6 Hidden Objects all over again

Discussion in 'Malware Help (A Specialist Will Reply)' started by mfozaydin, Jul 12, 2012.

  1. mfozaydin

    mfozaydin Private E-2

    Major Geeks,

    This is the real Deja Vu! My Avira scan gave me the same exact Root Kit files that I had back in September of last year, how can It be????? It was a long process and I can't believe I had to go through this again. Please help.

    Thanks.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Exactly what objects are you referring too? Attach a log. Many hidden objects can be normal.



    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
    Last edited: Jul 13, 2012
  3. mfozaydin

    mfozaydin Private E-2

    Chaslang,

    You can see these objects in the Avira scan results that I am attaching as well.These "6 hidden objects" are the same as 10 months ago, you can go back to my old threats with "Thisisu" and compare them. Here are all the scan results that I ran.

    Thanks.
     

    Attached Files:

  4. mfozaydin

    mfozaydin Private E-2

    Here they are.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you seem to have run the READ & RUN ME, I'll assume you forgot to attach the log from MGtools but you do have it installed.

    Shutdown ALL protection software before you run the below.

    Now download The Avenger by Swandog46, and save it to your Desktop.

    See the download links under this icon http://www.majorgeeks.com/images/dll.gif
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. mfozaydin

    mfozaydin Private E-2

    Chaslang,

    I ran the Avenger first but my laptop couldn't reboot I kept getting the BSOD so I started to Last Good Configuration. I ran the MGTools and am attaching the log.

    Thanks.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is of no use to us until Avenger ( or any other fix ) runs properly. Let's try a different way.

    Download and save combofix.exe directly on to your Desktop. Do not run it yet. Just save it!

    Uninstall Avira and Malwarebytes and then reboot your PC.

    After reboot, let's try the below fix with ComboFix. If for any reason, ComboFix does not run in normal boot mode, try again in safe mode.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now make sure that you are in normal boot mode and also only run GetLogs.bat if ComboFix successfully ran.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
     
  8. mfozaydin

    mfozaydin Private E-2

    Chaslang,

    I was able to reboot this time without BSOD. Here are the logs.

    Thanks.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. One more fix with ComboFix.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. mfozaydin

    mfozaydin Private E-2

    Chaslang,

    Here are the new logs.

    Thanks.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That did not work. Did you have any problems running ComboFix? Was all protection shutdown? I still see PC Tools Firewall.

    Try repeating all of last fix after booting into safe boot mode. Attach new logs.
     
  12. mfozaydin

    mfozaydin Private E-2

    Chaslang,

    It is my bad actually I may not have disabled the PC Tools Firewall Plus so I ran them both again please check the new logs and if it still did not work then I will proceed with your new instructions, let me know.

    Thanks.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Still did not work! Something else may be hiding that is blocking the fix. However please try it again in safe boot mode and then we will see if we need to try some other method and also possibly may need to run some other scans.
     
  14. mfozaydin

    mfozaydin Private E-2

    I tried to run the Avenger in safe mode but I got the BSOD again so I rebooted to last good configuration.

    Thanks.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Avenger????? Did you mean you ran the previous ComboFix procedure in safe mode?
     
  16. mfozaydin

    mfozaydin Private E-2

    Chaslang,

    I first ran the Avenger in safe mode the reason was that I thought you meant that one first:confused then I got the message and I ran the Combo Fix (shorter quote) in safe mode and am attaching the logs.

    Thanks.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay there is definitely something else hiding on your PC. The bad driver files are starting to multiply.

    Please run GMER per the below and attach the GMER log

    GMER - running with a random name


    Also run the below online scan from ESET and attach the log from ESET. Note it will likely tell you about the process.exe file in the MGtools folder. It is not a problem.

    Using ESET's Online Scanner
     
  18. mfozaydin

    mfozaydin Private E-2

    Chaslang,

    Here are the logs for GMER and ESET.

    Thanks.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please uninstall PC Tools Firewall.

    Also if you have not disabled Daemon Tools ( disk emulation per step 4 of the READ & RUN ME, please do this now ).


    Now please download the current version of combofix.exe and save it directly onto your Desktop



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run a new scan with GMER save the log to attach.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • the new GMER log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  20. mfozaydin

    mfozaydin Private E-2

    Chaslang,

    Here are all the logs. My laptop is running just fine except for I have uninstalled the protection software both the Avira and the PC Tools Firewall Plus for the removal process.

    Thanks.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay the registry keys we were trying to fix still did not get removed. There could be a permissions issue with the registry key. Let's try a fix to this and then see what happens.


    Now download SubInACL.msi from Microsoft.
    • Now double click on SubInACL.msi to run the installer. Accept any prompts you get about installing this.
    • Now download the below file and save it to your Desktop:
    • Now double click on resetperm.cmd to run this script. Be patient as this may take awhile to run.
    Once it finishes, reboot your PC.

    Now assuming the above ran properly, repeat the whole fix from message # 19 again.
     
  22. mfozaydin

    mfozaydin Private E-2

    Chaslang,

    1)I am unable to download the "resetperm.cmd", when I click on it message below appears, It is not a downloadable link.

    2) I re-did the procedure you outlined on message #19 anyway so I am attaching the logs. Once we resolve this I will also do it again after running resetperm.cmd as you mentioned.

    cd /d "%programfiles%\Windows Resource Kits\Tools"

    subinacl /subkeyreg HKEY_LOCAL_MACHINE /grant=administrators=f /grant=system=f /grant=users=r /grant=everyone=r /grant=restricted=r /setowner=administrators
    subinacl /keyreg HKEY_LOCAL_MACHINE /grant=administrators=f /grant=system=f /grant=users=r /grant=everyone=r /grant=restricted=r /setowner=administrators

    subinacl /subkeyreg HKEY_CLASSES_ROOT /grant=administrators=f /grant=system=f /grant=users=r /setowner=administrators >> %temp%\subinacl_output.txt
    subinacl /keyreg HKEY_CLASSES_ROOT /grant=administrators=f /grant=system=f /grant=users=r /setowner=administrators

    subinacl /subdirectories %programfiles%\ /grant=administrators=f /grant=system=f /grant=users=e

    subinacl /subdirectories %windir%\ /grant=administrators=f /grant=system=f /grant=users=e

    subinacl /subkeyreg HKEY_LOCAL_MACHINE\system\currentcontrolset "/grant=nt service\trustedinstaller=f" "/grant=nt service\bfe=f" "/grant=local service=f" "/grant=network service=f" "/grant=nt service\dhcp=f" /grant=administrators=f /grant=system=f /grant=users=r /grant=everyone=r /grant=restricted=r /setowner=administrators >> %temp%\subinacl_output.txt

    subinacl /keyreg HKEY_LOCAL_MACHINE\system\currentcontrolset "/grant=nt service\trustedinstaller=f" "/grant=nt service\bfe=f" "/grant=local service=f" "/grant=network service=f" "/grant=nt service\dhcp=f" /grant=administrators=f /grant=system=f /grant=users=r /grant=everyone=r /grant=restricted=r /setowner=administrators >> %temp%\subinacl_output.txt
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know what you mean. The link works just fine I guessing that you are not "downloading" it but rather are trying to run it. The output you showed ( and that is not a message it is the script showing what it is running ) is what is inside of the resetperm.cmd file.

    You need to downloaded it and save it to your PC as requested and try running it.

    Are you familiar with running the Registry Editor?

    Also side note, you should uninstall this >> Ask Toolbar
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Almost forgot. I also want you to run the below scan.

    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double click on the OTL icon on your desktop. (If running Vista or Win7 right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the Customs Scans/Fixes text-field.
      Code:
      netsvcs
      /md5start
      afd.sys
      atapi.sys
      csrss.exe
      dhcpcsvc.dll
      explorer.exe
      lsass.exe
      nsiproxy.sys
      regedit.exe
      services.exe
      svchost.exe
      tcpip.sys
      tdx.sys
      userinit.exe
      winlogon.exe
      /md5stop
      %systemdrive%\*.*
      %systemroot%\*. /mp /s
      %systemroot%\system32\*.sys /90
      %systemroot%\system32\*.exe /lockedfiles
      %systemroot%\system32\drivers\*.sys /lockedfiles
      %allusersprofile%\application data\*.exe
      
    • Now click the Run Scan button.
    • Two reports will be created:
      • OTL.txt <-- Will be opened
      • Extra.txt <-- Will be minimized
    • Attach both OTL.txt and Extras.txt to your next message. (See how to attach)
     
  25. mfozaydin

    mfozaydin Private E-2

    Chaslang,

    Here are all the logs except for "extra.txt" which wasn't created at the end of OTL scan.

    Thanks.
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now the reset of permissions appears to have worked because those items are not longer showing in GMER.

    Now shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Code:
    :OTL
    DRV - File not found [Kernel | Unavailable | Unknown] -- globalroot\C:\WINDOWS\system32\drivers\41223D.sys -- (41223D)
    IE - HKU\S-1-5-21-1455177488-1803624957-2378349180-1006\..\SearchScopes\{9F0F5B57-C7AD-4E78-8279-E9EAB2BAB777}: "URL" = [URL]http://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10400&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=^ABY&apn_dtid=^YYYYYY^YY^US&apn_uid=c254ad52-6c57-46bf-a6c6-b889205dc600&apn_sauid=44680646-3236-4963-9F8B-6CA5280DDC0D[/URL]
    FF - prefs.js..browser.search.order.1: "Ask.com"
    FF - prefs.js..browser.search.selectedEngine: "Ask.com"
    [2012/07/26 21:15:59 | 000,002,344 | ---- | M] () -- C:\Documents and Settings\M.Fevzi Ozaydin\Application Data\Mozilla\Firefox\Profiles\6ba90qyz.default\searchplugins\askcom.xml
    [2008/10/31 01:50:57 | 000,013,434 | ---- | C] () -- C:\Program Files\Common Files\ziry._dl
    [2008/10/30 23:33:13 | 000,014,474 | ---- | C] () -- C:\Documents and Settings\M.Fevzi Ozaydin\Application Data\sipeher.dl
    [2008/10/30 23:33:13 | 000,014,311 | ---- | C] () -- C:\Program Files\Common Files\wybyge.dat
    [2008/10/30 23:33:13 | 000,010,691 | ---- | C] () -- C:\Program Files\Common Files\uwexaw._dl
    [2008/10/30 21:24:15 | 000,012,410 | ---- | C] () -- C:\Documents and Settings\M.Fevzi Ozaydin\Application Data\nafe.dat
    [2008/10/30 21:24:14 | 000,019,998 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\giwubisyc.pif
    [2008/10/30 21:24:14 | 000,015,128 | ---- | C] () -- C:\Program Files\Common Files\uwan._sy
    [2008/10/30 21:24:14 | 000,014,662 | ---- | C] () -- C:\Program Files\Common Files\nubyzip.lib
    [2012/07/15 11:14:06 | 000,001,150 | ---- | M] () -- C:\bmnuq.txt
    :Commands
    [PURITY]
    [EMPTYTEMP] 
    [EMPTYFLASH]
    [REBOOT]
    • Now click the http://img3.imageshack.us/img3/407/otlrunfix.png button.
    • If the fix needed a reboot please do it.
    • Click the OK button (upon reboot).
    • When OTL is finished, Notepad will open. Close Notepad.
    • A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    • Attach this log to your next message. (See: How to attach)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the log from OTL
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  27. mfozaydin

    mfozaydin Private E-2

    Here they are:
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good. Let's get one more log from GMER just to make sure the below are really gone.
    Code:
    Reg             HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys@start                                                                1
    Reg             HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys@type                                                                 1
    Reg             HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys@imagepath                                                            \systemroot\system32\drivers\TDSSmhct.sys
    Reg             HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys@group                                                                file system
     
  29. mfozaydin

    mfozaydin Private E-2

    Here it is:
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  31. mfozaydin

    mfozaydin Private E-2

    Chaslang,

    Thanks a lot for your help on this matter. Laptop is fine and dandy but the question is now, am I a 10 type now if not how can I become one? :major

    Best regards.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds