a geriatric moment. I found the log in HitmanPro under the History heading with all the previous logs.:)

    Attached is the HitmanPro log from scan date 2015-2-13

    Thanks for your understanding and I really appreciate your help...
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall Google Chrome using Revo Uninstaller.
    Also uninstall Google Update Helper and any Google Toolbars....



    We need to run an OTL Fix

    • Right-click OTL.exe to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :files
    C:\Windows\Tasks\PC Optimizer Pro startups.job 
    
    :reg
    [-HKLM\SOFTWARE\Classes\AppID\escort.DLL]
    [-HKLM\SOFTWARE\Classes\AppID\escortApp.DLL]
    [-HKLM\SOFTWARE\Classes\AppID\escortEng.DLL]
    [-HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL]
    [-HKLM\SOFTWARE\Classes\AppID\esrv.EXE]
    [-HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}]
    [-HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}]
    [-HKLM\SOFTWARE\Classes\AppID\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}]
    [-HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}]
    [-HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}]
    [-HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}]
    [-HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}]
    [-HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}]
    [-HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
    [-HKU\S-1-5-21-4088145618-3139878618-2258819890-1000\Software\Local AppWizard-Generated Applications\PCOptimizerPro]
    [-HKU\S-1-5-21-4088145618-3139878618-2258819890-1000\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}]
    [-HKU\S-1-5-21-4088145618-3139878618-2258819890-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [-HKU\S-1-5-21-4088145618-3139878618-2258819890-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [-HKU\S-1-5-21-4088145618-3139878618-2258819890-1000\Software\PC Optimizer Pro]
      
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.





    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Now reinstall Google Chrome and rescan with Hitman again so I can see what remains. Attach log.
     
  16. BlackJaguar

    BlackJaguar Private E-2

    I could not see Google Update Helper to uninstall.

    Attached are the requested logs.

    Thanks!!!
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Follow the instructions here to reset your host file, then rescan with Hitman again and attach log.
     
  18. BlackJaguar

    BlackJaguar Private E-2

    I ran Microsoft Fix it to reset the host file...

    Attached is the latest HitmanPro log.


    Thanks again!
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent. How are things running at this point? :)
     
  20. BlackJaguar

    BlackJaguar Private E-2

    I upgraded to Internet Explorer 9. I have no problems using the browser. However, when I double click on any item on the desktop i.e. browsers,files or folders there are not opening. I have to click multiple times or rignt click and open.

    The desktop loads very slowly...:(

    Thanks!
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would say that's something to ask about in the software forum. :)

    However first try this: (It takes a LONG time to run so go off and do something else for a while as it does.)

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    After reboot, let me know the situation...
     
  22. BlackJaguar

    BlackJaguar Private E-2

    I ran Windows Repair and everything seems to be working fine.

    Thanks so much for all your help...I really appreciate you!!! ;)
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent! Ready for final steps? If so here they are...

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  24. BlackJaguar

    BlackJaguar Private E-2

    I followed the final steps...I currently have Malwarebytes Anti Malware and Avast Free Antivirus. :cool


    Thanks for everything!!! :wave
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are very welcome. :) Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds