first serious infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by CLD, Feb 4, 2011.

  1. CLD

    CLD Private E-2

    Hi,

    I have an infection that took away my administrator rights.

    I'm using Vista SP2 32 bit.

    I'm able to access the internet using an ethernet cable but downloading anything has been blocked.

    I'm able to run things from a flash drive.

    The drive letters have been changed. C is now G etc.

    I did as much as I could using your step by step instructions running everything from a flash drive.

    SuperAntiSpyware : I was able to run this off the flash drive and it detected this
    windows\system32\drivers\utqyndg5.sys.vir
    It wanted to reboot and when I did I couldn't find a log to save. I ran the scan again and it came back clean. This time there was a log available but I wasn't allowed to view it or save it. It wouldn't open.

    RootRepeal : I wasn't able to extract it.

    MGTools : It said I didn't have permission

    ComboFix: I was able to run that and attached the log.

    Any help would be greatly appreciated .
     

    Attached Files:

    Last edited: Feb 4, 2011
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Important: This task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base:

    How to back up and restore the registry in Windows]

    1. Download and then installSubInACL (SubInACL.exe)file from Microsoft.
    2. Click Start, Run and enter notepad and click OK to bring up the Windows Notepad program.
    3. Copy and then paste the following text into Notepad.

    Code:
    cd /d "%ProgramFiles%\Windows Resource Kits\Tools" 
    subinacl /subkeyreg HKEY_LOCAL_MACHINE /grant=administrators=f /grant=system=f
    subinacl /subkeyreg HKEY_CURRENT_USER /grant=administrators=f /grant=system=f
    subinacl /subkeyreg HKEY_CLASSES_ROOT /grant=administrators=f /grant=system=f
    subinacl /subdirectories %SystemDrive% /grant=administrators=f /grant=system=f
    subinacl /subdirectories %windir%\*.* /grant=administrators=f /grant=system=f
    secedit /configure /cfg %windir%\repair\secsetup.inf /db secsetup.sdb /verbose
    
    4. Save this Notepad file as Reset.cmd to your desktop. Be sure the Save as type is set to all files.
    5. Once you have save it properly, double-click the Reset.cmd file to run the script.

    * Note This script file may take a long time to run. Additionally, you have to run this script as an administrator.

    6. Now reboot your computer! You must do this before the above will take effect.

    Now see if you can run the other scans.
     
  3. CLD

    CLD Private E-2

    I was unable to install SunInAcl on the infected computer from a flash drive. The message I received was :

    The windows installer service could not be accessed. This can occur if the Windows Installer is not correctly installed. Contact your support personnel for assistance.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. CLD

    CLD Private E-2

    I'm going to start burning CDs right now and give it a shot.
    Thanks.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do let me know how you progress!! There are a few other things we can try if nothing works.
     
  7. CLD

    CLD Private E-2

    I will.
    Thanks again.
     
  8. CLD

    CLD Private E-2

    I'm a real novice at this. :-o

    Trinityhome disc--I didn't know how to configure it so it could connect to the internet for the virus scanners

    Kaspersky -- wouldn't load

    Avira-- didn't find anything

    Bitdefender--didn't find anything

    UBCD-- installed in safe mode but I didn't know what to do with it from there
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please try doing the below:

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then doube click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running.


    Now download and Run exeHelper

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log.

    Then try running these instructions: Using MGtools


    Attach the below logs when finished with all of the above:

    • C:\avplog.txt - from AVPfind
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools

    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  10. CLD

    CLD Private E-2

    I ran everything from a flash drive.

    SuperAntispyware didn't find anything.

    I couldn't load MGTools because I can't disable user account controls, I have no administrator control.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try running MGTools in safe mode. Let me know what happens. Where you able to run ComboFix again?
     
  12. CLD

    CLD Private E-2

    I attached a combofix log in my first post.
    I'll try MGTools in safe mode.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry, I have slept since then. LOL. Let me know if you can run things in safe mode.
     
  14. CLD

    CLD Private E-2

    No problem, after I typed my response I was hoping you didn't take it as criticism.
    I appreciate all of the efforts.

    I tried MGTools in safe mode and still the same issues, I don't have permission.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you right click the exe file and under properties check the security tab and add your account for the permissions? If you still can't run it, let's try this:

    Download OTL by Old Timer. and save it to your Desktop.

    * Double click on OTL.exe to run it.
    * Under Output, ensure that Minimal Output is selected.
    * Under Extra Registry section, select Use SafeList.
    * Click the Scan All Users checkbox.
    * Click on Run Scan at the top left hand corner.
    * When done, two Notepad files will open.
    o OTListIt.txt <-- Will be opened
    o Extra.txt <-- Will be minimized
    * Please post the contents of these 2 Notepad files in your next reply.
     
  16. CLD

    CLD Private E-2

    When I try changing the permissions in the security tab I receive " Class not registered"
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download SeDebug-Restore
    Save to your desktop and double click to run.

    Now see if you can run MBAM.
     
  18. CLD

    CLD Private E-2

    When I click on the link it says webpage can't be found
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It looks like sUBs has removed the file. Hang in there, I need to consult with the other malware fighters as to the next procedure to try in fixing your permissions issues.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please don't think that I have forgotten about you. We are still discussing this situation. ;)

    However, in the meantime, I would suggest that you try to back up all of your personal files and info in case we are left with having to do a reformat and clean install.
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, lets try a few things and see what happens>

    First, try this:
    http://fixitcenter.support.microsoft.com/Portal/

    Then if it doesn't fix your system, I want you to see if you can create a new user account with Admin. privileges.

    Let me know. ;)
     
  22. CLD

    CLD Private E-2

    I knew you guys didn't forget about me:)

    I tried to run fixitcenter and it said I don't have the correct .NEt framework and wanted to download it but all downloads are blocked.

    I couldn't create another user account
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use another PC to download the installer for the version of .NET Framework it wants. Then via a USB flash drive or CD, copy to this PC.

    For example, below is a link for version 3.5 and at the end of this you can see links for version 3.5.1 and 4

    http://www.microsoft.com/downloads/...fd-ae52-4e35-b531-508d977d32a6&displaylang=en
     
  24. CLD

    CLD Private E-2

    I tried to install NetFramework and it says that it is already installed on my computer.

    When I try to run Fixitcenter it says I don't have NetFramework installed.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does it mention a specific version number?

    It is starting to sound like there are too many problems within your copy of Windows and that you may have to perform a reinstall to fix it. Let me ask a couple other questions:
    • Do you have your Windows boot CD?
    • Have you attempted to run System Restore to go back to a restore point from before when your problems began?
     
  26. CLD

    CLD Private E-2

    For the heck of it I tried a couple of more times to get Fixitcenter to start and it actually opened and started scanning but it shut itself down while scanning and now when I try and start it again I get the message : its not a valid WIin32 application.


    To answer your questions :

    It said version number 2.0.50727

    I don't have a Windows CD .

    I can't access system restore because I don't have administrator rights.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does the C:\MGtools folder exist? And do you see the FixACLS.bat file in the folder?
     
  28. CLD

    CLD Private E-2

    The C drive letter has been changed to G but yes to both questions.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are both the C drive and the G drive bootable drives containing copies of Windows?
     
  30. CLD

    CLD Private E-2

    After I became infected it changed the letters on my drives.

    C became G and the recovery drive became C.

    Sorry to sound stupid but my Windows files are in G if that;s what you're asking.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm just trying to understand your setup. And what is drive I. Is this just a backup drive? And is it a removable or fixed drive?


    Please do the below after answering my questions.

    Please click Start, All Program, Accessories and you will see ( among other things ) a Command Prompt entry.
    • Right click the Command Prompt entry and select Run As Administrator.
      • It is critical that you run it this way.
    • If you do this properly, a command prompt window will open with a title of Administrator Command Prompt.
    • Enter the below commands at the command prompt each followed by the enter key. Try each command!!!! The bold black are commands. The purple/brown is merely informational.
    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    FixACLS <-- this will try to fix a limited number of permissions issues on a few files and folder. Tell me what error messages, if any, you see.
    nwktst <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    analyse <-- this will try to run TrendMicro Hijackthis. Click Twice on the Accept button to accept the license agreement if it shows. Then run a scan and save a log. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
     
  32. CLD

    CLD Private E-2

    The ( I ) drive is my flash memory stick.

    After I typed in fixacls

    About 10 "are you sure Y/N " are listed with a list of instructions

    at the very bottom is G:\mgtools

    Do you want any information from that before I proceed to nwkst?
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you say yes to all of them?


    Just continue.
     
  34. CLD

    CLD Private E-2

    After each Y/N it says for example :
    processed file G:\mgtools\sed.exe


    It didn't give me a chance to answer Y or N
    I can't do anything within the body of that list .

    I'm continuing now.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that is what I actually expected should have happened since the FixACLS program is set to auto reply with the yes. ;)
     
  36. CLD

    CLD Private E-2

    here are the 2 logs
     

    Attached Files:

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that shows a few things will run. Did analyse.exe run?

    Also try ShowNew from the command prompt. If it runs, a file named newfiles.txt will be created.
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your runkeys.txt log shows that you are not in Normal Startup mode per the request in step 4 of the READ & RUN ME. Many of your startup processes and many of your required Windows services are disable which may be the reason for some if not all of your problems. Are you unable to run MSconfig to get into normal startup mode.
     
  39. CLD

    CLD Private E-2

    sorry I forgot to add the Hijackthis log
     

    Attached Files:

  40. CLD

    CLD Private E-2

    I can get into MSConfig.

    I did read and try to follow the instructions before my first post.
    I must have missed that step.
     

    Attached Files:

  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so did you select Normal Startup? If so, reboot your PC and then per my previous instruction, run GetRunKey again from the command prompt and then attach the new runkeys.txt log.
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just noticed in your newfiles.txt log that you had Glary Utilities. Make sure that you have not disabled any startups with it either.
     
  43. CLD

    CLD Private E-2

    new log attached from normal startup mode
     

    Attached Files:

  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's much better. All of your services are no longer disabled. Are things working any differently?
     
  45. CLD

    CLD Private E-2

    I still don't have administrative control.
     
  46. CLD

    CLD Private E-2

    I'm still unable to download anything
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but based on your logs, it may not be due to malware. Let's cleanup some additional non-malware items and try a couple more things but I may be sending you off to the Software Forum to handle you permissions problems since they appear to be Windows problems not malware.

    Also answer a couple questions
    • Had you recently run any kind of registry cleaning tools or performance enhancement tools on this PC?
    • Have you tried using System Restore again after having run FixACLS?
    Uninstall Trojan Remover which you have setup to run from a removable drive and this is a bad idea to begin with.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - (no file)
    O4 - HKLM\..\Run: [TrojanScanner] I:\Trojan Remover\Trjscan.exe /boot
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (no file)
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
    O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - (no file)
    O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
    O23 - Service: TrueVector Internet Monitor (vsmon) - Unknown owner - C:\Windows\System32\ZoneLabs\vsmon.exe (file missing)

    After clicking Fix, exit HJT.





    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).




    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Any change to your status? I would not expect the above to change anything except remove a bunch of unnecessary/dead items.
     
  48. CLD

    CLD Private E-2

    To quickly answer your questions,

    Yes I've run registry tools in the past.
    I can't get into system restore the message I receive is : help and support was not able to start

    I was trying anything and everything to see if it would work that's why you'll find a mix and mess of "tools" on that computer.
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For future reference, DON'T. You do not need them and they can cause more harm then good.

    Okay but is this still the case after getting into normal startup mode since some services that were not running before are now running.

    Not really a good idea especially since your problems do not appear to be related to malware. You could have just made things worse.

    Do you have your Windows boot CD?
     
  50. CLD

    CLD Private E-2

    I can't move the mglogs.zip file, it won't let me.
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds