ACME bug survived MG Cleaning Procedures

Discussion in 'Malware Help (A Specialist Will Reply)' started by toddly, Oct 30, 2009.

  1. toddly

    toddly Private E-2

    Hi. I've got a nasty worm that has taken over my executables and totally eluded Major Geeks' cleaning procedures. Any program I open is hijacked by "ACME" and is renamed and re-iconed, so Microsoft Word becomes ACME Word, with a weird skull-like icon. And all the programs that have been hijacked cannot now be run. Consequently, I can no longer go online and have to transfer files via the USB.

    When I plug the USB storage drive from the infected computer into another, the other computer's AVG program identifies corrupted files on the USB storage device as being "Worm/Generic.APN", but I can find no other references to such a worm on the internet.

    This entire episode started after my computer's 'credit card modem' (for hooking into a phone line) died and I bought a new one. My computer said that the card required a particular driver, so I looked online for the driver. It was hard to track down, but I found one --I believe it was called spcolsv-- on a foreign site that my AVG didn't find too sketchy, so I downloaded it. While it did enable me to use the modem card initially, I later learned it also copied some odd programs to my computer, one called setup.exe and another spcolsv.exe. It then began a total takeover, and now I am stuck.

    I have run all the recommended malware removal programs with no luck. Most didn't even find the infection. I have copied all the logs into one folder, and I'm not certain which logs will be the most helpful for me to attach.
    I am running on Win2K, so newer antivirus products are not necessarily compatible.

    Any help anyone can offer would be greatly appreciated.
    Thanks!
    Please let me know which logs I should attach.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the individual logs please. Not the folder.
     
  3. toddly

    toddly Private E-2

    Tim,
    Thanks. I will attach the various log files with this post. Let me know if there are any I missed, as some logs said not to post them unless specifically requested, and some were hard to keep track of on the infected computer. The SuperAntiSpyware log didn't seem to include anything other than the various programs it ran, but I could include that in another post. Also, I don't know whether it makes any difference, but I ran most of the scans in Safe Mode, as the standard mode seemed to mess with the scans. Another thing I may not have mentioned is that the virus prevents me from opening the Task Manager. Thanks again!
    -Toddly
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need the C:\MGLogs.zip.....from running the C:\MGTools.exe

    And MBAM and SAS are way out of date and need to be updated and re-run. New logs for them too.
     
    Last edited by a moderator: Nov 4, 2009
  5. toddly

    toddly Private E-2

    Tim,
    Okay, I downloaded the specified programs again, run them, and enclosed the logs. In running the programs (as I do in safe mode, except SAS), I had some glitches that I thought may be potentially helpful in the machine's diagnosis.

    In running C:\MGTools, I got the message: "The system cannot find file C:\MGTools\ltime.exe" and another for "locate.exe"

    Later I got the notice "The dynamic link library mscoree.dll could not be found in the specified path."

    Malwarebytes came up with the error code: 732 (0,0). Also, I ran the full scan instead of the quick scan.

    When doing a search for the log files, I noticed hundreds of recent DESKTOP_.ini files that I don't believe I've ever had before. Also, the virus file spcolsv.exe is trying to run and apparently connect to the internet via something called maqqhk0ael that continually is trying to access the internet.

    The computer still takes forever to load and will not allow me to run Task Manager or the other programs that have been hijacked.

    When I tried to upload the zipped MG logs, I kept getting the message that I was missing a security token, so the files could not be loaded. So I simply attached the text filelog.

    Thank you very much for your help!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's see if we can manually update by downloading and running this: MBAM_RULES

    If that does not help, see Issue # 8 here: http://www.malwarebytes.org/forums/index.php?showtopic=10138


    download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator


    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif

    Once you've gotten one of them to run then try to immediately run the following.

    Now download and Run exeHelper from Raktor

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    • exeHelper log
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.
     
  7. toddly

    toddly Private E-2

    Tim,
    Okay, I succeeded in getting an updated mbam to run by copying the updated file to a zip drive then running it. It found and removed some viruses, but it did not get it all.
    Next, I tried to run the Rkill programs, and it seems none of them ran properly in safe-mode. When I went out of safe mode, all the Rkill programs were hijacked and corrupted by the virus.
    Still, I ran ExeHelper, but it didn't appear to find or fix anything.

    I actually had to run mbam four times because I ran it twice without the updates taking, and once when I tried using the computer in regular mode, the viruses went berserk again, so I ran the updated mbam again to clear out a few of the viruses that returned. Since then, I have been running everything in safe mode.

    Because I cannot tell which mbam log is which, I will paste the logs from the four scans. I am also including the exeHelper log and MGlogs as you requested. Since you asked for the MGlog, I went ahead and tried to run the program again, but got the following messages:"mscoree.dll not found", "cannot find ltime.exe," "program cannot initiate," and about another hundred "cannot find file" messages for various files it was looking for.
    Although you didn't mention the Rkill logs, I'm enclosing those as well.

    Thanks so much for your help!!
     

    Attached Files:

  8. toddly

    toddly Private E-2

    It turns out that I don't have any Rkill logs to send. But here are the MGlogs and exeHelper log. Thanks!
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It has been a month. Your system has changed in many ways. You have removed Norton and not replaced it. What are you using for an AV program? What other changes have you made that now will not allow MGLogs to produce a complete NewFiles log?

    Do this:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete this file:
    C:\WINNT\is-QKPDU.exe

    I need you to run all the scans again. Please download the latest version of SAS ( you will need to uninstall it first) and update it as well as updating the MBAM definitions. Then download a new version of ComboFix, which will just replace your old version. And then download the latest version of MGTools.exe and let it over write your present version. Run then all and attach the new logs.
     
  10. toddly

    toddly Private E-2

    Tim,
    Just to further clarify the situation with my sick computer, I do not turn it on except to run your fixes and obtain logs. It is so slow when the virus is running that it scares me what the virus night be doing, so I just keep it turned off. The virus corrupted all my internet access ability, so I cannot get on the internet using that computer. So I am forced to use friends' computers to see my email, etc.

    I stopped using Norton a few years back and began using AVG by Grisoft, and ZoneAlarm's firewall. Years after I had removed Norton I learned that its RECYCLER folder had continued growing until it literally took up 95% of my hard disk. So after finding the right solution, I removed it and restored my disk space. My computer was working fine until this virus. Now AVG has been hijacked and will not run, so I have no functioning AV program. Also, I am assuming that it is the virus that is not allowing MGLogs to run properly, or perhaps the limits of the NewFiles Log reflect that my computer has largely lied comatose except for the moments I try to run fixes. But when I watch the program, it appears to not run fully.

    I will attempt to run the programs you have suggested and get back to you after I finish. Thank you again.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I have a few other suggestions for you to download and transfer to this computer.

    Please try doing the below:

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then doube click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running.


    Now download and Run exeHelper

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log.

    I would also like you to try doing this and attaching that log:
    Win32KDiag - How to run
     
  12. toddly

    toddly Private E-2

    Tim,
    Well, it's been a long time, but I haven't given up on reviving my sick computer, and I performed the scans you had asked me to. Most notably, this time I received the following message:
    “System file is infected!! Attempting to restore. C:\WINNT\System32\comres.dll”

    Here's the chronology of fixes you'd asked me to run, and the results:

    Ran AVPFind.bat – It finished running in 8 seconds. Acplog.txt attached.

    Ran exeHelper – It finished running in 4 seconds. ExeHelperlog.txt attached.

    Ran SAS – First ran the Quick Scan. It took 27 minutes, found nothing. Then ran Complete Scan. It took 1 hour and found nothing.

    Ran Win32KDiag – It gave me the message, “WARNING: Could not get backup privileges!” Log attached.

    Feeling like I hadn't accomplished anything, and wanting to find something meaningful after such a long lapse, I decided to run Combofix and Malwarebytes.

    Ran Combofix – Received the message, “WARNING –This machine does not have a recovery console installed!!!” I believe it was later that I received the message “System file is infected!! Attempting to restore. C:\WINNT\System32\comres.dll” Combofix log attached.

    Ran Malwarebytes Quick scan, “No malicious items.” Let me know if you want me to send that log.

    Lastly, because I run all these programs off a flash drive (because the sick computer can't go online), I have found that my friend's computer (that I use to download the programs for the flash drive) detects the ACME bug infection on the flash drive and removes it. It seems the AVG program is able to recognize and remove the virus. So, I copied the AVG setup program on the flash drive and tried to install it on the sick computer in safe mode. I got this message, “Error: Action failed for registry key HKLM\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Windows: creating registry key”

    I hope the logs and messages give you a clue as to what's happening with my computer, and I thank you again for your help and patience.

    Thanks,
    Todd
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's been almost two months, so we need to have a new set of logs from you.

    First do this:

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2


    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      comres.dll
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\SystemLook.txt
    * C:\MGlogs.zip
     
  14. toddly

    toddly Private E-2

    Tim,
    Okay, I ran SystemLook and MGTools. SystemLook could not find the file comres.dll that we were looking for. MGTools gave me two messages:
    "The dynamic link library mscoree.dll could not be found in the specified path," and "The system cannot find the file C:\MGTools\ltime.exe. I looked in the MGTools file in the root directory, and ltime.exe was there, so I don't understand that problem.

    My logs should be up-to-date despite being 2 months old, because the virus killed my ability to go online, and I cannot open any file or program without it getting infected. Consequently, I only turn the computer on to run the programs you suggest, and I only run the computer in safe mode. After running the programs I turn the computer off until I hear back from you. So the system and registry should not have changed. But let me know if you'd like me to get another, fresh log file.

    I'm attaching the two log files from SystemLook and MGTools.

    Thanks again!!
    Todd
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    NOTE: This is just a bug in ComboFix. The comres.dll file is not found in Windows 2000 and ComboFix is falsely saying it is infected just due to the fact that it is missing.
     
  16. toddly

    toddly Private E-2

    Chas,
    Thanks for your input. But if you'd have read thru some of the previous dialog, you'd see that the computer is indeed infected, extremely infected. I cannot run processes such as Task Manager, and every program I run is immediately disabled and has its desktop icon taken over by something called the Acme virus.
    Can anyone tell me what to do about this: "The dynamic link library mfc90u.dll could not be found in the specified path."
    Apparently, many of my dlls cannot be found.
    Thanks.
    Todd
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm just commenting on comres.dll and nothing else. I just did not want anyone wasting time on this since it is a bug in ComboFix. TimW will continue to help you with the rest.

    Some of your problems may not be malware.... like the problem with mfc90u.dll
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your Newfiles log is empty. So I want you to download all the scans ( SAS, MBAM, ComboFix and MGTools.exe --> just drop it on top of the old version ) to a different computer and transfer them to this computer. ( There are instructions on how to update them manually).

    Then attach new logs.

    You can always go to start / run / type:
    sfc /scannow and have your Win2K disc handy. ( Run it at least twice ).
     
  19. toddly

    toddly Private E-2

    Tim,
    I downloaded new versions of MBAM, SAS, Combofix and MGTools, and ran them on my computer is safe mode (because in normal mode, the virus infects any app running). Here were the results:
    1. Ran MBAM full scan, took 41 minutes. FOUR infected objects were found. Log is attached.
    2. Manually updated virus definitions, ran complete scan: "no harmful software was detected."
    3. Ran Combofix: "Access to the specified device, path, or file is denied. 32788R22FWJFW\n.pif" Log is attached.
    4. Ran MGTools. As previously, I got a messages "Cannot find ltime.exe" and "The system cannot execute the specified program. The dynamic link library mscoree.dll could not be found..."

    Some questions:
    1. About 40 applications on the computer have had their icons replaced by the virus icon, should I assume these apps are still infected? Should I delete them?
    2. The virus had initially placed a new app icon on my desktop. It is still there. What should I do with it?
    3. I have not been running the computer in normal mode, only in safe mode. Should I now try running in normal mode to see what happens?
    4. I still have no internet connectivity, WORD, or any of another 20 or so apps that had been infected. Should I remove those programs? How can I do so if the uninstall files are infected and don't work?
    5. Is there some place that might want me to send them one of the infected files so that they could see it and figure how to remove it?
    6. How will I know when all the infected files have been healed or destroyed?

    Tim, thanks again for all your assistance and patience! I have attached the logs below.
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    None of your logs so far are showing any traces of malware, so you should boot into normal mode and run MGTools.exe.

    You have MGTools in the wrong place:
    C:\Documents and Settings\Todd Putnam\Desktop\February\February\MGtools.exe

    Please move it to C:\MGTools.exe ( directly on the root drive....C:\ ) then double click it. Attach the C:\MGLogs.zip
     
  21. toddly

    toddly Private E-2

    Tim,
    I went ahead and deleted all other versions of MGTools in other directories and re-ran MGTools from the root C: drive, and it came up with the same errors, unable to find files or execute programs. So I decided to run analyze.exe (HijackThis) by itself, which did run successfully.

    I have posted both logs below.
    Thanks!
     

    Attached Files:

  22. toddly

    toddly Private E-2

    Tim,
    As per your suggestion to try running the computer in normal mode (as opposed to safe), and then running MGTools, well, I TRIED.

    Apparently, the malware has hijacked the "Super Anti-Spyware" program on the desktop. For the first time in eons, I was successfully able to open the Task Manager, and noticed that SAS had begun running by itself. I waited for ten minutes for it to stop loading (or doing whatever it was doing). It never allowed the icons to appear at the bottom of the screen; and it wouldn't allow me to run any other program or to use the Task Manager to "End Process"; and it would not allow me to turn off the computer. I was forced to do a hard shut down.

    So much for normal mode? This is obviously a really nasty bug. Are you sure you don't want me to send you a copy to study up close?
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Bear with me as it has been a good while since I used W2K.....first use windows explorer to find and delete:
    c:\winnt\isRS-000.tmp
    c:\winnt\wmsoft08735.exe

    As to the file you want to send, please send it to Jotti:
    Click on the following link and use the below steps to scan a file:
    Virustotal
    Click the Browse... button.
    Navigate to the file FileToBeScanned

    • Where FileToBeScanned is the actual file to be scanned. Like

      C:\WINDOWS\System32\vdmt16.sys


    Do you have your W2K disc?

    Please go to start / run / type:
    services.msc
    When that window opens, scroll down to the Windows Management Instrumentation (WMI) service and tell me what it is set to.

    Go to start / run / type:
    sfc /scannow and run it at least twice.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds