After-effects of virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by icedcactus, Apr 20, 2013.

  1. icedcactus

    icedcactus Private E-2

    Hi,

    A couple of days ago I got the sirefef virus. I disconnected the computer from the network, Microsoft Security Essentials found & deleted sirefef and I also ran an Avast scan which found nothing.

    The computer is running fine (the only reason I found out I had a virus was because of the 'shutdown in one minute' message, one time) but I have been told it could be in a rootkit or have got into the BIOS? I am just wondering - if the computer seems to be fine and no more threats are being picked up, would it be recommended to re-build the computer just in case? Someone told me I should

    1. unplug existing hard drives
    2. flash the bios
    3. re-build with new hard drives

    just to be sure it is clean.

    Can anyone tell me how necessary all this is?

    Thank you
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to the Malware Removal Forum.

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. icedcactus

    icedcactus Private E-2

    Hi Kestrel, thanks for replying,

    I have followed all the instructions and attached the logs here.

    I had to run the first few things in safe mode because in normal startup I kept getting the blue screen and having to restart - after running the Anti Malwarebytes tool though this was fixed. I haven't connected the infected computer back to the internet yet as I was told not to but updated the Malwarebytes rules manually and used the Early Warning Scoring with Hitman.

    Thanks for your help
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 3 detections:

    • [RUN][SUSP PATH] HKCU\[...]\Run : SearchProtect (C:\Users\Laura\AppData\Roaming\SearchProtect\bin\cltmng.exe) [7] -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-3276226219-2925352310-2859855999-1000[...]\Run : SearchProtect (C:\Users\Laura\AppData\Roaming\SearchProtect\bin\cltmng.exe) [7] -> FOUND
    • [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\Users\Laura\AppData\Local\{ca53cce0-7971-9fa4-266c-e07b040bc62e}\n.) [x] -> FOUND

    Place a checkmark each of these items, leave the others unchecked.

    and the same for items on the files and folder tab.

    • [ZeroAccess][FOLDER] U : C:\Users\Laura\AppData\Local\{ca53cce0-7971-9fa4-266c-e07b040bc62e}\U --> FOUND
    • [ZeroAccess][FOLDER] L : C:\Users\Laura\AppData\Local\{ca53cce0-7971-9fa4-266c-e07b040bc62e}\L --> FOUND

    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Delete this file.
    C:\Windows\SysNative\drivers\08430239.sys

    Delete this folder:
    C:\Users\Laura\AppData\Roaming\SearchProtect

    Re-run RogueKiller again and attach the log.
     
  5. icedcactus

    icedcactus Private E-2

    Hi - I was able to tick next to the registry files in RogueKiller but not the files (no check box) - I think it said 'removed' next to them afterwards though so might have worked? Log is attached.

    I restarted the computer and went to delete the second file and folder, but had some problems - I couldn't see the SysNative folder at all, even with hidden folders enabled. I went to make sure that the hidden option was turned on and it said that the attributes couldn't be applied to all selected items..?

    The SearchProtect folder I could see but couldn't delete, it said the file or folder was open in another program (I don't have any others running).

    Thanks again, will await instructions..
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Windows\SysNative\drivers\[B]08430239.sys[/B]
    C:\Users\Laura\AppData\Roaming\[B]SearchProtect[/B]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Rerun RogueKiller again and attach the log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  7. icedcactus

    icedcactus Private E-2

    Hi - logs attached.

    Not sure if it's relevant but while the MGtools was running a bubble popped up on the task bar saying "pevFind.exe - Corrupt File. The file or directory C:\$Mft is corrupt and unreadable. Please run the Chkdsk utility."
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run RogueKiller, and attach the new log for me to see and then explain to me how things are running for you.
     
  9. icedcactus

    icedcactus Private E-2

    Hi

    New log attached.

    I think everything is running OK.. I had one blue screen yesterday but none today. Have not been getting any 'shutdown in one minute' notifications and the one telling me to run Chkdsk is gone.

    ...all good??
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 3 detections:
    • [RUN][SUSP PATH] HKCU\[...]\Run : SearchProtect (C:\Users\Laura\AppData\Roaming\SearchProtect\bin\cltmng.exe) [7] -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-3276226219-2925352310-2859855999-1000[...]\Run : SearchProtect (C:\Users\Laura\AppData\Roaming\SearchProtect\bin\cltmng.exe) [7] -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)

    Reboot the machine.

    Now rerun RogueKiller again. Attach new log.

    Delete this folder.
    C:\Users\Laura\AppData\Roaming\SearchProtect

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!

     
  11. icedcactus

    icedcactus Private E-2

    Hi again -

    I got as far as the second RK scan but same problem as last time with the folder, it says it is being used in another program.. logs attached.. I think RK found the same files I just deleted the second time though :(

    When I rebooted, it recommended letting it run chkdsk before startup so I did.. when it did start, I could no longer use Firefox (it just keeps crashing on startup). It said it can reset itself so I let it but did not help.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Repeat my steps in post number 10 for RogueKiller.


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Users\Laura\AppData\Roaming\SearchProtect
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Re run RogueKiller again and attach log.
     
  13. icedcactus

    icedcactus Private E-2

    Hi - logs attached.

    I deleted the two files in RK, then used OTM to move the other folder.

    OTM wanted a restart so I let it, then when I ran RK again the two files were back.. they won't die!!
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


    Code:
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "SearchProtect"=-
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "SearchProtectAll"=-
    [HKEY_USERS\S-1-5-21-3276226219-2925352310-2859855999-1000\Software\Microsoft\Windows\CurrentVersion\run]
    "SearchProtect"=-
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Rerun RogueKiller --- still there?
     
  15. icedcactus

    icedcactus Private E-2

    I don't want to jinx it but.. I think they might have gone?!

    Logs attached.. I even restarted twice after OTM to make sure!
     
  16. icedcactus

    icedcactus Private E-2

    oops.. actually attached this time
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, it certainly looks to be gone now. How are things running?
     
  18. icedcactus

    icedcactus Private E-2

    It still wants me to do the system repair startup instead of 'start windows normally' when i restart.. but I think that may have been happening before the virus anyway. Otherwise all good! Would you recommend doing anything further?
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes you can ask about that in the software forum. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  20. icedcactus

    icedcactus Private E-2

    Done and done!

    Thanks so much for all your help.. you are amazing!
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds