Bad Bad Infection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by HKGuns, Sep 23, 2011.

  1. HKGuns

    HKGuns Private E-2

    Ok, I ran through all the required steps and whatever I have is thwarting everything but MGTools.

    (All done in safe mode)
    SAS - On C drive -Starts to run and is terminated shortly after starting to scan.
    SAS - .com file -Starts to run and is terminated shortly after starting to scan.
    MB.exe -Even took the step of renaming it MT.exe as it appears whoever wrote this infection reads the scripts on this site. -Terminates shortly after starting to scan.
    combofix - Cannot get it to run in safe mode.

    Attached is the log file generated by MGTools which is the only software that would run.

    Other symptoms. Trend Micro Internet security was disabled and will not run due to a "permissions" issue. Windows defender is having a "DLL conflict". I also have a process running that is 100% not normal, it is named "1891711943:952XXX.exe". Edited to add: Obviously I've tried killing this process and it won't kill.

    Help is appreciated, I'm not a novice, but I'm not nearly as skilled as most of you are on this site.
     

    Attached Files:

  2. HKGuns

    HKGuns Private E-2

    Updated to add: I was able to get combofix to run and it says I am infected with rootkit zero access. I will post an update once I've run that through its course. Not sure why it wouldn't run and then suddenly ran fine. This really cheezes me off as I was only reading sports articles when I was infected.

    I can follow one of the other threads for this infection now that I know what I am dealing with. Thanks for looking!
     
  3. HKGuns

    HKGuns Private E-2

    Ran through the other thread on the rootkit removal. Could someone please give me a clean bill of health or make suggestions on further work I need to do?
     

    Attached Files:

  4. HKGuns

    HKGuns Private E-2

    Here is the win32kdiag attachment log as I could only add four on the last response.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any problems in your logs. However, let's have you do one more thing:

    Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  6. HKGuns

    HKGuns Private E-2

    Thanks so very much Tim! Here are the two files generated by the scan. (Note that this happened on Friday around 4:00PM or so, could be off by a couple of hours.) Since getting clean I have re-installed Trend Micro, Quick Time and Windows Defender.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look good. What malware issues are you still having, if any?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Wise word of advice: You should NOT be implementing fixes on your machine which were tailored uniquely for someone else's machine!! You could break your PC this way.
     
  9. HKGuns

    HKGuns Private E-2

    No issues. Just looking for confirmation from someone who knows a lot more than I do about this.....Like, not to use information in another thread for the same virus.

    Thanks for the advice Kestrel, I sort of figured that out after I was in mid stream with the repairs. I thought it was virus specific and not machine specific, but it makes sense that it is machine specific.

    Thanks so much for all your help! This is a great site and you all deserve medals for the work you do against these flippin criminals.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0


    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds