deepdive wont remove

Discussion in 'Malware Help (A Specialist Will Reply)' started by rstellers, Dec 9, 2008.

  1. rstellers

    rstellers Private E-2

    I followed all of the removal guide and still get one threat that superantispyware cant remove as well as spybot s&d cannot remove deepdive. attached are my logfiles.
     

    Attached Files:

  2. rstellers

    rstellers Private E-2

    thanks so much in advance for your help.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will have to be more specific than that.
    What is the exact file path.....and what is deepdive? There is nothing in your logs that look suspicious.
     
  4. rstellers

    rstellers Private E-2

    this is what SpyBot S&D is finding and cant remove. i tried it in safe mode too and no luck. When it tries to fix it it tells me the associated files are still in usein memory and could be fixed after restart.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now tell me if the issue still exists.
     
  6. rstellers

    rstellers Private E-2

    Ok so i merged that with my redistry and restarted and still get the same error.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please get me a new log from ComboFix.

    But first!! Make a backup of your registry.


    1. Click Start > Run.
    2. Type regedit
    3. Click OK.
    4. Navigate to and delete9if found- the following entries:

      HKEY_CLASSES_ROOT\toolbar.TB\CLSID
      HKEY_CLASSES_ROOT\toolbar.TB.1\CLSID
      HKEY_CLASSES_ROOT\AppID\toolbar.DLL
      HKEY_CLASSES_ROOT\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}
      HKEY_CLASSES_ROOT\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}
      HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}
      HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}
      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}
    5. Exit the Registry Editor.
     
    Last edited: Dec 15, 2008
  8. rstellers

    rstellers Private E-2

    I did find the 4th and 6th registry keys listed above and get the following error when trying to remove them.
    Cannot delete. Error While Deleting.
     
  9. rstellers

    rstellers Private E-2

    Here is a new combofix log even though i couldnt remove the registry keys you told me to.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    
    Registry::
    [-HKEY_CLASSES_ROOT\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
     
  11. rstellers

    rstellers Private E-2

    new logs...
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn't tell me if the issue still persists or not. :(
     
  13. rstellers

    rstellers Private E-2

    haha... sorry about that. yes the problem still exists just as before. i cannot remove the registry keys and spybot cannot remove it either. let me know. thanks for your help on this. this computer was so infected when i started i didnt think it would get clean without format and reinstall. :)
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    aarrgghhh....:(

    Download and Install Registrar Lite.

    Run Registrar Lite navigate to the following keys and take ownership of them (explained further down:

    HKEY_CLASSES_ROOT\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}

    To take ownership of the key do the following:

    * Copy & Paste one registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the regitry key.
    * Click-on Security in the Menu
    * Select Take Ownership
    * Now right click on the registry key and select delete
    * Repeat for both registry keys
    * Tell me the results. Any errors?
     
  15. rstellers

    rstellers Private E-2

    It tells me I did take ownership of both keys but i recieve an "ACCESS DENIED" error on both counts when trying to delete.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then we get more aggressive:

    Run Registrar Lite navigate to each of the following keys (one at a time) and take ownership of them (I explained how to do that further down).

    HKEY_CLASSES_ROOT\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}

    To take ownership of the key do the following:

    * Copy & Paste the registry key from above into the Address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    * Click-on Security in the top Menu
    * Select Take Ownership
    * Repeat these steps for all of the registry keys given above before continue to the next steps below.
    * Now leave RegistrarLite running and continue
    * Now run the fixME.reg REGISTRY PATCH below in this message.
    * Tell me the results. Any error messages?
    * Now in RegistrarLite click View and then Refresh
    * Now navigate one at a time to each of the above keys we took ownership of to make sure they were deleted.
    * If any of the keys still exist, move on down to PART 2 - Setting Permissions for Everyone below!.

    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    PART 2 - Setting Permissions for Everyone

    Run the below if some of the registry keys still exist after running the above steps.

    Now I want you to use Registar Lite again to navigate to each of the below keys (one at a time) by pasting them into the Address Bar and hitting return. But this time click the Security menu item and select Edit Permissions so we can change permissions to everyone ( I describe this down below the list of registry keys).

    HKEY_CLASSES_ROOT\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}

    After click Edit Permissions , here is what I expect you to see in the Group or user names area of the form:

    Everyone
    SYSTEM

    Select Everyone by clicking on it. Now at the bottom in the Permissions box click the check box for Full Control. The click Apply and then OK to get back to the main Registrar Lite screen. Nowright click on the registry key and select Delete. The click View and Refresh. Check to see if the registry key just deleted truly deleted. If so, move on to the next to work thru the whole list. If it does not delete, I want you to boot into safe mode and repeat these exact same steps to see if we can do it from safe mode.

    Then reboot your PC!

    Now see if they still exist.
     
  17. rstellers

    rstellers Private E-2

    So the registry patch says it is successfully added but is still there after refreshing. also when i change permissions to full control i still get "ACCESS DENIED" when trying to manually delete. I get the exact same results when doing this in safe mode. :(
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    AARRRGGGHHH!!! :)

    Please download the OTMoveIt3 by OldTimer.

    • Save it to your desktop.
    • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
    • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
    Code:
    ::Reg
    
    [-HKEY_CLASSES_ROOT\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}]
    
    :Commands
    [emptytemp]
    [Reboot]
    

    • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
    • Click the red Moveit! button.
    • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    • Close OTMoveIt3

    Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now...if that doesn't work we will try this, dang it!!

    Let's start by copying the bold text below to notepad. Save it as fixDNSC.reg to your desktop. Be sure the "Save as" type is set to "all files".

    * Please go to this link:http://live.sysinternals.com/
    * find the psexec.exe file listed in the list and click on it and download and save it to your Desktop. Doing this properly is critical for other steps below.
    * Now click Start, Run, and enter cmd and click OK. This will open a command prompt window with a prompt that shows the current folder you are in.
    * For you the prompt should show C:\Documents and Settings\User>
    * Now type cd Desktop and hit the enter key. There is a space after the cd.
    * If you do this properly, your prompt will change to C:\Documents and Settings\User\Desktop>
    * Type the below bold text and hit the enter key. This will open the Window Registry Editor. You will have to agree to the SysInternals License Agreement first that pops up.
    psexec -s -i regedit
    * In the Registry Editor click File, Import and then navigate to the fixDNSC.reg file on your Desktop from the previous fix and double click on it to import it into your registry. If it works properly you should get a success message.
    * If you get a success message continue on with the below, otherwise stop and explain to me any problems you had.

    Now, download a fresh copy of ComboFix and attach the new log, also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * ComboFix Log
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  20. rstellers

    rstellers Private E-2

    both keys still exist in the registry. here is the log file.:(
    UGHHHHH
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Next fix posted below....?
     
  22. rstellers

    rstellers Private E-2

    oops didnt see your last post. trying that now. thanks!
     
  23. rstellers

    rstellers Private E-2

    both keys still exist in registry. spybot still detects it too. here are logs...
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Hang in there.....I need to consult with Chas on this. :(
     
  25. rstellers

    rstellers Private E-2

    sounds good to me. I am in no rush... appreciate your guys help.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run the below procedure and make sure you reboot where requested:

    Resetting Registry and File Permissions





    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot check to see if the above registry keys have been deleted.

    Now also attach the C:\avenger.txt log
     
  27. rstellers

    rstellers Private E-2

    semi-great news...

    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2 was deleted from my registry.

    I did receive an error on the other registry key however saying "Error: Invalid registry syntax in command: HKEY_CLASSES_ROOT\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} Only registry keys under the HKEY_LOCAL_MACHINE hive are accessible to this program. Skipping Line. (Registry key deletion mode)"

    This happened after reseting registry and file permissions when i ran the script in avenger.exe.

    Log is from avenger is attached. Thanks.
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Did the above key get removed?
     
  29. rstellers

    rstellers Private E-2

    i did receive a success message however the key is still there. we recieved success messages before when using the fixME.reg and with the same results, but that was before resetting reg and file permissions, but same result none the less. :(
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is strange, I'm not sure if there is something still hiding that is locking this or the permissions are just not getting reset. Let's try a few things.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop overwriting and previous files of the same name. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now please run Malwarebytes and first make sure you UPDATE to the current definitions. Then run a full scan and make sure you fix what it finds before saving the log. I will ask for the log later. IMMEDIATELY REBOOT HERE!!!!!!

    After reboot please run SUPERAntiSpyware and first make sure you UPDATE to the current definitions. Then run a full scan and make sure you fix what it finds before saving the log. I will ask for the log later.

    Now download Registry Search (see the link titled RegSearch Download Link)
    • Extract the files from Regsearch.zip into a folder.
    • Doubleclick regsearch.exe to start the program.
    • In the top 3 boxes under the Enter search strings case independen) and click Ok... option, enter the below three strings (use copy and past)
      • 0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2
      • A8954909-1F0F-41A5-A7FA-3B376D69E226
      • 967A494A-6AEC-4555-9CAF-FA6EB00ACF91
    • Then click "OK".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well).
    Now attach the below three logs:
    • new Malwarebytes log
    • new SUPERAntiSpyware log
    • RegSearch.txt log
     
  31. rstellers

    rstellers Private E-2

    sorry about the delayed response. i have been moving and out of town for the holidays. here are the new logs. the fixmereg did say it was successful. I updated and ran malwarebytes and it did find one thing which it could not fix. superantispyware did find several thing despite it being clean last time i ran it. here are the logs.
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Important Notice: A new version of SUPERAntiSpyware is out that should help with this problem from Vundo.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this first log later.
    • Since this infection has been reappearing after a reboot, you will have to reboot again and then run an additional scan to make sure it comes back clean. Attach this second log too.
     
  33. rstellers

    rstellers Private E-2

    I uninstalled the old version and rebooted then reinstalled the new version and rebooted and ran the scan. It found 21 infected items and said it removed them all. upon reboot and a new scan it did remove all of the file infections but did not remove any of registry infections. I removed them again on second scan and rebooted but the entries still exist in registry. logs attached... :(
     

    Attached Files:

  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have asked our friends at SUPERAntiSpyware to check into this.

    In the meantime please do the below.

    Go here and download SysClean:

    http://www.trendmicro.com/download/dcs.asp

    You will need to download two additional files, one for viruses and the other for spyware. Instructions for which ones to download are found here:

    http://www.trendmicro.com/ftp/products/tsc/readme.txt

    After running SysClean, attach the log from it.



    Now run this Running GMER to detect rootkits and attach the GMER log.

    Also please run this Trend Micro RootkitBusterand see if you can get us a log from it too.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds