Need help with spyware infestation

Discussion in 'Malware Help (A Specialist Will Reply)' started by tovento, Aug 6, 2009.

  1. tovento

    tovento Private E-2

    Hey everyone...have been plowing through a problem on my laptop, and have tried a number of methods with limited success. Yesterday, I became infected with mal/spyware and have been trying to clean it up. It started with "Windows Antivirus Pro" which was manually somewhat cleaned out, but then turned to "System Security" and now "Privacy Center". It seems that each time I defeat one thing, another pops up.
    It seems to have hijacked internet search results as well.
    In addition, it has stopped windows defender from running.

    I have tried to install Malwarebytes on my computer, and it does install and runs, but as soon as I hit scan, it quits and cannot be re-started. I have tried renaming the install program, renaming mbam, etc.
    I then tried to run hijackthis, which also exits and cannot be re-run
    I tried combofix which displays the same behaviour.
    Even my registry scanner/cleaner quits after some time.

    I have tried the above in both regular mode and safe mode (running XP). After trolling around some more I found SDFix, which does run but did nothing to clean up my system.

    The only thing which has successfully run is MGTools. I am attaching my zip file and am hoping that someone can shed some light on this. I believe that if I can get malwarebytes to actually run, it'll clean up my issues.

    Thanks in advance!
     

    Attached Files:

  2. tovento

    tovento Private E-2

    Hey all. A bit of an update since yesterday. I have tried a few more tools and managed to get ccleaner to run. It actually scanned and cleaned the temp files. Here is my situation now:

    I can get into windows and work with no malware, etc popping up. The only error I get on logging in is that my windows defender is unable to run. If I try to run the service manually, it gives me an error that access is denied. Search links in Firefox/IE are still hijacked as well as me not being able to run programs such as Malwarebytes, Hijackthis, or combofix. I mention Firefox and IE specifically, as QTweb doesn't seem to have a hijacking issue (although I didn't use it that often, but it seems to be functioning normally). In the case of Malwarebytes, etc, I can run the program, but it quits. If I use explorer to go to the program's directory, the exe no longer has an icon associated to it (standard windows exe icon now shows). I'm guessing that something is actually affecting the file rather than it simply being blocked from running properly.

    One interesting thing I noticed is that Miranda IM now sometimes shuts down on program launch (it comes up momentarily, and then quits). Re-starting the program gets it to work just fine after that.

    I have attached an updated MGlogs.zip file to get help with this.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We need more than a log from MGtools, you need to attempt ALL steps in our cleaning procedure as noted below. Observe the additional tips/notes which could help.


    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.
    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First. If TDSSserv is not found, just continue on with the READ & RUN ME.
    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  4. tovento

    tovento Private E-2

    Thank you for the reply.

    I had actually ran through the steps earlier, but never really outlined exactly what happened at each step, so I'll put it up here.

    Add/remove programs: nothing on my list which matches the list on your site.
    CCleaner: ran and cleaned up temp internet files, etc. No effect

    Super Antispyware
    Runs, detects a number of trojans in memory and in registry. Once it scans registry for a few seconds, it quits and cannot be re-started. (the program icon changes there on the exe...just standard executible file icon, not the original program icon)

    Malwarebytes
    Installs, runs first time. I click on quick scan, and it gets to about 5 seconds, and then program quits. As above, am unable to restart the program. Exe has lost icon as well. I have tried renaming the setup file, and renaming mbam.exe (each time on fresh install) with no effect.

    Combofix
    I double click the file, I get a small box with a progress bar. Once the progress bar completes, I now have a directory c:\32788R22FWJFW\ with a number of executible files, etc. Nothing further happens.

    Root Repeal
    "Could not read the boot sector. Try adjusting the disk access level in the Options dialogue" is the error I get when trying to run the program. I go into options and change the disk access settings, but always get this error when running a file scan. I did get something out of the program, and the log is attached.

    MGtools
    As stated earlier, this was the only program which seems to have run properly and I attached the log file I previously obtained.

    I have tried these steps in both regular and safe mode with no change in the results. I do NOT have logs for SAS, MB or Combofix, as they do not run to a point where a log file is created. The forum won't let me repost my mglogs file, so please see my earlier post for that file.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What user account are you using to login to this PC? Based on something in your logs it looks like you used the JKratochwil account but this account does not appear to exist properly on this PC. Try using the guest77 or localadmin accounts which both have Administrator priviledges. See if you can run the required scans by logging on with one of these accounts.
     
  6. tovento

    tovento Private E-2

    Thank you for the suggestion, and for looking at this. I typically use the jkratochwil account for every day use, but have logged in using the guest77 account and tried running the scans with no luck.

    My latest update is that I tried UB4Win (Ultimate Bootdisk 4 Windows) to help me out. I ran a SuperAntiSpyware from the boot disk (after updating it), and it sure enough found 1800+ items infected. After a short stint of exe's not working properly after booting into my normal windows, things are working better. I'm not receiving popups all the time, nor am I having 8 copies of services.exe running. I am NOT out of the clear, though as I am still unable to run any scanning software in my native windows.

    I appreciate all the help thus far, but with the fact that I am unable to run anything, I am simply going to live with this until the weekend and wipe my system.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. This is probably the most secure thing to do especially since you found so many infected items. Your system may have been unreliable in the long run if you did not reinstall from scratch. Based on what I had seen in your MGtools logs, you were infected by a new infection going around which is very nasty and difficult to remove. The symptoms you were having with not being able to run any scanners is one of the main symptoms this infection causes. I could see that your C:\WINDOWS\system32\scecli.dll file (a necessary Windows file) was replaced by a fake copy. You also have some hidden RootKits which are also using ADS (Alternate Date Streams) to hide and make difficult to remove.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds