Windows Recovery Virus Help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by herbz100, May 5, 2011.

  1. herbz100

    herbz100 Private E-2

    I had a windows recovery virus on my desktop which really did bugger my computer. Its also hide all my files thinking they had been lost. Anyway I used a link from bleepingcomputer to rid the virus to the best of my ability however theres definately some maleware left on my computer.

    I have windows xp 34bit... The computer is very slow, and makes a noise very often where the floppy drive belongs.

    Combofix didnt work as it said there was not enough memory on the computer.

    I have added the rest of the logs..

    Thanks
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm will attempt to work up a fix for you, but it may not work. I need to warn you ahead of time that it appears that you have a Ramnit infection and could require a total clean reinstall to recover from this. In addition, just due to the security risks of it being a backdoor infection, you may still need to install just to be secure. Below is the normal boilerplate that we post for Ramnit infections.

     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I will post a starting fix just incase you wish to attempt cleaning which will likely not be successful, since you may have thousands of infected files.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,,C:\Program Files\yqloqqtu\hwdbbqdl.exe
    O4 - Startup: hwdbbqdlmgr.exe
    O4 - Startup: hwdbbqdlmgrmgr.exe
    O4 - Startup: hwdbbqdlmgrmgrmgr.exe
    O4 - Startup: hwdbbqdlmgrmgrmgrmgr.exe
    O4 - Startup: hwdbbqdlmgrmgrmgrmgrmgr.exe
    O4 - Startup: hwdbbqdlmgrmgrmgrmgrmgrmgr.exe
    O4 - Startup: hwdbbqdlmgrmgrmgrmgrmgrmgrmgr.exe
    O4 - Startup: hwdbbqdlmgrmgrmgrmgrmgrmgrmgrmgr.exe
    O20 - Winlogon Notify: !SASWinLogon - Invalid registry found

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\temp
    C:\Documents and Settings\Harshil\Local Settings\temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. herbz100

    herbz100 Private E-2

    Thanks Chaslang for all the information and advice. There seems to be alot of nasty stuff on the desktop. Ive been abit reluctant to reformat the computer as i will have to look for my restore cd, connect the modem etc....

    My father uses this desktop and is a real novice with websites and wouldnt know which ones are secure and think that this is the cause.

    Anyway i have carried out the information you have given me...

    There doesnt seem to be any real change to the desktop...When i google search it doesnt sometimes take me to the websites so i have to keep refreshing.

    Still a noise comming from the A drive constantly..

    O4 - Startup: hwdbbqdlmgr.exe
    O4 - Startup: hwdbbqdlmgrmgr.exe
    O4 - Startup: hwdbbqdlmgrmgrmgr.exe
    O4 - Startup: hwdbbqdlmgrmgrmgrmgr.exe
    O4 - Startup: hwdbbqdlmgrmgrmgrmgrmgr.exe
    O4 - Startup: hwdbbqdlmgrmgrmgrmgrmgrmgr.exe
    O4 - Startup: hwdbbqdlmgrmgrmgrmgrmgrmgrmgr.exe
    O4 - Startup: hwdbbqdlmgrmgrmgrmgrmgrmgrmgrmgr.exe

    These didnt exist.

    There were a few from the temp files that i couldnt delete..

    I have added the logs you require..

    Many thanks
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome but it is looking like this may be what you will have to do because of what the Ramnit infection has done to your PC. However let's try the below before deciding.

    Run the ESET Online Scan in the below link and attach the log:

    Using ESET's Online Scanner


    Then run the scan one more time and attach the second log. This will hopefully give us a better idea of the degree of infection.
     
  6. herbz100

    herbz100 Private E-2

    I had to carry this out in Safe mode as it kept comming back with something regarding a proxy server when doing it in normal mode....

    Many threats have come up here........yikes!!!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's is what I as suspecting. You did not attach a log, but I will repeat what I have already stated a couple times. You will have to reinstall.
     
  8. herbz100

    herbz100 Private E-2

    sorry here is the log.....

    So I presume i should just go ahead and reformat the computer?

    Do I just need to install windows xp again?

    Thanks

    Didnt realize that when i first attached them yesterday that the logs were exceeding there file limit. So i have cut them in half and added 2 logs.
     

    Attached Files:

    Last edited: May 13, 2011
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you need to back up your personal data, and NO EXECUTABLES as they are all likley infected. Also you have a C and a D drive and the both are infected and need to be formatted.

    Note if you back even one executable file that is infected, and rerun it in any form, you will start the infection all over again.

    Yes. And before reconnecting to the internet, make sure that you have all of your protection in place. Refer to the below on how to properly protect your PC:

    How to Protect yourself from malware!
     
  10. herbz100

    herbz100 Private E-2

    Thanks Chaslang, ive just managed to reformat my computer and rid of everything with a clean install of windows xp sp3.

    I will have a read thorugh of the protection link you gave me.

    Mnaaged to get my driver reinstalled for the internet which makes things easier.

    Just need to configure all the old hardware for my old computer. Thanks until next time.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds