Majorproblem

Discussion in 'Malware Help (A Specialist Will Reply)' started by newuser28, Jan 8, 2009.

  1. newuser28

    newuser28 Private E-2

    Hi there and happy new year!
    I've went throu all the steps and I could manege to get only 2 scans and I got 2 attachments for it.
    When I try to run other programs (i've been chenging names) i was getting message "" C:\Programfiles\TrendMicro.........is not valid Win32 application" I realy tried to get working. The virus i got wipe out my Avast4.8 antivuris program.
    To open a brouser it takes 1to 3 min to open.
    When i try to go and check my email at google/gmail i'm getting mesage
    " IE cannot open the Internet site http://mail.google.com/mail/?ui=1.
    Opetation aborted "
    Some place i've seen the message about missing file called " aswRunDll.exe"
    maybe this wiil put some light on the problem.
    Please help
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You attached one of the scans within the MGLogs.zip.....I need you to attach the entire C:\MGLogs.zip.
     
  3. newuser28

    newuser28 Private E-2

    Tim, which program should i use to get this log?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have the logs exactly where I said it was:

    C:\MGLogs.zip
     
  5. newuser28

    newuser28 Private E-2

    Is tit this?
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are not running any anti-virus program....which is probably why you are infected!

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it, but this time make the agreement for running HJT and let the program run until it tells you it is finished! Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  7. newuser28

    newuser28 Private E-2

    Tim,
    I've spent all this time to open and this program, but looks like its a real bad virus.
    When i try to open the zip i'm getting this messages;
    "The Compresed (Zipped ) Folder is invalid or corruped"
    or
    " C:\Documents..........\avenger.zip:Ether multipart or corruped ZIP archive"
    or
    "C:\Documents..........avenger.is not a valid Win32 application".

    With the help of another computer and USB i've downloaded and extracted to my other computer the "avenger" than i just copy and paste on the "sick' computer and i'm getting the message that this program " is not a valid Win32 application".

    What now?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you download ComboFix as instructed? Does it run?

    Can you access the registry or would you prefer not to?

    Those items need to be removed.

    If you have combo on the desktop:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    
    Drivers::
    srosa
    
    Folder::
    C:\Documents and Settings\df\Application Data\m
    
    Registry::
    [=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA\0000]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA\0000\Control]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA\0000]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA\0000\Control]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA\0000]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Get me the log as well as a new MGlogs.zip
     
  9. newuser28

    newuser28 Private E-2

    I yes i do have it and there is the same story, soon as i klock on it i get a message ........not a valid Win32 application.

    With your help i can accces the registry.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK.....first go to start / run / regedit.....now you will expand:
    HKEY_LOCAL_MACHINE

    then expand:
    System

    Next:
    CurrentControlSet

    Next :
    Enum

    Then:
    Root

    Now right click the LEGACY_SROSA and delete it.
    Do the same for: LEGACY_SROSA\0000

    Let me know if you have a problem with this.


    The other approach is to download and install Registrar Lite

    Run Registrar Lite navigate to each of the following keys (one at a time) and take ownership of them (I explained how to do that further down).

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA\0000
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA\0000\Control
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA\0000\Control
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA\0000

    To take ownership of the key do the following:

    * Copy & Paste the registry key from above into the Address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    * Click-on Security in the top Menu
    * Select Take Ownership
    * Repeat these steps for all of the registry keys given above before continue to the next steps below.
    * Now leave RegistrarLite running and continue
    * Now run the fixME.reg REGISTRY PATCH below in this message.
    * Tell me the results. Any error messages?
    * Now in RegistrarLite click View and then Refresh
    * Now navigate one at a time to each of the above keys we took ownership of to make sure they were deleted.
    * If any of the keys still exist, move on down to PART 2 - Setting Permissions for Everyone below!.


    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    PART 2 - Setting Permissions for Everyone

    Run the below if some of the registry keys still exist after running the above steps.

    Now I want you to use Registar Lite again to navigate to each of the below keys (one at a time) by pasting them into the Address Bar and hitting return. But this time click the Security menu item and select Edit Permissions so we can change permissions to everyone ( I describe this down below the list of registry keys).
    After click Edit Permissions , here is what I expect you to see in the Group or user names area of the form:

    Everyone
    SYSTEM

    Select Everyone by clicking on it. Now at the bottom in the Permissions box click the check box for Full Control. The click Apply and then OK to get back to the main Registrar Lite screen. Nowright click on the registry key and select Delete. The click View and Refresh. Check to see if the registry key just deleted truly deleted. If so, move on to the next to work thru the whole list. If it does not delete, I want you to boot into safe mode and repeat these exact same steps to see if we can do it from safe mode.

    Then reboot your PC!
     
  11. newuser28

    newuser28 Private E-2

    Hi Tim,

    Right from the begining I was unable to complete this step:

    Now right click the LEGACY_SROSA and delete it.
    Do the same for: LEGACY_SROSA\0000

    Let me know if you have a problem with this.


    So I moved on to the next step and downloaded *Registrar lite*.
    I followed your procedures step by step, everything went according to your instructions until it was time to make sure the keys were deleted when I navigated them.

    I further followed your instructions to Part 2- Setting Permissions for Everyone below. This went fine until I right clicked on the registry key and an error popped up that read: Access Denied! This occured for all the keys as I tried to right click and delete them.

    Can you please help me as I have tried the steps over at least three times and the same problem seems to cccur. Any help is appreciated.

    Thanks

    Andrew!
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-try doing the Registry patch I gave you.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  13. newuser28

    newuser28 Private E-2

    OK , here it comes,
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you manually remove this folder:
    C:\Documents and Settings\df\Application Data\m

    Have you tried renaming SAS, Combo and Avenger?

    Have you tried running both Combofix and / or Avenger in safe mode?

    Try running this:
    Resetting Registry and File Permissions

    Can you open the MGTools folder and double click the analyse.exe? It will produce a log for you to attach.
     
  15. newuser28

    newuser28 Private E-2

    Tim,
    I've removed " m " file from C:\Documents and Settings\df\Application Data\m

    I've rename all this programs, few times and i got same message ...........not a valid Win32 application.

    Some how i cannot to switch to Safe Mode, i've tried about 10 times, seems like nothing to it but i could not to switch.

    I run the Resetting Registry and File Permissions.
    i run the MGTools, but the log looks like is the old one (16Jan 2009)
    i've deleted this log and run the analyse.exe couple of time and i did not see new log, so i retrieve it from Recycle Bin, i run the program again and it looks like it's the same loge as before.
    So i've att. the loge, can u see any difference.?
     
  16. newuser28

    newuser28 Private E-2

    Forgot the log
     
  17. newuser28

    newuser28 Private E-2

    I can not see the attachment.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What I want you to do is to double click the analyse.exe inside the MGTools folder. It will open, do a scan only...then click save log.....save it to yur desktop. Attach that.
     
  19. newuser28

    newuser28 Private E-2

    ok,here come the log
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Look at what you attached. Do you see a HJT log within the MGLogs.zip? Are you not making the agreement to the license for HJT when you run the tool?

    C:\Documents and Settings\df\Application Data\m --> still exists.

    C:\MGtools\analyse.exe ---> this is what you need to double click and attach the resultant log.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Do you have your xp cd, as we may need to use it to remove items from the recovery console.
     
    Last edited: Jan 19, 2009
  21. newuser28

    newuser28 Private E-2

    As per your instructions:

    I don't know where to look to see HJT log.

    I've deleted again "C:\Documents and Settings\df\Application Data\m"
    Is there a special way to do it, so this file won’t come back again?

    C:\MGtools\analyse.exe i've run this tool few times,
    Program comes on and i can see as this program runs and than disappears,
    but i cannot find the log, it's not there at C:\Mgtools.... is it under different name? like "procdll.txt"?

    I run ATF-Cleaner.exe, i got one message " Cannot remove folder Dc56: The directory is not empty"
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's start by copying the bold text below to notepad. Save it as fixMe.reg to your desktop. Be sure the "Save as" type is set to "all files".

    * Please go to this link:http://live.sysinternals.com/
    * find the psexec.exe file listed in the list and click on it and download and save it to your Desktop. Doing this properly is critical for other steps below.
    * Now click Start, Run, and enter cmd and click OK. This will open a command prompt window with a prompt that shows the current folder you are in.
    * For you the prompt should show C:\Documents and Settings\User>
    * Now type cd Desktop and hit the enter key. There is a space after the cd.
    * If you do this properly, your prompt will change to C:\Documents and Settings\User\Desktop>
    * Type the below bold text and hit the enter key. This will open the Window Registry Editor. You will have to agree to the SysInternals License Agreement first that pops up.
    psexec -s -i regedit
    * In the Registry Editor click File, Import and then navigate to the fixDNSC.reg file on your Desktop from the previous fix and double click on it to import it into your registry. If it works properly you should get a success message.
    * If you get a success message continue on with the below, otherwise stop and explain to me any problems you had.

    Now, download a fresh copy of ComboFix and attach the new log, also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * ComboFix Log
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  23. newuser28

    newuser28 Private E-2

    I got to this point without any problems, and from here I don't understed what u r saying:

    "" Type the below bold text and hit the enter key. This will open the Window Registry Editor. You will have to agree to the SysInternals License Agreement first that pops up.
    psexec -s -i regedit
    * In the Registry Editor click File, Import and then navigate to the fixDNSC.reg file on your Desktop from the previous fix and double click on it to import it into your registry. If it works properly you should get a success message.
    * If you get a success message continue on with the below, otherwise stop and explain to me any problems you had.

    Now, download a fresh copy of ComboFix and attach the new log, also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * ComboFix Log
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!""

    which below bold text??
    what i've done i just copy & paste the above quote "REGEDIT4"
    after that i got the same prompt
    "C:\Documents and Settings\User\Desktop>"
    I can't go any further
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try this again......

    Let's start by copying the bold text below to notepad. Save it as fixDNSC.reg to your desktop. Be sure the "Save as" type is set to "all files".

    * Please go to this link:http://live.sysinternals.com/
    * find the psexec.exe file listed in the list and click on it and download and save it to your Desktop. Doing this properly is critical for other steps below.
    * Now click Start, Run, and enter cmd and click OK. This will open a command prompt window with a prompt that shows the current folder you are in.
    * For you the prompt should show C:\Documents and Settings\User>
    * Now type cd Desktop and hit the enter key. There is a space after the cd.
    * If you do this properly, your prompt will change to C:\Documents and Settings\df\Desktop>
    * Type the below bold text and hit the enter key. This will open the Window Registry Editor. You will have to agree to the SysInternals License Agreement first that pops up.
    * In the Registry Editor click File, Import and then navigate to the fixDNSC.reg file on your Desktop from the previous fix and double click on it to import it into your registry. If it works properly you should get a success message.
    * If you get a success message continue on with the below, otherwise stop and explain to me any problems you had.

    Now, download a fresh copy of ComboFix and attach the new log, also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * ComboFix Log
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  25. newuser28

    newuser28 Private E-2

    Tim,
    Looks like i got everything, except for ComboFix, here i got old message ."..........not a valid Win32 application."
    Please see new log from MGTools.
     

    Attached Files:

  26. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download the updated version from the link below and try running the scan once more. If necessary, rename the file.

    ComboFix.exe
     
    Last edited by a moderator: Jan 23, 2009
  27. newuser28

    newuser28 Private E-2

    I’ve renamed the file to, home.exe ; data.exe ; scan.exe ; ****.exe ; and always i got same message "..........not a valid Win32 application."
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    @Tim and BJ,

    Has anyone tried to remove the below from the infection?????

    Code:
    "C:\WINDOWS\system32\dllcache\"
    register.exe  Jan 18 2009       14848  "register.exe"
    sysinfo.exe   Jan 18 2009       68096  "sysinfo.exe"
    They are part of the problem. You may need to use the Recovery Console or a special boot disk like UBCD4Win or a Linux/Knoppix type disk to get anywhere with this. It seems like commercial programs really just cannot get around to being able to remove Bagle infections. They say they do but none of them really do..... at least not consistently.


    The below files and the SROSA registry keys are all part of the infection:
    Code:
    "C:\Documents and Settings\df\Application Data\m\"
    list.oct      Jan 19 2009        4102  "list.oct"
    data.oct      Jan 19 2009      864256  "data.oct"
    srvlist.oct   Jan 19 2009         631  "srvlist.oct"
    Additional other files may be hidden by the rootkit.
     
  29. newuser28

    newuser28 Private E-2

    No body has tried to remove the below from the infection?????

    ""Code:
    "C:\WINDOWS\system32\dllcache\"
    register.exe Jan 18 2009 14848 "register.exe"
    sysinfo.exe Jan 18 2009 68096 "sysinfo.exe" ""


    Wht is it Recovery Console or a special boot disk like UBCD4Win or a Linux/Knoppix type disk,
    how can i get this ?
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you tried to manually delete these files?


    Description of the Windows XP Recovery Console for advanced users


    See this UBCD4Win

    You still need a your Windows XP boot CD to use the Recovery Console or to create the UBCD4Win. Do you have your CD? TimW asked you this quite awhile ago but I did not see you answer. If you do not have your CD and cannot borrow one that matches your version of Window, you are in trouble amd may have to do a factory restore or you will have to investigate making a CD like this: SystemRescueCd


    It is not in the scope of this forum to provide detail instructions on creating special CDs like this nor how to use them which can be complicated if you are not an expert.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds