Malware changing permissions

Discussion in 'Malware Help (A Specialist Will Reply)' started by dacushing, Sep 17, 2011.

  1. dacushing

    dacushing Private E-2

    I have a windows xp laptop, and there is a piece of Malware on there that seems to change permission on every tool I install to fight it. I look at the permissions, and they seem alright, be when I try and double-click the executables, I'm told windows can't find the file or folder, you might not have permissions.

    I read the READ & RUN ME FIRST, but got stymied after installing SUPERAntiSpyware, I can't launch what I've installed. Windows security essentials was installed, but the service cannot start, as I get that lovely windows access error 0x80something 705 or whatever it is. I tried to run SAS in Safemode, as Administrator, still didn't have permissions, and it said it couldn't run in safe mode anyway. I even tried the Microsoft windows security essentials boot cd and the AVG boot cd to remove this, they ran fine, but found nothing. Any ideas?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    If you are having problems running Rkill, try downloading one of the below renamed copies of RKill
    Then try and continue on with other instructions of the READ & RUN ME FIRST. As noted at the beginning of the READ & RUN ME, do not stop if anything does not work. Just keep on going thru ALL steps and tell us about problems later once all steps have been attempted.
     
  3. dacushing

    dacushing Private E-2

    I've completed all the steps, turns out I was an idiot, the alternate launch for SAS worked. I'm attaching logs, as Microsoft security essentials still is claiming it's finding a backdoor, and I had to re-add my cd-rom drive. I haven't found any programs changing permissions lately , so I've made progress.
     

    Attached Files:

  4. dacushing

    dacushing Private E-2

    Two more logs are attached.

    Thanks for all your help thus far.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a Zero Access infection.

    Download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r



    Now download Junction,zip to your Windows folder
    • Please download Junction.zip and save it to your Windows folder (i.e, C:\Windows\Junction.zip This assumes C:\ is your Windows boot drive.)
    • Now unzip it and put junction.exeinto the Windows folder (i.e., C:\Windows\junction.exe)
    • Do not try to run it right now. We will run something that uses it later.
    Now we need to reset the permissions altered by the malware on some files.
    • Download and save inhertit.exe to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!
    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.
    And one more scanning tool I want to use to collect more information is OTL per the below.

    Please download OTL by Old Timer to your desktop.
    See the download links under this icon: http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    1. Double-click OTL.exe to run (Vista and Win7 right click and select Run as Administrator)
    2. When OTL opens, change the Output (at the top-right portion of the program) to Minimal Output.
    3. Put check-marks in LOP Check and Purity Check.
    4. Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.
    • When the scan is complete, two logs entitled OTL.txt and Extras.txt will be created on your desktop.
    • Attach both of these logs to your next message.
    Also attach the below log from Malwarebytes that you forgot to attach.
    Code:
    "C:\Documents and Settings\Linda.3CARSHALAP\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\"
    Sep 17 2011  1374 "mbam-log-2011-09-17 (19-47-03).txt"
     
  6. dacushing

    dacushing Private E-2

    Ok, thanks for giving up part of your weekend for this. I've attached the files you asked for.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks like Malwarebytes and ComboFix were able to remove your infection.

    Are you still having any malware problems?

    If Microsoft Security Essentials is still finding problems, tell me exactly where. We need to be sure that it is not just do to what has already been quarantined.
     
  8. dacushing

    dacushing Private E-2

    I came to the same conclusion late last night, it was finding things that MalWare Bytes had quarantined. Once I had Malware Bytes clean out its quarantine, Microsoft Security Essentials stopped finding stuff.

    Thanks for your help, I ow you a beer or 6 if your ever in the Greater Boston area.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds