Really messed up system

Discussion in 'Malware Help (A Specialist Will Reply)' started by mbrecon, May 5, 2008.

  1. mbrecon

    mbrecon Private E-2

    Background:I have a buddies computer that is having serious issues. It started with the explorer.exe restarting every seconds. It is now up and stable, but getting errors and the AntiSpy Spider keeps popping up. I also get errors stating that clbdll.dll is not a valid Windows image. The task manager and the regedit is disabled on every reboot and after the machine is up for some amount of time.

    Steps processed:I'm stepping through the malware removal steps. I'm to the part where you run the SAS and the machine keeps blue screening on me. I has not done it 3times. One time before following you steps (found SAS on another site) and twice following the steps out lined.

    Any clue why I'm getting this. Some quick searches so no occurrence of this before (I could be wrong since I'm new to this forum). I have tried to let the physical dump finish, but it never seems to so I don't know the offending file.

    Please help,
    Frank
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please try the below doing the below.

    Run SuperAntiSpyware

    • In SUPERAntiSpyware under Configuration and Preferences, click the Preferences button.
    • Click the Scanning Control tab.
    • Under Scanner Options uncheck the below two options
      • Use Kernel Direct File Access (recommended)
      • Use Kernel Direct Registry Access (recommended)
    • Then try doing a new full scan and tell me if it still crashes. And if it does still crash, just skip SUPERAntispyware and continue with the other instructions.
     
  3. mbrecon

    mbrecon Private E-2

    Thanks...that seemed to have worked. I feel bad since I seemed to have recognized that same wording from an earlier research effort before I started the step by step process outlined...please forgive me:cry

    I will proceed with the given directive.

    Thanks,
    Frank
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a problem. Just continue and when finished attach all of the requested logs. You have a rootkit problem and possibly some other issues we need to fix.
     
  5. mbrecon

    mbrecon Private E-2

    I'm happy to say the problem reported above is all that I encountered. I ran through the steps and the company is back to normal. No Antispy Spider, regedit and task manager working without having to submit the reg command everytime I wanted to access these programs.

    Thanks for the instructions, they worked great. You might want to just put a note in the instructions about unchecking the boxes if you get a blue screen of death. Might save the post from other people.

    Frank
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It would be a good idea to attach the logs. This infection can hide and not show any symptoms.

    Thanks for reminding me about adding the note to SAS. I meant to do just that but never got around to doing it.
     
  7. mbrecon

    mbrecon Private E-2

    Funny, as I hit send...I thought your reply might be that. Let me pull up the how to and make sure I get everything required.

    Frank
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There should be 4 logs from the READ & RUN ME:
    • SUPERAntiSpyware
    • Malwarebytes
    • ComboFix
    • MGlogs.zip from MGtools
     
  9. mbrecon

    mbrecon Private E-2

    I had to rerun all the test because when the system seemed to have been ok, I deleted everything except what I wanted to protect the system with.

    The good news is that on the rerun, SAS and Spybot came up clean. I have attached everything now (hope I didn't miss something).
     

    Attached Files:

  10. mbrecon

    mbrecon Private E-2

    Here is the SAS log.
     

    Attached Files:

    • SAS.log
      File size:
      659 bytes
      Views:
      2
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are still infected with the rootkit. First you need to disable Spybot's Teatimer as requested in the READ ME or it may get in the way of removal. Do this now before continuing. See: How to disable Spybot's TeaTimer

    Are the below from Programmer's File Editor.
    Code:
    2008-05-05 10:41 . 1999-01-31 10:13 634,943 --a------ C:\WINDOWS\system32\PFE32.EXE
    2008-05-05 10:38 . 2008-05-05 10:39 <DIR> d-------- C:\Temp\PFE32
    Do you know what the below are for? The last two folders are quite suspicious.
    Code:
    2008-04-27 18:17 . 2008-04-27 18:17 57,546 --a------ C:\WINDOWS\promogif3.gif
    2008-04-27 18:17 . 2008-04-27 18:17 24,351 --a------ C:\WINDOWS\promogif1.gif
    2008-04-27 18:17 . 2008-04-27 18:17 24,066 --a------ C:\WINDOWS\promogif2.gif
    2008-04-27 18:05 . 2008-04-27 18:05 <DIR> d-------- C:\Temp\zvebs14
    2008-04-27 18:05 . 2008-04-27 18:05 <DIR> d-------- C:\Temp\kvebs14

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {60024A7B-A180-4BEE-A8BA-89EFD5BF0150} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  12. mbrecon

    mbrecon Private E-2

    Sorry, I guess on the second install, I forgot the part about the TeaTimer..even though it is bold and red. Break out the wet noodle.

    I will run through your guidelines and try to pay attention. Thanks much.

    Frank
     
  13. mbrecon

    mbrecon Private E-2

    Yes, the PFE is Program File Editor. I installed it when I started on working on my friends system. I like having a better editor with line counting and such. Do you think it is infected? The folder in temp is where I unzipped it and I normally put in system32, so I can just hit it from the Run line.


    I do not know what the files are from 4/27. One of the directories has a binary logfile called zvKarru.log. When I Google it, it shows up limited, but is around the end of April and are post regarding malware. This is about the time he had issues. Should I outright delete them?

    Messenger and Viewpoint deleted (need to itemize or I will miss something again) ;)

    ComboFix ran. Do you need a logfile?

    Question on the last step:
    You say to create a *.reg file with the bolded text.

     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No I don't. I just wanted to make sure you knew what it was. Anything that is in the system32 folder that is not a Microsoft file should always be questioned.


    Yes!

    My previous fix got prematurely chopped off. Here is the rest of what I need you to do.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    The previous ComboFix log showed it the below, some of which are valid files but some were from the rootkit.

    Teatimer will get in the way of removal steps. And it can be a resource hog on some systems. Windows Messenger is an old outdated program that is no longer in use and Microsoft even removed it from Windows around the SP2 time frame. It is a frequent cause of random popups.
     
  15. mbrecon

    mbrecon Private E-2

    The "weird" directories in C:\Temp have been deleted.

    FixMe.reg ran fine and I got a successful message.

    Ran CCleaner. You didn't mention anything about a log here, but I attached it anyway.

    Ran GetLogs.bat and attached as requested.

    I think I got everything you asked. Please let me know if I missed anything.

    Frank
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because we don't need them for anything. ;)

    Yes! Based on your log it appears that you did not remove Windows Messenger or you removed it after getting the logs.

    Now that the rootkit is gone a couple other items showed up that need to be fixed.

    Delete the below file ( only delete it nothing else )
    C:\WINDOWS\system32\clbcfg.dat


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop (yes overwrite the previous file). Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.



    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  17. mbrecon

    mbrecon Private E-2

    I was going for extra credit on the CCleaner.log since I have missed so many other things :cool

    C:\WINDOWS\system32\clbcfg.dat...deleted.

    FixMe.reg, ran fine with a successful message.

    Revisited Windows Messenger issue. I ran the exe, but only disabled it, didn't uninstall..RTFS I guess.rolleyes

    Ran GetLogs.bat...see attachment.


    Frank
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    :D

    Okay the logs are clean but I just noticed an issue that you may want to fix. Apparently someone uninstall Microsoft .NET Framework 2 and it did not cleanup a service. The below can be seen in the HJT log.

    O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)

    You can fix this by doing the below:
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to ASP.NET State Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteaspnet_state into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.

    Then if you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  19. mbrecon

    mbrecon Private E-2

    Wonder what did that? There was a Windows update that had issues installing when I first got based the explorer.exe restarting every 5 seconds. Maybe it only to to the part of un-installing and never finished...weird. The ASP.NET service was already stopped and set to manual, but I changed it to disabled.

    Deleted aspnet_state and machine rebooted successfully.

    CF and MGTools are gone.

    Restore point refreshed.
    Question: When I first started working on the system, my first thought was just to restore, but it was not turned off. That is when my journey started. Can or have virus/malwares started doing tricky things like shutting that function off as part of the infection?

    I really appreciate all the help.

    Frank
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are referring to the service, it was doing nothing since the related update was not installed. You can get it from Microsoft Update if you wish to have the current version.

    Yes it can and does sometimes do this.

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds