ADV Virus Rmvr 2009

Discussion in 'Malware Help (A Specialist Will Reply)' started by legareth, Sep 1, 2009.

  1. legareth

    legareth Private E-2

    My apologies in advance if I'm doing something incorrectly.

    I have read through and attempted to do all of the things in Read & Run First, however in almost all cases I am able to install the software, however I am unable to run all but MGTools.

    HiJackThis runs for about 5 seconds and then simply disappears.
    Malwarebytes' install and runs for about 5 seconds before disappearing
    Combofix will run however receives multiple access denied errors while trying to scan.
    SuperAntiSpyware installs, however disappears after about 5 seconds.
    I tried running the kaspersky online scan, which ran for about 2 hours before disappearing.

    Unable to run regedit. I have run: REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f
    to enable registry, however this does not work when logged in under either standard or safe with networking startup.

    unable to launch taskmanager either.

    I have attached the MGtools log files.

    Any help would be greatly appreciated.

    Thanks,
    Dan
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are seriously infected. We have a lot of work to do to try to get you clean.

    First use add/remove programs and uninstall:
    Windows Antivirus Pro

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    -
    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\Avenger.txt
    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. legareth

    legareth Private E-2

    When I try to run add/remove programs I receive the following message twice.


    Error
    "c:\windows\system32\rundll32.exe" c:\windows\system32\shell32.dll,control_runDLL
    c:\windows\system32\appwiz.cpl

    I was able to insert the registry entries and run avenger, however when the system reboots, combofix does not run.

    I have attached the MGlogs.zip and avenger.txt files for your review.

    I now receive 3 errors every time I try to launch a program such as safari or firefox, then the program launches and appears to work correctly.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let do this as many of the items are still there>

     
  5. legareth

    legareth Private E-2

    Ok, so I downloaded all of the files on to another machine and burned them to a CD and then moved the files into the correct location on the infected machine.

    I ran MGTools.exe by following the instructions provided. The DOS window popped up and ran for approx. 30 seconds and then disappeared and it populated a mglogs.zip file.

    I ran FixAVP.exe and it almost immediately shut down windows. When rebooted the Avenger log file was generated, however the Getlogs.bat file did not run.
    I attempted to run Getlogs.bat myself, however I experienced the same thing. Runs for approx. 30 seconds and then shuts down (I never get a message that the scan is finished even after 1 hour). However this time, theMGlogs.zip file was not generated, meaning that all of files contained in the existing file are time stamped at the time that I ran the original file.

    There is no MGLogs.zip file to attach as none was generated. I did attach the avenger log file as that might have some useful info.


    Thanks,
    Dan
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have one of the new infections that is very difficult to remove. Please do the following:
    Win32KDiag - How to run
     
  7. legareth

    legareth Private E-2

    Ok, so I downloaded the file to my desktop and ran the program. I received an error that I did not have permission to run the file. I changed it from an exe to a com file and reran the program, it ran for about 30 seconds and then failed giving me the error.

    Win32kDiag1.com has encountered a problem and needs to close. We are sorry for the inconvenience.

    Send Error Report or Don't Send Error Report.

    I've attached a log file and will attach another in a few minutes as it appears that they terminated in 2 separate places.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  9. legareth

    legareth Private E-2

    I downloaded Inherit to a clean machine, burned it to a CD and then dragged and dropped from the CD to the infected machines desktop.

    I dropped Win32Kdiag.exe onto inherit.exe and received a message that said ok.

    I double clicked win32kdiag.exe and the program ran for approx. 5 minutes prior to posting this entry to the log file.

    cannot access: c:\windows\erdnt\8-19-2009\default

    then I get the same message as I received before that the program has encountered a problem and needs to close. We are sorry for the inconvenience.

    I'll attach the existing log in just a moment.
     
  10. legareth

    legareth Private E-2

    log attached
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is going to take a few fixes to try to get this sorted.

    First I want you to boot into the recovery console. ( Boot the machine with the OS cd in the drive, then you will chose "R" --> to go to the recovery console).

    At the command prompt, type:
    copy C:\WINDOWS\ServicePackFiles\i386\eventlog.dll C:\eventlog.dll
    Hit enter and then reboot.

    After you reboot:

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.Check your C:\Windows\system32\eventlog.dll ( first making sure it is there ) by right clicking it and choosing properties. Tell me what size it states.

    Now, uninstall any versions of SAS, MBAM already installed.
    Run CCleaner to remove any leftovers from SAS and MBAM.
    Make sure there are no folders existing for SAS or MBAM
    Empty the C:\Documents and Settings\Administrator\Local Settings\Temp folder.
    Now reboot.

    Now download current versions of SAS, MBAM, RootRepeal, ComboFix and run as per R&R ME.

    Now download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Try to run the exe file.

    Attach the below logs assuming all ran
    • avenger.txt
    • SAS
    • MBAM
    • RootRepeal
    • ComboFix
    • MGlogs.zip
    If MGTools does not run, go to start / run / type "cmd" without quotes and then type:
    cd C:\MGTools
    then type:
    ShowNew.bat
    hit enter....see if that runs.

    if not...try:
    GetRunKey.bat

    Let me know if it produces any errors.
     
  12. legareth

    legareth Private E-2

    Ok, so I booted up the machine using the OS disk and attempted to access the recovery console. I was prompted to choose the installation that I wanted to repair of which there is only 1. I was then asked for an administrator password. I have no idea what this is, or what it might be. I tried admin, administrator and leaving it blank.

    Now I can not boot windows at all, in either safe, safe with networking, safe with command prompt or normal. I also tried choosing last known good configuration and still unable to boot windows. The boot process runs for a minute or so, then the HD just stops.

    Any ideas?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you set the boot order in the bios to cd drive first and hard drive second? Is it still set that way?
     
  14. legareth

    legareth Private E-2

    I did not change my boot priority
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is it set at now? If it was set to cd first...then you could or should be able to boot to the cd.

    If set to hard drive first, did you boot to windows and then go into the cd? This would be the wrong way to access the recovery console.
     
  16. legareth

    legareth Private E-2

    Was set to CD,HD,Built LAN.

    I just changed to HD, CD, Built in LAN, however same result.

    The windows loading screen shows and the progress bar goes across for about a minute, then the screen goes blank and stays that way. After about 30 seconds the HD activity stops. Waited for over 1 hour and windows never loaded.


    Truly the only thing I did was attempt to access the recovery console, which required an admin password that I didn't have. I attempted admin, administrator and leaving the password blank. After the 3rd attempt I was forced to reboot and since this, I have been unable to boot into windows.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I should send you to the software forum at this point as we need you to be able to boot to windows. However, at this point you have three options. One is to do a repair installation. You could also slave your hard drive to another computer and we could work to remove the malware that way. Last, you can do a complete reformat and reinstall.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds