downloader.swizzor and 64-bit woes... (a.k.a. just making sure)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mimsy, Jan 27, 2008.

  1. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    Hi! :wave

    I think all the remnants of the virus are gone, but I was hoping that you wouldn’t mind going over my logs and just make sure. I’m paranoid about this computer, and I’d rather be safe than sorry.

    When I started up my computer for the day, to check forums, email, and then go and play the play The Witcher, AVG anti-virus started one of it automatic system checks, as it always does. Since running a game while AVG runs its scan usually makes the game laggy and choppy, I decided to wait and just surfed around a bit more while I waited. Right in the middle of posting in another MG forum, AVG popped up a message saying it had found a virus! Apparently something called downloader.swizzor was sitting in a folder in another account, and AVG wanted to verify that it was okay to quarantine that file and fix any damage the virus may have caused.

    I clicked on "quarantine", and a few minutes later another AVG window popped up and told me that everything was "successfully healed" and that I needed to reboot he computer to finish up the cleaning process. Like a good user, I promptly rebooted.

    Then, just to make sure that everything was cleaned away, I decided to go through the Read & Run thread, and post the logs here. However, I ran into some issues about half-way through.

    CCleaner ran on all three accounts without problems, and disabling UAC was smooth, simple, and easy. Combofix, on the other hand, would not run. It gave me two error messages, saying that a couple of registry files/folders could into be saved, and then shut itself down. That’s when I grabbed my laptop, open a notepad window and begun taking notes… unfortunately I wasn’t able to remember the paths to the files. I double-clicked on Combofix again, hoping the errors were just flukes, and it went straight to “preparing to scan”, then shut itself once more.

    At that point I decided to move on. I don’t have a Combofix log though, since it never made it that far.

    Spybot ran like a champ, and found absolutely nothing, so I don’t have a log from that application either. AVG anti-spyware also ran just fine, and I do have a log from that scan. I’ll be attaching it to this post.

    Then I tried to run MGTools, and this is where the real hassle started.

    UAC was already disabled, so I double-clicked the MGTools.exe file, and watched the DOS window that came up. After only a second or so an error message came up, saying that the function time.exe could not run, due to incompatibility with my 64-bit operating system. I clicked Okay, thinking that the rest of the scans might be able to run at least. As soon as I clicked, an identical error message came up and informed me that locate.com had the same problem. Clicking on Okay for that error message did not make it go away however, nor did clicking on the red x in the upper corner. I had to open TaskManager and end the process there, to get rid of the error message.

    Ever stubborn, I then moved on with the rest of the instructions, and right-clicked on GetLogs.bat and told it to run as administrator. The errors referring to time.exe and ocate.com being incompatible with 64-bit Vista came up again, but this time they both went away when I clicked Okay, and GetLogs seemed to be able to do its thing and produce scans and/or logs. Ones it was done with the rnkey one though, the 64-bit incompatibility messages came up again, and once again from time.exe and locate.com. This time, the locate.com message closed down and a message from Vista itself popped up and said "SteelWer WhoAmI application has stopped working". I closed that application, and the locate.com incompatibility message came right back.

    Once more I had to go to TaskManager to get rid of the persistent error message, and once more the MGTools application shut down when the error message did. I’m going to attach the logs anyway, since they still might have helpful information.

    Apologies for the long post… I live under the delusion that the more information I can provide, the easier it is for you to do whatever it is you need to do. To be honest. I really just want comforting reassurance that swizzor is completely gone.

    And now, if you'll excuse me, I need to go reboot so UAC turns back on. :)
     

    Attached Files:

  2. abri

    abri MajorGeek

    Hi Mimsy! :)
    I think everyone's avoiding you. Vista. ...
    Your tools didn't run correctly, so I think Chas is going to have to look at this. Did you run them according to the Vista instructions?
    abri
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    MGtools and many other programs for that matter, are not compatible with x64.
     
  4. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    That's okay, I can be patient. :) I haven't seen any pop-ups or other weird symptoms, so I'm starting to believe AVG did its job as thoroughly as it claims.

    I did follow the Vista procedure, but I wasn't surprised to see some compatibility problems. The vast majority of the applications I have installed, including my games, are in the "special 32-bit" Program Files folder.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Mimsy,

    If you have some time to experiment a little, I could try creating a variation of MGtools for x64. I don't have an x64 platform to test on so you could be our tester if you wish. ;)

    First I have to ask a question, did the MGtools.exe program actually run to extract all files into the C:\MGtools folder?
     
  6. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    I don't mind being a tester, as long as you don't mind that all I'll be able to do is follow instructions and give reports; what I know about how software actually works can't even fill a shot glass. :)

    Since there is a large number of files in the MG Tools folder, I assume the answer to your first question would be "yes". I can try listing them, but like I said, there is a lot of them. GetRunKey, analyse.exe, ShowNew, RegFix, and GetDetails.exe are some of them.
     
    Last edited: Jan 30, 2008
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for volunteering. Perhaps we can change the amount you know a little bit while doing this. ;) I'll work something up and post back in this thread when I have a chance. I will PM you too to let you know since it may take a while (maybe on the weekend).

    Sounds like the autoextraction ran OK. That was my first concern. I expect that many of the other tools will be issues including the use of the zip.exe file which is part of the tools. In fact, just go to the C:\MGtools folder and run the zip.exe file. What happens?
     
  8. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    So when this is over I will have software knowledge that has nothing to do with gaming? Wow. I'm branching out! LOL

    I'll look for the PM, but fair warning: I'm insanely busy for the next few days. My state's caucus is this Tuesday, and I'm volunteering a lot of time at a local campaign office. So in other words, take your time. I'll be watching this thread for updates too.

    Running zip.exe:
    A window blinks briefly, but then goes away. It looks like it is black with white text, so probably some kind of DOS window but it flashes past so quickly that that's all I can get out of it.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It will take alot of time anyway since I have to figure out how to do things without some of the tools already being used and that will not be easy.

    Try it from a command prompt. Click Start, Run, and enter cmd and click OK. The type the below command (we will test a couple other commands to to see what happens.

    cd C:\MGtools
    zip
    grep
    locate

    Tell me what happens after the zip, grep and locate commands.
     
  10. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    zip
    The command prompt responded by telling my the default action to this is to add ro replace zipfile entires, and then went on to give me a long list of commands (it looked a little bit like the response to "man <command>" in the Ubuntu installation I have used for over a year and really should know more about than I do).

    grep
    Usage: grep [OPTION]... PATTERN [FILE]...
    Try 'grep --help' for more information.

    locate
    A familiar window pops up and tells me that the feature locate.com can't be run due to incompatibility with my 64-bit version of Vista. The message is repeated in the cmd-window.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks!!

    Okay that sounds like zip.exe and grep.exe will possibly work with x64 and that locate.com will not.


    And from past experience I know that ltime.exe and swreg.exe will not work either. Let me see what I can put together.

    Also please try running processdll.exe from the command prompt and let me know if you get a message about being incompatible with 64-bit software or if you get another error message. This program does require the Microsoft .NET Framework software to be installed so a different error message may occur if it runs on x64 but you are missing the .NET Framework software.

    Then from the command prompt also try running the vfind.exe command and let me know if you just get help information on the program or an error about 64 bit compatibility.
     
  12. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    Okay... processordll.exe gave me a weird error message I have never seen before. So I took a screen shot and cropped it a bit to make it easier to read, and attached the error message to my post.

    vfind.exe produced a long list of help information, so that one seems to have worked.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look in Add/Remove Programs to see if you have anything saying Microsoft .NET Framwork (any version number of it. Could be 1.0, 1.1, 2.0 etc). Let me know. If not, you should check Microsoft Update to see if it appears anywhere in any of the downloads available for you. It would not be one of the Critical downloads.


    Also please download the attached GRK64.zip file and save it to your C:\MGtools folder. Then extract the contents of the ZIP file into the C:\MGtools folder. This will add a file named GRK64.bat to the folder. Try double clicking the GRK64.bat file. If it runs a notepad window will popup with a runkeys.txt log. Also it should add the runkeys.txt log to the C:\MGlogs.zip file. Attach the C:\MGlogs.zip file.
     

    Attached Files:

  14. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    First: The Programs list has .NET Framework 1.1 plus a hotfix for it.

    Second: GRK64.bat absolutely refused to work until I ran it as Administrator. Once I did, it ran, but it did say it failed to find a registry key. I tried to attach MGlogs.zip to this post, but I got an error message saying that I had attached it already.
     
    Last edited: Feb 2, 2008
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then it sounds like processdll.exe is not compatible.

    The command prompt window tells you to ignore messages about registry keys not being found. ;) Okay if it ran, then attach the C:\MGtools\runkeys.txt log which should be new. Not sure why it did not update the ZIP file.

    Did you see the below (or similar) as the last few lines in the command prompt window that opened when GRK64.bat was run.
    Code:
    C:\MGTools\temp\xrkey10.txt
    
    C:\MGTools\temp\xrkey12.txt
    
    updating: runkeys.txt (208 bytes security) (deflated 82%)
     
  16. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    I saw nothing about updating, and no references to C:\MGtools\temp

    File attached. :)
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you see the command prompt window?

    Now something in your log is unusual. Instead of showing then installation folder for GRK64.bat (which should be C:\MGtools ) it is showing C:\windows\system32

    It appears that you do not have UAC disabled. Did you get constant popup messages asking you to allow things to run as GRK64.bat ran? These tools normally require UAC to be disabled, then a reboot for it to take effect before running them.
     
  18. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    I always have UAC enabled, just because it seems like the smart thing to do. I completely forgot the part about it needing to be disabled to run these tools. And yes, I did see the command prompt window, but there were no messages about either updating or C:\MGtools\temp.

    Give me a few moments, I'll go disable UAC, reboot, rerun GRK64.bat, and attach the new MGlogs.zip.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you should normally keep UAC enabled, but to run certain program it is really necessary to disable it or you can have great difficulties in running the program. The tools that are part of MGtools will cause UAC to popup non-stop. They run best when UAC is disabled.
     
  20. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    I leave the room for five minutes, and the keyboard is hi-jacked... :D

    I tried to attach the new MGlogs.zip, but I once again ran into the error message that told me I had already attached that file. I did see something similar to these in the command window when I ran GRK64.bat:

    Edit:
    It occurred to me to try and attach the runkeys.txt file, and that seems to have worked. Any other file you need?
     

    Attached Files:

    Last edited: Feb 3, 2008
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It appears that you put the ZIP file here:

    C:\GRK64\GRK64.bat

    It needs to be in the same folder as the rest of the MGtools in order for things to work properly. That is why I had said to extract the contents of the GRK.zip file into the C:\MGtools folder. You do still have the C:\MGtools folder I assume from running MGtools.exe before. Please do the below:

    1. Delete the existing C:\MGlogs.zip file
    2. move GRK64.bat to c:\MGtools
    3. run the C:\MGtools\GRK64.bat file by double clicking on it.
    4. observe the messages in the command prompt window. The last line of output should be something like below since it will be trying to create a new ZIP file.
      • adding: runkeys.txt (208 bytes security) (deflated 82%)
    5. check to see if the C:\MGlogs.zip file was created.
    6. If it was created, attach it.
    7. If it was not created, start at step 3 again but this time right click the GRK64.bat file and select Run as Administrator and continue thru with the other steps and attach the MGlogs.zip file if created.
     
  22. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    Wow. I feel extremely stupid. :eek:

    Okay, I can fix this...

    • Deleted existing MGtools.zip file.
    • Moved GRK64.bat to C:\MGTools
    • Remembered just in time that I need to disable UAC, so did that and rebooted
    • Double-clicked GRK64.bat and watched the command window closely... it closed immediately after posting the last line, too fast for me to be able to see what it was.
    • Checked and found a new C:\MGlogs.zip It's attached to this post.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's great progress.

    We now know that this version of GetRunKey will run properly and that a ZIP file can be created and the log will be added to it.

    Now I need to get a modified version of GetLogs.bat and ShowNew.bat to you to try. ShowNew.bat needs to be finished before trying a new GetLogs.bat. It will take longer to get ShowNew.bat modified than it did GetRunKey.bat. So for now, make sure you re-enabled UAC and I will PM you when I have something new for you to try.

    Thanks for helping to test this out. It will help other's who are using x64 versions of Windows. Hopefully what we are doing here for Vista x64 also proves to work properly on Win2K and WinXP x64 versions. I would think that it would.
     
  24. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    Happy to help. I'll keep an eye out for another PM then. :)

    And UAC is back on. I feel kind of naked without it...
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds