Gone through read & run me first with no success please help with rootkit

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Anne808, Oct 25, 2009.

  1. Anne808

    Anne808 Private E-2

    Aloha, I downloaded a file 3 days ago & noticed my computer wasn't working correctly after that. Stuff kept on popping up on my computer. I then ran GMER and it started to scan & showed that there was 3 hidden roots on my computer. Shortly after, the scan stopped working & I was not able to remove the roots. I have used GMER several months ago to remove a rootkit successfuly! Now when I try to run GMER it will not run & a popup box states "windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item."

    I have gone through the "READ & RUN ME FIRST Malware Removal Guide."

    CCleaner did not work. A black screen flashed. Then nothing happened, I did wait to see if it would run with no success.

    I basically had the same problem while going through the VISTA cleaning procedure, which was either the flash of a screen or not having the appropriate permissions to access the item. In regards to not having the appropriate permission to access the file, I did try to run as administrator with no luck.

    Also, I had to download the tools for the VISTA cleaning procedure via a seperate computer since that infected computer will not allow me to access those websites, it redirects me to a different website every time I tried to access any antivirus or rootkit removal website.

    I was able to run ComboFix after another attempt and did attach the log. This is the only log I was able to get.

    Please help. Mahalo.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Did you interrupt Combo when it was running? The log is mostly empty.

    Please try doing the below:

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then doube click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running.


    Now download and Run exeHelper

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log.

    Then try running these instructions: Using MGtools


    Attach the below logs when finished with all of the above:

    • C:\avplog.txt - from AVPfind
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools

    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  3. Anne808

    Anne808 Private E-2

    Hello,

    I did not interrupt combo while it was running.

    Computer wouldn't allow me to download AVPFind.bat. I used my other computer to download it & transfer to the infected computer.

    Computer wouldn't allow exeHelper to run, I tried to run it from my thumb drive & was not allowed to. A popup stated I do not have the appropriate permissions. I am logged on as administrator & am still unable to run.

    Computer did not allow superantispyware.com/onlinescan.html to finish, I got all the way to the step right before "Click here to Start" & it stopped working. The screen to click here to start did not come up at all, I waited a long time.

    While running MGtools a popup stated "ProcessDII.exe - Common Language Runtime Debugging Services Process id=0x10ac (4268), Thread id=0x179c (6044). Click OK to terminate the application. Click CANCEL to debug the application." I clicked cancel. Was clicking cancel ok? Then another popup stated "ProcessDII.exe - No debugger found. Registered JIT debugger is not available. An attempt to launch a JIT debugger with the following command resulted in an error code of 0x2 (2). Please check computer settings. cordbg.exe !a 0x10ac. Click on Retry to have the process wait while attaching a debugger manually. Click on Cancel to abort the JIT debug request." I clicked Retry, was that correct?
    MGtools has seemed to be stuck for awhile now. Should I just close it?

    Mahalo
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. Anne808

    Anne808 Private E-2

    Hi,

    Sysprot will not run. I tried to download it and my computer wouldn't let it download. So, I put it onto my computer via my thumb drive & it still would not run.

    Win32Diag would not download also. So I got it on via thumb drive, it still would not run. But, I found directions to "run" it via the "run" program on my computer with some wierd prompt. I hope this helped. The log is attached.

    Please help, I use this computer for work & am getting worried about the functionality of my computer. I really really appreciate all your help!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do the below to make a copy of the good system file into the root folder of your hard disk so that we can use it to fix your problem.

    1. Click on the Start button, then click on Run...
    2. In the empty "Open:" box provided, type cmd and press Enter
      • This will launch a Command Prompt window (looks like DOS).
    3. Copy the entire blue text below to the clipboard by highlighting all of it and pressing Ctrl+C (or after highlighting, right-click and select Copy).
      copy C:\WINDOWS\system32\logevent.dll C:\ /y
    4. In the Command Prompt window, paste the copied text by right-clicking and selecting Paste.
    5. Press Enter.
      • When successfully, you should get this message within the Command Prompt: "1 file(s) copied"
        NOTE: If you didn't get this message, stop and tell me first. Executing The Avenger script below will not work if the file copy was not successful.
    6. Exit the Command Prompt window.

    Now download The Avenger by Swandog46, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now do the following (make sure you redownload the file. Do not use the old copy.):

    • Download this Win32kDiag(If on your desktop - Right click and choose copy / then Open my computer, click on the C drive and in the window paste it there) and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log

    C:\win32kdiag.exe -f -r

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Then attach the below logs:

    • C:\avenger.txt
    • the new log from Win32kDiag
    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
    Last edited: Nov 8, 2009
  7. Anne808

    Anne808 Private E-2

    Hello,

    I was able to do the cmd prompt & the file was copied & I exited the cmd prompt window.

    I then clicked to download avenger to my desktop. It was saving to my desktop, then the zipped file disappeared from my desktop. I do not know what happened & where it went, it was there one second and disappeared the next second. I tried to save avenger in safe mode & regular mode. Please advise on what I should do.

    Thank you so much for your help with this horrible problem on my computer.

    Aloha!
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    See if you can continue on with the instructions. I would like to see the log from running the windiag32 fix ( Win32kDiag.txt on your desktop). I would also like to know what happens when you try to run the MGTools.exe.

    Now you should have C:\logevent.dll .....I want you to drag and drop it on top of the C:\WINDOWS\system32\cngaudit.dll. Tell me if you can do that.

    Did you do a search for Avenger?

    ( I apologize for the delay in responding....health issues. :( )
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds