Trojan Horse Crypt.ANVH in AFD.SYS

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by widmerj1, Jan 10, 2012.

  1. widmerj1

    widmerj1 Private E-2

    I have reviewed the entire Vista and Win 7 Malware Removal/Cleaning Procedure document and am confident that I can execute it. However, prior to doing so I would just like to ask if that is your recommended process for this problem. My AVG had the file whitelisted and I read elsewhere that it was not a good idea to "remove" those files.

    If you think I should follow the guidelines prescribed here I will certainly do so.
    Thanks!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Correct! Don't remove it.

    Yes you should follow our cleaning procedure and attach the logs we requesst. DO NOT RUN any scans with AVG. In fact, it is recommended to uninstall AVG so that you can properly run ComboFix and to avoid having AVG get in the way of malware removal.
     
  3. widmerj1

    widmerj1 Private E-2

    I first started with the Fixing Google Redirection/Hijacking Problems list of steps.

    Attached are the two logs that were generated from GooredFix and tdsskiller.exe

    It appeared to me that the GooredFix.txt did not solve the problem so I proceeded on. The tdsskiller.exe found the exact item I described and suggested to "CURE" the item. After reboot the problem did not seem to be there any longer.

    I was not sure if I should go on to the MBR and beyond to the full cleaning.

    Please advise.

    Thank you!!!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While this is useful because we would have asked you to run some of these steps later, it will not fix this problem.

    Your TDSSkiller log shows the below two items. Run TDSSkiller again and if they still show, delete them and only them:

    23:15:52.0999 5992 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
    23:15:53.0000 5992 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip


    Yes get the log from MBRcheck and attach it and then immediately move on to the READ & RUN ME core instructions as this is what we will need information from inorder to provide manual fixes that will still be necessary.
     
  5. widmerj1

    widmerj1 Private E-2

    OK. Here are the newest logs for tdsskiller and MBR.

    Now working on all of the Malware Removal steps.

    Will post logs as they become available.

    Thanks.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No. Please complete all the steps and then attach all the logs. We cannot work up a fix until we have all the results.
     
  7. widmerj1

    widmerj1 Private E-2

    Sorry. Meant to say, "when all of the logs are available".
     
  8. widmerj1

    widmerj1 Private E-2

    SuperAntiSpyware was running when I went to bed. The log said it completed but I was not able to do the following steps:


    • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
    • Make sure everything has a checkmark next to it and click "Next".
    • A notification will appear that Quarantine and Removal is Complete. Click OK and then click the Finish button to return to the main menu.
    • If asked if you want to reboot, click Yes.

    I do not see a place to get at the threats it found and quarantine them.

    Do I need to run this again before moving on?

    Thanks.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just continue on.
     
  10. widmerj1

    widmerj1 Private E-2

    After reboot I have no network on the PC. My original home network is gone. My wireless network is visible but has limited - no Internet access.

    I am sending this via iPad which is still able to use the wireless network.

    I have tried to restart the modem and router and computer to no avail.

    Any solution to this before I move on?

    Thanks
     
  11. widmerj1

    widmerj1 Private E-2

    I used a System Restore Point (from after the middle of the night reboot when SAS had completed but I did not get to quarantine) to reestablish my network and internet.

    What now? Should I now move on to Malware Bytes and the rest of the steps? I'm worried about losing the internet connection again.
     
    Last edited: Jan 13, 2012
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes. We need the other logs so that we can properly help you. They will contain the information we will need to get things fixed up.
     
  13. widmerj1

    widmerj1 Private E-2

    I got through Malwarebytes without any issues.

    Combofix has been sitting on the Scanning for Infected files...this usually takes 10 minutes screen for nearly two hours.

    It never reached the message about changing the time.

    Should I let it continue or kill it?

    If I kill it what should I do next? Try combofix again or move on?

    Thanks
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    More than likely, you will not be able to kill ComboFix and may have to hold in the power button to shut down your PC.

    Do not attempt to run ComboFix again. Just move on to the next steps. But do tell me whether you had all protection software disabled? Also is User Account Control ( UAC ) disabled?
     
  15. widmerj1

    widmerj1 Private E-2

    How long should RootRepeal take? It has been sitting on the Initializing, please wait screen for around two hours. I now it is working because it found "hibefil.sys" locked to windows.api

    Thanks.

    By the way, I let ComboFix run through the night and I do have a log for it as well as SAS and Malwarebytes so I'm close to being able to send all of the logs.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can terminate RootRepeal and move on to MGtools which at this point is going to be the most important log we need.
     
  17. widmerj1

    widmerj1 Private E-2

    At long last, here are my logs.

    There is no file for RootRepeal as it did not run properly.

    Thanks.

    James
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download Farbar Service Scanner and run it on the computer with the issue.
    • Make sure "Include All Files" option remains checked.
    • Press "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please attach this log to your next reply.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After attaching the log from Farbar's Service Scanner, continue with the below.
    First please run MSconfig and put your PC into normal startup mode as requested in step 4 of the READ & RUN ME.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS2\Services\Tcpip\..\{21A7F731-933E-43A9-BA4A-BD74EE16153C}: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS3\Services\Tcpip\..\{21A7F731-933E-43A9-BA4A-BD74EE16153C}: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS4\Services\Tcpip\..\{21A7F731-933E-43A9-BA4A-BD74EE16153C}: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS5\Services\Tcpip\Parameters: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS5\Services\Tcpip\..\{21A7F731-933E-43A9-BA4A-BD74EE16153C}: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS6\Services\Tcpip\Parameters: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS6\Services\Tcpip\..\{21A7F731-933E-43A9-BA4A-BD74EE16153C}: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS7\Services\Tcpip\Parameters: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS7\Services\Tcpip\..\{21A7F731-933E-43A9-BA4A-BD74EE16153C}: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS8\Services\Tcpip\Parameters: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS8\Services\Tcpip\..\{21A7F731-933E-43A9-BA4A-BD74EE16153C}: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS9\Services\Tcpip\Parameters: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS9\Services\Tcpip\..\{21A7F731-933E-43A9-BA4A-BD74EE16153C}: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS10\Services\Tcpip\Parameters: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS10\Services\Tcpip\..\{21A7F731-933E-43A9-BA4A-BD74EE16153C}: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS11\Services\Tcpip\Parameters: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS11\Services\Tcpip\..\{21A7F731-933E-43A9-BA4A-BD74EE16153C}: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS12\Services\Tcpip\Parameters: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS12\Services\Tcpip\..\{21A7F731-933E-43A9-BA4A-BD74EE16153C}: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS13\Services\Tcpip\Parameters: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS13\Services\Tcpip\..\{21A7F731-933E-43A9-BA4A-BD74EE16153C}: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS14\Services\Tcpip\Parameters: NameServer = 93.188.163.205,93.188.160.125
    O17 - HKLM\System\CS14\Services\Tcpip\..\{21A7F731-933E-43A9-BA4A-BD74EE16153C}: NameServer = 93.188.163.205,93.188.160.125
    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  20. widmerj1

    widmerj1 Private E-2

    Here is the FSS.txt

    Now starting on the next list of instructions.
     

    Attached Files:

    • FSS.txt
      File size:
      3.3 KB
      Views:
      5
  21. widmerj1

    widmerj1 Private E-2

    I could not find those O17 lines in HJT. Please see log.

    I did not do any fixing or move on to ComboFix yet.

    Should I proceed with the rest of the instructions?
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, also do the below to fix a problem that is stopping some services from running.
    • Please click Start, and type regedit into the search box.
    • You should see a regedit.exe and icon appear in the Programs area of the Start Menu.
    • Right click on regedit.exe and select Run As Administrator.
    • Then in the Registry Editor click File, Import.
    • Navigate your way to the C:\MGtools folder and locate the FixW7FW.reg file and select it.
    • Then click the Open button and allow this to be added into your registry
    • Tell me what happend exactly. Like do you get any error messages or do you get a success message?
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Continue on anyway and see my other message about importing a registry patch.
     
  24. widmerj1

    widmerj1 Private E-2

    "Cannot import C:\MGTools\FixW7FW.reg:Error accessing the registry."
     
  25. widmerj1

    widmerj1 Private E-2

    Combofix asked to update and is now running "restore point, etc."
     
  26. widmerj1

    widmerj1 Private E-2

    Here are the logs requested.

    Thank you.
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are looking much better now. One more fix to do.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  28. widmerj1

    widmerj1 Private E-2

    Here are the most recent logs.

    Thank you.
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not address what I requested in the last line of my previous message
     
  30. widmerj1

    widmerj1 Private E-2

    Sorry about that. Everything seems to be working great at this point.;)
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good because your logs are clean. ;)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  32. widmerj1

    widmerj1 Private E-2

    I can't thank you enough.

    I will work through the suggested items to protect against future Malware attacks.

    The only thing I see that may not have worked 100% is the MGTools cleanup left behind an assortment of files in the C:\MGTools\ directory.

    I think this may have happened because I did not realize that my Firewall was running when I clicked on the batch file. It seemed to terminate in the middle when the Firewall asked me to confirm if the program was safe.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this may have cause the full execution to fail. You can either cleanup manually or redownload and run MGtools.exe again. And after it finishes, just make sure your protection is disabled and then run MGclean.bat
     
  34. widmerj1

    widmerj1 Private E-2

    Thanks again. It is a relief to see scans with no problems found.

    I know this is probably not your area but I noticed when I started on the "How to Protect Yourself from Malware" steps that my "Windows Update" has been failing to install since the 13th. I tried most of the things that Microsoft had as suggestions in their support area with no success.

    Any thoughts?
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try shutting down Comodo and any other protection software and see if that helps.

    If not, then try the below.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now open Repair_Windows.exe
    • Go to Start Repairs tab.
    • Choose "Custom Mode" and press "Start".
    • Create a System Restore point if prompted.
    • In the Custom Mode window, select the following repair options:
      • Repair Windows Firewall
      • Repair Internet Explorer
      • Repair Hosts File
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Windows Updates
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • If asked to reboot the computer for the changes to take affect, make sure other tasks in the program are not still running before accepting to restart.
    Reboot after running Windows Repair.


    If neither of those help, try posting in the Software Forum for additional ideas.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds