Major Malware attack; blocking attempts to fix

Discussion in 'Malware Help (A Specialist Will Reply)' started by Beagdad, Nov 13, 2012.

  1. Beagdad

    Beagdad Private E-2

    I got hit with some kind of nasty malware/virus yesterday on my Dell desktop. I tried to get around it with a system restore to no avail. I then downloaded the newest versions of TDSKiller, Fixit, etc. as I've been down this road before on here.

    While this virus has url redirection attributes, it is also doing other things like stopping the cleanup software from running, not allowing updated definitions, etc. Not even letting me doing anything in safe mode.

    Could you please let me know how I should proceed from here.

    Thanks!
    Drew
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What OS are you using?
     
  3. Beagdad

    Beagdad Private E-2

    Windows XP. I was frustrated earlier I can't believe I forgot to included that.

    Thanks!
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you open task manager?
     
  5. Beagdad

    Beagdad Private E-2

    Yes I can.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Type in explorer and see if you can get your desktop to show up.
     
  7. Beagdad

    Beagdad Private E-2

    I could always access the desktop. It's just that when I try to run any of the anti-malware software it will not run. Also firefox will not open; the error comes up saying it's already open, which it is not. (doesn't show in task manager processes)
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What have you tried to run> Can you open any browser? Could you download tools to a different computer and transfer them via USB?
     
  9. Beagdad

    Beagdad Private E-2

    I ran SUPERAnti-Spyware and Malwarebytes Anti-Malware. In both instances it would not allow me to get the most up to date definitions.

    I was able to download newer copies of TDSKiller, Fixit, Goored (there was another I can't recall- not in front of the home computer right now), but when I ran them they just hung or immediately closed.

    One more thing I forgot to mention..the infection got activated when a fake "you have malware" screen came up and my wife hit the button to clean it out. Whenever that fake screen has happened to me in the past I quickly closed it, ran anti-spy and anti-mal and it was cleaned up. Not so lucky this time.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you transfer or download the latest version of MGtools and save it to your root folder. Try to run it and attach the C:\MGLogs.zip if it runs. Let me know.
     
  11. Beagdad

    Beagdad Private E-2

    Tim,

    Got it to run. Thanks!
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download The Avenger by Swandog46 to your Desktop.
    Extract avenger.exe from the Zip file and save it to your desktop.

    1. Run avenger.exe by double-clicking on it.
    2. Click OK at the warning to continue to use The Avenger
    3. Do not change any of the check box options!
    4. Shut down your protection software now to avoid possible conflicts.
    5. Copy everything in the Quote box below, and paste it into the Input script here: part of The Avenger
    6. Now click the http://img33.imageshack.us/img33/9159/executeavenger.jpg button
    7. Click Yes to the prompt to confirm you want to execute.
    8. Click Yes to the Reboot now? question that will appear when The

      Avenger finishes running.
    9. Your PC should reboot, if not, reboot it yourself.
    10. A log file from The Avenger will be produced at

      C:\avenger.txt and it will pop-up for you to view when you login after reboot.
    11. Attach this log to your next message. (See:

      HOW TO: Attach Items To Your Post )
    Now try to run the other scans and attach the logs that you can get.
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    And attach the new MGLogs.zip.
     
  13. Beagdad

    Beagdad Private E-2

    OK, will do as soon as I get home. Should I run in safe mode?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run it in normal mode if you can.
     
  15. Beagdad

    Beagdad Private E-2

    Tim, I ran Avenger, but had to run it in safe mode. (output is attached).

    I finally found the fake anti-virus software that keeps invoking in normal boot (and once in safe mode when I hovered over it.) It is called System Progressive Protection. That is what is preventing me from executing programs in the normal windows boot.

    Still can't run some of the other programs in safe mode either.

    Goored crashes every time

    TDSKiller and FixTDSS don't do anything after you confirm that you want to run them. They just disappear.(Not listed in task manager)

    I was able to flush the Java, IE, and DNS caches and that's it. Firefox won't open.

    Onward and upward.

    Thanks,
    Drew
     

    Attached Files:

  16. Beagdad

    Beagdad Private E-2

    Last night I ran comboxfix and discovered I have a RootKit ZeroAccess infection, but combofix got stuck after telling me that. It ran 8 hours and was still just sitting when I went to bed.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  18. Beagdad

    Beagdad Private E-2


    Malwarebytes Anti-Rootkit shows 2 problems found, but then the software hangs/not responding. I attached a screenshot.
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  20. Beagdad

    Beagdad Private E-2

    Tried it and couldn't get it to boot with their instructions. Ran Rkill which killed 3 processes, but couldn't find malware and was ineffective. So frustrated.
     
  21. Beagdad

    Beagdad Private E-2

    I failed to mention that with the Kapersky rescue cd...when I rebooted, windows started normally and ignored the cd. No menu came up as the instructions (#4) mentioned.
     
  22. Beagdad

    Beagdad Private E-2

    Good news at last Tim! I re-burned the disk and this time the system recognized the Rescue CD. After I rebooted I reran the Malware Bytes Anti-Rootkit and cleaned out more malware. Also got TDSKiller to run, caught another 7 medium risk issues.

    Couple of things still going on. Microsoft Security Essentials won't re-start, Super Anti-Spyware can't get updates, and the same for Malware Anti-Malware.
     
  23. Beagdad

    Beagdad Private E-2

    Uninstalled software and re-installed and then it worked. You can close the thread. Thanks again Tim!:cool
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am afraid you have a faked MBR partition. Please re-run MGTools --- run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't
    double click, use right click and select Run As Administrator).


    Attach the new C:\MGLogs.zip.
     
  25. Beagdad

    Beagdad Private E-2

    why do you think there is a faked MBR partition?

    I am running MGTools and after a while it has gotten hung on; these are the last 2 statements on the screen


    MiscInfo.Bat - 10/20/2012 version 0.10
    User Account List Seen From WMI
     
  26. Beagdad

    Beagdad Private E-2

    tried again this morning to no avail...this time I remembered to attach the zip file.
     

    Attached Files:

  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This existed in your first MGLogs:
    Code:
    Partition Disk #0, Partition #1 
    Partition Size 10.33 MB (10,829,824 bytes)
    It is no longer there. :)
     
  28. Beagdad

    Beagdad Private E-2

    Ohhh...so what should I do now? :confused
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you having any malware issues?​
     
  30. Beagdad

    Beagdad Private E-2

    Not seeing any. Only things that have occurred that seem out of the ordinary are 1) on start up there's a pop up window asking if I want to run malwarebytes (I hit cancel) and 2) MGTools got stuck when I tried to run it.

    Otherwise things seem fine. Needless to say I won't be doing any online banking for a while to be sure. And already changed my password for it on a different computer.
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link
    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  32. Beagdad

    Beagdad Private E-2

    All right, all set. Thanks again Tim, I really appreciate the help!
     
  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     
  34. Beagdad

    Beagdad Private E-2

    Apparently there is worse issue. Got the BSoD (see attached). I googled the message IRQL_NOT_LESS_OR_EQUAL and found that most answers were that a driver(s) were out of date and/or corrupted. (needless to say I am backing stuff up)

    I ran MajorPro's driver check and it found 18 outdated drivers. I replaced 2 (that's the limit per day unless you buy it), but I'm wondering if the rootkit problem damaged the hard drive. What do you think?
     

    Attached Files:

  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your hard drive wasn't "damaged". Just infected. I suggest you pursue your driver issues in the software forum. And good luck. :)
     
  36. Beagdad

    Beagdad Private E-2

    Will do. Thanks!
     
  37. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds