Infected with Win 7 Antivirus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by DeGreatSaiyaman, Dec 15, 2011.

  1. DeGreatSaiyaman

    DeGreatSaiyaman Private E-2

    Hi all,

    Approximately three weeks ago my computer became infected with the "Win 7 Antivirus" virus. After fighting it for a couple hours I managed to use the information at here to fix it. Unfortunately, it keeps coming back, and it is getting to the point that I can't use my computer.

    I am also getting browser redirects more and more frequently, and a process named PING.EXE is taking up ~20% of my CPU and lagging my internet like crazy.

    I followed the steps in your READ ME FIRST post, with some success. Here are the attached logs.

    Any help would be greatly appreciated, as I am at wit's end!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You forgot to attach the Mglogs.zip file from running MGTools.exe. Can you do so now please?

    Also...

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
     
  3. DeGreatSaiyaman

    DeGreatSaiyaman Private E-2

    Thanks for your interest in my problem!

    The file GetUnKey was the only file in the MGLogs.zip, but here is the zip file anyway.

    TDSSkiller found nothing, nor did MBRCheck.

    Additionally, several files named desktop.ini have appeared on my desktop and in my downloads folder overnight, with some text about shellclassinfo.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please click Start, All Program, Accessories and you will see ( among other things ) a Command Prompt entry.
    • Right click the Command Prompt entry and select Run As Administrator.
      • It is critical that you run it this way.
    • If you do this properly, a command prompt window will open with a title of Administrator Command Prompt.
    • Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple/brown is merely informational.
    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools> GRK64 <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    SN64 <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.

    Do you now have a complete MGlogs.zip?


    Run this if not:

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  5. DeGreatSaiyaman

    DeGreatSaiyaman Private E-2

    After typing cd \MGTools and GRK64, the prompt returns text saying "64 Bit Windows OS found" followed by press any key to continue. After pressing a key, the window just hangs and does nothing else (although I'm not sure what is supposed to happen). I am therefore unable to type SN64 afterward.

    I will try running OTL now.
     
  6. DeGreatSaiyaman

    DeGreatSaiyaman Private E-2

    Here are the attached logs from running OTL.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r



    Now we need to scan the system with this special tool.
    • Please download Junction.zip and save it to your root folder (C:\Junction.zip)
    • Unzip it and put junction.exe in the root folder (C:\junction.exe)
    • Now click Start => Run... => Copy and paste the following command in the run box and click OK:
      cmd /c junction -s c:\ >C:\log.txt
    • A command prompt window opens and also a license agreement from SysInternals will appear.
    • Accept the license agreement and the scan will begin.
    • Wait until a log file opens. Attach this C:\log.txt when it finishes (the command prompt window will close when it finishes). (How to attach items to your post)
    • NOTE: It scans your whole hard disk so if can take a long time. Be patient and don't do anything else while it is scanning.


    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\Windows\assembly\temp\kwrd.dll
    C:\Users\Robert\AppData\Local\o5cp76v2qk5kvq
    C:\ProgramData\o5cp76v2qk5kvq
    C:\Users\Robert\AppData\Local\pltlgn5f0xfj6kyw5qlc5r666y6h
    C:\ProgramData\pltlgn5f0xfj6kyw5qlc5r666y6h
    C:\Users\Robert\AppData\Local\v6ty32s6fy3mfn
    C:\ProgramData\v6ty32s6fy3mfn
    C:\Users\Robert\AppData\Local\f5dd21x6qb8wjf
    C:\ProgramData\f5dd21x6qb8wjf
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  8. DeGreatSaiyaman

    DeGreatSaiyaman Private E-2

    After putting junction.exe in my C:\ directory, I copy pasted that line into my run box, but it did not work correctly. The command prompt window flashed open and closed immediately and there was no window that popped up nor a log placed on my desktop.

    I ran the Win32kdiag as well, but I'm not sure that it worked properly. The log is attached.

    Should I continue and try running the Combofix or do we need to figure out what's wrong with Junction first?
     

    Attached Files:

  9. DeGreatSaiyaman

    DeGreatSaiyaman Private E-2

    I went ahead and ran the Combofix and GetLogs in hopes that it would stop this annoying PING.EXE issue (which it did!) Still can't get Junction to return with anything.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "combofix"=-
    
    File::
    C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Templates\f5dd21x6qb8wjf
    C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Templates\o5cp76v2qk5kvq
    C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Templates\pltlgn5f0xfj6kyw5qlc5r666y6h
    C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Templates\v6ty32s6fy3mfn
    C:\Windows\assembly\GAC_32\Desktop.ini
    C:\Windows\assembly\GAC_64\Desktop.ini
    C:\Windows\assembly\temp\@
    C:\Windows\assembly\temp\bckfg.tmp
    C:\Windows\assembly\temp\cfg.ini
    C:\Windows\assembly\temp\keywords
    C:\Windows\assembly\temp\lsflt7.ver
    C:\Windows\assembly\temp\U\00000001.@
    C:\Windows\assembly\temp\U\00000002.@
    C:\Windows\assembly\temp\U\00000004.@
    C:\Windows\assembly\temp\U\000000c0.@
    C:\Windows\assembly\temp\U\000000cb.@
    C:\Windows\assembly\temp\U\000000cf.@
    C:\Windows\assembly\temp\U\80000000.@
    C:\Windows\assembly\temp\U\80000004.@
    C:\Windows\assembly\temp\U\80000032.@
    C:\Windows\assembly\temp\U\80000064.@
    C:\Windows\assembly\temp\U\800000c0.@
    C:\Windows\assembly\temp\U\800000cb.@
    C:\Windows\assembly\temp\U\800000cf.@
    
    Folder::
    C:\Windows\assembly\temp\U
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.



    Run OTL again like you did in post # 4. Attach the log please.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  11. DeGreatSaiyaman

    DeGreatSaiyaman Private E-2

    All of them ran smoothly, looks like we're finally getting to the bottom of this infection. Thank you so much for your patience and time!!!
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That last set of logs look good. How are things currently running for you?
     
  13. DeGreatSaiyaman

    DeGreatSaiyaman Private E-2

    Looks like it's running well! I'll give it a day or two to make sure nothing pops up, then run through the final steps with you.

    One question: what antivirus would you recommend I get now? I was using ESET but the virus went right through it and then killed it. There's still remnants of ESET on my computer that combofix kept detecting but it's not there as far as I can tell.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's kill off what remains of ESET then. :)

    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    ekrn
    SecCenter::
    {77DEAFED-8149-104B-25A1-21771CA47CD1}
    {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
    {CCBF4E09-A773-1FC5-1F11-1A056723366C}
    Folder::
    c:\program files\ESET
    C:\ProgramData\ESET
    C:\Users\Robert\AppData\Roaming\ESET
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    As you said, let a couple days go by and then follow final steps if all is still well.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  15. DeGreatSaiyaman

    DeGreatSaiyaman Private E-2

    Its baaaaaaaack! :(

    PING.EXE and the random 3 letter virus has returned, gave it a fake manual activation and ran Fixncr to allow me to use applications, then ran RKill to temporarily disable it to allow me to run combofix. Attached are both of those logs.

    Why won't this go away??
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  17. DeGreatSaiyaman

    DeGreatSaiyaman Private E-2

    Sorry about the delay, here's the logs.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I will just keep you moving along while Kestrel13! is not around.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  19. DeGreatSaiyaman

    DeGreatSaiyaman Private E-2

    heres the logs, computer is running very stably but its just not running as well as it used to. It chugs a lot in games that it really shouldn't have trouble running, so something must be abusing it still!
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have some services that were disabled by the infection:
    Code:
       Base Filtering Service is NOT running  
       Windows Firewall Service is NOT running  
       Windows Firewall Authorization Driver Service is NOT running

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now open Repair_Windows.exe
    • Go to Start Repairs tab.
    • Choose "Custom Mode" and press "Start".
    • Create a System Restore point if prompted.
    • In the Custom Mode window, select the following repair options:
      • Reset Registry Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • If asked to reboot the computer for the changes to take affect, make sure other tasks in the program are not still running before accepting to restart.
    Please download MiniRegTool.zip and unzip it.

    • Run the tool.
    • Copy and paste the following into the edit box:

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_BFE
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MPSSVC
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MPSDRV\0000
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MpsSvc
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mpsdrv
    • Check List Permissions radio button.
    • Press Go button and attach the result (Result.txt) that pops up. A copy of Result.txt will be saved in the same directory the tool is run
    Now click Start and type regedit into the Search box. You should see regedit.exe and its icon appear up above. Right click on this and select Run As Administrator to run the Window Registry Editor with Admin permissions.
    • Then in the Registry Editor click File, Import.
    • Navigate your way to the C:\MGtools folder and locate the fixW7BFE.reg key and select it.
    • Then click the Open button and allow this to be added into your registry
    Tell me what happend exactly. Like do you get any error messages or do you get a success message?


    If you received a success message then repeat the above import but with below to files from the MGtools folder.
    • fixW7FW.reg
    • FixW7FWdrv.reg
    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:

    C:\MGlogs.zip
     
    Last edited: Dec 24, 2011
  21. DeGreatSaiyaman

    DeGreatSaiyaman Private E-2

    Sorry for the delayed post again. All the steps went smoothly, however my computer is continuing to run extremely poorly compared to its previous performance. Something is still causing it to chug and struggle to run games even though task manager is showing less than 10% CPU and 20% memory being used.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not look like it. I expect that you had error messages importing those registry patches.



    Now download SubInACL.msi from Microsoft.
    • Now double click on SubInACL.msi to run the installer. Accept any prompts you get about installing this.
    • Now download the below file and save it to your Desktop:
    • Now right click on resetperm.cmd and select Run As Administrator to run this script. Be patient as this may take awhile to run. Also it is imperative that you Run As Administrator. This is not the same thing as your user account having administrator priviledges.
    Once it finishes, reboot your PC.



    Now press the Windows key and the R key at the same time to bring up the Run box. Type in regedit and hit OK.
    • Then in the Registry Editor click File, Import.
    • Navigate your way to the C:\MGtools folder and locate the fixW7BFE.reg key and select it.
    • Then click the Open button and allow this to be added into your registry
    Tell me what happend exactly. Like do you get any error messages or do you get a success message?



    If you received a success message then repeat the above import but with below to files from the MGtools folder.
    • fixW7FW.reg
    • FixW7FWdrv.reg
    Now no matter what happens with importing the above registry patches, just continue with the below.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\MGlogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds