Internet Security 2011 for Windows XP

Discussion in 'Malware Help (A Specialist Will Reply)' started by adown, Feb 16, 2011.

  1. adown

    adown Private E-2

    Apologies, I got quite confused at one point and so Avast was not uninstalled.

    Followed MS link and seems to have solved it

    The items have NOT returned to device manager.

    All the actions requested have been carried out, but in Safe Mode (with networking) as a normal boot gets:

    "STOP: c000021a {Fatal System Error} The Windows Logon Process system process terminated unexpectedly with a status of 0xc0000135"

    MB full scan found 2 items - log attached

    Avenger and MGlogs attached
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I had a typo in my last fix with Avenger and need to create a new fix. In the meantime while I create the fix, please manually delete the below:

    C:\ComboFix << a folder
    C:\QooBox << a folder
    C:\avenger.txt << a file
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The STOP error is troubling and may be difficult to fix. It could require a repair install. Do you know exactly when this began? Like after what particular steps did it begin. While it have something to do with the linger hooks from the malware that has embedded itself deep into this PC, it could mean that Windows is broken.

    As an FYI ( but don't do anything with these links yet since we have more work to do), the below are some related links to this STOP error that may or may not be useful ( more likely not useful than useful ):

    How to troubleshoot a "STOP 0xC000021A" error

    Advanced troubleshooting for general startup problems in Windows XP


    Now on item that could be the cause of the stop error is this infected file C:\WINDOWS\system32\us?rinit.exe which MBAM has not been removing. This file is causing your real userinit.exe file not to be run and could be the reason for the STOP error. Let's see if we can remove it with Avenger.

    Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. adown

    adown Private E-2

    As I recall it happened after I disabled System restore and then restarted.

    Ran Avenger - log attached

    Checked for items - all removed BUT, strangely, I did see 2 userinit.exe files. One has a standard 'command prompt' icon whilst the other has a 'windows security centre'-esque icon - the same as the one the malware anitvirus had.
    The version with the standard prompt has a Version tab in the Properties dialog, which confirms it as a Micrsoft file. The other has no Version tab. For some reason they are also about 10 files apart when ordered by filename which is strange given they are the same filename...

    MGlogs attached
     

    Attached Files:

  5. adown

    adown Private E-2

    Just booted up machine and managed to do so in normal mode without blue screen.

    Upon reaching desktop I got an alert from Comodo (as I now have no other protection in place) saying that C:\cleanup.bat was attempting to edit zip.exe
    I 'disinfected' the file and rebooted without any errors.

    i do have some odd files in the root though:

    cleanup.bat
    cleanup.exe
    zip.exe
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes see my last fix and previous MBAM logs. This is 2nd one it part of your problem and what we are trying to delete.


    Yes see if you can manually delete the one with no version tab. Try using safe boot mode if necessary. Let me know what happens.

    No it is not really strange. ;) The file is not really named userinit.exe which is why you saw the ? in my fix and in your previous logs from the scan tools. The malware has inserted other non-printable characters into the file name that make it appear like it is named userinit.exe They do this to make it harder to find and harder to fix. Deleting the wrong one will make it impossible for you to log into your PC.


    Just an FYI about the sizes of the files:

    The good one is:
    Code:
     26,112 2008-04-14 05:42:40  C:\WINDOWS\system32\userinit.exe
    The bad one is:
    Code:
    153,088 2008-04-14 05:42:40  C:\WINDOWS\system32\us?rinit.exe
     
    Last edited: Feb 22, 2011
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not problems. The 1st two are from Avenger and the last is a tool used by ComboFix and Avenger to ZIP files. MGtools also uses zip.exe but the one for MGtools is maintained in the C:\MGtools folder.
     
  8. adown

    adown Private E-2

    successfully deleted userinit.exe file (bad version)

    I only mention cleanup.exe because Comodo identified it as having a trojan virus in it
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After a reboot, does a full scan with Malwarebytes no longer detect the bad one ( shown with the question mark in previous logs )?

    Are you currently having any malware problems? If yes, what?

    Yes I understand, but these kind of false detections happen for many files. Comodo and other scanners will popup messages about MGtools too. So I was informing you where the files came from and why they were not problems. ;)
     
  10. adown

    adown Private E-2

    Am currently running MB full scan, will attach log when finished.

    I do not seem to be having any malware problems now.
     
  11. adown

    adown Private E-2

    Ran full MB scan - no malware detected!!:)
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. adown

    adown Private E-2

    One final thing. I had worked through the final steps and got as far as preventing future malware.

    As such I installed S&D and during a scan it detected the Antivirus 2011 malware that originally infected the machine.
    I tried to the fix the problems but it said they may be in use (they are registry entries) and so I allowed it to run at startup. It was still unable to remove them.

    Therefore, all S&D logs attached from today.

    Also, I followed the instructions to remove MG but I still have a number of files in the MG Tools folder and the root has cleanup.bat, .exe and zip.exe and MGTools.exe. Can these be deleted?

    Sorry to keep dragging this out!
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those are just a few inactive leftovers from things we already removed but let's see if we can get them all removed. You will need to redownload Avenger since we will first see if it can be used to remove these items.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now attach the C:\avenger.txt log
    If Avenger ran okay, rerun Spybot and see if the same registry keys are still being detected.
     
  15. adown

    adown Private E-2

    Sorry for the delay, my firend took his laptop back and I forgot to follow-up on here.
    After the last step Spybot was clear and so I carried out the final steps.

    Thanks so much for your help, we both thought it was a gonner!

    To anyone else who has the same malware, please be aware that they really do get a load of personal information, enough to phone my friend on his mobile and demand money for anti-virus software to remove the malware!

    Thanks again, it's really appreciated.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Yes this infection opens backdoors and steals info. You friend should also take the time to check with all financial institutions to make sure no illegal activity has been occurring. He should continue to check for a few months since stolen information is not always used immediately. Also ALL passwords for ALL accounts (on his PC and for banks, credit cards, online accounts,..... etc) must be changed since you cannot be sure what information has been stolen.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds