Infected Computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sailor63, Nov 17, 2009.

  1. Sailor63

    Sailor63 Private E-2

    Hello,
    Thanks in adavnce for your help. I have used your malware removal before and it worked like a charm, this time however it came back and I do not know what else to do...:(

    I am sorry I do not remember what brought this about but in the end I found that the computer was infected by
    "File Name: C:\WINDOWS\system32\drivers\ndis.sys"
    "Threat Name: Trojan horse Rootkit-Agent.Dl"

    I ran in order everything I could from this forum and I am attaching the logs. I thought it was removed because of ComboFix finding and removing it. But about an hour later I get another notice from AVG that it is still there.

    The computer has been removed from the internet and network. All other computers on network have been inspected and found to be virus free.

    I will try and answer any question to the best of my ability. Sorry for not remembering everything.

    Again thanks in advance for all your help

    Chip
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the ComboFix log.

    It appears as though you did not allow MGTools to run to completion. Please run it again and this time make the agreement to run HJT and let the scans run until it tells you it is finished. Then attach the new log.
     
  3. Sailor63

    Sailor63 Private E-2

    Thank You TimW, I could not find the orignal Combofix log so I ran a new one for you. When I run ComboFix is reboots my computer each time. The MGTools starts out with "c:\MGTools\swreg.exe is not a valid Win32 Application" like a 100 times, the Dos Box says Access is Denied. And it seems to complete as I get the zip file. Hope this helps.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please try the appropriate fix. Also remove these from your trusted zone:
    Then use windows explorer to find and delete:
    C:\WINDOWS\Tasks\cdiV9R 1236255302.job

    Now see if you can't run and then attach a new MGLogs.zip
     
  5. Sailor63

    Sailor63 Private E-2

    Thanks for the continued support.
    I downloaded the fix form XP pro and extracted to system32 folder. I deleted the cdiv9r 1236255302.job file. However I can not find any of the trusted zones files you want me to remove. I looked in IE>Tools>Internet Options>Security>Trusted sites Nothing in there, or in Local intranet. Looked in Firefox can not find anything. Searched the C drive to include hidden folders nothing. Seached in Reg Edit and only found //about.htm and //exclude but did not delete in reg edit. Looked in windows firewall. Could not find it in Spybot S&D, googled how to remove trusted zones. I am at a loss on this one.:cry

    I tried running MG again and got the same errors. Please let me know where those file are to remove. Combolog does not tell me where they are. Sorry


    Happy Thanksgiving
    Chip
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try this:

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The red is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.

    If it still does not run properly:
    Please download this MGbeta.zip file to the C:\MGtools folder. Then extract the two files from it overwriting the current GetRunKey.bat and ShowNew.bat programs you have. Then double click on the GetLogs.bat file in the C:\MGtools folder. When it finishes running, attach the new C:\MGlogs.zip file.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This will not help! The reason MGtools is not running properly is because the full executable was not downloaded. See the ComboFix log which shows the below
    Code:
    2009-11-18 13:34 . 2009-11-13 13:30 518626 ----a-w- C:\MGtools.exe
    The program should be redownloaded from this link MGtoolsand overwrite the previous bad download and then run it. The current version of MGtools.exe is 2,385,076 bytes in size.
     
  8. Sailor63

    Sailor63 Private E-2

    I tried TimW first and recieved error "C:\MGTools\swreg.exe is not a valid Win32 application about 100 times. Ran the shownew did not recieve any errors log is below mgtoolsnewfiles.txt.
    I then did chaslang suggestion and it also ran with no errors log is attached mglogsgood.zip.

    Again Thank you very much for the help and Happy late Thanksgiving.

    Chip
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. Are you still having any malware issues?
     
  10. Sailor63

    Sailor63 Private E-2

    I believe so. I removed AVG antivirus (which told me about the virus) and installed Comodo, it will not update. Plus the windows firewall shows as On in the Security Center window but if I go to the windows firewall window the Off box is checked. Comodo says that "The network firewall is not functioning properly!". I go to Comodo system status and click on run diagnostics it says nothing is wrong. Any ideas? Nevermind on the Firewall figured it out. Still can not update though.
     
  11. Sailor63

    Sailor63 Private E-2

    Not updating is a problem on my end I believe. If I find any more malware I will post in this thread? Forgot to tell you that I scanned with Comodo and it found nothing.

    Thanks for all your help
    Chip
     
  12. Sailor63

    Sailor63 Private E-2

    Well I got Comodo to update and I scaned again and it found a virus in the same file.
    Location: C:\WINDOWS\system32\drivers\ndis.sys
    Malware Name: Virus.Win32.Protector.B@82810198
    Action: Detect
    Status: Success

    It will also pop up a message saying it found the same Virus...

    :cry
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach the log from Combo and re-run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Attach the new C:|MGLogs.zip.

    Now stop bumping your thread or you will never get a reply.
     
  14. Sailor63

    Sailor63 Private E-2

    I think I will reformat the drive, this is taken to much time from you and me. BTW your bump comment is not warranted I answered your question it just took 3 replies. I never bumbed and waited longer for a reply. Again thank you for your help and time it is greatly appreciated. Happy Holidays

    Chip
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    My frustration was just that....you posted two messages on the 3rd. That was ok as it was in reply to mine. The one on the 4th, although it was understandable in that you were giving additional info, pushed you again back to the end of the line.

    If you still want to continue this without doing a reformat, I am willing to continue to try to help you. But I understand if you do not.

    The file being found by Comodo could be a false positive as the ndis.sys file is a legit system file. Without it you probably couldnt boot.. It could be corrupted, which is why I asked for the new logs.
     
  16. Sailor63

    Sailor63 Private E-2

    Thank you for the response and your contiuned support but I am still going to reformat, it is just easier. You more than I have wasted enough time on this little bugger that I also believe is a false postive. Again thank you for your time, it is and has always been appreciated.:):wave
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. :)
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below comment may be too late if you have already formatted.
    Yes it is a system file but it is infected which you can observe in the newfiles.txt log by the size. The file just needed to be replaced from a backup which also can be seen in the log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds