malware cleanup maybe a rootkit... help needed.

Discussion in 'Malware Help (A Specialist Will Reply)' started by darrenfoster1976, Aug 17, 2010.

  1. darrenfoster1976

    darrenfoster1976 Private E-2

    Hi there,

    Got a laptop here it had antivirus 2009 installed on it. Ran rkill and malware bytes and it seemed to clean the machine up.

    But on the restart some services wouldnt run for instance antivirus software, the diagnostic policy service, unable to run DDS, rootkit revealer, just to name but a few.

    Attached is my Mbam log, TDSSkiller log, Rootrepeal log cant provide any more because im having problems getting anything else to run.

    I ran Gmer but it gives me a bsod with 0x0000008E im guessing thats the rootkit doing that.

    Sorry cant help any more than that but looking forward to your reply.

    Darren
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.

    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.


    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this aother user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:

    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. darrenfoster1976

    darrenfoster1976 Private E-2

    Hi,

    As requested,

    All scans done in safe mode.

    Uac Turned off

    superantispyware log attached
    mbam log attached
    combofix no log didnt give one ended and froze pc had to reboot after ten minutes waiting for anything.
    rootrepeal log attached
    mgtools log attached

    Look forward to hearing back.

    Darren
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why have you run the scans in safe mode?

    I see you ran ComboFix, but did not attach the log.

    Use add/remove programs to uninstall:
    Java(TM) 6 Update 11
    Java(TM) 6 Update 4
    Java(TM) 6 Update 7

    Now use windows explorer to find and delete:
    C:\Users\Adam\AppData\Local\Gliqeb.dat
    C:\Users\Adam\AppData\Local\Xjufafisequpal.bin

    Now boot into normal mode and download and install:
    Java Runtime 6

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  5. darrenfoster1976

    darrenfoster1976 Private E-2

    Ok thank you for the reply...

    So far so good...

    uninstalled Java 6 upd 11, upd 4, upd 7, not using add remove programs as this wouldn't work because the installer stalled.

    so used revo uninstaller and that removed it.

    Found the files you mentioned and removed them.

    Tried to install java but couldn't because the installer stalled. Just sat there with the hour glass for ten minutes.

    Tried to run the C:\MGtools\GetLogs.bat file, it ran and came up with the cmd screen with the program just said wait for logs to appear. Waited twenty minuted and nothing happened. Incidently using vista I right clicked the icon and ran as administrator.

    So no logs sorry.

    I think the installer is dorked, tried to install java in safe mode also but it gave me the spiel about installer not being available in safe mode. Also tried revo to install a program but that failed too.

    Darrem
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  7. darrenfoster1976

    darrenfoster1976 Private E-2

    Its not just that there are other symptoms as well. The internet sign on the taskbar wont allow any internet in normal usage but in safe mode with networking fine.

    Installer not working.

    control panel only showing a few icons.

    and it just feels wrong.

    I will try the installer clean up though and let you know.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This sounds like you are having system issues. Can you go to start / run / and type:
    sfc /scannow --> have your OS cd handy.

    Otherwise, try to run the C:\MGtools\GetLogs.bat file in safe mode and attach a new log.
     
  9. darrenfoster1976

    darrenfoster1976 Private E-2

    Hi there,

    Just wanted to thank you guys with your help in removing the virus.

    We did an sfc /scannow and got messages of lots of corrupt files most of which couldn't be repaired. Went down the route of Reinstalling the OS in the End.

    Thanks guys for your help.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds