The "Permission" Virus Disables my Anti-Virus programs

Discussion in 'Malware Help (A Specialist Will Reply)' started by AndyTran1985, Aug 30, 2009.

  1. AndyTran1985

    AndyTran1985 Private E-2

    I have the virus like this thread here:
    http://forums.majorgeeks.com/showthread.php?t=196003&highlight=antispyware+appropriate+permissions


    -MY OS: is windows vista 32 bit.

    -Cannot post logs:
    I also have a mgtools problem.
    where it displays "32 bit windows os not found"

    *Currently i cannot post up logs without mgtools.


    symptoms:
    1. Every anti virus program i tried running and hijack this it displays that
    "windows cannot access the specified device, path, or file. you may not have the appropriate permissions to run access the item"

    Things I've Tried:
    1. I tried erasing all the new files in system32 that was on the 28th, when i first got the virus.
    2. I emptied my temporary internet files folder.
    3. revealing hidden files
    4. Rootrepeal stalls when i tried using it to follow the thread similar to my problems (above).

    Thank you, any help would be greatly appreciated. :)
     
  2. AndyTran1985

    AndyTran1985 Private E-2

    another symptom is that it denies permission to erase certain folders as well, i tried to erase mgtools folder to reinstall and it denied that.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I also want to know what files are showing in the MGTools ...so open a command prompt again and input this:
    dir C:\MGtools > c:\filelist.txt

    Now go to the MGTools folder and tell me what happens when you try to run SN64.bat
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    • Open a command prompt in Windows and run the below commands
      • cd C:\
      • MGtools.exe
      • capture the output from the command prompt window. Seeing a message like below is normal
        • 32 bit Windows OS found
      • Seeing a message that says 32 bit Windows OS not found is not normal
      Tell me what you get.
     
    Last edited: Aug 30, 2009
  5. AndyTran1985

    AndyTran1985 Private E-2

    still says the same message that it's not found
     
  6. AndyTran1985

    AndyTran1985 Private E-2

    i tried the thing with the sn64, it runs for a brief second and goes away.


    another symptom of my virus is that once i try to use a an antivirus, its folder will have a permission error too. i cant erase it's folder.

    thanks, tim
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure about that? The normal message would be 32 bit Windows OS found

    There is no message that it prints to say 32 bit Windows OS not found.

    It either prints a message for finding 32 bit or 64 bit OS's. It does not print one about them not being found.

    You need to capture the output from the command prompt window to a file or you need to get a snapshot of just that window so that it is legible.
     
  8. AndyTran1985

    AndyTran1985 Private E-2

    oh my goodness.
    it does say windows 32 bit found
    you are absolutely right.
    I don't know if it always said that and i click on the getlogs.bat it also says windows 32 bit found.

    but my problem is still there, the window closes quickly after it opens.


    thanks for the help so far tim.
    i hope this works out.
     
  9. AndyTran1985

    AndyTran1985 Private E-2

    Hi Tim / chas , so what do I do next?

    thanks chas, thanks tim.

    i am still unable to run mgtools.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First let me ask if you are sure you followed the instructions give here: Using MGtools for running MGtools with Vista. If you did not disable UAC and reboot and if you did not right click and Run as Administrator then you are going to have problems.

    If the above is not what the problem is, you need to give us the info from a command prompt window that was requested since what you had already been telling us was incorrect info. Click Start, Run and enter cmd and click OK. This will open a command prompt window. In the command prompt window enter the below commands each followed by a carriage return.

    cd C:\MGtools
    ShowNew.bat

    Copy and paste the output from the command prompt window here so that we can see what happens. You can copy this by right clicking on the top bar of the the command prompt window and use the Edit commands to Mark and then Copy the info. You can save it into a file to attach or you can just paste it into a message here.
     
    Last edited: Sep 1, 2009
  11. AndyTran1985

    AndyTran1985 Private E-2

    hi chas.

    I followed the vista steps for using mgtools when i first used it.
    I dont think the UAC is the problem.


    I tried what you suggested with the cmd prompt.
    cd c:\mgtools and then shownew.bat

    as soon as I hit enter with shownew.bat typed in.
    the cmd prompt window closes immediately
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Open a command prompt window again and enter the below command and hit enter

    calc

    Does the calulator open?

    If yes, type the below command and hit enter

    dir

    Does the above give a directory listing?

    If yes, type the below command and hit enter

    cd C:\MGtools

    Does the prompt in the window change to show C:\MGtools>

    If yes, type the below commands and hit enter (there is a space before and after each > sign):

    set > env.txt
    dir > dir.txt

    If the command prompt window is still open, type the below command, hit enter and tell me what happens:

    sn64.bat


    Also attach the below files if you got to this point:
    C:\MGtools\env.txt
    C:\MGtools\dir.txt


    And no matter what happens with all of the above, see if you run any of the below. Attach logs if they run.


    Running GMER to detect rootkits

    Using ESET's Online Scanner
     
    Last edited: Sep 1, 2009
  13. AndyTran1985

    AndyTran1985 Private E-2

    i tried everything all the way down to the part of sn64.bat and the window closes immediately as soon as a hit enter on sn64.bat.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then attach the below two logs and try running the two procedures given
    C:\MGtools\env.txt
    C:\MGtools\dir.txt
     
  15. AndyTran1985

    AndyTran1985 Private E-2

    attached are the requested items. thank you.
     

    Attached Files:

    • dir.txt
      File size:
      2.8 KB
      Views:
      6
    • env.txt
      File size:
      1.4 KB
      Views:
      7
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to try running those two other scans I requested from GMER and ESET.
     
  17. AndyTran1985

    AndyTran1985 Private E-2

    oh i didnt see that. ok i will try to run those two scans. thanks.
    ill get it done right now
     
  18. AndyTran1985

    AndyTran1985 Private E-2

    followed the gmer scanning guidelines exactly.
    it ran for 10 minutes and detected about 15 infected items in drivers, ect.
    and then all of sudden it shut off after it found something.

    i notice a pattern with all my antivirus and rootkit scanners, that once it finds that one item then it shuts off and then after i try to run the program again it displays the not having permission prompt.

    im going to run the esets scanner next.
     
  19. AndyTran1985

    AndyTran1985 Private E-2

    i ran eset and the permission problem is still there. It found 5 trojans, i attached them to this reply. The 5 it found, wasnt the same ones that was spotted by gmet. is there an online root kit revealer? the virus seems to only disable computer applications, but not online ones.

    what should i do next? thanks.
     

    Attached Files:

  20. AndyTran1985

    AndyTran1985 Private E-2

    and the log.txt
     

    Attached Files:

    • log.txt
      File size:
      2.6 KB
      Views:
      6
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not everything being printed by GMER is necessarily a problem. In fact most of what it prints is typically quite normal.


    Sounds similar to infections plague XP where some system files are infected and are the root cause. You would be the first person with Vista that I have seen with this infection if this is the case. Open Windows Explorer ( Right Click Start and select Explore) and navigate to the below folder and files an right click on them. Select Properties and tell me the exact file sizes in bytes:

    C:\windows\system32\netlogon.dll
    C:\windows\system32\scecli.dll

    These are two of the 3 commonly used in XP for the infection. The 3rd is eventlog.dll but this file does not exist in Vista. The infection could also be using other files in Vista since there are many more new possibilities.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It found 3.;) All things you or someone else downloaded some of which were not a good idea. You need to go thru your PC right now and delete all downloads of cracks and other illegal software. If any of this software was installed, you need to uninstall it.
     
  23. AndyTran1985

    AndyTran1985 Private E-2

    lol. thanks.


    netlogon.dll is 578 KB size and 580 KB size on disk

    scecli.dll is 173 KB size and 176 KB size on disk



    i havent downloaded any cracks or illegal software in months.
    I dont think that could be the problem, do you think so?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I stated, I needed the file size in bytes not KB. Also there is at least one more file we know of on Vista that could be infected, so give me the files size (in bytes) of c:\windows\system32\cngaudit.dll

    In fact, try running the below procedure and attach the requested log:

    Win32KDiag - How to run


    Do you have an intallation DVD for Vista?

    Problems do not always manifest themselves immediately. Sometime it is a slow deterioration. I cannot say that this was your source for sure. When you got infected, what were you doing? What website were you on? Were you downloading anything? Were you trying to open any online videos? Did you install any special codecs?
     
  25. AndyTran1985

    AndyTran1985 Private E-2

    netlogon.dll is 592,384 bytes size
    593,920 bytes size on disk


    scecli.dll 177,152 bytes size
    180,224 bytes size on disk


    i don't have an installation dvd for vista.
    I'm going to run the suggested win32kdiag tonight.


    I go on hulu and surfthechannel a lot to watch shows and surfthechannel, most of the time have popups. I sometimes click on them to exit instead of ctrl alt delete out. So it could actually be any given day. I don't download any movies or music. I haven't downloaded any codecs since 2 years ago.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay. The also tell me the size in bytes of c:\windows\system32\cngaudit.dll

    I only need the size in byes not the bytes size on disk.

    Also please run the below in addition to the Win32kDiag already requested.


    Now we need to scan the system with this special tool.
    • Please download Junction.zip and save it.
    • Unzip it and put junction.exe in the Windows directory (C:\Windows).
    • Go to Start => Run... => Copy and paste the following command in the run box and click OK:
      cmd /c junction -s c:\ >log.txt
      A command window opens starting to scan the system. Wait until a log file opens. Attach this log that is in the Windows folder.
     
  27. AndyTran1985

    AndyTran1985 Private E-2

    The requested win32kdiag log is attached.

    cngaudit.dll is 62,976 bytes


    i will do the junction one now
     

    Attached Files:

  28. AndyTran1985

    AndyTran1985 Private E-2

    uh oh. junction won't run like the others.

    so for only win32kdiag works. ( i attached the log in my previous reply.)
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I can see your problems from the Win32kDiag log, but please try the below.

    • Extract the Junction.exe file from the ZIP file again but this time save it to C:\junction.exe
    • Now try the below which is slightly different than last time.
    • Go to Start => Run... => Copy and paste the following command in the run box and click OK:
      cmd /c C:\junction -s c:\ >log.txt
      A command window opens starting to scan the system. Wait until a log file opens. Attach this log that is in the Windows folder.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First I want you to copy the below file to your root folder.

    C:\Windows\System32\logevent.dll

    If you don't know how to copy the file, just navigate to it and right click on it and select Copy. Then navigate back to your C:\ folder and right click and select Paste. MAKE SURE the file is copied into the root folder before you continue because the fix will not work if the file is not copied there.



    Now download The Avenger by Swandog46, and save it to C:\avenger.zip. You MUST save it here.
    • Extract avenger.exe from the Zip file and also save it to c:\avenger.exe Again you MUST save it there.
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now do the below.

    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    "%userprofile%\desktop\win32kdiag.exe" -f -r



    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  31. AndyTran1985

    AndyTran1985 Private E-2

    great! the window stayed open. It's all black at the moment. 2 minutes have passed and it's still black. ill wait for a bit longer and let you know if anything comes up
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume you are referring to running junction. It can take quite awhile for it to finish scanning since it is going to look thru ALL files and folders on your hard disk. Just wait.
     
  33. AndyTran1985

    AndyTran1985 Private E-2

    i opened up avenger.

    i don't see "input script manually" or a magnifying glass
     
  34. AndyTran1985

    AndyTran1985 Private E-2

    i pasted what avenger looks like.
    i don't see input script manually or Script file to execute.
     

    Attached Files:

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that. I was on an older PC at the time that did not have my updated procedures. The first part of those instructions for Avenger should be like below.




    Now download The Avenger by Swandog46, and save it to C:\avenger.zip. You MUST save it here.
    • Extract avenger.exe from the Zip file and also save it to c:\avenger.exe Again you MUST save it there.
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
     
  36. AndyTran1985

    AndyTran1985 Private E-2

    when putting this in the script box
    "C:\logevent.dll | C:\WINDOWS\system32\cngaudit.dll"

    and pressing execute, it says:

    error: invalid script a vaild script must begin with a command directive
     
  37. AndyTran1985

    AndyTran1985 Private E-2

    nm i forgot to put

    Files to move:




    it worked
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then it should have rebooted your PC. Then you need to continue.
     
  39. AndyTran1985

    AndyTran1985 Private E-2

    thanks for everything so far.
    i'm going to sleep. I will finish up with the rest of the steps.

    and attach the rest of the logs
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not wait. If you don't continue, the infection could respread making it more difficult to fix.
     
  41. AndyTran1985

    AndyTran1985 Private E-2

    oh ok, ill continue
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! Get me the below logs ASAP.

    • Avenger
    • the new win32kdiag log
    • the new MGlogs.zip
     
  43. AndyTran1985

    AndyTran1985 Private E-2

    i have all the logs attached.
    =]
     

    Attached Files:

  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall this Viewpoint Media Player while I look thru your logs.

    Also see if you can run the procedure given with junction a few messages back and get me that log. We may need to fix some permissions in other folders. Also I already see some other malware now that we got the other scans to run.
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also attach this log file:


    C:\Windows\System32\log.txt
     
  46. AndyTran1985

    AndyTran1985 Private E-2

    junction still doesn't run and i erased viewpoint media player.


    it wont let me attach
    C:\Windows\System32\log.txt

    and said error in attach management
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then continue with the below.

    You need to run MSconfig and put your PC into Normal Startup mode as requested in step 4 of the READ & RUN ME.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Sep 19, 2009
  48. AndyTran1985

    AndyTran1985 Private E-2

    i have the requested logs uploaded.
    thanks!
     

    Attached Files:

  49. AndyTran1985

    AndyTran1985 Private E-2

    it said that i already attached avenger.txt and wont let me attach it again.

    i do have mgtools uploaded in previous reply.


    thanks!
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It seems that it never finished running completely to make the new log, but it deleted the what we asked it to.

    Where exactly do you have the junction.exe file located?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds