Chronic malware removal help?

Discussion in 'Malware Help (A Specialist Will Reply)' started by A_Tiny_Pony, Mar 28, 2010.

  1. A_Tiny_Pony

    A_Tiny_Pony Private E-2

    Hi. So, I hope I'm doing this right, apologies if not. I've gone through the general purpose cleanout a couple of times with no luck, and would like help cleaning this system. will attach the neccessary logs upon request.

    Basically, this is my girlfirend's laptop, and while she can rule out suspicious crack and hack websites and disreputable porn vendors, it's nevertheless gradually been getting more and more decrepit as far as the internet goes. She has had CA Antivirus for a couple of years, but last year it started failing to get into contact with the update server. Their helpline wasn't all that helpful,and no amount of their troubleshooting seemed to be able to fix it. Suffice to say the problem spontaneously fixed itself about a week before the re-subscription fee was due. Understandably unimpressed, she managed to extricate herself with difficulty from that program, but the upshot is that she's had almost a year happily surfing with practically no antivirus protection. She'd been getting some redirects, so I installed and ran a couple of your recommended programs with no result.

    NOW she's running ESET Nod32 as antivirus but was already experiencing browser redirects and 'surprise tabs' fairly constantly in both explorer and firefox, and neither this nor any of the usual tools are picking up any problems. The only result of the new antivirus was that the computer started doing a "this system has to shut down in 60, 59 etc seconds" about halfway through scans. After some googling we found out how to run "shutdown -a" or "-w" or something similar in command.com to let the scan finish, but it didn't actually find anything, and after a few weeks of being killed mid-shutdown with command.com, the shutdown timer stopped appearing . Eset nod is now blocking suspicious IP's constantly the moment she leaves the safe harbour of Gmail, the redirects, reloads and interruptions are reaching plague proportions, and "Bad Image" errors have begun popping up madly on several running processes, including gnotify.dll and sensapi.dll (seeming to do with google's mail monitor) and dwintl.dll (attributed to dwwin.exe, which google tells me is something to do with windows' diagnostic service failing to run properly. I've got some screenshots to show a couple of examples of both the blocked IP's and the bad image popups.

    Out of other ideas, I ran your xp cleanup routine, with no results, the only interesting hiccup was that while running combofix, i got a message saying
    "combofix has detected the following realtime scanner(s) to be active:

    antivirus: CA Anti-Virus"

    BUT, CA was uninstalled months ago. Sorta one of the causes of this whole mess. So, I opened some browser windows, restarted and redisabled the current antivirus before twigging to the fact that the program was long dead, then closed the lot before continuing. Couldn't find CA anywhere, couldn't be bothered searching every running process to find out if it was actually there. Hoping that brief recess didn't affect combofix's running, but the CA thing is something to think about. Are you guys able to help me? If so, what do you need me to attach? Is there anything i've missed? I'm perfectly happy to run the procedure again if so. I'll be checking back regularly and resisting the urge to double-post. Having never done this before, I have no idea how quickly you guys move through the huge number of requests for help you must get.
    Cheers,
    D
     
    Last edited: Mar 28, 2010
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the requested logs for us to review:
    SAS
    MBAM
    RootRepeal
    ComboFix
    C:\MGlogs.zip
     
  3. A_Tiny_Pony

    A_Tiny_Pony Private E-2

    Hokay, so- sorry guys. I've attached the three logs i brought with me but I don't actually have the laptop with me (I knew this was going to be a problem), and overlooked the MGlogs one when I was collecting the logs.
    Anyway, I don't have that one, and I can't find the rootrepeal log. My dearest is bringing the lappy over tonight, so i'll dig up the other two in a few hours. If I can't find the rootrepeal one, am I just able to go through the read-and-run-me-first and run it again, or do I need to do that and the XP procedure step by step again?
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Once you have the computer back in your possession again, please put ComboFix directly on the desktop, not where you are running it from:
    Running from: c:\fixinthings\ComboFix.exe

    It appears as though you have two AV programs:
    AV: CA Anti-Virus *On-access scanning enabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
    AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

    If so, uninstall one.

    I will wait for the MGlogs.zip for further instructions.
     
  5. A_Tiny_Pony

    A_Tiny_Pony Private E-2

    Yeah, so that's the interesting thing, I uninstalled it via add-remove programs in maybe december. It hasn't been installed for some time. Any tips on how to ferret it out and kill it dead?
    In other news, my girlfiend's off for the easter weekend, so no laptop for a bit. Prolly safest just to run whole routine again, post the lot up soon.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will be here when you are ready. And yes, it would be a good idea to run all the scans again.
     
  7. A_Tiny_Pony

    A_Tiny_Pony Private E-2

    So, ran scans again. First set of attachments. Only interesting things of note are that Combofix still reckons CA Antivirus is installed, and that after SAS scan, NOD (the actual antivirus software) started picking up a threat.
     

    Attached Files:

  8. A_Tiny_Pony

    A_Tiny_Pony Private E-2

    i'm sure saying 'bump' here is in bad taste. attached the mgtools logs.
    Edit: let me know what you need from me next.
     

    Attached Files:

    Last edited: Apr 6, 2010
  9. A_Tiny_Pony

    A_Tiny_Pony Private E-2

    so, here's a new wrinkle. Laptop started up fine this morning, so i tried to start it in safe mode to see if NOD could get the little bugger, which it's finding in the operating memory. It did the thing that it's been doing with safe mode, which is get to mup.sys and then restart, so i turned it off.

    Now, it gets to the loading windows screen and then flashes up a bluescreen for half a second, which after much restarting i figured out says something like

    STOP:C000218 {Registry File Failure}
    The registry is corrupt cannot load the hive (file:)
    \systemroot\system32\config\SECURITY
    or its log or alternate
    is corrupt, absent or not writeable

    Just letting you know what's happening.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, your logs are clean. Your biggest problem is lack of RAM:
    Total Physical Memory 512.00 MB
    Available Physical Memory 57.46 MB

    Your other issue sounds like a software problem and would best be discussed in that forum. I would suggest your first step of action would be to go to start / run / and type:
    sfc /scannow to see if you have any corrupt or missing files. Run it twice.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  11. A_Tiny_Pony

    A_Tiny_Pony Private E-2

    Thanks heaps for that, it made a hard decision a bit easier. Knowing it was clean, my girlfriend elected just to retrieve the useful stuff and format. Of course, after the enema it's running much better. Sorry for late reply, only just got word that the lappy was working a-ok again. Spose i'll see if it'll fit more ram, or a bigger one or something, just to grease the wheels.
    What you guys do is amazing, and i'm big-upping you to my friends and browsing the merch in celebration.
    Consider this a job well done!
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. If you want to check to see what you system can handle as far as RAM is concerned, you can go to crucial.com and have it scan your system.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds