Malware Problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by MadDogg80, May 2, 2010.

  1. MadDogg80

    MadDogg80 Private E-2

    My computers been getting increasingly slower and has recently been disabling my antivirus sporadically. Over the past few days the computer has been constantly crashing and freezing up while doing nothing more than browsing.

    I've ran all of the steps in the Read and Run me first section and will attach them to this post. The computer seems much better already...hard drive doesn't seem to be working nearly as hard now :). Just want to be sure that the steps in the cleaning procedures have removed all that was there.

    I had some much more serious problems a few months back and received tremendous help here. Since encountering those problems I've been using mainly Firefox with NoScript installed (my wife uses Chrome on occasion). I am aware that McAfee offers terrible protection but I figured I would stick with it until my subscription runs out and then look for another alternative. Once these problems are sorted out though I will definitely be uninstalling McAfee immediately and probably shell out a few dollars to upgrade Malwarebytes and Super Antispyware from their free versions and looking for an effective free firewall :).

    Thanks in advance for any and all assistance...hopefully I am in the clear now.
     

    Attached Files:

  2. MadDogg80

    MadDogg80 Private E-2

    and here is the log for MGtools.

    Note: Just after I submitted that post McAfee blocked and removed an Artemis trojan so it seems there is something still lingering there. At least whatever was shutting McAfee down to allow that stuff through previously is gone now.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Artemis is not a trojan. It is a name McAfee has given to their supposed newer scanning technology. See: http://www.mcafee.com/us/enterprise/products/artemis_technology/index.html

    IMHO: A cause of many false detections and confusion.


    You need to run step 6 of the READ & RUN ME as requested to disable your Disk Emulation software since it is clouding up the logs. Do this now before continuing.

    You have a Master Boot Record infection that McAfee is not telling you about.



    Please download HelpAsst_mebroot_fix.exe by noahdfear and save it to your Desktop
    • Double click HelpAsst_mebroot_fix.exe to run it and follow any prompts.
      • If the tool detects an mbr infection
        • please allow it to run mbr -f and shutdown your computer.
        • Upon restarting, please wait about 5 minutes after bootup, and then click Start>Run and type the following bolded command, then hit Enter.
          • helpasst -mbrt
        • Make sure you leave a space between helpasst and -mbrt
        • When it completes, a log will open.
        • Attach this log to your next message.
      • If the tool DOES NOT detect an mbr infection and completes running:
        • Click Start>Run and type the following bolded command, then hit Enter.
          • mbr -f
        • Make sure you leave a space between mbr and the -f
        • Now, please do the Start>Run>mbr -f command a second time.
        • Now shut down the computer (do not restart, you must shut it down), wait a few minutes then start it back up.
        • Give it about 5 minutes after the bootup and then click Start>Run and type the following bolded command, then hit Enter.
          • helpasst -mbrt
        • Make sure you leave a space between helpasst and -mbrt
        • When it completes, a log will open.
        • Attach this log to your next message.
    No matter what happens with the above, attach the above logs and then immediately continue with the below in normal boot mode!


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. MadDogg80

    MadDogg80 Private E-2

    Thanks for the quick reply!

    I apologize for missing Step 6 in the READ & RUN ME FIRST section. I haven't used that emulation software in a long time and could have swore I had uninstalled it long ago...guess not. I disabled it using the steps outlined and will be uninstalling it once everything is sorted out.

    I ran all the additional steps you gave me and I've attached the 3 log files.

    HelpAsst_mebroot_fix.exe seemed to run fine but it followed the second scenario you outlined in that it completed running. I manually ran mbr -f twice, shut down, and then ran helpasst -mbrt as you instructed.

    While running Avenger McAfee immediately identified a file (falsely) that it created as a ZapChast.gen trojan and deleted it. I had to close Avenger, disable McAfee and then run it again. I hope that didn't mess anything up.

    While running the GetLogs.bat file an error message popped up several times. It was a pop up window titled 16 bit MS-DOS Subsystem and the error message was as follows.

    C:\Windows\System32\cmd.exe
    NTVDM has encountered a System Error
    NTVDM has encountered a System Error c0h Choose 'Close' to terminate the application

    The batch file seemed to hang up and kept repeatedly saying "a process could not be completed because it is in use by another process". I hit ignore on the pop up window and the .bat file resumed what it was doing. The pop up window appeared again shortly after but MGTools continued to run and I waited until it had finished before closing the error window.

    My computer seems to be running somewhat better but there is still more noise than usual coming from the hard drive. The HelpAssistant folder is also still present in C:\Documents and Settings and there is a HelpAsst.backup folder that I just noticed located in C:\

    I was going to just try deleting these folders but I will wait for further instruction.

    Thanks!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your logs, you still have the infection and the procedure did not work properly due to McAfee getting in the way of the removal process. Since McAfee is not detecting or removing the malware, you will have to uninstall McAfee so that we can manually do what it cannot do.

    After you uninstall McAfee, reboot your PC, then repeat the instructions I gave you in message #3 and attach the new logs. We have almost a 100% success rate with this procedure.
     
  6. MadDogg80

    MadDogg80 Private E-2

    I uninstalled McAfee Security Centre, rebooted and ran all of the steps from post #3 again. I have attached the logs. It doesn't seem that it has worked, the help assistant folder is still there under C:\Documents and Settings and the hard drive is chugging along while it is recopying all of my info into it.

    I wish I had dumped McAfee a few months ago when I had my first major infection which it was completely helpless against.....
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay McAfee did not uninstall properly. Also it looks like you may have a few other infections which are complicating the MBR infection removal. Let's first cleanup McAfee.

    Please download and run this: McAfee Consumer Product Removal Tool

    Now please see step 6 of the READ & RUN ME and run it to disable your Disk Emulation Software which is making the rest of the cleanup more difficult. Make sure that you remain in the disabled state until we are finished with malware removal. If you are already disable, you can ignore this, but I need to be sure that you have disable it and you keep it that way.

    Then uninstall My Way Search Assistant

    Now delete the C:\Avenger folder since it is getting very large and making your logs also get to long.


    Now go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v
    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.ca/myway
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.ca/myway
    O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing)
    O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    The above will not finish off the MBR infection but we need to get this out of the way before continuing and I need to be 100% sure that you have no disk emulation software (like Alcohol and Daemon Tools ) running!
     
  8. MadDogg80

    MadDogg80 Private E-2

    I used the MCPR.exe to completely remove McAfee Security Centre and followed all of the new steps you gave me.

    I didn't re-enable the emulation software and ran ran defogger again just to be sure something hadn't re-enabled it. The defogger logs said that everything was already disabled. I attached the defogger log so you can be 100% sure that it is disabled.

    I could not find My Way Search Assistant under Add/Remove Programs. I'm sure that I had removed that program a long time ago.

    I'm not sure if TDSSKiller worked properly. I copied and pasted the bolded command into Start > Run but TDSSKiller seemed to only run for about 2 or 3 seconds and it said it didn't find anything.

    When I ran Hijack This only the first two items you gave me were there. The two items related to McAfee must have been removed when I ran MCPR.exe

    Anyhoo, here are the new logs and thank you so much for all of your help!!:)
     

    Attached Files:

  9. MadDogg80

    MadDogg80 Private E-2

    oops...forgot I said I would attach the defogger log
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks! I just needed to be sure since it could mislead us in interpreting the logs.

    It worked properly and indicates that you do not have a TDSS infection that I was concerned about. Thus the MBR infection is what we have to focus on now.

    I want you to run all of the steps from message # 3 again beginning with the line that says
    Make sure that you even redownload the tool.

    Also it is extremely important that you wait at least the 5 minute interval of time as specified and DO NOT do anything else on the PC while waiting, Try to be very exact in following the instructions.

    If it does not work properly this time, we will have to resort to using your Windows XP boot CD. Do you have one? We need to run the Recovery Console from the CD as the Recovery Console installed using ComboFix will not work properly to remove this infection.
     
  11. MadDogg80

    MadDogg80 Private E-2

    OK, I went thru all of the steps again that you suggested, even redownloaded the tools and made sure to wait more than 5 minutes after powering up following the helpasst_mebrootfix_exe was completed.

    Help Assistant folder is still there :(

    I was under the assumption that I had a Windows Boot disc shipped with my Dell PC. I found the wrapped up CD with the Microsoft logo that is covered in bar codes and tracking numbers and opened it up to find that it is a useless disc for Microsoft Plus!.......I saved every disc that came with the computer and it looks like Dell didn't give me anything....guess I'm screwed or will have to contact them....may be better off just buying a new PC than having to deal with them....

    Here are the logs anyhoo. Thank you for all of your help!

    Note: The forum won't allow me to upload the avenger log (even tried to rename it). It's saying the file has already been uploaded in this thread. Guess that means the results are the same as the previous one?
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  13. MadDogg80

    MadDogg80 Private E-2

    I looked into that link from Dell and it doesn't look like it will work for me. There are only a handful of systems which it says that process is compatible for...sadly the Dimension 8400 isn't one of them.

    I did some searching on the dell community forums but couldn't find anything which seemed relevant to my problem or that I could understand :(
    Any solutions to fix master boot records involves using the Windows recovery disc....I guess it was Dell's policy back then not to include a Windows disc with their systems? They gave me a back up disc for everything but Windows rolleyes
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you borrow a Windows XP boot CD from someone? But do note that fixing the mbr may prevent access the the Dell Restore Utility, which allows you to press a key on startup and revert your computer to a factory delivered state. There are a couple of known fixes for said condition, though the methods are somewhat advanced. If you are unwilling to take such a risk, and you will either need to restore your computer to a factory state or allow your computer to remain having an infected mbr ( and the latter not recommended since it can be very dangerous to your security especially financially ).
     
  15. MadDogg80

    MadDogg80 Private E-2

    Sorry to bump, but there were only a handful of posts above me and I've figured a couple things out (not sure if either will be of help).

    I dug around my computer a bit and found that Dell did not ship physical backup discs for windows but gives the option to burn a Windows OS backup disk one time only. I burned the disc but I'm not sure whether this backs everything up to the factory defaults or whether this backup OS disk will be infected also.

    I also found on the Dell website that my computer has a system restore option. Here is the link that outlines it.

    http://support.dell.com/support/topics/global.aspx/support/dsn/en/document?c=ca&l=en&s=gen&docid=3E48AE3870775D64E040A68F5B2877D4&journalid=85D18542BF2B1968E040AC0A63E97650&Query=&SystemID=&ServiceTag=&contenttype=&os=&component=&lang=&doclang=&toggle=&dl=

    This would wipe everything on my hard drive out though. There are steps for backing up data. I could live with losing most everything and having to reinstall my programs. But if would really like to keep some documents and files. If I were to backup some documents etc. to a CD would they be clean or would I risk reinfection when transferring them back to the computer after the Restore process was complete?

    Thank you so much for all of your help, I really appreciate what all of you guys do here!! Hopefully there is still a chance to be rid of this nasty MBR infection without wiping out my hard drive but if that is the easiest way to go I am prepared to do so :cry
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it would and hopefully it woud rewrite the drive from an image which includes rewriting the MBR. If it does not rewrite the MBR, you would have wasted you time because you would still be infected.

    However do note that it is possible that if the System Restore option you are referring to was going to try restoring from a drive partition on your hard disk, that it may not work at all since the act of attempting to fix the MBR infection could have possibly broken it.

    You can back up all your personal data. This infection is not known to infection your personal data and rarely impacts other files on the system at all.

    Yes there are other possible options like trying to boot to the Recovery Console you installed with ComboFix and then running the fixmbr command. You may or may not be able to even boot to this installed Recovery Console due to this infection, but you can try. You will see the options for it show on your screen shortly after you start your PC. You need to respond by hitting the up/down arrow key (quickly) to choose the Recovery Console and then hit enter. Then you will need to select your Windows installation ( normally # 1 the C:\Windows installation). The when you finally get to the command prompt, which is a black screen with a C:\Windows> prompt, you will have to enter the fixmbr command. You will get a warning about this since you are running a Dell system with a Non-Standard MBR (thans Dell) but fixing the MBR with fixmbr is the only option other than the factory restore.
     
    Last edited: May 9, 2010
  17. MadDogg80

    MadDogg80 Private E-2

    Thank you Chaslang,

    I decided yesterday that I didn't want to risk losing access to the Dell Restore Utility since that is my last line of defense. I was also kind of intrigued at getting a completely fresh start. There were a large number of programs and files on my computer anyways which I haven't used in a very long time, if anything this was a convenient way to clean things up :).

    So I reset the system back to factory delivered state and spent quite a few hours yesterday going thru an almost five year backlog of Windows/Microsoft updates. It was also nice to see the older, leaner version of McAfee again (which served me perfectly up until the new version of McAfee bloatware came out. I removed McAfee and installed new virus protection and firewall software using the handy guide found in the "How to Protect Yourself from Malware" thread. I installed Avira for virus protection but also noticed it is in the list for Spyware as well. Does Avira offer sufficient real-time protection for both? Would using SUPERAntiSpyware as well cause conflicts.

    If you require any more logs to ensure that Dell Restore completely removed the infection let me know. (It seems that it has, computer is running like a dream).

    And thank you again so much for all of your help!!! I can't help but feel like I've wasted your time when this is the way things ended up. I would have definitely attempted the fixmbr command if it wasn't for the chance of losing my PC's last lifeline for this or any future infections (If I get another one on this silly machine I think I may throw it thru the window lol).
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It would be a good idea to download the current version of MGtools and attach a new log just to be sure.

    You're welcome. No it is not a waste of time. We have learned something here. The infection is evolving again. The creators have now learned how we have been removing it and they changed the infection to block our fixes. We will now have to determine what they have modified so that we can adjust things on our end to detect and remove the new forms of infection. If companies like Dell would learn to not make modifications to Windows and would provide proper CD/DVDs with their PCs so that users can repair things without requiring a reinstall, life would be easier for all.
     
  19. MadDogg80

    MadDogg80 Private E-2

    Definitely agree with that one!

    I've run MGTools again and have attached the logs. Hopefully the big bad one is gone now, but I imagine some small things would show up such as the My Way Search Assistant virus which Dell shipped with the PC, I tried removing it from Add/Remove programs but it just shows up again, I seem to remember there being a trick to getting rid of it permanantly.

    Once again Chaslang, I can't thank you enough for all of your help!
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Your MBR infection is gone. ;)

    I don't see MyWay in your install list. I just see a browser main page setting, but do the below anyway.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.ca/myway
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    After clicking Fix, exit HJT.


    Now locate the C:\MGtools\RemMWS.bat file and double click on it.



    Now if you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go to add/remove programs and uninstall HijackThis.
    3. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    4. After doing the above, you should work thru the below link:
     
  21. MadDogg80

    MadDogg80 Private E-2

    Awesome! Thanks again chaslang! Hopefully this is the last time I will ever need to post in this section of the forum ;)
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds