I Don't Know

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sopheatia, Nov 11, 2011.

  1. sopheatia

    sopheatia Private E-2

    It all started a day ago. I caught some nasty thing called protect.exe. I manged to rename it, move it to a folder, and delete it. I knew it wasn't over yet so I went to look up some info on the nasty thing and found my websites were starting to redirect themselves. I downloaded avg because that's what the sight was telling me to do. Turns out avg wouldn't work so I tried avast. I came up with lots of things one in particular was Win:32malware-gen, which lead me to this site. In one of the forums with that exact topic. I tried to follow instructions as good as possible, for every computer is different. After that I decided to fallow the Malware Removal guide. Step by step starting with (Fixing Google Redirection/hijacking and other redirection problems) then moved on to (READ & RUN ME FIRST. Malware Removal Guide) to this (Windows XP Malware Removal/Cleaning Procedure). Thing got worse and then they got better but the problem still isn't solved.

    I was able to remove avg with the avg removal guide. I also removed avast because it was not helping. Couldn't get tdsskiller or rootrepel to work. Reloaded java. Ran estscan, mbrcheck, gooredfix, superantispywere, mgtools and malwerebytes. (Note: in the order the forum told me to.) On the other hand combofix starts and begins doing its thing but stops after it gets to the (I'm going to scan for infections should only take about ten minuets) faze. A message popped up saying that a certain virus was on my computer and that it was very dangerous, if I had problems connecting to the internet to reboot and run combofix again. I should of wrote down the exact virus info but I figured combofix would run threw and I'd get a log. I waited 8 hours and combofix never moved from that spot. Tried to run it again and it stopped there as before, only no warning message.

    I am at a loss of what to do now. I keep getting a message telling me to update flash player, even when uninstalled. The message will continuously pop up, I got it up to thirty stacks once. A proxy server still happens on my firefox every time I restart the computer, as well as internet explorer. I don't use a proxy, nor do I use internet explorer. Internet explorer will open on its own. My firewall said it was on while it was off and then randomly changes when I look at firewall settings. Several update shield logos will appear next to the clock, mainly when I was running combofix. Not all logs can fit hear. I hope this info will help, and thank you for your time.:major
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you attach the C:\Mglogs.zip from running C:\MGTools.exe please.
     
  3. sopheatia

    sopheatia Private E-2

    sure can :cool
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good afternoon! :) You have an infected MBR (Master Boot Record) Please be warned that you would be wise to back up any important data before proceeding with the next step of attempting to fix your MBR.

    Do you have your XP boot CD? If not:

    This is a download of an .iso file of just the Recovery Console for XP.
    Burn to CD with Nero or other 'disc image' capable tool and boot.

    XP Recovery Console.

    You can use ImageBurn to create the disc.

    Boot to the bios after creating the disc, and change the boot order to CD/DVD as first boot device. Then insert the CD and reboot. Once you are in the Recovery Console, type:
    fixmbr

    then exit. Reboot to normal mode and re-run MBRCheck and attach the new log.
     
  5. sopheatia

    sopheatia Private E-2

    :( I,m sure I did it right :cry
     

    Attached Files:

  6. sopheatia

    sopheatia Private E-2

    OHH and hello to you :)
    I did exactly as instructions said. Rote the file to the CD and booted from CD. Ran the fixmbr. It said it was a success but still having same issues.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What are you using for AV protection? I don't see any listed in your add/remove programs file.

    Please attach the log from running ComboFix:
    * C:\ComboFix.txt

    Use windows explorer to find and delete:
    C:\Documents and Settings\Sopheatia\Application Data\B4AD1
    C:\Program Files\D1B80
    C:\Documents and Settings\Sopheatia\Local Settings\Temp\2147483647.dat
    C:\Documents and Settings\Sopheatia\Local Settings\Temp\kJ87hjKF.exe.part

    Now re-run MBRCheck and attach that new log.

    Also, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
    * MBRCheck log
     
  8. sopheatia

    sopheatia Private E-2

    No AV protection. As I said before AVG wouldn't work, so I downloaded avast. But avast was spamming me harder than the malwhear, so I had it removed. It was also going to cause conflict with your pro grams. I used AVG removal to get rid of AVG and just un installed avast.

    I tried to run combofix again, because you said you wanted a log, but it stalled in the same spot as before.

    I deleted the files that you asked and ran the MBRCheck as well as the MGtools. I ran into an error whilst running MGtools that stated [The application failed to initialize properly (0xc0000135)]. HijakThis did not pop up in the proses of running MGtools.

    :confused
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to make 100% sure that you are booting from the Recovery Console on the CD and not the installed version of the Recovery Console that it already on your harddisk. If you boot your hard disk, you will not be able to fix the MBR properly because you will have already loaded the infection which will block the fix..
     
  11. sopheatia

    sopheatia Private E-2

    Downloaded enus\x86\mseinstall.exe and found a virus win:32/Patchload.O, was succeeded in disinfect.

    Ran fixmbr again and it claimed to be a success. Yes, I am sure that I booted from CD. The first time i tried I messed up and put in a blank CD :-o and tried to run RC off of HD. It got about 3 ticks in and stalled. The CD actually works.

    I'm afraid things are getting worse though. I'm starting to see advertisements in words such as harddisk, application, step, ect. I can see them on even your website :( and windows media player is opening randomly with things I've never seen.

    Same error on mgtools.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We are starting to notice that there must be a new form of this infection as many people are doing a fixmbr command but still having a faked MBR message in MBRCheck. We need to look into this. Have patience.

    Note: You also do not have MGTools directly on your C: drive as requested.

    Please download mbr.exe and save it to the root directory, usually C:\ <- (Important!).

    * Go to Start > Run and type: cmd.exe
    * press Ok.
    * At the command prompt type: c:\mbr.exe >>"C:\mbr.log"
    * press Enter.
    * The process is automatic...a black DOS window will open and quickly disappear. This is normal.
    * A log file named mbr.log will be created and saved to the root of the system drive (usually C:\).
    * Copy and paste the results of the mbr.log in your next reply.

    If you have a problem using the command prompt, you can just double-click on mbr.exe to run the tool.
     
    Last edited: Nov 13, 2011
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not be doing anything that we do not ask you to do!

    Tell me exactly what you see when you boot your PC and also tell me what phases/stages you go thru in booting from the CD. When finished booting the CD, exactly what are you seeing on the screen.
     
  14. sopheatia

    sopheatia Private E-2

    haya guys :)

    @chaslang sorry I wasn't thinking.
    this is how it boots

    hp pavilion boot screen

    black screen saying; Press any key to boot from CD
    key pressed space bar

    blue screen saying; Setup
    Press F6 if you need to install 3rd party device (5 seconds remaining)
    Setup is loading files (lots of files)

    Setup is starting windows

    Windows XP Home Edition Setup
    Welcome to setup
    This portion of setup program prepares Microsoft (R) Windows (R) XP to run on your computer
    -To setup WINDOWS XP now, press Enter.
    -To repair a WINDOWS XP installation using Recovery Console, press R
    -to quit setup witnout installing WINDOWS XP, press F3
    key pressed R

    black screen saying, Microsoft Windows XP (TM) Recovery Console
    The Recovery Console provides system repair and recovery functionality
    Type EXIT to quit the recovery console and restart computer
    1:\windows
    Wich windows instalation would you like to log onto
    {to cancle, press Enter}? key pressed 1 and then Enter
    {C:\windows} fixmbr and then enter

    a warning about the potential harm this action could do

    and then a success note

    i could get the rest of the info if i did it again but not until you ask me to :)

    @TimW MGtools is in the main C: drive :confused it's not in a folder or anything. should i uninstall and try to install to c: again?

    instaled mbr.exe to C: only once i run it my computer stalls. it gets as far as

    Stealth MBR rootkit/Mebroot/Sinowal/TDL4
    detector 0.4.2 by Gmer, http://www.gmer.net
    Windows 5.1.2600 Disk: Maxtor_6E040L0
    rev.NAR61EAO-> HarddiskO\DRO-> \device\Ide\IdeDevicePOTOLO-3

    device: opened successfully
    user: MBR read successfully
    Kernel: MBR read successfully
    user and kernel MBR ok

    no log :( because the computer crashes every time I run it :cry

    Note: i maniged to stop some thing from hapinign like the adds in words by using task maniger to close Plugin-container.exe and iexplore.exe to stop the download flash player pop up. should I not do that?
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to the below link and follow the instructions for running TDSSKiller from Kaspersky

    Be sure to attach your log from TDSSKiller
     
  16. sopheatia

    sopheatia Private E-2

    I tried everything :major it wont work. I renamed it. Uninstalled it and reloaded it like ten times. It wont do anything. I get the to the run option and click run but nothing happens. This kilobytes. :(
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boot from the CD again and get into the Recovery Console again. This time do not enter the fixmbr command. Please just type in map and hit enter. I want you to tell me what output you get from this command. You will have to write it down and then type it into a message.
     
  18. sopheatia

    sopheatia Private E-2

    This is what happened

    C: NTFS 39198MB \Device\Harddisk4\Partition1

    I: 9MB \Devise\Harddisk4\Partition2

    H: \Device\CdRom0
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay log back into the Recovery Console and this time we will use fixmbr again but with a new parameter added so that the correct disk is fixed. run the below. Note the space after fixmbr

    fixmbr \Device\Harddisk4

    Then reboot and continue with the below.

    Also here are a few more things for you to do
    1. You are quickly approacing the point where you do not have enough free disk space and your computer will run poorly/slowly when free disk space gets low. And you have a rather small hard disk by todays standards. Your log shows:
      • Size 38.28 GB (41,101,688,832 bytes)
      • Free Space 4.57 GB (4,912,091,136 bytes)
    2. Uninstall SUPERAntiSpyware
    3. Uninstall Ask Toolbar
    4. Uninstall StartNow Toolbar
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    • After reboot, please save Win32kDiag file to your desktop.
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    "%userprofile%\desktop\win32kdiag.exe" -f -r


    Now run a new scan with MBRCheck.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • the Win32kDiag.txt log
    • the new MBRcheck log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  20. sopheatia

    sopheatia Private E-2

    You are a demigod sir. :-D The fixmbr said it was a success. Managed to remove the useless programs. I have been wanting to get rid of that messenger for ever. :) fixme.reg was a success. The avenger was a success. I'm not 100% positive that win32kdiag ran all the way through. I wasn't sure what mbrcheck to use so i went with the one on desk top let me know if i should of used the one on c: that i was informed to download earlier. MGtools came up with this error;
    HijackThis
    Error Details:
    An unexpected error has occurred at Proceduure: modMain_CheckOther1Item() Error#5-Invalid procedure Call or argument
    Windows version: Windows NT 5.01.2600
    MSIE version: 8.0.6001.18702
    HijackThis version: 2.0.4
    and then came up with this error again;
    The application failed to initialize properly (oxc0000135).

    I'm not sure the redirection problem is fixed as Internet Explorer opened win I submitted the error for hijackthis. The flash player download pop up has stopped and the plug-in isn't attempting to burn out my cpu. I didn't mention that before but at random my computer would just go bizerker and I would have to stop the process. Thing are running smoother than before and it feels like i have control over my computer again. Somethings still iffy about it though. :major
     

    Attached Files:

  21. sopheatia

    sopheatia Private E-2

    Startup is nasty. It asked me to put in a pass word I had that feature disabled. It took a really long time to lode and still hasn't got the start menu up. The entire screen was black for like sixty seconds and by some miracle I was able to get into the start property's and open desktop feature, just to be able to get back online. Kind of scary :( and I lost the ability to do everything now. All I have is the internet screen as my last hope. I can can still rig it to get around though just can't close a window or I'll never see it again. LOL
     
    Last edited: Nov 14, 2011
  22. thisisu

    thisisu Malware Consultant

    Whenever you ran the map command and received this; Did you shutdown or reboot the computer before running the fixmbr \Device\Harddisk4 command?

    Or did you run map and fixmbr \device\harddisk4 in the same session while in the recovery console?
     
  23. sopheatia

    sopheatia Private E-2

    no i restarted before the fixmbr \harddisk\4
     
  24. thisisu

    thisisu Malware Consultant

    Can you boot back into the recovery console, and type the map command again, let us know the output.

    Then, DO NOT reboot or shutdown. Just wait for one of us to respond. I'll be online for the next half hour if you're still here to respond.
     
  25. sopheatia

    sopheatia Private E-2

    kk but startup is scary i don't know if it will start agin
     
  26. thisisu

    thisisu Malware Consultant

    Remember to BOOT FROM THE CD. ;)
     
  27. sopheatia

    sopheatia Private E-2

    sorry toulk so long I had to pece together an some old computers and they are slow. slow, it takes like 10 minn to load a page LOL. but any way I got it at the RC and the map said the same thing as it did befor
     
  28. thisisu

    thisisu Malware Consultant

    fixmbr \Device\Harddisk1

    try that, then reboot and rerun MBRCheck.
     
  29. sopheatia

    sopheatia Private E-2

    It tells me that;
    The old master boot record cannot be read
     
  30. thisisu

    thisisu Malware Consultant

    Ok, just exit out of the recovery console and try the below:

    http://img833.imageshack.us/img833/7035/aswmbricon.gif Please download aswMBR by Avast! to your desktop.
    • Double-click aswMBR.exe to run it (Vista and Win7 right-click and select Run as Administrator)
    • Select No when asked Would you like to download latest Avast! virus definitions?
    • Click the [FixMBR] button.
    • Follow the prompts and reboot

    Once back in Windows, rerun MBRCheck .
     
  31. sopheatia

    sopheatia Private E-2

    aswMBR.exe will not open :( I only have 17 processes running some are oping and closing and I can see in the applications tab SysFadr pops up and disapers when I open apps. but nothing happens when i try to open aswMBR.exe
     
  32. thisisu

    thisisu Malware Consultant

  33. sopheatia

    sopheatia Private E-2

    It worked. Well kind of. It found 16 traces no identified threats. :) program is still idle right now what should I do?
     
  34. thisisu

    thisisu Malware Consultant

    If it's still idle, try rebooting into and rerunning it. Let us know if still finds a problem.

    If not, attach a NEW log from MBRCheck.
     
  35. sopheatia

    sopheatia Private E-2

    Ran all the way threw. Hears the log.
     

    Attached Files:

  36. thisisu

    thisisu Malware Consultant

    Reboot back into Recovery Console ( the one on the CD / _not_ the one built in into your hard drive )
    type in map in the command prompt again.
    give me the output once again.
    Await for further instructions.
     
  37. thisisu

    thisisu Malware Consultant

    You may want to give this tool a try: http://pxnow.prevx.com/antipopureb.exe
    Save it to your desktop and run.
    It's about the only infection I've heard of that will prevent you from restoring a clean MBR.

    The AntiPopurb_Log.txt will appear on your desktop when it has finished. Attach this log to your next message
     
  38. sopheatia

    sopheatia Private E-2

    :) Here it is. Hope that worked
     

    Attached Files:

  39. sopheatia

    sopheatia Private E-2

    map is still the same;

    C: NTFS 39198MB \Device\Harddisk4\Partition1
    I: 9MB \Device\Harddisk4\Partition2
    H: \Device\CdRom0
     
  40. thisisu

    thisisu Malware Consultant

    If map is still the same, type the following

    fixmbr \device\harddisk4

    Not sure why this is not correcting your MBR yet. You're absolutely positive you're running off of the CD correct?
     
  41. sopheatia

    sopheatia Private E-2

    It said that it was a success. Ran an MBR cheek and this is what it came up with.
     

    Attached Files:

  42. sopheatia

    sopheatia Private E-2

    Is that what is supposed to happen ?
     
  43. thisisu

    thisisu Malware Consultant

    It sounds like you are doing it correctly to me.

    I don't mean to doubt you. It's honestly just because I have never seen fixmbr from CD unable to restore a clean MBR. I do not think the other Malware Fighters have either.

    You aren't the only one experiencing this problem now though, there are multiple threads currently active where fixmbr / bootrec /fixmbr is simply not resolving the MBR infection.

    How are things running on the PC? You are still getting redirected correct?

    Please be patient as we try to think of other ideas.
     
  44. thisisu

    thisisu Malware Consultant

    We may have to remove a partition from a CD, first let me know if you are able to see it in Windows.

    Open My Computer, what Hard Disk Drives are listed?
    Do you see any parititon that is around 8-9MEGABYTES (MB) ?

    If so, what is the drive letter of this partition?
     
  45. sopheatia

    sopheatia Private E-2

    Its OK. :) I understand you guys are doing your best. I've never seen any thing like this either. That why I am working with you to try a solve this puzzle :major .

    Things are a little messed up. It is almost like I am using just a fragment of windows OS to manage. Kind of like I'm in safe mode only not. It is hard to describe. Yes, I believe the redirection problems are still there but not as bad as before. My home page has changed itself to MSN. It has been so long since I changed it I forgot how to put it back:-D.

    There is only one HD that is showing [ Local Disk {C:} ] . Not seeing anything about a partitions.
    No name. Type: Local Disk. File system: NTFS. Used space: 36,296,814,592bytes 33.8 GB. Free space 4,804,874,240bytes 4.47 GB. Capacity: 41,101,688,832bytes 38.2 GB. Allow Indexing Service to index this disk for fast file serching. All disk drives: Name- Maxtor 6E040L0 Type- Disk drives, Name- HL-DT-ST DVDRRW GWA-4166B Type- DVD/CD-ROM drives.
    WARNING{Volumes} Volume information for this disk cannot be found. This may happen if the disk is a 1394 or a USB device on a Windows 2000 machine.
    Location: Location 0 (0). Manufacturer: (Standard disk drives). Device status: This device is working properly. Policies: Enable write caching on the disk. Driver Provider: Microsoft. Driver Date: 7/1/2001. Driver Version: 5.1.2535.0. Digital Signer: Not digatally signed.
    Driver files:
    C:\WINDOWS\system32\DRIVERS\disk.sys
    C:\WINDOWS\system32\drivers\PartMgr.sys

    I didn't know what to look for so i wrote down everything i could find. Note: I wouldn't let me populate the volumes.

    I am able to see the CD on windows.

    Just let me know what to do next.:-D
     
  46. thisisu

    thisisu Malware Consultant

    Start > Run > diskmgmt.msc
    A window called "Disk Management" should open.

    Can you take a picture of what is here?
     
  47. sopheatia

    sopheatia Private E-2

    Ran the disk management and it came up with this error message: [Logical Disk Manager] The RPC server is unavailable.

    Disk Management screen said: Unable to connect to Logical Disk Manager service.

    How do you take a screen shot? Never done it before.
     
  48. thisisu

    thisisu Malware Consultant

    Were you in Safe Mode when you attempted that?

    Doesn't really matter now. Here are the steps to resolve your MBR infection.

    You may want to print out the rest of these instructions.
    -------------------------------------------------------
    I am still working out the kinks of this procedure so let me know if you have any questions before proceeding. A lot of problems with the partition tables are caused by this infection and can take some time to fully resolve.

    First, download Download gparted-live-0.10.0-3.iso (115.1 MB)
    You will need a blank CD to burn this ISO to. You can burn the .ISO using software like ImgBurn.

    Now boot off of this newly created CD.

    http://img829.imageshack.us/img829/5772/gpartedsplash.th.png
    You should be here...
    Press ENTER

    http://img5.imageshack.us/img5/7286/gpartedkeymaps.th.png
    By default, "do not touch keymap" is highlighted. Leave this setting alone and just press ENTER.

    http://img404.imageshack.us/img404/9840/gpartedlanguage.th.png
    Choose your language and press ENTER. English is default [33]

    http://img140.imageshack.us/img140/7958/gpartedgui.th.png
    Once again, at this prompt, press ENTER

    You will now be taken to the main GUI screen below
    http://img32.imageshack.us/img32/1122/gpartedo.th.png
    According to your logs, the partition that you want to delete is 8.02 MB (MiB)
    Click the trash can icon to delete and then click Apply.

    You should now be here confirming your actions:
    http://img233.imageshack.us/img233/1533/gpartedsteps.th.png

    Now you should be here:
    http://img696.imageshack.us/img696/8471/gpartedsuccessclose.th.png

    http://img194.imageshack.us/img194/7753/gpartedboot.th.png
    Is "boot" next to your OS drive? -- According to your logs, your OS drive is the 38GB (GiB) size partition.

    If "boot" is not next to your OS drive under "Flags", right-mouse click the OS drive while in Gparted and select Manage Flags

    In the menu that pops up, place a checkmark in boot like the picture below:
    http://img196.imageshack.us/img196/3483/gpartedmanageflagsboot.th.png

    Now double-click the http://img822.imageshack.us/img822/641/gpartedexit.png button.

    You should receive a small pop up like this:
    http://img88.imageshack.us/img88/8986/gpartedexitreboot.png
    Choose reboot and then press OK.

    Now reboot into the Windows XP recovery console USING THE CD and execute the following commands from the command prompt:

    • fixmbr
    • fixboot
    • exit

    Once back in Windows, attempt to rerun MBRCheck and attach its latest log.
     
  49. sopheatia

    sopheatia Private E-2

    That was amazing ;)
     

    Attached Files:

  50. thisisu

    thisisu Malware Consultant

    :cool

    Are you having any other issues?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds