malicious trojan on vista (reply to chaslang)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by loke91, Jan 3, 2012.

  1. loke91

    loke91 Private E-2

    i was reading chaslang's post and tried to reply but the thread was locked http://forums.majorgeeks.com/showthread.php?t=139681

    I followed every step he gave to the letter. Installed malwarebytes, super-anti spyware, combofix, rootrepeal, and mgtools. All scans went smoothly besides the combofix scan. It said my microsoft security essestials scanner was active (running combofix and another scanner is obviously harmful to your pc) so I tried to disable the security essentials protection. Sure enough, my security tab in the control panel said that security essentials was turned off but I couldn't access security essentials or the firewall. I even tried uninstalling security essentials and combofix still said it was interfering. How can I bypass the firewall (which I don't have access to) in order to run combofix?

    my logs for superanti spyware, malwarebytes, rootrepeal, and mgtools are attached
    View attachment mb log.txt

    View attachment MGlogs.zip

    View attachment RRlog.txt.txt

    View attachment SAS log.txt
     
  2. loke91

    loke91 Private E-2

    i do apologize for my previous spamming i was merely trying to private message chaslang (i needed 50 posts) and I was in a hurry
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geek!

    You should not be trying to spam other threads to increase your post count and you should not be trying to PM for help anyway. The fastest way to get help is to follow the instructions in the cleaning procedures and start your own thread here. See: Forum Rules and Guidelines


    Right click on the C:\MGtools\FixWFW.bat file and select Run As Administrator. This will run very fast.



    Uninstall the below old versions of software:
    Babylon toolbar on IE
    Java(TM) 6 Update 15
    Java(TM) 6 Update 7

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
    O2 - BHO: IWantThis - {50FC0EC5-BEA7-4d57-909D-6380A5AD5697} - C:\Program Files\IWantThis\IWantThis.dll
    O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
    O15 - Trusted Zone: http://www.yoyogames.com

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    See the download links under this icon http://www.majorgeeks.com/images/dll.gif
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. loke91

    loke91 Private E-2

    Thank you for your help!,
    C:\MGtools\analyse.exe did not find:

    O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
    O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll

    this is probably because i deleted babylon toolbar like you told me to,
    the fixme.reg was added to my registry successfully
    after I finished your instructions there was still a redirect problem on all browsers, I was then asked to perform a windows update, which I did, still had redirect problems
    Here are the logs:

    also there is a persistent: "dell wireless WLAN card wireless network controller stopped working and was closed" error message which pops back up everytime I ex out of it
     

    Attached Files:

    Last edited by a moderator: Jan 8, 2012
  5. loke91

    loke91 Private E-2

    note: my user account control is still disabled
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your MGlogs.zip file is very incomplete. Please follow the instructions to get a new log again and make sure you allow it to finish running before attaching the log. Also if you are getting any error messages or having a problem running it, tell me what they are.

    Yes UAC needs to stay disabled until we finish. We have to finish removing malware before continuing on to fix the problems with your networking stuff including the Windows Firewall.
     
  7. loke91

    loke91 Private E-2

    here is the new mglogs.zip i uninstalled windows firewall that was probably blocking the scan before, and sorry for the late reply
    View attachment MGlogs.zip
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have to perform fixes more expediently. Waiting 10 days inbetween responding allows your infection to spread and mutate and make a fix I created 10 days ago not useful.

    You also need to uninstall Sandboxie because it appears to be getting in the way of fixing your problems. Do this now before continuing.

    Now we need to run another fix with Avenger.

    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now please download Farbar Service Scanner and run it on the computer with the issue.
    • Put a check mark in each option box on the left side.
    • Click "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please attach this log to your next reply.
    Now goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7 make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Then attach the below logs:
    • C:\avenger.txt
    • the FSS.txt log from Farbars Service Scanner
    • the TDSSkiller and MBRcheck logs
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. loke91

    loke91 Private E-2

    here are the logs, thanks again, still same redirect problems, same dell wireless WLAN card error message, can't download microsoft updates, and I haven't had the computer on for a long time but usually if it's on for a while there's a blue screen which says its shutting down to prevent hardware damage, here are the logs:
     

    Attached Files:

    Last edited by a moderator: Jan 20, 2012
  10. loke91

    loke91 Private E-2

    New MGlogs.zip file
     

    Attached Files:

    Last edited by a moderator: Jan 20, 2012
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We need to get a log from ComboFix. Please download it from the below link and save it to your Desktop. DO NOT rename it.

    ComboFix

    Then right click on ComboFix.exe and select Run As Administrator. Ignore any messages about your security software still running and just allow ComboFix to run. After it finishes, it should reboot your PC. After reboot, attach the C:\ComboFix.txt log.
     
  12. loke91

    loke91 Private E-2

    I ran combo fix, after about 20 minutes it showed an error message saying it detected a rootkit zero access virus, it then rebooted, after the reboot there was an error message saying my recycle bin was corrupted, and I searched my whole hard drive for the combofix.txt log and couldn't find it, still redirect problems
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please try the following.
    • Reboot into safe mode
    • Shutdown any protection software that may be running.
    • Also close all other non-essential applications.
    • Now try running ComboFix
    • Attach the log if it runs.
    Reboot normally and let me know the results.
     
  14. loke91

    loke91 Private E-2

    combofix ran correctly, the recycle bin still got corrupted, I can't run anything now there's an error message when i try to open anything which says this registry has been marked for deletion, or access denied, i backed up all my important files just in case everything gets deleted. Here's the Log:
    View attachment ComboFix.txt
     
  15. loke91

    loke91 Private E-2

    nevermind i rebooted the computer and everything seems to be running finee!!!! Thank you so much you saved me about $150 in pc repairs. I will follow your guide on how to protect from malaware
     
  16. loke91

    loke91 Private E-2

    I've been trying to install the vista SP2 update. Windows update failed because there was some sort of trust issue. I then tried to manually install SP2. After I downloaded SP2 standalone it said that I had to install SP1 first. I then downloaded SP1 standalone and it said the update was already installed on my pc. I then looked in the updates section in the add/remove programs and could not find SP1. Very confused and would appreciate your help.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    No! We are not finished yet.

    Now rerun Farbar's Service Scanner and attach the new FSS.txt log

    Now download another new version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7 make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Then attach the below logs:
    • FSS.txt
    • C:\MGlogs.zip
     
  18. loke91

    loke91 Private E-2

    here are the logs
    View attachment MGlogs.zip
    View attachment FSS.txt

    a few questions about running comodo firewall: there seems to be a prompt for every new program/web page I visit/ startup file, how am I supposed to know which programs to allow?, also can I use windows firewall with comodo?, and is comodo's defense+ a form of AV and therefore shouldn't be run with Avira AV?
    also, does the free version of avira without web protection leave my PC vulnerable?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay they look good now.

    Some people have a problem understanding the way Comodo's protection software works and dealing with all the popups. Typically over the first couple weeks it may take getting used to it and it requires that you answer lots of questions to keep all of your legit software to be recognized/approved in the firewall. You should know the difference between when you are running something and when you are not. For example if you ran MGtools.exe and started getting notices from Comodo about it, obviously you know you ran it and it is okay even if Comodo detects an issue. Also sub programs ( batch files and other exe's ) that are part of MGtools may also get detected. You should also realize that you are the one running them and you need to allow them. The same logic applies to other programs like your browsers and other tools you use.

    No you cannot use the Windows Firewall with Comodo's Firwall. You must only use one firewall. If you cannot deal with Comodo, then uinstall it and use the Windows Firewall until you find a different firewall that may be easier for you to understand.

    No.






    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  20. loke91

    loke91 Private E-2

    I don't think you ever had me disable disc emulation software so I skipped that step, I still get the persistent error message: "Dell Wireless WLAN Card Wireless Network Controller Stopped working and was closed." is this an issue?, also as I explained earlier I can't update my vista Service Pack
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That was step 6 of the READ & RUN ME.

    I will give you another set of instructions to run but this may wind up being something you will have addredd in our Software Forum. But first try the below to reset permissions.



    Now download SubInACL.msi from Microsoft.
    • Now double click on SubInACL.msi to run the installer. Accept any prompts you get about installing this.
    • Now download the below file and save it to your Desktop:
    • Now right click on resetperm.cmd and select Run As Administrator to run this script. Be patient as this may take awhile to run. Also it is imperative that you Run As Administrator. This is not the same thing as your user account having administrator priviledges.
    Once it finishes, reboot your PC.

    After reboot, see if there is any change.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds