ComboFix -Access denied 2of3

Discussion in 'Malware Help (A Specialist Will Reply)' started by jefzef, Oct 15, 2010.

  1. jefzef

    jefzef Private E-2

    This is a post for my second machine. This one was infected with AV2010, but had browser misdirects before that.

    ComboFix delivers a series of Access Denied messages. I've run RKill and exehelper, they haven't helped. I'm including the only logs I've been able to obtain so far.

    Thanks
    Jeff
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You will have to reboot into safe mode, I would prefer to see a combofix log and I definately need to see logs from running MGTools, which you know all about as you successfully ran it on the first computer we are trying to fix.

    So, into safe mode and run Combofix and MGTools. :) Attach logs once done.
     
  3. jefzef

    jefzef Private E-2

    Access denied for ComboFix in safe mode too. MGlogs are attached.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What are you using for anti virus?

    Please navigate to C:\MGTools\analyse.exe, run it, do a system scan only and save a log file to attach for my reviewal.

    Java(TM) 6 Update 21 <--- Uninstall this outdated Java.

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :dir
      {FF331~1
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Tell me how the machine is running, and what problems you still have, if any.
     
  5. jefzef

    jefzef Private E-2

    I was running McAfee, but when I first started running anti-malware stuff, it was going nuts on me, interfering with everything, popping up the main console window constantly, so I uninstalled it for now.

    Now for bad news.

    analyse.exe - access denied

    uninstall old Java (I also tried to do this before posting) - access denied "windows installer service could not be accessed"

    System Look log is attached.

    OTM ran at first, once I hit "move it", I lost my desktop and I had only my wallpaper on the screen for at least a half hour, after which, I rebooted. When it came back up, access was denied. No log, and no idea if it accomplished anything.

    TDSSKiller log attached. Whatever it did, it didn't stop the denial of access to any of the programs needed, including ComboFix.

    A new MGlogs.zip file is attached.
     
  6. jefzef

    jefzef Private E-2

    Files
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Navigate to this folder using windows explorer and tell me or screenshot what is inside.

    C:\Documents and Settings\JZef\Local Settings\Application Data\{FF331D41-319E-412F-9B87-F75FB6AD8D80}

    I would not worry too much about combofix not being able to be run for now, later we will try renaming it and attempt running it again. and regarding the java, you should ask about that in the software forum once we are done here.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    Run TDSSKiller again and attach it's log

    Rename Combofix.exe to abc.com and try and run it in normal mode, iif not successful try safe again.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Tell me how the machine is behaving now. And don't forget to tell me the contents of that folder.
     
  8. jefzef

    jefzef Private E-2

    Contents of folder in question:

    Renaming ComboFix doesn't help because, unlike the other programs that are denied access, this one does run. However, everything it tries to do when running gives the message "access denied". If left alone, the blue screen fills with a series of "access denied" messages.

    Temp deletions done.

    All the logs I could get are attached.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    C:\Documents and Settings\JZef\Local Settings\Application Data\{FF331D41-319E-412F-9B87-F75FB6AD8D80} <--- Delete this folder!

    When running TDSSKiller why did you skip action on this file?

    You need to run TDSSKiller a 4th time and let it fix it! Do so and show me a log reflecting this.

    Once you have done so and have also deleted that folder you can do this, and hopefully we will be nearing towards wrapping up then.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  10. jefzef

    jefzef Private E-2

    I have no idea how that got by me, my apologies.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I have work soon so won't be able to respond again until later on tonight. In the mean time, tell me how the computer is behaving.
     
  12. jefzef

    jefzef Private E-2

    No worries, you're the boss and your time is greatly appreciated.

    OK, good news first. ComboFix works now and I'm attaching a log. Browser redirects seem to have stopped. Windows Update now works.

    Bad news. During Windows Update, graphics card driver update was attempted and aborted because of what seemed to be an install/uninstall issue similar to the Java. It was supposed to revert to the old driver, but didn't and it won't accept if from the cd either. Viewing VGA res now.

    Still denied access to analyse.exe, OTM.exe
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay, let's keep going then. Yes, the redirects stopped because of that folder we deleted/and due to TDSSKiller.
    Not an issue for the malware forum unfortunately. :(

    Antivirus 2010 <--- Uninstall this.

    LiveUpdate Notice (Symantec Corporation) <--- I see this installed, what products are you using from symantec?

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    kkti
    DFBCFDBA
    File::
    c:\windows\system32\drivers\gnsoqwtt.sys
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Don't forget to answer my question about symantec.

    Soon you will need to reinstall antivirus (You said you were using Mcafee but uninstalled it due to it hindering our cleaning process)
     
  14. jefzef

    jefzef Private E-2

    Tried to uninstall AV2010. Says an error occurred and I don't have access to globalroot\systemroot\system32\userinti.exe

    Symantec - used to have Norton Utilities, also items that refuse to go away with uninstall
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Bear with me, I need to consult my colleagues about something before we make the next move.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  18. jefzef

    jefzef Private E-2

    Kaspersky found and deleted 3 of the files you had me download and 3 files in the system restore. Nothing more.

    Your Uninstaller appeared to work on AV2010. The only option that worked was quick uninstall, so I have no idea how complete it was.

    It also uninstalled Java, but I'm unable to install the latest version. When I run it the cursor hourglasses for a second then nothing.

    Symantec Live update is gone now too.

    After running Your Uninstaller, I was able to reinstall my video drivers, however Windows Update still has several failures.

    Also got this message after a crash:

    The system has recovered from a serious error.

    BCCode : 1000008e BCP1 : C0000005 BCP2 : BD0651BD BCP3 : B017D2C0
    BCP4 : 00000000 OSVer : 5_1_2600 SP : 3_0 Product : 256_1

    C:\DOCUME~1\JZef\LOCALS~1\Temp\WER6e98.dir00\Mini102110-01.dmp
    C:\DOCUME~1\JZef\LOCALS~1\Temp\WER6e98.dir00\sysdata.xml

    Thanks
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    One more sweep through your logs before I decide what to do next. It may be that I send you to the software forum for any outstanding issues.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  20. jefzef

    jefzef Private E-2

    Latest MGtools logs attached.
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    C:\Documents and Settings\JZef\Local Settings\TEMP

    Any remaining issues will have to be worked out in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds