GAC_32 and _64/desktop.ini removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by ladyindigo, Jul 21, 2012.

  1. ladyindigo

    ladyindigo Private E-2

    Hey all, this forum is a lifesaver. Picked this guy up yesterday through a file that AVG swore wasn't infected until it started throwing this up into my system. Mainly getting reports of the file, an attempt to "install Flash" that went away sometime through the required scans you guys ask for, slow-moving computer at times, and a weird forced shutdown or two. During the MGTools scan this also popped up: "The ordinal 1108 could not be located in the dynamic link library WSOC32.dll."

    Attaching all the scans you asked for, I actually removed the RogueKiller files it found once before because I wasn't sure if I was allowed to or not before posting it to the forum. They came back. I'd appreciate any help you guys can give!

    Somehow I ended up with two RogueKiller logs so my MalwareBytes long is going in my next post.
     

    Attached Files:

  2. ladyindigo

    ladyindigo Private E-2

    Now I feel stupid, put up another post because I didn't realize this was an approval thing. Here's my Malwarebytes log and an updated RKreport log because...it's a long story, I thought I was supposed to go into other threads and mess around before posting, and anyway, I don't think I removed anything that wasn't related to the virus, feel free to tell me to run it again if need be.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now that you had RogueKiller remove the infection, please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  4. ladyindigo

    ladyindigo Private E-2

    File attached! It actually didn't even bring up the HijackThis window, I can run it again to be sure but the other times I ran the program it did pop up and I did accept the license agreement. I also got that "The ordinal 1108 could not be located in the dynamic link library WSOC32.dll" message again, not sure what to do with that and couldn't find mention of it in the FAQ.

    I'm actually currently in safe mode, would you like me to see what AVG pulls up when out of safe mode? Should I be running any scans from there?
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to remove one of your AV programs:
    AVG 2012
    Microsoft Security Essentials

    Please try to boot into normal mode and re-run ComboFix. Make sure it is on your desktop and do not do anything while it runs.

    Let me know what happens. ( Attach the log if it is successful ).
     
  6. ladyindigo

    ladyindigo Private E-2

    Augh, sorry, could've sworn I'd gotten rid of Security Essentials. Taken care of now. You actually never asked me to run Combofix before, would you like me to or did you mean another program? When I first tried it stated AVG might cause compatibility errors, should I disable AVG temporarily while it scans?

    On startup:
    Runtime error, C:/windows/system32/nvvsvc.exe request Runtime terminate it in an unusual way.
    AVG found c:/windows/system32/services.exe Trojan horse Patched_C.LXT detected on open.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, while we work on your infection, you need to either disable AVG or uninstall it.

    You're right, I got confused with another thread, so here is the link for combo:

    Please download ComboFix to your desktop and run it. Do not do anything while it runs. Attach the log when it is finished.
     
  8. ladyindigo

    ladyindigo Private E-2

    Thought I'd disabled AVG and apparently did something wrong, AVG attempted to attack a file in Combofix while Combofix was running and deleted it. Tried to restart. Now Combofix won't reinstall and Internet access is mysteriously unavailable. No idea what happened and I really need this fixed immediately.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do the below so that we can boot to System Recovery Options to run a scan. There will be two options to choose from. One if you do not have your Windows 7 boot DVD and another when you have your DVD.

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Option1: Enter System Recovery Options from the Advanced Boot Options:

    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    Option2: Enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  10. ladyindigo

    ladyindigo Private E-2

    Apologies for being snappish in my last post, didn't mean to press whatever I did that messed with Combofix and now I'm very frustrated and concerned I've destroyed my computer or my Internet in some way. I'm unable to access the Internet through my computer right now, I'm using a roommate's laptop. How can I get internet access to download this file and use it properly?
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    As stated, download to a flash drive and plug the flash drive into the infected computer. Follow the instructions. ;)
     
  12. ladyindigo

    ladyindigo Private E-2

    Sorry for the lack of reading comprehension, moment of panic. I swear I am at least 70% not-idiot when it comes to technology. Really. At the very least I know what a flash drive is.

    Scan log is attached!
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Save fixlist.txt to your flash drive.

    • You should now have both fixlist.txt and FRST.exe on your flash drive.

    Now reboot back into the System Recovery Options as you did previously.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows can continue with the below.

    Running MGTools.
     

    Attached Files:

  14. ladyindigo

    ladyindigo Private E-2

    Fixlog.txt attached, running MGTools now as instructed.
     

    Attached Files:

  15. ladyindigo

    ladyindigo Private E-2

    Attaching MGlogs. Still no Internet access but no weird popup on the MGTools scan this time.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    1. Go to Start ==> Run (or Windows key+R)
      • Type the following in the run box and click OK: notepad c:\windows\inf\nettcpip.inf
        (note that there is space after notepad)
      • The above file will open in the notepad.
      • Under TCP/IP Primary Install section find the following: Characteristics = 0xA0
      • Edit 0xA0 and replace it with 0x80 (replace A with 8)
      • Under File menu click Save and close the notepad.

    2. Go to Start ==> Control Panel. Double-click Network Connections. Right-click Local Area Connection, and select Properties.
      • On the General tab, click Install a popup window opens.
      • Select Protocol from the list and then click Add.
      • A new window opens, click Have Disk....
      • In the browse... box type c:\windows\inf
      • Click OK.
      • Select Internet Protocol (TCP/IP), and then click OK.
      • On the Local Area Connection Properties screen select Internet Protocol (TCP/IP) and click Uninstall, and then click Yes.
      • Wait until it asks to restart, and then restart as requested. Continue with the below after restarting.

    3. Go to Start ==> Run (or Windows key+R)
      • Type the following in the run box and click OK: notepad c:\windows\inf\nettcpip.inf
        (note that there is space after notepad)
      • A file opens in the notepad. Under TCP/IP Primary Install section find the following: Characteristics = 0x80
      • Edit 0x80 and replace it with 0xA0 (replace 8 with A)
      • Under File menu click Save and close the notepad.

    4. Go to Start ==> Control Panel. Double-click Network Connections. Right-click Local Area Connection, and select Properties.
      • On the General tab, click Install
      • A popup window opens. Select Protocol.
      • A new popup window opens. Select Internet Protocol (TCP/IP), and then click OK.
      • Wait until it asks to restart, and then restart as requested. Continue with the below after restarting.

    5. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    6. Then attach the below logs:
      • C:\MGlogs.zip

     
  17. ladyindigo

    ladyindigo Private E-2

    When I try to save nettcpip.inf it says access is denied, haven't tried the others yet. UAC controls are what they're supposed to be, how can I enable access?
     
  18. ladyindigo

    ladyindigo Private E-2

    There is also no Network Connections or Local Area Connections area in the control panel as you describe, it says 'Network and Internet' and opens to 'Network and Sharing Center', 'HomeGroup', and 'Internet Options'.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    http://img406.imageshack.us/img406/3189/windowsrepair.gif Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.

    • Now open Repair_Windows.exe
    • Go to Start Repairs tab.
    • Choose "Custom Mode" and press "Start".
    • Create a System Restore point if prompted.
    • In the Custom Mode window, select the following repair options:
      • Repair Windows Firewall
      • Repair Internet Explorer
      • Repair Hosts File
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Windows Updates

    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • If asked to reboot the computer for the changes to take affect, make sure other tasks in the program are not still running before accepting to restart.
     
  20. ladyindigo

    ladyindigo Private E-2

    Ran and repaired everything as instructed and restarted the computer when prompted. Still no Internet access, though, looking at my Network center it shows me as permanently 'Identifying'.
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download the afd.zip file I have attached to this message.
    Extract afd.reg to your desktop.
    Then double-click afd.reg and allow it to merge into the registry.
    Let me know if you received a successful message or not before proceeding.

    AFD Fix
     
  22. ladyindigo

    ladyindigo Private E-2

    Merge was successful!
     
  23. ladyindigo

    ladyindigo Private E-2

    After a reboot the Internet is still not working, can someone please assist me?
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry for the delay, I lost internet service on Sat. afternoon and just got it back. Some of your internet services were not running. Let's recheck. Please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip
     
  25. ladyindigo

    ladyindigo Private E-2

    No problem. I apologize for this if it undoes some work, but I work from home and honestly couldn't spend 2 days without regular access. I did a system restore from a point very shortly before the virus infected which fixed my Internet (virus is of course still there). I tried to re-run everything you'd said to run except for ComboFix since my mistake with that/AVG seemed to cause the Internet issue, and to uninstall the antivirus programs except for AVG. I'm attaching the MGTools log along with the other three programs from the FAQ in case it'll help to show you where I'm at.
     

    Attached Files:

  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Files/folders tab and locate these detections:

    c:\windows\installer\{09f948c7-4371-e3ea-4a76-a064ded63fb9}\U --> FOUND
    [ZeroAccess][FILE] Desktop.ini : c:\windows\assembly\gac_32\desktop.ini --> FOUND
    [ZeroAccess][FILE] Desktop.ini : c:\windows\assembly\gac_64\desktop.ini --> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.


    Rescan with HitmanPro,Choose to Delete these two files if they are detected:


    • Trojan.Generic.7552386 (Engine A)" />
      BackDoor.Maxplus.6342" />
      Trojan.Win32.Sirefef!IK"
      C:\windows\assembly\gac_32\Desktop.ini
      C:\windows\SysWOW64\RGSS102E.dll

    Ignore all other detections.
    Afterwards, click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * RogueKiller log
    * HitmanPro log
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  27. ladyindigo

    ladyindigo Private E-2

    Everything's basically running well, no virus encounter popups (though AVG is disabled right now), not encountering any problems and haven't restarted so can't see if my startup is slowed down. I mainly just want to make sure this is gone so I can pay my bills without worrying about keyloggers at this point.
     

    Attached Files:

  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds