catchme.sys and other possible malware... Windows XP

Discussion in 'Malware Help (A Specialist Will Reply)' started by Rezinus, Mar 25, 2011.

  1. Rezinus

    Rezinus Private E-2

    I have recently removed some infected files from scans I performed, however I still think there may be remnants remaining or other malware that the scan did not find.

    I also deleted a catchme.sys file from a registry scan which is malware, afaik. I then searched regedit and found LEGACY_CATCHME which I am unable to delete.


    Can someone assist in cleaning my PC completely?
    All help is GREATLY appreciated!
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    catchme.sys is just part of GMER which is used by ComboFix and some other tools.
     
  3. Rezinus

    Rezinus Private E-2

    From what I understand catchme.sys is malware, after reading other threads here about catchme.sys.

    As far as I know, ComboFix uses catchme.exe, not .sys but I could be mistaken.
    I would like help finding out if there are other issues on my PC as well if possible.

    Thanks for the reply, btw.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. Rezinus

    Rezinus Private E-2

    TimW,

    I have done all the steps for XP cleaning and everything came up fine except for Malwarebytes' which found an infected file.
    The file in question was:

    Malwarebytes' Anti-Malware 1.50.1.1100

    *EDIT by dr.moriarty: Inline log removed and attached

    However the catchme.sys was found during a registry scan using Glary Utilities, which I have deleted.
    My PC seems to be acting differently now, which I why I want to know if I am still infected.
    My main problems are my PC seems to have slowed down a bit, especially during start up which makes a grinding sound from inside the PC before Windows XP loads. I also notice internet issues such as not being able to view .pdf files and Bleeping Computer chat room not loading.

    What do you recommend?
     

    Attached Files:

    Last edited by a moderator: Mar 25, 2011
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You need to provide the requested logs as instructed in the Windows XP Malware Removal/Cleaning Procedure:
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry I was confused because of this thread here where Chas says:
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See the below more than 3 year old thread explaining this. See what I stated in message # 16 too

    http://forums.majorgeeks.com/showthread.php?t=145834
     
  9. Rezinus

    Rezinus Private E-2


    I was able to get all logs however I ran into a confusing situation.
    When I began to run ComboFix, I received a message saying "AVG Free Anti-Virus 2011 needs to be closed before proceeding."

    I downloaded this software recently to do a scan but it kept freezing my PC when Windows would start, so I uninstalled it (or so I thought). I even did a REGEDIT search to find entries associated with AVG and most were deleted successfully. However I ran into quite a few entries that would not allow me to delete.
    When I went into Control Panel>Security Center it also identified AVG Anti-Virus, and it said "virus scanning is on". So apparently my PC still recognizes AVG Free Anti-Virus as being a running process even after uninstalling it. How do I correct this issue??


    I went ahead and performed all required scans (which hopefully were not compromised by this AVG issue), and I am attaching the logs.
     

    Attached Files:

  10. Rezinus

    Rezinus Private E-2

    MGTools log:
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. You can try running the AVG removal tool to see if it finds any traces:
    AVG Removal Tool.

    We can then do this:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    SecCenter::
    {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    Quit::
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Tell me what issues you are still having, if any.
     
  12. Rezinus

    Rezinus Private E-2

    TimW,

    I performed the tasks you requested, however I ran into some issues with the ComboFix task.


    As far as the AVG, I ran the removal tool however both my PC and ComboFix report AVG as being active.


    As for ComboFix, I did exactly as you said however the scan portion failed to perform and I had to manually shut down my PC after about 45 minutes. Upon restart, my Windows froze and I had to manually shut down once again.
    The ComboFix did initiate the update service and restarted, however I received the same "AVG is still running" message. After that the ComboFix began to start like normal but just stopped responding.

    What should I do now??
    Thanks for the help so far btw folks!
     
  13. Rezinus

    Rezinus Private E-2

    I also forgot to mention that when I ran the AVG uninstaller tool, the log indicated many registry keys that were unable to be deleted.

    Some of these were the same registry entries that I was unable to manually delete myself.
    I have a feeling those registry entries might be what is causing the program to remain active on my system.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run CCleaner. Both the cleaner and the registry. Make sure to do the backup when prompted. Hopefully that will remove all leftovers from AVG. Let me know what you find.
     
  15. Rezinus

    Rezinus Private E-2

    TimW,

    It seems the AVG is removed from my PC from what I can tell so far. Your help was very much appreciated.


    The only thing I need is your advice on how to remove the scanning tools I installed from the XP Malware Removal guide (ComboFix, MGTools, RootRepeal etc.)

    Thanks again!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  17. Rezinus

    Rezinus Private E-2

    Thank you for that chaslang!

    Everything seemed to work well, except there is a folder remaining on my C:/ drive labeled "ZZZZZZ" with a seperate folder inside labeled "BackEnv".

    When I tried to delete the file I received an "Access Denied" message.
    BackEnv seems to be associated with ComboFix, so how do I remove this remaining folder?
    Thanks again!
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Did that work?
     
  19. Rezinus

    Rezinus Private E-2

    Hi TimW,
    Quick question before I proceed...


    Do I copy this exact text to the input box?:

    Folders to delete:
    C:\ZZZZZZ --> make sure it is the exact name!!



    By that I mean do I paste the "--> make sure it is the exact name!!" as well, or just "Folders to delete:
    C:\ZZZZZZ"...?
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just copy:

    Folders to delete:
    C:\ZZZZZZ

    Is that the correct number of Z's?
     
  21. Rezinus

    Rezinus Private E-2

    TimW,

    I performed that tasks and this is the log that appeared upon startup:


    Logfile of The Avenger Version 2.0, (c) by Swandog46
    http://swandog46.geekstogo.com

    Platform: Windows XP

    *******************

    Script file opened successfully.
    Script file read successfully.

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    Rootkit scan active.
    No rootkits found!

    Folder "C:\ZZZZZZ" deleted successfully.

    Completed script processing.

    *******************

    Finished! Terminate.



    Now when I looked in my C:/ drive, there is now a folder labeled "Avenger" and inside the folder there is the same "ZZZZZZ" folder.
    What should I do with these folders, and how do I remove the Avenger program if it is no longer needed?

    Thanks again for all your help. It was very much appreciated.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should be able to just delete the Avenger folder.
     
  23. Rezinus

    Rezinus Private E-2

    Ok, sounds good.

    How do I remove the Avenger software from my desktop? Do I just delete that as well?
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  25. Rezinus

    Rezinus Private E-2

    I was able to delete the Avenger program and the .zip file in the Avenger folder, however the "Avenger" folder and the "ZZZZZZ" folder still refuse to be deleted. I even ran Malwarebytes FileAssassin tool and was able to delete the .dat files inside the ZZZZZZ folder, yet I still can't delete the two mentioned folders.

    When trying to delete I get a message saying to make sure the file is not write protected or in use: access denied.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Open the folder and right click the folder inside. Choose properties and click on the security tab. Set your user account to have full permissions. Then do the same with the main folder. Then see if you can delete it.
     
  27. Rezinus

    Rezinus Private E-2

    TimW,

    Under Properties, no Security tab is available.
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    On which? The Avenger folder or the ZZZZZ folder?
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boot in safe mode try deleting. If that does not work, navigate downward in the folder/file directory structure to the lowest level file/folder and delete it first and the work your way toward the top level which is the C:\Avenger folder.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also something else that may fix the no security tab issue is the below.



    So to see and unhide the Security tab, just use the following steps:
    1. Launch Windows Explorer or MyComputer
    2. Click on the Tools at the menu bar, then click on Folder Options.
    3. Click on View tab.
    4. In the Advanced Settings section at the bottom of the list, uncheck and unselect (clear the tick) on the “Use simple file sharing (Recommended)” check box.
    5. Click OK.
    See the below where the above came from and more info is included too:

    http://www.mydigitallife.info/2006/07/19/missing-or-no-security-tab-found-in-windows-xp-professional/
     
  31. Rezinus

    Rezinus Private E-2


    Ok,
    I have tried deleting in safe mode which didn't work, and I tried ticking the security tab option as TimW suggested, which was unsuccessful for me as well.

    I have tried the second part of your advice yet as I am a little confused as to how to perform the task.
    Do I do that in Safe Mode? I am also not sure what the folder/file structure is or the level thing is. Sorry for the confusion.


    This thing really is a pest.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normal boot mode.


    C:\Avenger is a folder. Inside this folder there can be other folders and other files. If you just keep navigating down from the root Avenger folder you will eventually hit the lowest level item ( either a file or a folder ). You need to work backwards from this point deleting files first and then the folder that contained the files until you get back up to the top which is the Avenger folder. Once there is nothing else under the Avenger folder, you should be able to delete it. You are having a problem with Windows permissions ( quite common and somewhat of a bug in Windows ). It is not a malware problem.

    Also note that you need to make sure that you have viewing of hidden and system files enabled to make sure that you are not missing the viewing of any files in the folders you are trying to remove.
     
  33. Rezinus

    Rezinus Private E-2

    Thanks chaslang,
    I was finally able to remove the folders after following all procedures.

    When I went to Properties>Security tab, I went into Advanced settings and changed Administrative permissions to "allow" as it was set to "deny".
    After checking "Show hidden files etc" I was able to remove the folders just fine.

    So should I keep the allow settings the way they are now, to allow full administrative permissions? Or do I change it back to default?
    I ask because I checked permissions on other folders, and all of them are set to "allow" under the Security tab.



    Thanks again to everyone, you guys are the best!
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Yes. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds