Persistent Malware problem!

Discussion in 'Malware Help (A Specialist Will Reply)' started by iwalke, Sep 27, 2011.

  1. iwalke

    iwalke Private E-2

    Hi, I have been having problems with my laptop for about a month now, where my browsers keep crashing, and now won't open at all (other than IE8 64-bit, which can't run flash). I also can no longer open most programs, and hence have not attached any logs as I haven't been able to get any malware removal tools working.

    I'm running windows 7 and would greatly appreciate your help.

    Thanks
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator


    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif


    * Double-click on the Rkill desktop icon to run the tool.
    * If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    * A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    * If not, delete the file, then download and use the one provided in Link 2.
    * If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    * Do not reboot until instructed.

    If you are having problems running Rkill, you can download iExplore.exe or eXplorer.exe, which are renamed copies of Rkill.com, and try them instead.

    * If the tool does not run from any of the links provided, please let me know.
    Once you've gotten one of them to run then try to immediately run the following.

    Now download and Run exeHelper from Raktor

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    If you already have them installed, be sure to update Malwarebytes and SUPERAntiSpyware before the scan!

    Now run this: Using Malwarebytes Anti-Malware

    Now run this: SUPERAntiSpyware - running & getting a log

    Now run this: Using MGtools



    Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans

    • exeHelper log
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.
     
  3. iwalke

    iwalke Private E-2

    Hi Tim, thanks for the quick reply. I've attempted to run each of the Rkill downloads but unfortunately none have succeeded. For each, when I click 'run as administrator' and get asked if I want to make changes to the computer, but when I click 'yes' on this dialogue box, it just closes and nothing happens.

    Any further guidance would be appreciated. Thanks.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you run MGtools ? Try to save it directly to the C: drive and run the exe. ( If using Vista or Win7, right click and run as Administrator ).
     
  5. iwalke

    iwalke Private E-2

    Unfortunately I can't run this either - tried saving directly to my C: drive, but was told that I don't have permission to save to this location and to contact the administrator to gain permission.
    As far as I know, this is the only log in for the pc and should be the administrator account.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try one more:

    Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  7. iwalke

    iwalke Private E-2

    Still no dice I'm afraid. Same problem, nothing happens after I click to run as administrator.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    • Please download a ZeroAccess Removal Tool (By Webroot)to your desktop.
    • Double click on it to run it (If running Vista or Windows 7, right click on it and select "Run as an Administrator")
    • Type y and press enter to run the scan .
    • Hit any key to exit once it has finished it's scan.
    • Attach the log which will be in the same location as you ran the tool from. (Should be desktop)


    Download and run Win32kDiag per the below instructions:

    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log

    C:\win32kdiag.exe -f -r



    Now download Junction,zip to your Windows folder

    • Please download Junction.zip and save it to your Windows folder (i.e, C:\Windows\Junction.zip This assumes C:\ is your Windows boot drive.)
    • Now unzip it and put junction.exeinto the Windows folder (i.e., C:\Windows\junction.exe)
    • Do not try to run it right now. We will run something that uses it later.

    Now we need to reset the permissions altered by the malware on some files.

    • Download and save inhertit.exe to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!

    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.

    And one more scanning tool I want to use to collect more information is OTL per the below.

    Please download OTL by Old Timer to your desktop.
    See the download links under this icon: http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif

    1. Double-click OTL.exe to run (Vista and Win7 right click and select Run as Administrator)
    2. When OTL opens, change the Output (at the top-right portion of the program) to Minimal Output.
    3. Put check-marks in LOP Check and Purity Check.
    4. Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.



    • When the scan is complete, two logs entitled OTL.txt and Extras.txt will be created on your desktop.
    • Attach both of these logs to your next message.
     
  9. iwalke

    iwalke Private E-2

    Thanks for the reply again. Have only tried the zero access removal tool, and this opened a msdos window briefly before that immediately closed and no scan was performed.

    I haven't proceeded with your other steps as this didn't work.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try doing the rest of it and let me know how that goes.

    Also try this:
    Go to the below link and follow the instructions for running TDSSKiller from Kaspersky

    Be sure to attach your log from TDSSKiller
     
  11. iwalke

    iwalke Private E-2

    Win32kDiag would not save to C: Drive either. Same problem with Junction.exe.

    Inherit.exe did not run, although it saved to the desktop, it just wouldn't open. TDSSkiller had the same problem as this.

    Sorry, I know this is a bit frustrating!
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download this file to your desktop

    Kaspersky Virus Removal Tool

    Run the program you have just downloaded to your desktop (it will be randomly named )

    First we will run a virus scan.

    • On the first tab select all elements down to Computer and then select start scan.
    • Once it has finished select report and post that.


    Do not close AVPTool or it will self uninstall, if it does uninstall - then just rerun the setup file on your desktop.

    Now an analysis scan


    • Select the Manual Disinfection tab
    • Press the Gather System Information button
    • Once done , still on the Manual Disinfection tab click the little icon of a file which is the "reports" button. Now click on Manual Disinfection report.You should see an option to save a report here with a little button with an icon of a disk. Attach this log please.
    • The file is located at C:\Users\your name\Desktop\Virus Removal Tool\setup_9.0.0.722_05.01.2011_20-34\LOG\avptool_sysinfo.zip


    Try this in both normal and safe modes.
     
  13. iwalke

    iwalke Private E-2

    When I try that link for the Kaspersky download I get a 404 message. Is that definitely the correct link?

    Thanks
     
  14. thisisu

    thisisu Malware Consultant

  15. iwalke

    iwalke Private E-2

    Thank you.

    I have tried running the Kaspersky virus removal tool in both normal and safe modes and on both attempts the program would not open (same issue as with the other programs).

    Any more help would be appreciated.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try going HERE to fix the file association issue with exe files. Then see if you can run any tools.
     
  17. iwalke

    iwalke Private E-2

    I downloaded and ran the exe reg fix and this ran and said that it succeeded. However, still no joy when trying to run the exe files.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There isn't much else we can do. You can try creating some of these start up disc's, but I am afraid you may end up reformating anyway.

     
  19. iwalke

    iwalke Private E-2

    Okay, well thanks for your help. I can restore my laptop to factory settings, and that will solve the problem, but I have done this before and everything works fine at first but after a few weeks problems start to creep in again and this culminates in me not being able to open programs.

    If I restore the system and then come back here would you be able to run me through what to do to check if my system is clean?
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Certainly. Once you have reimaged, install all your AV and AS programs and then follow the Read and Run First instructions. We will look at the logs to make sure there was not any malware in the reimage.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds