Calling all Wizards-Can get rid of this pest!

Discussion in 'Malware Help (A Specialist Will Reply)' started by flnative, Apr 15, 2010.

  1. flnative

    flnative Private E-2

    I have tried everything per the guidelines and then some. Files are uploaded. Combofix would not dowload/blocked.

    I get the browser redirects from searchs and occasional browser opens. From my initial scans, there is something going on with a DLL in system32/drivers...forgot the driver name but started with an "a".

    Any help would be mucho gracias!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    Did you shutdown 100% of McAfee first as instructed? If not then that was your problem. McAfee will get in the way of legitimate malware removal programs. Even Windows Defender should have been shutdown.


    Please run this: GMER - running with a random name and attach the log from GMER. I suggest that you shutdown McAfee before running it or you will likely have problems.
     
  3. flnative

    flnative Private E-2

    I turned off MCaffee (have since unistalled it); it was saying combofix was a Trogan. All hell broke lose when I initially turned off and tried to download combofix... a vrius severely attacked my system... it took me a while to get superanitspyware to run.. but managed kill this new virus I got when trying to dowload combofix. (bizaare to say the least). All my files would not run after getting rid of the virus. I download some fix regedit file and fixed that problem. So now trying to figure out what to do next.

    I was able to download combofix and will do gmer next... but that program was a bit jittery when launching previously.
     
  4. flnative

    flnative Private E-2

    here is the files.. not sure what I need to do with gmer.. do I run scan or just post the intial start files?

    I see that combofix fixed something.. but I still have the browser redirect problem.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We need to find a backup for one of your drivers that has been infected.


    Please download SystemLook from one of the links below and save it to your Desktop.

    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it. (If you are using Vista, please right-click and select run as
      administartor)
    • A blank Windows shall open with the title "SystemLook v1.0-by Jpshortstuff".
    • Copy and Paste the content of the following codebox into the main textfield under "File":
    Code:
    :filefind
    fasttx2k.sys
     
    
    
    • Please Confirm everything is copied and Pasted as I have provided above
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. You can close this notepad window as the log will already
      be saved as SystemLook.txt on your Desktop ( if you downloaded and ran SystemLook to your Desktop as requested ).
    • Please attach this log in your next reply.
    Note: The scan may take a while from several seconds to a minute or more depending on the number of
    files you have and how fast your computer can perform the task.
     
  6. flnative

    flnative Private E-2

    Here is the file.
    Thanks
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, please rerun GMER just like the previous time.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • the new log from GMER
    • C:\MGlogs.zip
    Are you still having redirection issues?
     
  8. flnative

    flnative Private E-2

    The combofix seemed to have a hiccup when trying to reboot.. was stock on the logging off Windows screen after about 10 minutes I powered off and on.. and it resumed the scan.

    Deleted the files but still have the redirect browser issue.
     

    Attached Files:

  9. flnative

    flnative Private E-2

    I ran again.. this time ran smoother. but still have infection.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First you need to make a copy of your backup of the fasttx2k.sys which is here:

    C:\WINDOWS\OemDir\fasttx2k.sys

    and put the copy so that it is located here c:\fasttx2k.sys

    We need to make sure this is completed properly before we can proceed so I will be asking for a new MGtools log a little further down to verify you have completed this properly.


    Now we also need to create a batch file to run from the Windows Recovery Console ( henceforth just called the RC ) which will make steps

    easier for you when we do get to using the RC.
    • Open notepad
    • Copy the contents of the Code Box below into the notepad window.
    • Click File -> Save As...
    • In the File name: field, type C:\grfix.txt, then click Save.
    • Close notepad
    Code:
    ren c:\windows\system32\drivers\fasttx2k.sys fasttx2k.old
    copy c:\fasttx2k.sys C:\WINDOWS\system32\dllcache\fasttx2k.sys
    copy c:\fasttx2k.sys c:\windows\system32\drivers\fasttx2k.sys
    Now double check the C:\grfix.txt file by double clicking on it and make absolutely sure that it looks exactly like I gave above noting to maintain spacing which is
    why my instructions stated to copy ( typing could lead to mistakes ;) ). If it looks okay, just let me know that you have this grfix.txt file created properly.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use
    right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  11. flnative

    flnative Private E-2

    grfix.txt file looks the same.

    Zip uploaded.
     

    Attached Files:

  12. flnative

    flnative Private E-2

    still have the browser search redirct and occasional browser popup. I also get that nasty XP Defender virus when I have any VP down during these tests. I usally get rid of it with SAS. I guess when I'm away and forget to turn back on the VP software, it dials up a website and downloads it.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It should! We did not run the fix yet. We just created the files needed to perform the fix ;) when we boot into the Recovery Console which comes now.



    Now we will boot into the Windows XP Recovery Console. You should print these to have on hand while offline. Also read thru all of them now to be sure you understand before starting them.
    • Restart your computer.
    • Shortly after restart and way before Windows loads, you will be prompted to choose which Operating System to start. Pay attention it flashes fast and you will only have about 1 or 2 seconds to hit a key!
    • Use the up and down arrow key to select Microsoft Windows Recovery Console that was installed with Combofix and hit enter after selecting.
    • Later you will be asked to enter which Windows installation to log onto. Type 1 and press 'Enter'.
    • At the C:\Windows prompt, type the following bolded entries, and press 'Enter' (note the spaces before each C: ):
    batch C:\grfix.txt C:\grflog.txt

    After the above finished (which will be quick), type in Exit and press enter and your computer shall reboot. Reboot back in to Normal Mode and run Combofix once more.

    Now also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the new c:\combofix.txt log
    • the C:\grflog.txt file
    • C:\MGlogs.zip
     
  14. flnative

    flnative Private E-2

    I get the Blue Screen of Death.. tried 3 times. Can not run the RC. Next steps?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Exactly when?


    Do you have a real Windows XP bootable CD?
     
  16. flnative

    flnative Private E-2

    I get the blue screen after I select the console.. it tries to load, but ends up failing. saying it stopped to protect the computer. Says to run scandisk or may have virus.

    I have the original disc.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then try using it to boot to the Recovery Console. See this: http://support.microsoft.com/kb/307654 and the section titled How to use the Recovery Console

    If you get into the C with the CD, then just complete my instructions.
     
  18. flnative

    flnative Private E-2

    I'm stuck. Blue Screen for normal RC startup. And now, the bootable disk I get an error when it tries to load up. Gives me an error that acpi.sys file is corrupted. It forces me to restart.

    Any other options to get around the RC?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this an original Windows XP boot CD or a copy? And make sure that it is a real Windows XP boot CD not a factory restore CD.


    Other ways which are more difficult:
    • put the hard disk into another PC as a slave drive and manually replace the problem files
    • make another type of boot CD and hope that it will boot. One possibility is the below OTLPE CD
    Creating OTL-PE Environment
    1. Please print out these instructions for reference.
    2. Be aware that the OTLPE.iso file is a large download.
    Step 1

    • Download ISOBurner this will allow you to burn REATOGO-X-PE ISO to a cd and make it bootable.
    • Double-click IsoBurner-Setup.exe to install the program.
    Step 2

    • Download >OTLPE.iso< and save it to your Desktop.
    • NOTE: This file is 292Mb in size so it may take some time to download.
    • Once downloaded, double-click the OTLPE.iso file and ISOBurner will open.
    • Burn the .iso file to a CD. Additional instructions on doing this can be found in the below link:
    Step 3

    • Insert the CD into the drive of the problem computer and reboot.
      • Note: If you do not know how to set your computer to boot from CD follow the steps >here<
    • The computer should now display a REATOGO-X-PE desktop (be patient - this takes a long time to load)
    • Double-click on the OTLPE icon.
    • When asked "Do you wish to load the remote registry", select Yes
    • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
    • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
    • OTL should now start.
     
  20. flnative

    flnative Private E-2

    I have the disk... tried running it but gave me a prompt that says setup did not find any hard disk drives in your computer. I downloaded the driver ( I think it was the right one).. tried again and pressed F6 during disc OS setup to try and install controller driver.. but got another prompt... could not find some .txt file...

    I will try your other method. I guess. Bout to give up.
     
  21. flnative

    flnative Private E-2

    I'm currently booted with the ISO method . I'm tping from iPhone.
    Not sure what to do now. I scanned with Otlpe and nothing to report.
    What to do ?
     
  22. flnative

    flnative Private E-2

    Ever since the ISO install... and trying to save DLLs to my desktop that was going to be used to get the bootable OS disc to load.. (had error could not locate hardrives).. my system will no longer boot up.. Blue Screen. Now I can only run in safe mode.

    So my problem has now gotten worse. I need instructions what to do. What do I do with booting from OTLP ISO.. thanks.
     
  23. flnative

    flnative Private E-2

    Update.... brought my computer to work. Got IT guy to reinstall OS. Seems like the virus is gone... but now the system is very very slow. I cannot download updates from Microsoft... my CPU is at 100%. I just download some fix that MS had for download issues.. but the startup of the computer when windows installs is slow. I could not download IE6 back to IE8, the SP2 is what kept getting hung up on the install process.. 100% CPU kicks in and then nothing will happen, so I end up cancelling the process.

    Is there a quick test to determine, if there is a conflict going on?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry but you will have to continue in the Software Forum now since these are no longer malware issues after you have reinstalled. Your other choice is to go back to the same "IT guy" and have him figure out what he did.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds