Locked out of universities network, still have some bad malware problems, please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by halberdklown, Dec 9, 2009.

  1. halberdklown

    halberdklown Private E-2

    Around a week ago, a friend sent me a link to this site on some anime he always watches named bleachportal.net, he's has been using it for years and so i thought why not i'll check it out. Lo' and behold when i go on the site, its pop up upon pop up and then my computer freezes and turns off. After each subsequent restart it freezes and then im forced to manually shut my laptop off. After noticing my internet was not working anymore i decided to go to the library to use their computer. Checking my email i discovered that the Universities network security center sent me an email, saying my system was infected with some malicious virus and that my internet privileges would be removed until i fixed the issue, they said it could possibly be something called a torpig botnet. so here i am, hoping i can get some answers, did all the steps on the Read Me (have a windows xp laptop, service pack 3) and here are my logs. Finals week was a bust thanks to the hassle of not having a readily available computer, so hopefully i can resolve this to help get things done asap!
     

    Attached Files:

  2. halberdklown

    halberdklown Private E-2

    Re: Locked out of universities network, still have some bad malware problems, please

    here is the last log
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Locked out of universities network, still have some bad malware problems, please

    Hi there and welcome. :)

    We have a file we need to restore afterwards and some remnants of symantec to remove but first we have more pressing matters:

    Please try not to reboot the machine or turn it off whilst we work through the below:

    1. Please go to add/remove programs and uninstall the following software which is out of date and rather useless.

    • Ad-Aware 2007

    2. Tidy up!
    C:\Documents and Settings\Administrator\Desktop

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage.

    You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.


    3. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    File::
    C:\WINDOWS\Temp\$$$dq3e
    C:\WINDOWS\Temp\$67we.$
    C:\Documents and Settings\Administrator\Desktop\livlvhjhvkjckjvboobooo.html
    C:\Documents and Settings\Administrator\Local Settings\temp\STS7.tmp
    C:\Documents and Settings\Administrator\Local Settings\temp\MAR5.tmp
    c:\windows\system32\musowewo.dll
    c:\windows\system32\pefuwiwi.dll
    c:\windows\system32\diwikewo.dll
    
    Folder::
    C:\WINDOWS\Temp\xsw2
    C:\WINDOWS\Temp\PDFC
    c:\documents and settings\All Users\Application Data\Viewpoint
    
    DirLook::
    c:\program files\oiidri
    c:\program files\jcsrly
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "00b2bd65"=-
    pagasadasa"=-
    "CPM03818ef9"=-
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    4. Delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    5. Now run Radix:

    Using Radix To Detect Rootkits

    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix and the log.txt from Radix.

    7. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!

    Thanks
    Kes13!
     
    Last edited: Dec 16, 2009
  4. halberdklown

    halberdklown Private E-2

    Re: Locked out of universities network, still have some bad malware problems, please

    Thank you very much for replying! it seems that my computer may have gotten slightly worse for some reason: for one, when trying to go through all of your steps, i was somewhat able to clear up my desktop, combofix seemed to go smoothly, i was unable to delete any of the files located in either of the TEMP folders you told me to look in, Radix kept freezing in the same location each time: when it was searching for hidden processes. I just stopped after the third try and will provide what got logged down so far. MGtools seemed extra difficult to do this time, after a great amount of times i had to press ignore on all the windows that popped up, it ended up freezing my entire system, after which i was forced to do another manual restart. what i could read from what was being posted, however, seemed to say "the process could not open the file because it is in use by another process", something like that. combofix had me restart while i used it because it detected a rootkit. a more pressing matter: after i followed the procedure to disable my antivirus and all that for the sake of a seamless scan for all the programs i've had to use (mine is Mcafee), it seems that something is blocking me from being able to enable it to start up again, despite that the option "prevent Mcafee services from being disabled" is still checked. I hope something can be done about this :(
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Locked out of universities network, still have some bad malware problems, please

    Explain. What windows popped up?

    Your MGlogs.zip is incomplete so I can see you had some trouble, please refer to this section for any error messages. I cannot verify that the files are wanted dead are indeed desd without seeing complete logs from you.

    Using MGTools (scroll down to error messages)

    So combofix warned you that you have a rootkit? Let's do this and see how your PC behaves:

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    Fcopy::
    C:\WINDOWS\ServicePackFiles\i386\atapi.sys | C:\WINDOWS\system32\drivers\atapi.sys
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "00b2bd65"=-
    pagasadasa"=-
    "CPM03818ef9"=- 
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now let's get rid of Norton completely because having this floating around still whilst you have MCAfee could be causing you even more instability!

    Please give the Norton Removal Tool (SymNRT) a run > reboot your machine and then run it again for good measure.

    Now, after having referred to the error messages section I linked you to above, I would like for you to do the below and hopefully get us some complete MGlogs.zip.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
    Last edited: Dec 14, 2009
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Locked out of universities network, still have some bad malware problems, please

    Are you still with me? You have an MBR infection that we need to fix.
     
  7. halberdklown

    halberdklown Private E-2

    Re: Locked out of universities network, still have some bad malware problems, please

    I apologize for not being able to respond before, but I've been stuck here at my university during our winter break this past week and i've been completely locked out of the Internet, not to mention that for some strange reason, combofix was completely erased from my computer when I did your previous intructions (not the most current ones). That aside, I will be able to come home tomorrow morning, so a response will come your way as soon as I can get Internet back up on it. Would it be safe for me to log into my homes wireless network? Also I noticed last time combofix failed to update itself. I am responding now through my phone, and once again apologize for my lateness

    on a side note I was able to successfully complete your instruction on using the norton removal tool.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Locked out of universities network, still have some bad malware problems, please

    We will have you download the combofix beta tomorrow where I will explain more about that and also come up with a fresh fix for you :)
     
  9. halberdklown

    halberdklown Private E-2

    Re: Locked out of universities network, still have some bad malware problems, please

    thank you for your patience! I've managed to come back and I should be ready to tackle this thing! one question though, would it be safe to connect my laptop to my home network? or would there be too much of a risk to contaminate the other computers we have connected to it as well?
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Locked out of universities network, still have some bad malware problems, please

    Now boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    After running the fixmbr command and boot back to normal mode, continue with the below.

    Now go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Run the new MGTools.exe and attach the C:\Mglogs.zip that it generates as well as the log from combofix.
     
    Last edited: Dec 19, 2009
  11. halberdklown

    halberdklown Private E-2

    Re: Locked out of universities network, still have some bad malware problems, please

    whenever i try to boot into the recovery console, it give me an error message, saying that a problem has been found and windows has been shut down to prevent damage to my computer. then,
    technical information:
    *** STOP: 0x0000007B (0xF78D2524, 0xc0000034, 0x00000000, 0x00000000)
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Locked out of universities network, still have some bad malware problems, please

    Hello again.

    I need to find out exactly how you are trying to boot to the Recovery Console. Sounds like you are trying to boot Windows. Are you using an original CD? Is it actually booting the CD and how far do you get?

    Are you using an installed version of the Recovery Console like from ComboFix? Another method?

    Does this only happen when trying to use the Recovery Console?
    Thanks
    Kes13!
     
  13. halberdklown

    halberdklown Private E-2

    Re: Locked out of universities network, still have some bad malware problems, please

    I am using the recovery console that was installed with combofix, so when my computer starts up, I get a menu that asks if I want to boot into windows or the console, so I do it, the progress bar comes up and after it starts movin a bit it crashes and gives me the aforementioned error message
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Locked out of universities network, still have some bad malware problems, please

    Good morning. Take a look at this thread here:
    Web browsers/ internet work intermittently
    and try what was done in it. The user used the UBCD4win CD.
     
  15. halberdklown

    halberdklown Private E-2

    Re: Locked out of universities network, still have some bad malware problems, please

    i think i may have fixed the mbr problem with rootrepeal (i just scanned, it detected a rootkit and i just rightclicked and selected restore and reboot, when i scanned again it didnt appear). and here is the MGtools log. i did recieve a pop up that came up with this message:
    C:\WINDOWS\system32\cmd.exe
    C:\PROGRA~1\Symantec\S32EVNT1.DLL. an installable virtual device driver failed DLL initialization. choose close to terminate the application
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Locked out of universities network, still have some bad malware problems, please

    No you haven't...the MBR infection is still there sadly.
     
  17. halberdklown

    halberdklown Private E-2

    Re: Locked out of universities network, still have some bad malware problems, please

    darn! hope the mgtools log can provide some good insight into a solution!
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Locked out of universities network, still have some bad malware problems, please

    You need to fix your MBR as we have already pointed out, and because you are having trouble getting into the recovery console I linked you to some other things to try:
    Web browsers/ internet work intermittently


    and try what was done in it. The user used the UBCD4win CD.

    Have you tried any of this yet?
     
  19. halberdklown

    halberdklown Private E-2

    Re: Locked out of universities network, still have some bad malware problems, please

    oh yes, i tried to make the CD but since i dont have an original windows xp cd (it never came with my computer) i decided to try the other options that were suggested in that thread.
     
  20. halberdklown

    halberdklown Private E-2

    Re: Locked out of universities network, still have some bad malware problems, please

    also, i've tried asking around for a copy of windows xp but unfortunately my friends all have vista machines or macs
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Locked out of universities network, still have some bad malware problems, please

    Did you notice the 3rd item listed?
     
  22. halberdklown

    halberdklown Private E-2

    Re: Locked out of universities network, still have some bad malware problems, please

    i managed to create a cd from the procedures for people without a windows xp cd. when i tried opening the recovery console, however, i received this message:
    Setup did not find any hard disk drives installed in your computer.
    make sure any hard disk drives are powered on and properly connected to your comp...etc
    setup cannot continue. to quit Setup, press F3
     
  23. halberdklown

    halberdklown Private E-2

    Re: Locked out of universities network, still have some bad malware problems, please

    Why didn't rootrepeal work? I thought it had the ability to fix the mbr infection, which I was able to detect, seemingly fix, and can no longer detect after subsequent rootrepeal scans
     
  24. halberdklown

    halberdklown Private E-2

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Locked out of universities network, still have some bad malware problems, please

    Then I suggest that you look into making the UBCD4win by borrowing a Windows XP CD from some one and making this CD to see if it will work. If none of these are working then you may have other non-malware issues and may need to reinstall but will have to delete and recreate hard disk partitions to since just doing a format and reinstall will not fix the master boot record.


    You will know when you get the infection fixed by looking for the below files. If they are gone, you have gotten the infection removed. These files will keep returning after a reboot until the MBR infection has been fixed.
    Code:
    "C:\WINDOWS\Temp\"
    $$$dq3e       Dec 14 2009        6789  "$$$dq3e"
    $67we.$       Dec 14 2009       14419  "$67we.$"
    xsw2          Dec 21 2009           4  "xsw2"
     
    Last edited: Dec 25, 2009
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Locked out of universities network, still have some bad malware problems, please

    Quite simply because it cannot. Sorry! That's just the way it is. A better question would be why can't your protection software fix it. They obviously cannot either. In fact the majority of them do not even detect the infection.

    PrevX also had at one time stated they could detect and fix the newer forms of these MBR infections ( see: http://www.prevx.com/blog/120/MBR-rootkit-changes-itself-and-strikes-again.html ) Whether they still can remains to be seen since the infection is constantly changing. But you could look into trying PrevX to see if it helps. You could try their tool: Prevx 3.0 Additional MBR infection info from PrevX was published here:http://www.prevx.com/blog/131/MBR-Rootkit-reloaded.html
     
    Last edited: Dec 25, 2009
  27. halberdklown

    halberdklown Private E-2

    Re: Locked out of universities network, still have some bad malware problems, please

    i ran PrevX and it came back with a "clean system" result. also, i checked "C:\WINDOWS\Temp\" and have included a print screen of what i saw, it appears as though those files have been removed!

    http://farm3.static.flickr.com/2597/4214467890_b05cab7941_b.jpg
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Locked out of universities network, still have some bad malware problems, please

    I suggest that you reboot your PC and attach a new log from MGtools. (download and run the new version). So we can be sure they are gone. Make sure that you do the reboot since this is what would normal trigger their return.


    Also are you still having any problems? If so, what are they?
     
  29. halberdklown

    halberdklown Private E-2

    Re: Locked out of universities network, still have some bad malware problems, please

    here is the new mgtools log
     

    Attached Files:

  30. halberdklown

    halberdklown Private E-2

    Re: Locked out of universities network, still have some bad malware problems, please

    i forgot to put this on my previous post: currently, i dont have the beeping and random freezing of the computer, which is great, but for some reason something seems to be blocking me from enabling the on-access scan of my McAfee Enterprise 8.5.0i, despite the fact that when i checked the console, the option for "prevent McAfee services from getting disabled" was selected.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Locked out of universities network, still have some bad malware problems, please

    Uninstall McAfee and then run the below if possible (not sure if it works on Enterprise version) then reboot no matter what. After reboot, reinstall McAfee and see if it works.

    McAfee Consumer Product Removal Tool


    Your logs are clean but you should uninstall the below:
    NOD32 FiX v2.1 << illegal hack
    Prevx << we are finished with it now and you don't need this service to always be running.


    Also I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds