Help please. Malware won't let me install malwarebytes and internet isnt working now.

Discussion in 'Malware Help (A Specialist Will Reply)' started by metalmilitia, Nov 3, 2015.

  1. metalmilitia

    metalmilitia Private E-2

    Hey guys I ended up with a nasty virus/malware last night. It won't let me install malwarebytes or run trendmicro virus scan or bit defender. I actually think I may have gotten the virus from downloading bit defender from a fake website that looked like bit defender. Also, my internet won't work on chrome now but it works on IE with mad amounts of popups. On chrome it says, DNS_PROBE_FINISHED_NXDOMAIN.

    What's my first step here? I just managed to get superantispyware installed and it seems to have removed some stuff but my internet still isnt working.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. metalmilitia

    metalmilitia Private E-2

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Managed to run CC cleaner and rogue killer. I disabled UAC but i'm on Windows 10 anyways.

    Here's my log from Rogue Killer.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bsdriver -> Found
    • [PUP|VT.PUP.Optional.Shopperz.BrwsrFlsh] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cherimoya (system32\drivers\cherimoya.sys) -> Found
    • [PUP|VT.PUP.Optional.ModGoog] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\globalUpdate (C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /svc) -> Found
    • [PUP|VT.PUP.Optional.ModGoog] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\globalUpdatem (C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /medsvc) -> Found
    • [PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bsdriver -> Found
    • [PUP|VT.PUP.Optional.Shopperz.BrwsrFlsh] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cherimoya (system32\drivers\cherimoya.sys) -> Found
    • [PUP|VT.PUP.Optional.ModGoog] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\globalUpdate (C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /svc) -> Found
    • [PUP|VT.PUP.Optional.ModGoog] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\globalUpdatem (C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /medsvc) -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs : C:\ProgramData\SmartPurple\SmartPurple64.dll [x] -> Found
    • [Suspicious.Path] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs : C:\ProgramData\SmartPurple\SmartPurple32.dll [x] -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.

    ...and the same for these entries on the file tab please...

    • [PUP][File] C:\Windows\System32\drivers\bsdriver.sys -> Found
    • [PUP][Folder] C:\Program Files (x86)\globalUpdate -> Found

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.

    Are you able to run any of the other tools in the Read and Run Me First now?
     
  5. metalmilitia

    metalmilitia Private E-2

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    I deleted files as you instructed but it did not leave a log file on my desktop. I exported another log file as I did the first time. If this isn't correct I can try again but there was no log file on desktop of in the rogue killer folder i installed to.

    Malwarebytes still will not install after I rebooted. The error is "malwarebytes could not call proc" I've tried renamed the install file to sss.log as well as renaming the install destination folder and program name.

    TDSS Killer worked, said there was 0 infections.

    HitmanPro worked, log attached.

    Seems like BSdriver is still running and won't delete because of that.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Run RogueKiller again (just a scan) and attach log. Let me see what remains.

    Were you able to run MGTools.exe?
     
  7. metalmilitia

    metalmilitia Private E-2

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    When I try to open MG tools website it won't let me download it, says it's a dangerous website.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Do this if you can:

    Please download Combofix to your desktop. Please refer to these instructions prior to running.
     
  9. metalmilitia

    metalmilitia Private E-2

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Just tried ComboFix, it's not supported on Windows 10 and won't install.

    Here's the log from Rogue Killer.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    SystemLook

    Please download SystemLook from one of the links below appropriate for your operating system and save it to your Desktop.
    Download 32 Bit
    Download 64 Bit

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      dnsapi.dll
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  11. metalmilitia

    metalmilitia Private E-2

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Here's the systemlook file.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  13. metalmilitia

    metalmilitia Private E-2

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Here are the requested files.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.


    Download Fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)


    Also at this point, I want to double check the status of things by having you run another scan with FRST like in my last message and attach the new FRST.txt and Addition.txt logs.
     

    Attached Files:

  15. metalmilitia

    metalmilitia Private E-2

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Here's the fixlog, still says it can't move BSdriver and cherimoya.
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Don't forget this part:

    Also perform a fresh scan (scan only) with Hitman and attach the new log.
     
  17. metalmilitia

    metalmilitia Private E-2

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Here you go
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    And once more, re run RogueKiller, scan only, and attach log.
     
  19. metalmilitia

    metalmilitia Private E-2

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Here you go.
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Run Systemlook again like you did before in post#10 and attach log. FRST is still reporting the file missing yet I replaced it....
     
  21. metalmilitia

    metalmilitia Private E-2

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Here it is
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bsdriver -> Found
    • [PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bsdriver -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.

    ...and the same for this one on files tab....
    • [PUP][File] C:\Windows\System32\drivers\bsdriver.sys -> Found

    When it is finished, there will be a log on your desktop.
    Attach it to your next message. (How to attach)





    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :Files
    C:\Windows\System32\drivers\bsdriver.sys
    C:\Windows\system32\Drivers\cherimoya.sys
    C:\PROGRA~1\SHOPPE~1\Lalhiqm.ba
    
    :reg
    [-HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bsdriver]
    [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bsdriver]
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.


    Download Fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)

    Then attach the below logs:

    Fixlog.txt


    Run a scan with FRST like you did in post#12 and attach the new FRST.txt
    Run a new scan with RogueKiller - attch that log too please.
     

    Attached Files:

    Last edited: Nov 3, 2015
  23. metalmilitia

    metalmilitia Private E-2

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    When I try to shut down the 2 registry and 1 file item from BSdriver it says error[5] beside them after I click delete. It lists BSdriver in the processes tab, is it not letting me delete them because it's still in use?
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Grr, it's stubborn!! Continue on with the other steps.... :)
     
  25. metalmilitia

    metalmilitia Private E-2

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Here we go, that took a while. Think I got everything you asked for.
     

    Attached Files:

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    I have to go to sleep soon. :( I am asking colleagues for assistance with this. In the mean time:


    Delete any RogueKiller logs or fixlists's/fixlogs etc that may be cluttering your desktop.

    Follow as much of this self help guide as you possibly can, skipping any steps that do not work (remember you can try running Malware Bytes in safe mode if necessary)
    attach any logs you were able to get, and let me know how you get on.
     
  27. metalmilitia

    metalmilitia Private E-2

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Ok thanks for your help! I'll check back in tomorrow.
     
  28. metalmilitia

    metalmilitia Private E-2

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    I tried installing MalwareBytes onto my flash drive from my desktop and then running it on my infected laptop. Seemed to almost work but my laptop gave the error that it can't run because dnsapi.dll is missing! grrr
     
  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    I don't understand that because the first thing I did was to replace it with a fresh copy. :(

    Follow the instructions here to run the System File Checker

    https://support.microsoft.com/en-gb/kb/929833

    Then see if Malware Bytes will run.
     
  30. metalmilitia

    metalmilitia Private E-2

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    I tried to remove bsdriver.sys manually and it says I dont have access to edit or delete the file but my account is the only active account and is the Admin. It appears as though the default "Administrator" account has control of the windows folder. I tried to take access and it still wouldnt work.
     
  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Good evening.

    Did you try System File Check?
     
  32. metalmilitia

    metalmilitia Private E-2

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Yes, here's the log file. It says Windows resource protection found corrupt files but was unable to fix some of them. Actually it wont let me upload the log. too big i guess
     
  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Which ones was it not able to fix? Will Malware Bytes now run?
     
  34. metalmilitia

    metalmilitia Private E-2

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    I think I just fixed it. I downloaded a program called Dr. Web CureIT and it removed the bsdriver.sys and now my internet is working again.

    Malwarebytes is scanning right now.
     
  35. metalmilitia

    metalmilitia Private E-2

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Heres the logs from MBAM. I changed them from xml to txt file.
     

    Attached Files:

  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    That's good news!

    See the sticky thread here to see how to attach the Malware Bytes log in it's proper format.
     
  37. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    Are you still with me, metalmilitia?
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Help please. Malware won't let me install malwarebytes and internet isnt working

    It's not dangerous and the instructions in the READ & RUN ME and the Using MGtools instructions even warn you about issues with browsers saying this. ;) You should have downloaded and run it and attached the log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds