Abnormally hard to purge re-direct malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by wyldmage, May 6, 2010.

  1. wyldmage

    wyldmage Private E-2

    So, first off, I'm generally quite capable of handling malware/viruses on my own, but am closing in on 24 hours at hunting through forums (including this one), multiple restarts, safe modes, etc, and still no luck...

    What I have left (the other parts of whatever I caught) is merely redirecting browser clicks, particularly from Google searches.

    As I post this, going through the stickied posts to make sure I provide the information needed:

    Operating system: Vista 32 bit (computer is about a year old)
    Anti-virus currently installed: AVG

    I do have msconfig controlling my startup, because I don't know how to actually remove all the orphaned entries. It is far easier to me than going through and actually uninstalling the random crap that came on the laptop (Symantec, Aim, etc). Some programs, such as Aim and MSN, specifically screw with your startup every time you run them, and keeping them disabled via msconfig has worked best for me. Other options would be appreciated, but for now I have it on a controlled startup.

    Programs + Features has been gone through and checked.

    Have downloaded all programs listed under the Vista cleaning thread. Have run the following programs in my efforts BEFORE starting on the list of to-do's listed here:
    Combofix
    HijackThis
    Spybot S&D
    AVG Antivirus
    Malwarebytes
    CCleaner
    Restriction Removal Tool


    SAS scan found a couple issues (log attached)
    Malwarebytes scan found nothing (log attached)

    Combofix restarted the computer (I have Daemon Tools disabled as best I know how, but the virtual drive settings still exist, and required it restarting to disable).
    Then shortly after stage 6A, bluescreen crashed. Moved on to the next step instead of trying repeatedly.

    Ran RootRepeal twice, both times it froze up at "C:\windows\winsxs\Manifests". Second time, I waited 15 minutes (after it reached that point) before giving up.
    Both times, about 5 minutes after closing the window a new error window pops up:


    Error received when running MGtools.exe:
    Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item.
    UAC *is* off however, so I'm not sure where the problem is stemmin from.

    Even after running everything, I still have
    i4jdel0.exe
    located in
    c:\users\username\appdata\local\temp
    which from online searches shows to be a common virus, and undetected by what I've used so far (or at least it hasn't been fully removed)
    Obviously simply deleting the file has not had lasting impact, so it has something pulling it back from another location.

    No logs were generated by the ones that wouldn't run or errored.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you disbled your AV software and any disc emulation software before trying to run MGTools.exe?

    Go to start / programs / accessories / and right click Command Prompt and choose to run it as administrator. Once the command window opens, do this:
    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
     
  3. wyldmage

    wyldmage Private E-2

    Antivirus was entirely closed down (no running processes). Same with disc emulation.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does the C:\MGtools.exe file exist?

    Was the C:\MGtools folder created?
     
  5. wyldmage

    wyldmage Private E-2

    Okay. Actually woke up this time I think before checking the thread...

    MGTools.exe was the file I downloaded. Restarted my computer (drive emulation is on, UAC is off, AV is off). Ran the file again (it is in desktop/install files/ folder). And it worked o_O

    So here's the log

    And now, yes the mgtools.exe file exists in the C:\mgtools folder that was now created.

    Should I bother with the scans requested via the command prompt, or are those included in the zip archive it generated when installed/ran (did both at once i believe).
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See step 6 of the READ & RUN ME. This must be off and it needs to remain off while we are working on removing your infection. Doing otherwise could make it impossible to fix your problem.

    Also while looking at the READ & RUN ME, please see the last part of step 4. You must put your PC into normal startup mode with MSconfig. You should not be using it like this to control startups and services.

    Not following the above instructions has delayed the ability for us to get started and we will also need to get a new log from MGtools.

    Please delete MGtools.exe from this folder. It does not belong here and you don't need it anymore now that it ran and created the C:\MGtools folder

    Not necessary now.

    After completing ALL of the above, please do the below.

    Run this: GMER - running with a random name and attach the log from GMER


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note: You also have AVG9 and Norton 360 installed. You must uninstall one of these immediately before running MGtools again. This was also stated in the beginning of the READ & RUN ME.
     
  8. wyldmage

    wyldmage Private E-2

    I cannot uninstall Norton. When I go to Programs for the uninstall, and click it, it takes about 20 minutes before freezing up. When I terminate the process (after a couple hours waiting), it remains in the uninstall list.

    I think I've gotten Daemon Tools fully "not doing anything" to my system. And I explained why I have msconfig being used. There are over 100 orphaned entries that were still being ran or attempted EVERY startup, some of which were programs that I didn't want to be run and wouldn't turn their startup off via options (MSN, AIM).
    However, have reset it to normal mode.

    Ran the MGtools scan just fine, but both times I've tried running GMER, my system has ended up stalling out (unresponsive) for over 20 minutes. Once after I hit "scan", the second time just on the initial loading.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See step 4 of the READ & RUN ME which gives you better methods for controlling startups.

    Please run this: Finding TDL with RootRepeal

    Attach the requested log
     
  10. wyldmage

    wyldmage Private E-2

    Downloaded the file - RootRepeal.exe

    Attempted to run it, got blue screen.

    Rebooted in safe mode and tried. Blue screen again.

    "Bad_Pool_Data".
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! It is still trying to load and you have not downloaded and run Defogger to your Desktop as requested in step 6 of the READ & RUN ME. We cannot help you if you do not follow our instructions. The use of Daemon Tools is masking the real root of your problems and making it difficult to impossible to locate the real problem. Either uninstall this problematic software or disable it as requested. Then attach a new log from MGtools after running C:\MGtools\GetLogs.bat like you previously have run.

    You downloaded Daemon Tools ( SPTDinst-v169-x86.exe ) on May 6th which is the same day you posted here.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds