help win64/patched.a and more

Discussion in 'Malware Help (A Specialist Will Reply)' started by brownstarpink, Feb 23, 2013.

  1. brownstarpink

    brownstarpink Private E-2

    so I have an infected file "system32" on top of that there is an installer file 57e77af6-bc3a-14be-5b2d-1abc9d4c6878 that keeps trying to automatically install a flash player every minute. I have tried an AGV boot/repair disk and it didnt help so I am here reaching out for help, I have done all the steps as per the read first and await instruction.

    thanks in advance
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have not completed them until you attach the requested logs. ;)
     
  3. brownstarpink

    brownstarpink Private E-2

    I read the wrong how to woops :p

    ok so i did these instructions and it put a lock next to some of the files I was talking about....neat.

    I have attached the two logs

    thanks again for being patient
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. brownstarpink

    brownstarpink Private E-2

    ok I am walking on eggshells now :) I have gone over both the threads I was on three times to make sure I have completed everything. After doing so alot of the suspicious activity has seemed to stop over the last few days. only thing that seemed sideways is some wonky desktop icon stuff which probably means nothing.

    Thanks for your time in reviewing my problem.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you have a Zero Access infection. We need to run another scan tool to collect another log. Then we will be able to work up a fix.

    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  7. brownstarpink

    brownstarpink Private E-2

    ok, it is attached
     

    Attached Files:

  8. brownstarpink

    brownstarpink Private E-2

    Oracle America keeps trying to instal something that looks to do with java, so far I have been saying no as I want to wait until we are finished to make any changes. If you say its ok to instal it though I will
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you knowingly put the below on your PC and do you know that they are valid?



    Download this >> View attachment fixlist.txt


    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows and continue with the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. brownstarpink

    brownstarpink Private E-2

    "C:\Users\Owner\Desktop\New folder\prime95.exe

    WiFi2HiFi.lnk @Owner : C:\Users\Owner\AppData\Roaming\Microsoft\Installer\{A25D5B05-29A2-4493-9E31-4B7487580607}\_B59FE27F021882CD5B9C31.exe"

    I cannot vouch completely for the above, It was an iphone/desktop ap that transmits the sound from my desktop to my iphone. I assumed being an iphone ap it was safe.

    when scan was running a pop up appeared about a steel werx who am i application being stopped. I also get prompted to instal jucheck.exe over and over again. Other then that things are running smooth

    I have attached new logs.
     

    Attached Files:

  11. brownstarpink

    brownstarpink Private E-2

    the java update automatically trying to install seems to have stopped.

    the wifi2hifi aplication is starting up with my computer and running in the background. I cant confirm if they are trustworthy but assumed they were since they are distributed through itunes.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then we will ignore it unless you are still having problems.

    Your logs are clean, but you have some damage to repair from the infection.



    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. brownstarpink

    brownstarpink Private E-2

    thanks again for the help

    I have attached the file

    no problems so to speak of. after the last bit the firewall blocked wifi2hifi which doesnt even work like its supposed to anyways so ive left that alone, it also blocked filemaker which is a shared program around here so i opened that one up.

    other then that its been smooth sailing.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Looks good now.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds