Malware- Can't fully remove

Discussion in 'Malware Help (A Specialist Will Reply)' started by KcThrows, May 27, 2010.

  1. KcThrows

    KcThrows Private E-2

    Okay, so I'd like to mention...I did not perform all the steps in the READ and RUN ME FIRST. I did read them all.

    I have done them all, but probably not in the order needed or with the logs.

    Mainly, I had this problem a month ago where one day I had the fake antivirus program appear. I did the basic, scan and uninstall. No problems! Next day....major problems. I couldn't even open programs or run .exe stuff. Eventually I removed what I thought was all of it by doing the quick ctrl alt delete task manager trick and closing the program out before it fully loaded. Than I deleted everything I found with no problems after. During that I used Mbam, SpyBot, SAS, AVG, and I messed around with Combo and rkill. (I had some basic instructions)

    So, now, a month later. I noticed more sluggish problems. So I figured I had malware somehow since I wasn't home for a week and my family doesn't listen to any serious advice /sigh

    So! I did some scans, looked around. Boom! The program started back up. It hasn't been to bad yet. I scanned and keep finding stuff. One point I couldn't update and all that.

    So, my question is. With the programs I have installed now.

    SAS paid.
    Mbam paid.
    AntiVir Pro.
    and Comodo.

    I also used SandBoxie but I doubt my family has been.

    (side note, this is XP pro...seems to be on my vista laptop since they used it as well....guess thats another days work)

    Should I follow all the steps again? I just recently found this site and I did some of the things listed which makes me worry since I read "do not repeat these steps".

    Some verification would be great. I'll follow whatever is said and post back!

    Wish I found this forum earlier! Looks like a lot of help is offered here. Thanks in advanced.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can attach the logs from MBAM and SAS and combofix showing what they removed. (Although you shouldn't have been using combofix with just basic instructions without supervision as you probably know, it's a very powerful tool)

    Also you will have to run the other tools outlined in the R&R. Attach logs and I can give you a set of instructions :)
     
  3. KcThrows

    KcThrows Private E-2

    Alright! Here's all the files.

    Nothing in SAS or Mbam.....

    ComboFix found a rootkit and had to reboot...except when it wouldn't run after reboot.....so I did it again and made sure I had everything closed. So the log is there for that.

    Also, MGtools had that error but before I could finish reading the fix it went and finished so the logs are there as well. I hope that's okay.

    I'm still being redirected for websites, especially this one. FF wouldn't even connect, IE eventually got on here.

    Also, I remember seeing it said my E drive was infected which I use to hold several files, mainly a game. That's my extrenal drive...which...I have used on other computers. I have a feeling they may be infected. My laptop had this problem but nothing seems to show now.

    Hope everything is here!
     

    Attached Files:

  4. KcThrows

    KcThrows Private E-2

    here's the last log I have.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you do not boot from the E Drive then you have nothing to worry about, and no it isn't saying that your games are infected.


    1. Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    2. Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.

    3. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
    • R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    • R3 - URLSearchHook: (no name) - - (no file)
    • O20 - Winlogon Notify: 40471205922 - Invalid registry found
    • O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
    • O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
    • O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
    After clicking Fix exit HJT.


    4. Use windows explorer to find the following bold file and delete it if possible.

    • C:\WINDOWS\system32\hlp.dat

    5. Now we need to use ComboFix to be rid of some malware and also clear up from the avg you were once using.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    SecCenter::
    {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    
    Driver::
    AvgLdx86
    avg9wd
    
    File::
    C:\WINDOWS\system32\hlp.dat 
    C:\WINDOWS\system32\drivers\drw88.tmp
    C:\WINDOWS\system32\drivers\avgntflt.sys
    C:\WINDOWS\system32\drivers\avgntdd.sys
    C:\WINDOWS\system32\drivers\avgntmgr.sys
    C:\WINDOWS\system32\avgrsstx.dll
    C:\WINDOWS\system32\drivers\avgmfx86.sys
    C:\WINDOWS\system32\drivers\avgldx86.sys
    C:\WINDOWS\SYSTEM32\avgrsstx.dll
    C:\Documents and Settings\JER\Local Settings\Application Data\4T227ly4
    C:\Documents and Settings\JER\Local Settings\Application Data\1040348557
    C:\Documents and Settings\JER\Local Settings\Application Data\8xRhp4r1
    C:\Documents and Settings\All Users\Application Data\4T227ly4
    C:\Documents and Settings\All Users\Application Data\1040348557
    C:\Documents and Settings\All Users\Application Data\8xRhp4r1
    C:\Documents and Settings\JER\Templates\4T227ly4
    C:\Documents and Settings\JER\Templates\1040348557
    C:\Documents and Settings\JER\Templates\8xRhp4r1
    C:\WINDOWS\SYSTEM32\DRIVERS\jsbib.sys
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    
    Folder::
    C:\Documents and Settings\JER\Local Settings\Application Data\jhfwprmqi
    C:\Documents and Settings\JER\Local Settings\Application Data\xfugtmrqx
    C:\Program Files\AVG
    
    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the new log from SUPERantispyware.

    7. Let me know now how the machine is behaving. Do the redirects persist?
     
  6. KcThrows

    KcThrows Private E-2

    So..ran into the problem this morning....I can't start my PC up. It goes to the load screen, goes past the run xp or recovery console than the screen just stays black. Any ideas what to do?

    I have some pictures on there I want to recover :(

    Should of gotten them off last night!
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  8. KcThrows

    KcThrows Private E-2

    To be honest...that article really confuses me. I'll keep reading it and hope it makes sense.

    Is there anything I can do since I still have the options for

    Safe Mode
    Safe Mode with Networking
    Safe Mode with Command Prompt
    Enable Boot Logging
    Enable VGA mode
    Last Known Good Configuration
    Directory Services Restore Mode
    Debugging Mode

    and than there is also the screen that appears when I start up that offers
    Recovery Console
    or start Windows XP

    :note:

    As of now, I do not have the CD's for XP. I'm waiting to see if my dad has them.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would first see if Last know good config works, then safe mode w/networking.
     
  10. KcThrows

    KcThrows Private E-2

    Last Known Config went to a black screen as well. Just like a normal boot up.

    Also, safe mode w/ networking just like regular safe mode started up and got about 2/3 of the screen down with some text like it was running stuff than stopped there and froze.

    Any other ideas without the CD?
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Probably not. But you can try running a virus rescue disc:
    Kaspersky Rescue Disk.

    You will have to create this disc using a different computer. Then you need to change your bios to boot first to cd and see if that helps.

    If you have registry keys that were infected and removed by SAS, you will need your xp disc or one of the exact same version.
     
  12. KcThrows

    KcThrows Private E-2

    I think I'll wait till I get the CD's which....should be in an hour or so. I guess than use what you said in the other post? Still slightly confused but I'm sure it will be more explainable when I'm actually doing it.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is easy to follow esp since you can boot to the recovery console.
     
  14. KcThrows

    KcThrows Private E-2

    Looks like I'm on hold for the discs! So I'll reply asap as soon as I can...

    not sure what to do in the meantime. Hope I don't lose my pictures and such!
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is this a desktop computer or a laptop? If a desktop, do you have access to another desktop computer?
     
  16. KcThrows

    KcThrows Private E-2

    It's a desktop. I have another desktop set up right next to it as well actually. Which I am using for the forums.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good, then you can take out the infected hard drive and slave it to the uninfected computer, making sure first that you have all your AV and AS programs updated. You should then be able to run the scans on that computer.
     
  18. KcThrows

    KcThrows Private E-2

    Okay, so basically, I open up my infected desktop (which is easy) unplug the hard drive (which is easy) and it's sort of like running a scan on an external hard drive? Is there anything I should know before I try this? Or a few more detailed steps? I think I'm mainly worried about infecting my other computer too.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only other thing you need to do with the hard drive is make sure to change the jumper pin so that it is a slave drive. Your other hard drive that is clean should already be set to master. Then before you plug it in, make sure your AV and AS software is fully updated. You should be able to run all the scans with the infected slave drive plugged in. Make sure that you set the scanning tools to include the infected drive.

    I would first install this on the clean drive:
    AutoEater.
     
  20. KcThrows

    KcThrows Private E-2

    Quick question while I'm waiting to get home and do this. Would it be easier to use the start up CD's? Or the slave drive idea?

    Mainly curious as the infected PC is very compact and it will take me a little to get the hard drive out. Secondly, I am probably going to wait until my father is home so I don't have to worry about the "my fault" problem and I might as well get the CD's than. (He was away this weekend hunting so was stuck waiting).

    Basically since it doesn't start up does that mean registry was deleted? Just wondering to see if scans will fix it or I will need both in the end regardless. Thanks for all the help so far! I'll be looking into backing up and better protection next time so avoid all these problems.
     
    Last edited: May 31, 2010
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have your xp disc, then I would first attempt the link I gave you for recovering from a corrupt registry.

    If that does not work, I would do the slave drive install, see if you can clean it up with the scans and if worse comes to worse, copy your data and files over to the clean hard drive and then reformat the infected hard drive once it is back in it's case.
     
  22. KcThrows

    KcThrows Private E-2

    Okay thanks! I'll try and see what happens. I mainly just want the data for some files and pictures anyway...may have Windows 7 soon so I won't be to upset! (College kid anyway, I have time to set up a computer anyway.....)

    Thanks again!
     
  23. KcThrows

    KcThrows Private E-2

    Little iffy on finding the CD's and even if they are the right ones...so for now my dad put the other hard drive in the computer and I'll install the second one as soon as I install / update my AV and AM programs plus the one you mentioned.

    Only problem right now...is my internet won't work on that specific computer. Having trouble with the set up since I'm using a router plus it says the ethernet driver isn't installed and won't install....although...updates worked somehow. Just not the internet.
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are planning on upgrading to Win7, then you may only wish to save your files and personal data ( no exe files) on the other computer and then you can just go ahead and put the hard drive back and reformat and install Win7.
     
  25. KcThrows

    KcThrows Private E-2

    Is it safe to just take the files off like pictures and such than?

    If I'm just going to do that, after I hook up the hard drive and all that and have access, is there a safe way of taking the files off i want? I'm just worried about a reinfection. I assume just make sure I have everything updated and that autoeater like you said....and than after that, still scan? Or just drag the non .exe files I want off?

    Really appreciate all the help.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would go ahead and run the scans and let me see them. Afterwards, we may just be left with saving your pictures and such.
     
  27. KcThrows

    KcThrows Private E-2

    Okay, just to clear up, which scans am I doing? Just my AV and AS?

    (Still waiting on updates, service pack 3, virus updates, etc etc)
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run:
    SAS
    MBAM
    MGTools
     
  29. KcThrows

    KcThrows Private E-2

    Okay, will do! I'll reply asap when everything's ready.
     
  30. KcThrows

    KcThrows Private E-2

    Update...I'm having a hard time hooking up the hard drive so I have to wait on the right connection. Something with different hook ups?

    Just wanted to post in case topics are deleted after some time. Thanks for all the help so far. Sorry for the delay!
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem. We will be here when you are ready.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds