Malware disabling Anti-virus programs

Discussion in 'Malware Help (A Specialist Will Reply)' started by dujas, Jan 8, 2013.

  1. dujas

    dujas Private E-2

    The problems started maybe a week or so ago. The first symptom was the firewall on McAfee Total Protection turned off. Even when it appears to be on, looking at the firewall settings shows it to be off and attempting to turn it back on results in it turning itself off again a split-second later. This symptom persists after following the instructions of this website.

    At first McAfee Virtual Technician on their support site showed components that weren't running. Later scans turned up missing files. These problems persisted after reinstallations. Once McAfee scans proved fruitless, next we tried Spyware Doctor (real-time protection not enabled with McAfee real-time protection enabled). Intelli-Scans turned up mostly low priority infections, with some higher priority infections such as Trojan.Generic and Suspicious.Cloud.7.L. The scan would ask for a reboot and most of the infections would still be there.

    At one point, an intelli-scan was stopped and we ran a full scan instead. After a scan or 2, a full scan came out clean and we had thought the source of the problem gone. McAfee tech support was able to re-enable the firewall, but it didn't last. Now, in addition, Spyware Doctor full scans freeze on some file named ATT00001.lnk, even in safe mode with networking.

    Running 64-bit Windows 7. Manage attachments button does not seem to be functioning at the moment. I got it to pop up once, navigated to another window to see what to provide, and the window turned black. Closed it and now the manage attachment button appears to be doing nothing. Will try rebooting or something and see if I can attach logs in an edit.

    All right, logs now attached. TDSSKiller found nothing and generated no logs, although there were a couple errors when it started. Something to the effect of certain pieces unable to be found.
     

    Attached Files:

    Last edited: Jan 8, 2013
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-18\$d546dc1194d41a5c8965c2b814303c9e\n.) -> FOUND
      [HJ INPROC][ZeroAccess] HKLM\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-18\$d546dc1194d41a5c8965c2b814303c9e\n.) -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)

    Reboot and re-scan with RogueKiller and attach that new log as well.

    Now run CCleaner and clean out your temp folders.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Attach the new C:\MGLogs.zip.
     
  3. dujas

    dujas Private E-2

    I believe these are the files requested. Prior to the response received, I tried Spyware Doctor again. This time a full scan was able to run successfully. It found and cleaned a couple trojans, although I think one may have been a false positive.

    Roguekiller kept requesting to download an updated version. The first time, I clicked no. After the reboot, I tried the update, but the new file had the same version number as the old one and asked me to update again. I closed the new one and ran the scan with the old copy a second time.

    At first, I misread that last part and ran MGTools again before I found the mistake and ran the bat file. I assume it's safe to try to reinstall McAfee and see if the firewall will finally stay up?
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean, but let me point out that it is a very bad idea to allow all users to have admin. privileges.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link
    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  5. dujas

    dujas Private E-2

    I'm not sure I'm in the clear yet. One new symptom: Internet Explorer is no longer working properly. It's extremely slow. Most options are grayed out until the page loads and escape doesn't stop it from loading. No problems of this sort prior to the last round of cleaning. Fortunately, someone else had previously installed Google Chrome. I haven't had to use it until now. Everything loads just fine in Chrome, so it isn't an internet issue.

    I found a webpage http://support.microsoft.com/kb/318378, where I found and tried to run Microsoft Fix It. The first time I ran it yesterday, there were 3 issues: Smartscreen Filter Disabled, the number of simultaneous connections allowed to a server has changed, and Data Execution Prevention disabled. It claimed to fix all 3 problems, although Internet Explorer still wouldn't run right and the issue Data Execution Prevention disabled was there every time it ran. Today, it appears all 3 issues are back again.

    I suppose it's possible this is just residual damage from the virus or the cleaning process. It took help from McAfee tech support to get the firewall up and running again. So far so good on that front. At the very least, I would like to find a way to get Internet Explorer up and running again. Reinstalling it doesn't seem to work. It sees I have the current version and quits out. Apparently, you can't really uninstall IE in Vista; it appears to be more of a rollback. Not sure if "uninstalling" and reinstalling will fix the problem.

    In any case, what should my course of action be now?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try this, if it doesn't work, you may need to post in the software forum for further assistance:

    Download
    Windows Repair
    by Tweaking.com and unzip the contents into a
    newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win
      7, use right click and select Run As Administrator
      )
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds