Internet Security 2011 for Windows XP

Discussion in 'Malware Help (A Specialist Will Reply)' started by adown, Feb 16, 2011.

  1. adown

    adown Private E-2

    I have a laptop that has "Internet Security 2011 for Windows XP"

    I have run Avast as a boot scan and caught nothing.
    Spybot S&D crashed when run and will not run now as it says it is a read-only file, even though SpypotS&D.exe is not even in the install folder!

    Have run through the checklist with the following results:

    Tried to install & run SAS. it crashed.
    Ran SAS Portable - this crashed during registry scan - so moved on
    MB crashed during quick scan
    COMBOFix crashed
    Attached RRlog.txt
    Succesfully ran MGTools. Log attached.

    Any advice greatly appreciated, this is a real stinker!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now see if you can run the other scans.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. adown

    adown Private E-2

    Firstly, thanks for your speedy response.

    So....

    (during all this, the original Malware is still running and trying to block stuff)

    Ran the script - log attached
    ran CCleaner
    Ran SAS Portable - got to the same point and crashed - did find one threat "system.BrokenFileAssociation"
    Then crashed
    Ran MB - crashed
    Ran GetLogs - log attached

    The malware is also giving periodic alerts about remote host attacks from an ip address.
    It also claims to have found 4 trojans in iexplore.exe and url.dll

    Not sure what to do now...
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please Disable Spybot's TeaTimer --> Should have been done as per the R&R instructions!

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Please download GMER and save it to your desktop:
    • Unzip (extract) it to your desktop.
    • Disconnect from Internet and close all running programs.
    • There is a small chance this application may crash your computer so save any work you have open.
    • Double-click gmer.exe to run it.
    • Let the gmer.sys driver to load if asked.
    • If it gives you a warning at program start about rootkit activity and asks if you want to run a scan... click NO.
    • Click the Rootkit tab.
    • Make sure all the boxes on the right of the screen are checked, EXCEPT for "Show All".
    • Then click the Scan button. Wait for the scan to finish.
    • Once done, click the Copy button.
    • This will copy the results to the clipboard. Open Notepad and press CTRL + V to paste the log, and save it to your desktop. Attach this log to your next reply.
    NOTE: If you're having problems with running gmer.exe, try it in Safe Mode. This tool works in Safe Mode whereas many other rootkit revealers do not.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip
     
  5. adown

    adown Private E-2

    Hi there,

    To my knowledge Teatimer was not running.
    In fact, both Spybot and Teatimer have become read-only files that I cannot unlock or delete and they will not run!

    Ran avenger - log attached
    Restarted as part of avenger, malware still running.

    Ran GMER - log attached

    Ran get logs - log attached
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message
     
  7. adown

    adown Private E-2

    Ran TDSS - no threats found - log attached
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try it again.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip
     
  9. adown

    adown Private E-2

    Registry entry was succesful
    Ran avenger script, got this:
    "Error: Invalid syntax in command:
    "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vbma7f5c"
    Skipping line (registry value deletion mode)."

    Clicked OK

    Got same with all entries, clicked OK, allowed reboot.

    Upon reboot, machine stops at windows logo whilst loading bar continues to move, never seems to make it to login. Tried rebooting but get same problem. Then, bluescreen! rebooted again then tried safe mode and it booted.

    Log attached.

    Ran CCleaner.
    Ran GetLogs - log attached


    Gonna get to bed now, will attack this further tomorrow hopefully.
    Thanks for all your help so far.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


    This infection is known to be a backdoor trojan.
    • This may allow hackers to remotely control your computer, steal critical system information and download and execute files.
    If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please go to a different known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.



    Please read these for more information:

    How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
    When Should I Format, How Should I Reinstall



    Bring up Device Manager by right clicking My Computer and selecting Properties. Then click the Hardware tab and then select Device Manager.

    Look under System Devices section, do you see something like [cmz vmkd] or [cmz vmkd] Virtual Bus

    If you find a match to what I said to look for then right click on it and select Disable ( not select Delete at this time )

    Then reboot your PC. After reboot, continue with the below.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :reg
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vbma7f5c]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vbma7f5c\Enum]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vbma7f5c]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vbma7f5c\Enum]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\vbma7f5c]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

    Rename Combofix to cf454.com and try and run it again.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
    Last edited: Feb 16, 2011
  11. adown

    adown Private E-2

    Ok...

    Disabled device

    Ran avenger - log attached

    Ran OTD - log attached

    Ran Combofix - This got further than previously but froze at the attached image. It stayed like this for over an hour and froze the rest of the machine. Had to force a reboot.

    Ran getlogs - log attached
     

    Attached Files:

  12. adown

    adown Private E-2

    I should also point out that the device I previously disabled is no longer disabled in device manager. Not sure when this happened, probably reboot?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable it again in device manager. While you are there, is there anything that looks like: vbma7f5c

    If so, also disable it. Tell me what you find and if on a reboot they are still disabled.
     
  14. adown

    adown Private E-2

    Ok, so disabled it again, could not see anything as you describe.
    Restarted and it was still disabled.

    As usual, a dialog box comes up saying "Your computer is making unauthorized copies of your system and Internet files. You should immediately run full scanning on your system to prevent unauthorised access to your data.
    click YES to run Antivirus scanner right now."

    I usually click NO but it still runs. This time I just left the dialog box open and carried on with the procedure.

    Ran avenger script - log attached
    After restart it didn't make it to Windows and eventually restarted itself again. When it reached Windows the device was still disabled.

    Ran OTM -log attached

    Tried to run combofix but to no avail again. Had to force reboot.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OTM states it did fix what we wanted it to. But I am doubtful, so please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  16. adown

    adown Private E-2

    Attached.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We are making progress.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):




    Code:
    :Processes
    explorer.exe
    
    :Services
    vbma7f5c
    :Files
    C:\Documents and Settings\All Users\Application Data\.wtav
    C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    C:\WINDOWS\system32\drivers\vbma7f5c.sys
    C:\WINDOWS\Temp\{E9C1E0AC-C9B1-4c85-94DE-9C1518918D01}.tlb
    C:\Documents and Settings\Administrator\Local Settings\Temp\svldj.tmp
    :Commands
    [purity]
    [ResetHosts]
    [createrestorepoint]
    [emptytemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * OTM Log
    * C:\MGlogs.zip
     
  18. adown

    adown Private E-2

    OTM log attached
    Rebooted after running OTM and went to check whether item was still disabled.
    Got this error:
    "C:\Windows\system32\rundll32.exe Application not found."

    Getlogs attached.
     

    Attached Files:

  19. adown

    adown Private E-2

    Just got home from work and booted the laptop ready for the next round:

    Noticed Avast wasn't running, tried to run avast.exe and a dialog pops up asking what program I want to use to open it! This seems to happen with all .exe files.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the avplog.txt file that is will hopefully be created on your Desktop as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post)

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator


    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif


    * Double-click on the Rkill desktop icon to run the tool.
    * If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    * A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    * If not, delete the file, then download and use the one provided in Link 2.
    * If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    * Do not reboot until instructed.

    If you are having problems running Rkill, you can download iExplore.exe or eXplorer.exe, which are renamed copies of Rkill.com, and try them instead.

    * If the tool does not run from any of the links provided, please let me know.
    Once you've gotten one of them to run then try to immediately run the following.

    Now download and Run exeHelper from Raktor

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Your logs are not showing HJT. Are you making the agreement to run it?

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * exeHelper log
    * C:\MGlogs.zip
     
  21. adown

    adown Private E-2

    AVPlog attached

    rkill.scr worked

    exehelper attached

    I don't remember when I was asked about HJT but I'm sure I agreed to it.

    Getlogs attached
     

    Attached Files:

  22. adown

    adown Private E-2

    Should've mentioned, exe files now work.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is the device still disabled? We are going to give it one more shot, and if we still can't resolve this, I have asked Chaslang to intervene.




    Code:
    :Processes
    explorer.exe
    
    :Services
    vbma7f5c
    
    :Files
    C:\WINDOWS\system32\drivers\vbma7f5c.sys  
    C:\WINDOWS\Temp\{E9C1E0AC-C9B1-4c85-94DE-9C1518918D01}.tlb
    C:\Documents and Settings\All Users\Application Data\.wtav
    :Commands
    [purity]
    [ResetHosts]
    [createrestorepoint]
    [emptytemp]
    [start explorer]
    [Reboot]

    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    Now immediately open Device Manager and see if you can't delete [cmz vmkd] or [cmz vmkd] Virtual Bus.

    Now go to C:\MGTools\analyse.exe and run it.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * HJT log
    * OTM Log
    * C:\MGlogs.zip
     
  24. adown

    adown Private E-2

    just a quick one, where will the HJT log be?
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It will open on your desktop. There will be a button to save a log. ;) It's what analyse.exe is....renamed HJT.
     
  26. adown

    adown Private E-2

    After running OTM it asked for reboot and I allowed.

    Now back to the same problem of exe not opening, inlcluding the system dialog box to access hardware manager
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Curious. Re-run exeHelper.
     
  28. adown

    adown Private E-2

    OTM log attached for what it's worth
     

    Attached Files:

  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That wasn't the log. It was the script. See if you can't find the current log.
     
  30. adown

    adown Private E-2

    Ran exehelper again - log attached - fixed the exe problem

    Uninstalled item in Device Manager

    Tried to run analyse.exe but got:
    "Windows cannot acess the specified device, path or file. You may not have appropriate permissions to access the item."

    Getlogs attached

    OTM attached (hopefully!)
     

    Attached Files:

  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Something I am missing is recreating those files. Have patience and let's see what Chaslang has to add to this. He should be on later today.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try a few other steps. Some of this will be may be a little redundant, but I want collect info to really see the full current status.

    Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot. You can just close this log for now you will attach it later.


    Now please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
    Now also please re run TDSSkiller. I want to see a current log to make sure nothing has changed since the last run.


    Also, please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1



    Download Mirror #2
    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :regfind
      vbma7f5c
      :service
      vbma7f5c
      :filefind
      vbma7f5c.sys
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. You can just close this notepad window since the log is already saved on your Desktop. Be patient! It may look like it is not doing anything, but it takes awhile for this to scan thru your whole system look for matches.
    • Please attach the SystemLook.txt log found on your Desktop to next reply.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • the log from MBRcheck
    • the log from TDSSkiller
    • the log from SystemLook
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  33. adown

    adown Private E-2

    Firstly, thanks for stepping in and helping out, greatly appreciated.

    Secondly, here's ya logs!
     

    Attached Files:

  34. adown

    adown Private E-2

    and one more...
     

    Attached Files:

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Looking pretty good now! How are things working?

    Does Device Manager still show [cmz vmkd] or [cmz vmkd] Virtual Bus


    By the way you should not be renumbering / saving MGlogs.zip. It should always be just MGlogs.zip and it is automatically updated with the current info we need. You should not be saving additional copies with different names.
     
  36. adown

    adown Private E-2

    Just tried to run system dialog to access device manager and got:

    "C:\WINDOWS\system32\rundll32.exe
    Application not found."

    The malware application is also still running
     
  37. adown

    adown Private E-2

    Just ran exehelper again and managed to access device manager.

    the device has not returned.

    Should I force quit the malware application? It has a system tray icon as well.
     
  38. adown

    adown Private E-2

    Just ran MB, found 7 items, fixed them.
    Log attached.

    Malware software no longer comes up at login.

    Running SAS now while I go to bed.

    Looks like we might be getting there.....
     

    Attached Files:

    Last edited: Feb 19, 2011
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What malware application are you referring to?

    Are you still having any problems after the last Malwarebytes scan and have you rebooted after running Malwarebytes?


    See if you can run ComboFix now as requested in the READ & RUN ME.
     
  40. adown

    adown Private E-2

    OOk, so...

    The application I referred to is the Internet Security 2011 for Windows XP fake antivirus which was the most obvious manifestation of the malware.
    Following the MB scan and restart that has now gone.

    I am just running CF and will attach log.

    Should I toggle the restore point now?

    Also, the primary .exe files for S&D have become hidden and read-only. I am unable to run these, delete or alter the read-only setting of them.
     
  41. adown

    adown Private E-2

    It seems that CF will still not run properly.
    It gets to the point of "scanning for infected files etc"
    but then stops at this point and never progresses....
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No do not touch system restore until requested.

    Please run thisResetting Registry and File Permissions

    And then do the below:


    Please download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r


    Now download Junction,zip to your Windows folder
    • Please download Junction.zip and save it to your Windows folder (i.e, C:\Windows\Junction.zip This assumes C:\ is your Windows boot drive.)
    • Now unzip it and put junction.exeinto the Windows folder (i.e., C:\Windows\junction.exe)
    • Do not try to run it right now. We will run something that uses it later.

    Now we need to reset the permissions altered by the malware on some files.
    • Download and save inhertit.exe to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!
    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.
    Now see if you can get ComboFix to run properly.
     
  43. adown

    adown Private E-2

    Log attached.

    Combofix still the same. It freezes the clock once it gets going, the mouse is still responsive but I can't quit it or shut down, have to force reboot.
     

    Attached Files:

  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The infection you had can cause many problems. Sometimes it can also break/corrupt variious applications including protection programs and malware removal tools. Let's try to clean up some possible problems.

    Uninstall Avast and Spybot Search & Destroy. If you have a problem uninstalling them with Add/Remove Programs, use the below tool to see if you can uninstall them.

    Revo Uninstaller

    Do not reinstall them or any other protection programs until I ask you to do so and please only install what I request.



    Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  45. adown

    adown Private E-2

    Unfortunately I need to give the laptop back to my friend tonight so I may have to stop where I am.

    Following the inherit fix I have been able to change the read-only permissions of the S&D files and have re-installed it succesfully.

    Avast is still working and additionally I have installed just the firewall section of Comodo.

    It seems that the system is running fine now, although combofix freezes part way as mentioned.

    Amazingly, my firend recieved a voicemail today from the same 'company' trying to get money for the software! Not sure of the full details as he deleted the voicemail but they obviously got a fair amount of data from the laptop.

    It's annoying that it has taken so much work from me and you kind fellows, but I really can't afford to spend any more time on someone else's laptop.

    I really appreciate all your help on this, at a few points I thought we would never shift it!

    If there are some essential things that are easy to carry out I can forward the details to my friend but he is certainly not a tech-head and will have difficulty with more than basic computer inputs.
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Okay then I we just need to cleanup from what we have installed and run before you give it back. Run the below and then manually remove any leftovers that remain like the renamed MGlogs.zip files that the below would not know about to remove.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  47. adown

    adown Private E-2

    I was so close......

    Just toggled the restore point and went into Add/remove programs to check for leftovers. There was an Antivirus 2010 entry, I foolishly clicked remove and Comodo popped up saying it was infected with a Trojan. Ran MB and it found something, which I removed. Restarted and get BSOD.

    It seems the malware is still there.

    I am able to boot in safe mode.

    I will run through the checklist from the start until I hear from you.

    So close......
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do what I request in message # 44 and attach those logs. Even if you have to do this in safe mode that is fine. After completing those steps, run Malwarebytes and select Perform a full scan. This will take longer so be patient and let it finish. Attach the new log from Malwarebytes.

    NOTE: If you already ran my final cleanup steps, you will need to redownload Avenger and MGtools.


    Also does Device Manager show [cmz vmkd] or [cmz vmkd] Virtual Bus coming back??
     
  49. adown

    adown Private E-2

    OK, so I had run SAS portable already - log attached

    Ran MB as a quick scan found Antivirus 2010 - log attached

    Ran Avenger script - log attached

    ran MGTools - got this error\;

    "C:\Windows\system32\cmd.exe
    C:\program files\Alwil Software\Avast 5\aswMonVd.dll
    An installable Virtual Device driver failed DLL initialization. Choose close to terminate the application."
    tried pressing Close a number of times - eventually had to click Ignore.

    MGlogs attached

    Runnign Full MB scan
     

    Attached Files:

  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you forget to uninstall Avast as requested? I still see it in Add/Remove Programs and my last fix has now broken it since it was supposed to be uninstalled. Please use Revo Uninstaller to uninstall it immediately.

    This kind of error was described in the Using MGtools link. See the below link for a possible fix:

    16 Bit MS-DOS Subsystem Error Message When You Install a Program


    You forgot to answer my question about whether those items returned to Device Manager


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
    O1 - Hosts: ÿþ1\
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
    O4 - HKLM\..\RunOnce: [Cleanup] C:\cleanup.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-21-789336058-1417001333-839522115-500\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User '?')
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (file missing)
    O23 - Service: PEVSystemStart - Unknown owner - C:\ComboFix\PEV.cfxxe

    After clicking Fix, exit HJT.




    Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds