"disk antivirus professional"- removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by biologicalbeing, Mar 11, 2013.

  1. biologicalbeing

    biologicalbeing Private E-2

    Hi
    I got the disk antivirus proffesional virus late last week from trying to stream a movie from letmewatchthis.com

    I initially had trouble starting my computer in safe mode w/ networking because my F8 button will not work.. so I was connected to a network for approximately 20 mins while it was popping up its ads and not letting me open anything

    so i shut down and turned my laptop off over the weekend to do some research, change all my passwords from a secure computer, and then i followed the READ and RUN ME thread completely.
    however before i found your forum was when i ran the maleware bytes (1st attatchement) this morning. i had also run the rouge killer this morning. with both of these i deleted/quarentined after. the other scans i did this evening (hitpro,mg,tdss) i did not act upon due to your warning.

    I have attatched 5 of the reports, I have more reports for malwarebytes and rougekiller if those would be neccesary to see as well.

    Any information I could get from you would be so appreciated, I am worried after reading about backdoor trojans/rootkits...
    thanks very much and hope to hear back
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:


    • [RUN][SUSP PATH] HKCU\[...]\Run : RMAconce (rundll32 "C:\Windows\iscsdmin.dll",CreateProcessNotify) [-] -> FOUND
      [RUN][SUSP PATH] HKUS\S-1-5-21-3093575814-117418520-1359992000-1000[...]\Run : RMAconce (rundll32 "C:\Windows\iscsdmin.dll",CreateProcessNotify) [-] -> FOUND
      [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-21-3093575814-117418520-1359992000-1000\$4638309f8315b409b8e59ea5080cbab6\n.) [x] -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Files/folders tab and locate these detections:


    • [ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-21-3093575814-117418520-1359992000-1000\$4638309f8315b409b8e59ea5080cbab6\@ [-] --> FOUND
      [ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-21-3093575814-117418520-1359992000-1000\$4638309f8315b409b8e59ea5080cbab6\U --> FOUND
      [ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-21-3093575814-117418520-1359992000-1000\$4638309f8315b409b8e59ea5080cbab6\L --> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot yet.

    Run Hitman and have it fix these:
    C:\Windows\iscsdmin.dll
    C:\Windows\System32\iscsdmin64.dll

    Reboot and rescan with both RogueKiller and Hitman and attach those new logs as well.

    Tell me how things are running now.
     
  3. biologicalbeing

    biologicalbeing Private E-2

    Hello TimW
    I have attatched the hitmanpro log after deleting both:
    C:\Windows\iscsdmin.dll
    C:\Windows\System32\iscsdmin64.dll

    and rebooting.

    i have attatched the final RK report [7] of what it looks like today, after the reboot from Hitmanpro.

    report [2] and [3] show the before and after initial scans which i ran (and then deleted the whole list...) before I found your forum!!!!:-o

    this was yesturday morning, which is when i restarted my laptop after 5 days of avoiding it and ***was suprised to see that the disk antivirus pop ups did not start popping up...***

    let me know if thats an issue ( the deleting), and what I do with the RK_quarantine folder now on my desktop?

    sincerely thank you for your follow up,
    B.B.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good. What issues are you still having, if any?
     
  5. biologicalbeing

    biologicalbeing Private E-2

    none, i have switched all my passwords post these scans, so I should be secure now to work on my laptop with banking and school?
    Thanks very much for your help, can I delete the RK-quarantine folder on my desktop??

    B.B
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, and you are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  7. biologicalbeing

    biologicalbeing Private E-2

    Dear TimW
    my laptop is definitly not running properly, it has slowed down significantly and my university mail (run by Zimbra) will not ever load,.. i have to use the " click here if you are using a slow connection or old computer, to the standard HTML version".. this has never happened before.

    Also, I just recieved 3 text messages from microsoft to my phone, verification code's, which as far as I can research means that someone is trying to get into my hotmail account? The first verification code got text to me the night I got the virus. Then i recieved none until today (3 in a row).

    also, my internet explorer keeps having a issue, needs to search for a solution and then close the tab.
    This happens consistantly, almost everytime I open it up.

    plus, I can physically hear my laptop running from somewhere inside, under the left side, making alittle scratching noise.

    I am in the last 2 weeks of school right now,writing papers and researching, I dont have the time to reformat it but I feel that damage has been done by this rootkit.zeroaccess/trojan that has not been elimated with the scans.

    What do you recommend?
    I would like to just use it the next 2 weeks to get school over with and then have summer break to reformat, but are all of my accounts continuing to be comprimised? I feel that a keystroke logger dosent exist if this person is needing to ask Microsoft for a verification code to try and change my hotmail password.

    Let me know what you think!
    B.B
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use a different computer to change your passwords. Then let's take another look:

    Re-run all the scans from the Read and Run first instructions and attach the new logs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds