HELP. Malware/Rootkits keeping me from running any security software

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by REM414, Dec 31, 2010.

  1. REM414

    REM414 Private E-2

    All,
    I've run into one tough bit of Malware. It began when Avast (I have the free version) popped up saying there was a security issue. Once it did pop up it disabled Avast, both the resident piece and the executable file. After that, the waring came up that the computer was infected and I needed to click yes to fix it. This was obviously the "fake" AV at work. I then tried to run Malwarebytes (MBAM) and it began to run then disappeared. It cause the exe file to become unusable (saying it couldn't be found or that I don't have the security rights) I tried to rename the MBAM exe file as a random name and as winlogin. Neither worked. I also tried pulling the MBAM directory from another machine, same problem.

    After this I tried running every other AV - Anti-malware program I could think of, and each of them did the same (you name it I tried it). I tried to run Housecall (thinking an online program might work) Housecall began to run, then stopped. It then caused my internet explorer to get the same "locked out" status. I still have google chrome, but that's because I didn't try and download or run anything from there.

    I then gave HiJack a go, so I could post a log file here in the forums. It ate that as well. It began to run, stopped, now the program gives an error when I try to run the exe file again. I have looked at all of the load and run processes in the registry (only one looked strange, and I deleted it) the processes that are running are all OK, but there are a few svchost entries that I'm sure contains my issue. I tried running process explorer, to see if I could get any deeper into what is running. It didn't even start, and locked the exe file.

    I have done all of this starting in normal XP, and all of it also in safe mode. No luck at all. I tackled a bunch of these on different machines, including the one that just won't let you run exe files at all. This is a first for me. Any help at all would be greatly appreciated.
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator


    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.

    Now download and Run exeHelper from Raktor
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Now run this: Using Malwarebytes Anti-Malware

    Now run this: Using MGtools

    Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans
    • exeHelper log
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.

    NOTE:
    • If you have problems downloading on the problem PC, download the tools and the manual updates for Malwarebytes onto another PC and then burn to a CD. Then copy them to the problem PC. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. REM414

    REM414 Private E-2

    Hello Dr, thanks for you response. Here are the logs that I could provide. Malwarebytes wont run no matter if I run RKill or not, this malware has it (and other common AV/Malware programs) pegged. As a side note, I did run TDSSKiller as requested by the folks at malwarebytes. I deleted the hidden service it found, but it doesn't seem to go away after reboot. As he said, this is a "BAD guy". Thanks for you help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you already have a thread in progress at Malwarebytes ( here: http://forums.malwarebytes.org/index.php?showtopic=71601&st=0&p=368270&#entry368270 ) you really need to finish working with them. It is a waste of precious resources and can cause problems when you work in multiple forums at the same time and thus this is frowned upon.

    I will give you a tip to mentioned to LDTate who is helping you and you can reference this thread to him. The below is seen in your logs and the root cause of it is why you have this problem:

    \\.\globalroot\Device\svchost.exe\svchost.exe
     
  5. REM414

    REM414 Private E-2

    OK, that makes sense. I just though there might be differing approaches (and there seemed to be) I used TDSSKiller and tried to delete the locked nasty service per LDTate's instructions and it just doesn't go away. I'll work with LDTate to see this through. Sorry for causing any duplication of effort, I do appreciate the help.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes because of what I mentioned. It is in your MGlogs.zip file and this was also in the DDS.txt log that you attached for them.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds