Fake Virus Scanner Took Over System

Discussion in 'Malware Help (A Specialist Will Reply)' started by OldGeezer_64, Feb 19, 2011.

  1. OldGeezer_64

    OldGeezer_64 Private E-2

    Hi, Old Geezer here.

    I have computer experience so can bumble my way through most instructions.:-D

    The malware took over the system and will not allow any programs to run. I started in Safe mode and was able to connect to the net. I have followed your Read/Run and attached the logs.

    All scanners were run in safe mode as each time I restarted per the instructions the Malware was still in control. I felt it best to run all scanners and save logs in safe mode.

    I have not yet restarted in normal mode as I wanted to get instructions before trying it. No sense in letting the critter regenerate files we have already fixed.

    Looking forward to hearing from you.

    O.G.
     

    Attached Files:

  2. OldGeezer_64

    OldGeezer_64 Private E-2

    The last log

    O.G.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach this log:
    Code:
    C:\Documents and Settings\Administrator\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\"
    mb1832~1.txt  Feb 19 2011        2462  "mbam-log-2011-02-19 (12-40-19).txt"
    Your log did not include the one for running HJT. Did you make the agreement when you ran MGTools?
    Please go to C:\MGTools\analyse.exe and run it. Attach the log when you are ready.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I see you were attaching as I was replying. Please reboot into normal mode and run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  5. OldGeezer_64

    OldGeezer_64 Private E-2

    Hi TimW,

    Thanks for the fast reply. All I did was leave the room for a beer and you had already replied. Fast, real fast.;)

    The putter is working in normal mode. The fake virus scan is not popping up when I restarted in normal mode.

    I ran the .bat as requested but don't see the .zip file. I attached the Hijack.log file thinking this is what you wanted to see.:confused

    Attached the log requested.

    O.G.
     

    Attached Files:

  6. OldGeezer_64

    OldGeezer_64 Private E-2

    Sorry tim,

    My Bad. I found the .zip. Attached

    O.G.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you ran the getlogs.bat, it should have produced a log at C:\MGLogs.zip.

    In the meantime, re-run HJT and do a system scan only. Then select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do not do my last fix until I can review the MGLog.zip.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\All Users\Application Data\TEydAJxIvxCQie.exe
    C:\Documents and Settings\All Users\Application Data\TsAOHXBPc.exe
    C:\Documents and Settings\All Users\Application Data\aYCaY8XtWrIFNlu.exe
    C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\Enh.exe
    C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\oeikodixr\vlrjcstsikk.exe
    C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\cpikpqjnd\vcwhlamsikk.exe
    
    Folder::
    C:\Documents and Settings\All Users\Application Data\fGmDnMo05200
    C:\Documents and Settings\All Users\Application Data\~aYCaY8XtWrIFNlur
    C:\Documents and Settings\All Users\Application Data\~TsAOHXBPcr
    C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\oeikodixr
    C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\cpikpqjnd
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Note: If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run CCLeaner and then make sure you clean out this folder:
    C:\Documents and Settings\HP_Administrator\Local Settings\Temp\

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  10. OldGeezer_64

    OldGeezer_64 Private E-2

    Well that was a trip Tim,

    The FixME.reg ran OK and completed its' work.:)

    When I saved the .txt file and dropped it onto Combofix it started to run but "froze" solid.:( I waited about 20 minutes to make sure it was not running and had to do a power init. Restarted the system in normal mode and tried it again with a new copy of the .txt file. It ran OK.

    There are two files in the TEMP folder that would not delet. The system says the are in use. I had not other programs open so I don't know what went wrong.

    I then ran MGlog and it ran OK.

    I've attached the requested logs.

    O.G.
     

    Attached Files:

  11. OldGeezer_64

    OldGeezer_64 Private E-2

    Sorry Tim,

    forget to past the file names that could not be deleted.

    _hphtra07.log

    hpodvd09.log

    O.G.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Don't worry about those two files. You are looking very much better, though we still have a few things to do.

    Please Disable Spybot's TeaTimer --> Should have been done as per the R&R instructions!

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    jjaksr
    
    File::
    c:\documents and settings\All Users\Application Data\aYCaY8XtWrIFNlu.exe
    c:\documents and settings\All Users\Application Data\TsAOHXBPc.exe
    c:\windows\system32\drivers\ccyfsycs.sys
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Note: If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  13. OldGeezer_64

    OldGeezer_64 Private E-2

    Tim,

    I had McAfee installed on the computer. However there are no short-cuts showing and nothing shows if I try to fine it with find files/folders. I pulled up Task Manager and MSsheild.exe shows as a running process. When I shearch for the MCagent.exe program it also does not show up.

    I tried to run Combofix but it tells me MCafee is running.

    Any suggestions?

    Thank you.

    O.G.
     
  14. OldGeezer_64

    OldGeezer_64 Private E-2

    Tim,

    I worked on the Mcafee problem. Did a complete search and found no .exe for the program but did find A LOT of remnants kicking around. Found the MCpR.exe for cleaning up the MCafee program.

    Took a chance and downloaded it and ran it. It took all the remaining parts off the system. At this point I cannot find any part of MCafee.

    I then ran Combofix and it ran fine. Attached the log generated.

    Please tell me I didn't do wrong with the MCafee stuff.


    O.G.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did fine, but I still need the new C:\MGLogs.zip to be sure everything has been removed. ;)
     
  16. OldGeezer_64

    OldGeezer_64 Private E-2

    Tim,


    Oooops, I was tired after cleaning the MCafee stuff and didn't read you intire instruction.

    Attached is the MGlog.zip file you need.

    Thanks for you patients.

    I just got home from work and saw you reply.

    O.G.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good. The only thing I want you to do is to use windows explorer and try to find these two files and delete them:
    C:\Documents and Settings\All Users\Application Data\~aYCaY8XtWrIFNlur
    C:\Documents and Settings\All Users\Application Data\~TsAOHXBPcr
    Both of them are 152 bytes.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  18. OldGeezer_64

    OldGeezer_64 Private E-2

    Tim,

    Deleted the two files.

    Downloaded the Defogger and tried to run. It would not run. I don't think I had any CD Emulation on the system to start with. I did run it as per the instructions in the Read/Run when I started out and it did run but don't know if it did anything.

    I completed you clean up instructions without any further issues.

    The machine is running Great and has never been better.

    I will be making a donation to your site.

    Thanks for all the help.

    If anything needs to be done for the Defogger issue let me know.

    O.G.
     
    Last edited: Feb 21, 2011
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes......
     
  20. OldGeezer_64

    OldGeezer_64 Private E-2

    Tim,

    Oooops again.

    Please see my edited reply.

    O.G.
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know that everything is running well. And you are most welcome. If you had no disc emulation software, there is nothing that needs doing. Safe surfing!! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds