The "Permission" Virus Disables my Anti-Virus programs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by AndyTran1985, Aug 30, 2009.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please answer the question in my previous post and then also do the below.

    Please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log.


    How are things are working?
     
  2. AndyTran1985

    AndyTran1985 Private E-2

    it found 3 things.
    i attached the screen capture this reply.

    i also attached a screen capture of the "associations" problems to some of my programs like windows media player. I cannot erase certain anti-virus program folders that was affected, it's denying me permission.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let me try this again. I still need an answer to the below question asked a few messages back:

     
  4. AndyTran1985

    AndyTran1985 Private E-2

    oh sorry. i keep forgetting to type about that.

    Junction.exe is in C drive
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure that you have junction.exe there and not just a Folder named Junction???? It must say junction.exe exactly or you do not have the file where requested. According to the last MGlogs.zip file you attached, neither Junction.zip or Junction.exe are in your Windows folder.
     
    Last edited: Sep 25, 2009
  6. AndyTran1985

    AndyTran1985 Private E-2

    i took a screenshot of the root folder, just in case i might be mistaken.
    but it looks like that its there. pls view the attach file.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then right click on it and select Run As Administrator and tell me what happens.
     
  8. AndyTran1985

    AndyTran1985 Private E-2

    it opens up for less than a half a second (i see the black window), and then closes immediately.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then move the junction.exe file into your C:\Windows folder


    Then run the below command like previously run:

    "%userprofile%\desktop\win32kdiag.exe" -f -r


    Then attach the new log from Win32kDiag. We will hold off on running Junction from the Windows folder until I see the output from Win32kDiag
     
  10. AndyTran1985

    AndyTran1985 Private E-2

    i attached the new log here.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you move junctions.exe to your C:\windows folder first?

    Seems you had a bunch more permissions issues that just got fixed.
     
  12. AndyTran1985

    AndyTran1985 Private E-2

    yep, i moved the junction file into windows folder before running win32k
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download and save Inherit to your Windows folder.

    Then from your Windows Explorer window, drag junction.exe ontop of inherit.exe.

    Tell me what happens.
     
  14. AndyTran1985

    AndyTran1985 Private E-2

    wow sorry. i didn't see your newest message.


    When i dragged junction.exe on top of inherit.exe it said "OK"
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please stop posting unnecessary messages. You need read the sticky threads: Don't Bump! It Only Hurts You!!!

    You were just lucky that I happened to notice your two additional posts (one yesterday and one today) which would have had you waiting until about 10/19 or 10/20 for an answer. As stated in the above, we answer threads in queue order and today is the day your thread came up in the queue based on your last message from 10/9. If I did not delete your bumps, you can see that about 5 more days of waiting time would have occurred. As stated in the above, that's how busy we are.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator ) DO NOT attach a log right now. I will ask you to attach one later after we run other scans some of which will be repeats to make sure no reinfection has occurred.


    Please run the below command like previously run:

    "%userprofile%\desktop\win32kdiag.exe" -f -r

    Then attach the new log from Win32kDiag.




    Now we need to reset the permissions altered by the malware on some files.
    • Download and save inhertit.exe to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!
    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    • A command prompt window will open and also a license agreement from SysInternals may appear for Junction.
    • Accept the license agreement if it appears and hopefully the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While FixPerm.bat is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the log from Win32kDiag
    • C:\MGlogs.zip
    Make sure you tell me how things are working now! If you still have problem, make sure you are specific about what they are. For example, earlier you said the below
    This is not specific. You need say exactly what folders.
     
  16. AndyTran1985

    AndyTran1985 Private E-2

    Hi, i just read the bump thread, I'm sorry about that. Thank you for being patient with me.


    i got down to this part and ran into trouble.

    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). "


    I don't have that file in my mgtools folder.
    (i attached the screenshot for you to see.)
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have to complete the instructions in the order written or they will not work. The earlier part of the last message said you need to download and run the current version of MGtools. This was before trying to run FixPerm.bat
     
  18. AndyTran1985

    AndyTran1985 Private E-2

    hi chas,

    yes i went in order of your last message. The first thing i did was download the latest version of mgtools and copied and overwrite the old mgtools in my root folder.

    and went to the item in your order.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But then you must not have run the new MGtools.exe program as requested. If you did, you would see the FixPerm.bat file. Try running the new MGtools.exe file. If you do run it and still don't see the FixPerm.bat file then you did not download the current version of MGtools or you are not running the one you were suppose to download.
     
  20. AndyTran1985

    AndyTran1985 Private E-2

    can you check the link that you gave me. I tried using that link again and started the process over, just in case i missed something the first time, i still dont see fixperm.bat.


    ill go through what i did.

    First thing i did was:
    "Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. "

    ----> i clicked on the mgtools link in your reply and downloaded the newest one and then overwrite the old one in my root folder.
    -----> then i right click on mgtools.exe and ran it as administrator.

    and then followed the next steps, until i was suppose to look inside the mgtools folder to find fixperm.bat, i didn't see fixperm.bat.



    SOMETHING I NOTICED:
    after trying that a few times and it didnt work, i tried to erase the mgtools folder and start from scratch. It said i didnt have permission to that actiondoes being denied to that folder has something to do with the virus and not fixperm.bat not being in the folder?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is nothing wrong with the link. The problem is on your end. It is most likely a permissions issue related to your original infection. Delete all copies of the MGtools.exe file that you currently have on your PC. Then download the below one to your C:\Windows folder (yes we are saving it someplace non-standard). You should then have C:\Windows\MGtools.exe BUT DO NOT RUN IT YET.


    Shut down your protection software ( this includes your antivirus and also Windows Defender).


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Now run the same win32kdiag.exe -f -r fix that you have previously run.


    Now click Start, Run, and enter cmd and click OK. This should open a command prompt window. If the command prompt window enter the below commands each followed by the enter key. There is a space after the cd

    cd C:\Windows
    MGtools.exe

    Does MGtools run? If not, what happens exactly.

    If MGtools runs, attach the new C:\MGlogs.zip file.

    Either way attach the logs from exeHelper and Win32kDiag.
     
  22. AndyTran1985

    AndyTran1985 Private E-2

    The new mgtools.exe in c:\windows does run.
    i uploaded the 3 new logs.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not run win32kdiag.exe -f -r you simply ran win32kdiag.exe. You probably just double clicked on it. You need to run it with the -f -r options to have it fix all the problems found and attach a new log. See how I asked you to run it in msg # 65.
     
  24. AndyTran1985

    AndyTran1985 Private E-2

    here is the updated win32diag.txt, done correctly.
    thanks
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now go back and open the command prompt window again and run the MGtools.exe program that is in the C:\Windows folder like last time. Tell me exactly what happens and how long it takes to run. It did not run properly last time.
     
  26. AndyTran1985

    AndyTran1985 Private E-2

    It opened up normally like any other times that i scanned with it.
    It took about 13 minutes to finish running and finishing. (20 seconds before it started scanning, with a lot of text on the black screen)

    i attached it's scan
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Apparently your C:\MGtools folder has been locked by the malware. Thus when you run the new program, it is not extracting new files (like FixPerm.bat) into the existing C:\MGtools folder which is why you are not seeing that file.

    See if you can download and save the below file into the C:\MGtools folder

    http://forums.majorgeeks.com/chaslang/files/FixPerm.bat

    Let me know what happens. Make sure you actually see it in the C:\MGtools folder. If you don't seem to be able to save it there, see if you can save it to C:\Windows
     
  28. AndyTran1985

    AndyTran1985 Private E-2

    I ran it both in my root folder and c:\windows folder.

    Both times they run and i get a bunch of ok's and i click to continue each time.
    (that signifies that it found items to fix)

    until there were no more ok's, the screen cmd screen is black through the whole time, it runs for about 3 more minutes without ok's and closed by itself.

    I click on permbat to run it again, there were still the same ok's at the beginning and it runs for 3 more min again and close by itself
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But did you try just downloading it to the C:\MGtools folder as requested?

    It will show the same thing everytime it is run. Is there a junclog.txt file in the C:\MGtools folder?
     
  30. AndyTran1985

    AndyTran1985 Private E-2

    No, i didn't just download it into the folders, as requested. i ran them.
    ( I wasn't suppose to run them?)

    yes, there junclog, i've uploaded it to this reply
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually no! But I still need to know if you can download and save it into the C:\MGtools folder as requested.
     
  32. AndyTran1985

    AndyTran1985 Private E-2

    yes i was able to save the file into the c:/mgtools folder
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then do the below.
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop.
    C:\win32kdiag.exe -f -r


    Now repeat the above and attach the log from the second run only.

    Now right click on C:\MGtools\FixPerm.bat and select Run As Administrator.

    After FixPerm.bat finishes, continue with the below.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the new log from the 2nd run of Win32kDiag
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  34. AndyTran1985

    AndyTran1985 Private E-2

    there isnt a win32kdiag in my c: folder, so i ran the one on my desktop
    "%userprofile%\desktop\win32kdiag.exe" -f -r

    it's running run now
     
  35. AndyTran1985

    AndyTran1985 Private E-2

    ok i've uploaded the logs.

    (runpermbat is still behaving before only runs for 5 minutes and the cmd window is blank)
     

    Attached Files:

  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now run MSconfig and put your PC into normal startup mode as requested in step 4 of the READ & RUN ME.

    Uninstall the below software:
    SeekService 1.0 build 129

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O23 - Service: RCGACX - Unknown owner - C:\Users\andy\AppData\Local\Temp\RCGACX.exe (file missing)
    O23 - Service: SeekService Service - Unknown owner - C:\ProgramData\SeekService\seekservice129.exe
    O23 - Service: ThreatFire - Unknown owner - C:\Program Files\ThreatFire\TFService.exe (file missing)
    O23 - Service: TYKOR - Unknown owner - C:\Users\andy\AppData\Local\Temp\TYKOR.exe (file missing)
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    After clicking Fix, exit HJT.

    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  37. AndyTran1985

    AndyTran1985 Private E-2

    I've attached the newest logs to this reply.
     

    Attached Files:

  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not tell me how things are working so I will assume that all is good since your logs are clean. You need to get properly protected ASAP which is included in the below. I strongly suggest that you stop running C:\Program Files\DNA\btdna.exe as it may be the root of your problems. At an absolute minimum, stop running things like this when your PC boots. Only run them when using is and then terminate it immediately, but preferably don't run at all.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  39. AndyTran1985

    AndyTran1985 Private E-2

    Thanks so much chas, my computer seems to be running much better now!
    It's been two months of computer problem horror! I'm very happy that you stuck with me on this for that long and fixed the problems.

    The only problem that remains is the permission problems to certain folders, the two i can recall off the top of my head is gmer.exe on my desktop and runnerscanner.exe that is also on my desktop. I can't erase them. It says i dont have permission to them. (FFF folder in my C drive and SSS in my program files folder could'nt be erased either)


    btw. if i dont purchase the full version of superantispyware and malwarebytes, then they are practically provide no protection?
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Try dragging problem files or folders on top of inherit.exe and then see if you can delete them. Also try deleting in safe boot mode. Let me know what happens. We could make a fix with Avenger or ComboFix if necessary.

    Not practically. They provide no protection unless purchase. The free versions are after the fact scanners.
     
  41. AndyTran1985

    AndyTran1985 Private E-2

    I used "File-Assassin" from malware bytes.
    It deleted it fine.

    Looks like everything is running great!
    I'm going to purchase superantispyware.

    Thanks again!!!
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds