Help Cleaning FILs rig

Discussion in 'Malware Help (A Specialist Will Reply)' started by Karkas, Jun 1, 2009.

  1. Karkas

    Karkas Private E-2

    My father-in-laws rig is badly infested. I ran the sticky and its much better but at least one svchost process remains and causes the system to freeze, esp. when launching "my computer"

    I'm attaching the scan logs from the sticky.

    Please let me know whatever additional info you need

    Thanks in advance!

    P.S. Someone slap me for ever volunteering to build him a rig!
     

    Attached Files:

  2. Karkas

    Karkas Private E-2

    I figured I'd add more info, I hope it is useful.:)

    The process which seems to be causing the system freeze is a svchost process.

    I found if I kill the process the system freezes go away (for the most part). Killing prompts system shutdown, but a shutdown/a command stops that... It uses remote procedure call service which I understand can not be disabled.

    Would I be able to delete the file then try to repair windows or sfc /scannow to try to replace it?

    I attached a screen shot with some details that may be useful. If this info is way off base just ignore it.

    Thanks again guys:-D
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Karkas


    The below fixes are specific to your problem and should only be used for issue(s) on this machine. Also, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    Question: Did you receive any error messages while running MGTools? The contents of your attached MGLogs.zip didn't contain the expected set of logs. Make sure that you have saved MGTools.zip to and ran it from your C drive where Windows is installed.

    Step 1:
    We're going to use ComboFix to remove some malware.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 2:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 3:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\combofix.txt

    Make sure you tell me if you had any problems running this procedure - if you get any error messages when running GetLogs.bat, and give a description of how things are working now!

    dr.m
     
  5. Karkas

    Karkas Private E-2

    Dr. M

    Let me start by thanking you and your anti-malware partners for the help you provide a million times :-D

    Having said that I am still having problems with the system freezing for 5 - 30+ seconds every few minutes or so. (I can force a 30+second system freeze by opening "my computer."

    Running svchostanalyzer show that svchost process I mentioned in my 2nd post still restricted access & killing it seems to alleviate system freezing.

    To address your 1st question; I'm not sure if the 1st time I ran MGtools there was an error, I walked out of the room after it started the scan for a minute and when I came back the system was rebooting. Since it appeared there was teh .zip file with data inside, I assumed it rebooted as part of the normal process.

    Running your fixes this time presented to errors to me other than combofix update not being run (this machine was not connected to the internet and since it was updated just a few days ago I assumed this would not be an issue).

    I did run the update after I connected the internet and it DID grab an update so I hope this isn't a problem for you/me (sorry:cry).

    Here are the logs:
    Problem: When I looked for the combofix.txt log it was gone. I know it was there after I dragged the CFscript.txt onto combofix.exe, but now it's gone... I included the mglog from before rescan (mglogs2.zip).

    I reran everything in your post to get the combofix.txt file. When I ran getlogs.bat the system crashed. After it rebooted I deleted the incomplete mglogs.zip, and reran getlogs.bat. This time no system crash and I included the file (mglogs.zip)
     

    Attached Files:

  6. Karkas

    Karkas Private E-2

    Should have said...
    Sorry about that it wouldn't let me edit my post.
     
  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    I found no further signs of infections in your recent logs.

    Notes: After checking on:

    c:\docume~1\Ben\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys
    I didn't have a problem downloading and installing CPU-Z to my Program Files folder. *Did you download it or did you just run it without saving the application?

    * Re: your last post reply - I have these ideas and or questions for you:
    • Does it happen if no browsers are open?
    • Does it happen if the cable to the internet is disconnected?
    • Does it happen if protection software is disabled?
    • Does it happen in safe boot mode?

    dr.m
     
  8. Karkas

    Karkas Private E-2

    I'm confused, I don't remember discussing anything to do with that cpuz you listed and it isn't in the file path you listed. What are you asking?:-o:confused

    In a nutshell: At anytime I can force a 5 - 10 second freeze simply by opening "My computer".

    If I try to open "my Computer" when online & browsing this often results in a 1 - 3 minute total system freeze. Simply trying to browse the internet causes the computer to freeze for 10 - 30 seconds every 15 seconds or so.

    If I'm offline it takes a long time to get the system to freeze unless I open "my Computer" which usually causes the 5 - 10 second freeze I listed above.

    Note:The OS install on this system is only about 2 - 3 months old and there was absolutely no "my computer" lag/freeze prior to him contracting this malware.
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, karkas

    The above is something I saw that looked strange in that directory from your last logs:
    CPU-Z is a freeware that gathers information on some of the main devices of your system.

    Now - back to your answers. You need to find out if it happens in Safe Mode. If it does ( and your logs appear to be clean ), it may be due to some damage caused by the malware you had. *If it does not happen in Safe Mode - something is being loaded while you're in Normal Boot Mode and you'll have to figure out what.

    Let's try some online scans!

    1) This procedure explains how to get to the PandaActiveScan site to setup and perform an online scan. It also explains how to obtain a log so you can attach it to a message. You must use Internet Explorer to run this scan and make sure your Sun Java version is current.

    * If you are in safe mode, reboot into normal mode now.

    To start the online scan go here: Panda ActiveScan


    To run the Online Scan continue with the below steps.
    1. When the page appears, click the Scan your PC button.
    2. In the next window, click the Check Now button
    3. Click the Scan Now button
    4. If you get a prompt about an Active-X component, allow the component to be installed.
    5. Now a download to your PC will begin. This is a required component for the scan. It contains detection information. (Note: It may take a while to download based on your connection speed.)
      • A second prompt will appear to allow the component to be updated
    6. When the scan is finished close the popup window and then click See Report
    7. Click Yes to the prompt, then click Save Report
    8. The default report name is Activescan.txt. Just save it where you can find it so you can attach to your message.

    2) Now also run Using BitDefender Online Scan

    Then attach the below logs to your next reply:
    • ActiveScan.txt
    • bdscan.txt

    dr.m
     
  10. Karkas

    Karkas Private E-2

    I put that on his system when I overclocked it, I'm sure I DL'd it.

    Here are the logs, FYI the E drive was an old infested drive that I neutered so he can longer boot from it (due to has last malware infestation).

    NOTE: The BDScan did not allow to change the save type to text from html. I tried giving it the .txt file extention anyway, but the file was too big to add as an attachment. Here is the link to get it http://www.box.net/shared/ielk7bzcth. Dunno what else to do... I followed the bitdefender scan directions exactly.:confused
     

    Attached Files:

  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Karkas -

    I need to know definitely whether or not you have the system freeze problem while in Safe Mode.

    Do the following:
    • Toggle your System Restore to flush your old restore points. Disable And Enable System Restore
    • Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!
    • Run ATF Cleaner by Atribune

      • This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
      • * Double-click ATF-Cleaner.exe to run the program.
      • Under Main choose: Select All
      • Click the Empty Selected button.

      If you use Firefox browser

    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Now - update ALL Scanners and run them - attach the below logs to your next reply.
    • SASlog.txt log
    • Malwarebytes Anti-Malware log
    • ComboFix.txt
    • MGlogs.zip

    Remember to answer my question and to describe how the PC is now running.

    dr.m
     
  12. Karkas

    Karkas Private E-2

    I followed the new instructions and am sad to report that I still seem to have the exact same problems with system hang as before.

    On a positive note I think I can definitively say that there is absolutely no system hang in safe mode or even safe mode with networking. I used if for several hours including internet browsing and left it running for over 24 hours and never saw it hang once.

    At anytime I can force a 5 - 10 second freeze simply by opening "My Computer".

    If I try to open "My Computer" when online & browsing this often results in a 1 - 3 minute total system freeze. Simply trying to browse the internet or typing into the browser causes the computer to freeze for 10 - 30 seconds every 15 seconds or so.

    If I'm offline it takes a long time to get the system to freeze unless I open "My Computer" which usually causes the 5 - 10 second freeze and no drives will be shown until it frees up again.

    If I access "My Computer" through another program I don't get a system freeze. Example: When I went to upload the logs I clicked the "Browse" button in the manage attachments window, then selected "My computer" and it showed "My Computer" contents instantly with no system freeze at all.

    Anyway, here are the logs

    Thanks again dr.m
     

    Attached Files:

  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Karkas

    * A reminder to follow my steps for log generation in the order given, to avoid extra work determining the current status of the machine.

    IMPORTANT EDIT: A question -
    Referring to the files that SAS deleted from the E drive under the Trojan.Agent/Gen-ImageDocFake heading... were they files that you know were valid?


    Step 1:
    The problem not incurring in Safe Mode means it is obviously due to a driver, process, or service that runs in normal boot mode but not safe mode. Let's try something -
    • Click on Start, then Run ... type services.msc into the box that opens up, and press OK.
    • On the page that opens, scroll down to locate a reference to Ati Hotkey Poller
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the "Start-up Type" to Disabled.
    • Click OK until you get back to Windows Explorer.

    Step 2:
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named C:\DeQuarantine_log.txt
    • I will ask for this log below

    Step 3:
    Using Windows Explorer - navigate to and delete the following:
    C:\WINDOWS\system32\gxvxccount

    Step 4:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    *Re-boot

    Step 5:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\DeQuarantine_log.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
    Last edited: Jul 1, 2009
  14. Karkas

    Karkas Private E-2

    I'm not sure since it isn't my rig. Though I'm fairly sure the docs were valid. No idea about most of the rest of it though...


    I had no problems following your instructions and the only thing of note was after I ran everything and tried to launch my browser to post the logs the internet connection was lost. I rebooted and was able to connect to the internet again. Maybe nothing, maybe important to you. (ati hotkey poller is still disabled).

    Oh and I couldn't delete C:\WINDOWS\system32\gxvxccount. It was already quarantined @ C:\Qoobox\Quarantine\C\WINDOWS\system32\gxvxccount.vir, so I left it there undeleted.

    Unfortunately it looks like the computer is running as horribly as before:cry

    Logs attached
    Thanks
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There was a typo in the last fix dr.moriarty gave you. The below file
    C:\Qoobox\Quarantine\C\WINDOWS\system32\ATIODE.exevir

    should have been named
    C:\Qoobox\Quarantine\C\WINDOWS\system32\ATIODE.exe.vir

    The missing period cause it not to be restored from the quarantine folder. If you know how to copy & rename files from one folder to another. Just copy the above file back to the C:\windows\system32 folder and then right click on it and select Rename and remove the .vir extension so that the file is only named ATIODE.exe

    This is not due to any remaining malware. Back a few messages ago, you said things ran fine in safe boot mode. You need to determine what from the list of startup processes and services that you are loading may be causing the problem when you boot in normal mode.

    This is the place where MSconfig should be used to do debugging. With MSconfig you can selectively disable Startups and various non-windows services to see if you can locate which one is responsible for your problem. I put non-windows services in bold print since you need to be extremely careful what you disable under the Services tab of MSconfig. When you select the Services tab, first check the box at the bottom that says Hide All Microsoft Services This way you will not disable any critical Microsoft services.

    This is a process of elimination where you are trying to zero in on the possible problem. I suggest you first start by running MSconfig and selecting only the Startup tab and then click the Disable All button. Then click OK. Then reboot in normal (not safe ) boot mode. You will be in selective startup mode but that is okay while debugging.

    If disabling the Startups does not remove the problem. Move on to the Services tab and remember to hide Microsoft services first. Then uncheck half of the services and then click Apply, OK and then reboot. If no luck, reenable the first half of the services, and uncheck the second half then click Apply, OK and then reboot. Assuming this fixes the problem, then slowly add services back in until you find the one that causes the problem.

    Let us know how this goes or if you don't understand something.
     
  16. Karkas

    Karkas Private E-2

    Thank you for all of your help guys, chaslang was right that it was a program (carbonite) that was causing the lockups. I'm in contact with the company atm to figure out why. They claim it couldn't do it, but they are reviewing the logs anyway.

    Thanks again guys! You are awesome!:-D
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Interesting. They also make the below claim online:
    I guess they have to redefine meaning of never or the meaning of slow.:-D
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds