Malware hiding from me

Discussion in 'Malware Help (A Specialist Will Reply)' started by chasgreghall, May 8, 2008.

  1. abri

    abri MajorGeek

    Hi chasgreghall,

    It may not be possible to clean your machine because of the software you're using.

    When you ran Panda, did you run the online Activescan or did you install their software? You have two folders - Panda Software and Panda Security - which look like they belong to Panda's resident security programs. If you have two antivurs programs on your computer, you need to uninstall one of them. You should keep Nod32 as the resident antivirus and completely uninstall the other one.

    Then uninstall the various tools we used that you listed in your last post.

    Then I would like for you to go back to where we started which was with the online scans, because you were still able to use these when we started.

    Go to
    Alternate Scans and look for the section on Free Online Scanning Tools. Run all of them except Panda and Kaspersky.

    Hopefully you will be able to recover some lost ground with these scans.

    When you've finished them, I would like for you to do a scan of your Windows files. To do this go to Start / Run and copy/paste in sfc /scannow

    If missing or corrupted operating system files are identified, you may be asked to insert your Windows XP installation CD. If the scan begins and closes within a few seconds, then it means it did not run. If it doesn't run correctly try it again. If it does run correctly, you may have to run it a second time in order to get the prompt for your cd.

    If you make any progress with the above, please reinstall Combofix and the MGTools and run them. In any case, please attach whatever logs you get and let me know how this goes.

    Thanks.
    abri
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note to Abri: You are most likely going to need to use the Recovery Console to remove the root causes of the infection since they cannot be removed while Windows is running.
     
  3. chasgreghall

    chasgreghall Private E-2

    abri,

    do i need to continue with your instructions or wait for recovery console instructions.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't run any other steps!

    Do you have a bootable copy of your Windows XP SP2 CD?


    If you have this CD, I want you to read thru the below to familiarize yourself with it and print it so you can refer to it while offline since you will not be able to browser once starting the below.
    1. Put the Windows XP CD into the CD ROM tray and close the tray. You may get a popup window asking about installing Windows XP. If you do, just close that window.
    2. Then restart your computer
    3. This should cause your computer to boot from the CD instead of the hard drive..(if not your you'll need to enter the BIOS and set the boot order so the CD ROM is first in the list.)
    4. You should get a "Press any key to boot from CD" message! Press a key to do that otherwise it will by pass the CD boot.
    5. After it boots up, you will see it load a bunch of files (be patient it can take a little while) and eventually you will see a menu where you can select the "Recovery Console" by pressing R It is normally the middle item in the list. Press R
    6. You will see a list of possible Windows partitions with numbers next to them. Select your Windows Installation (which is C:\Windows) by typing the number next to it (which should be 1) and press enter.
    7. It will ask you for the Administrator password is next (so make sure you know it). It you never gave it a password it is probably blank. If it is blank, just press enter. If you have set one then type it in and hit enter. It will tell you if you enter the wrong password.
    8. When you enter the correct password you will get a prompt that looks like this: C:\WINDOWS>
    After you get to this point, I just want you to take your CD out of the drive and type exit and then hit the Enter key. This should reboot your PC back into normal Windows. Then come here and tell me if you were able to do all of the above without any problem. The above will not fix anything. This steps will come next. First I just want to know that you can successfully accomplish booting into the command prompt of the Recovery Console.
     
  5. chasgreghall

    chasgreghall Private E-2

    I was successfully able to get to the C:\Windows prompt in the recovery console.:)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We will be booting to the Recovery Console in a moment, but first I want to do a little initial cleaning. If anything does not run/work for any reason, just continue.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.




    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Manually delete as many files as it will let you delete from the C:\Windows\system32\downld folder to simplify later steps.

    Now manually delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\chall\Local Settings\Temp





    Now read thru the below to familiarize yourself with it and print it so you can refer to it while offline since you will not be able to browser once starting the below.
    1. Put the Windows XP CD into the CD ROM tray and close the tray. You may get a popup window asking about installing Windows XP. If you do, just close that window.
    2. Then restart your computer
    3. This should cause your computer to boot from the CD instead of the hard drive..(if not your you'll need to enter the BIOS and set the boot order so the CD ROM is first in the list.)
    4. You should get a "Press any key to boot from CD" message! Press a key to do that otherwise it will by pass the CD boot.
    5. After it boots up, you will see it load a bunch of files (be patient it can take a little while) and eventually you will see a menu where you can select the Recovery Console by pressing R It is normally the middle item in the list. Press R
    6. You will see a list of possible Windows partitions with numbers next to them. Select your Windows Installation (which is C:\Windows) by typing the number next to it (which should be 1) and press enter.
    7. It will ask you for the Administrator password is next (so make sure you know it). It you never gave it a password it is probably blank. If it is blank, just press enter. If you have set one then type it in and hit enter. It will tell you if you enter the wrong password.
    8. When you enter the correct password you will get a prompt that looks like this: C:\WINDOWS>
    Now from this command prompt window, here are some things I want you to do. Enter the below commands (the commands are in bold black) in the order given. I will add comments in purple. In the below commands there are spaces after commands like cd, attrib, del, and rd

    cd system32 <-- the prompt should change to C:\WINDOWS\SYSTEM32>
    attrib -r-s-h mdelk.exe <-- there is a space after the attrib and after the -r-s-h
    attrib -r-s-h WINTEMS.EXE
    del mdelk.exe
    del WINTEMS.EXE

    cd system32\drivers <-- the prompt should change to C:\WINDOWS\SYSTEM32\DRIVERS>
    attrib -r-s-h hldrrr.exe
    attrib -r-s-h srosa.sys
    del hldrrr.exe
    del srosa.sys
    cd downld <-- the prompt should change to C:\WINDOWS\SYSTEM32\DRIVERS/downld>
    dir <-- this will give you a list of all files in the downld folder. For each file in this folder you need to execute the below del command and replace the file.bat or file1.exe with the real file names.
    del file1.bat
    del file1.exe
    etc

    After you get all of the files deleted (double check by executing the dir command as often as necessary) then continue with the below.
    cd .. <-- the prompt should change back to C:\WINDOWS\SYSTEM32\DRIVERS>
    rd downld

    If the del commands do not work just type exit to leave the Recovery Console and boot into Windows and just come back here and tell me exactly what happened. Do not do any of the below!

    If the above worked then continue with the below.

    • Make sure your cable that connects you to the internet is unplugged
    • Take the CD out of your drive (if may not let you until you type exit and reboot begins) and type Exit to reboot; however, reboot into safe boot mode.
    • In safe boot mode run SUPERAntiSpyware and save a log if it runs.
    • In safe boot mode run Malwarebytes Anti-Malware and save a log if it runs.
    • Now reboot into normal boot mode, and run C:\MGtools\GetLogs.bat by double clicking on it.
    Now plug your cable back in and come here and attach the below 3 logs
    • SUPERAntiSpyware
    • Malwarebytes
    • C:\MGlogs.zip
    NOTE: Unless you get to this tonight, I will not be around until sometime Sunday evening EST.
     
    Last edited: May 25, 2008
  7. chasgreghall

    chasgreghall Private E-2

    Wow!!! You are the Bomb!
    Here is a progress report...
    I ran ATFcleaner.
    In the recovery console, everything worked except deleting the directory downld.
    I still could not boot to safe mode.
    I ran SUPERAntiSpyware and Malwarebytes Anti-Malware in normal mode.
    I fixed the problems and attached the log files.
    Now I can get into Outlook, when I couldn't before !!!!!!!!!!:-D
    Let me know what else I need to do.
    Thanks again.
     

    Attached Files:

  8. abri

    abri MajorGeek

    Hi chasgreghall,

    Your computer is still infected. Chaslang can work miracles in recovering almost any computer from the worst of conditions, but it is only a matter of time until your computer will be reinfected, because you have no way of stopping up the holes (i.e. no updates). Just for your information, look at xp pro at amazon. There are good open source alternatives to everything now except the operating system.

    In order to make progress for the moment, you will need to use your computer sparingly and try not to reboot any more than necessary. Malware files get started on reboot. I need some information and the fastest way will be for you to help me find it.

    What are the following files and the one folder? You can right-click on all of them and go to properties and see if there is any information at all that might tell you what they are. The one which is a folder called "m", you can open and see if there is anything in it. If so, please let me know what is in there. Do not open any files!

    in this folder C:\Documents and Settings\chall\Application Data\ look for the following:

    a1 Apr 29 2008 4547672 "a1"
    a2 Apr 29 2008 2170646 "a2"
    M May 9 2008 "m"


    Now please do the following:

    1) Go to C:\Documents and Settings\chall\Local Settings\Temp\ and delete anything Windows will allow you you to delete.

    2) Run one of the cleaners, either CCleaner or ATF Cleaner. If these won't run, but you can get the interfact to CCleaner, go through the objects ticked on the Windows tab (which is the one on top when you open the program) and delete everything you can out of the folders which are mentioned by hand.

    3) Then run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
    O4 - HKLM\..\Run: [winlogon] C:\WINDOWS\csrss.exe
    O4 - HKCU\..\Run: [drvsyskit] C:\WINDOWS\system32\drivers\hldrrr.exe
    O4 - HKCU\..\Run: [german.exe] C:\WINDOWS\system32\wintems.exe
    O4 - HKCU\..\Run: [mule_st_key] C:\Documents and Settings\chall\Application Data\m\flec006.exe

    After you click fix, just close hijackthis.


    4) Download and install Erunt. Use it to create a backup of your registry.

    5) Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the File Type type is set to "all files" Once you have saved it, look for it on your desktop and when you find it, double-click it and allow it to merge with the registry.
    6) Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the 'Execute' button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt


    7) Run one of the cleaners, either CCleaner or ATF Cleaner. If these won't run, but you can get the interfact to CCleaner, go through the objects ticked on the Windows tab (which is the one on top when you open the program) and delete everything you can out of the folders which are mentioned by hand.

    8) Please run C:\MGtools\GetLogs.bat and attach the fresh MGlogs.zip it generates along with the Avenger log.


    Let me know how things are running now?

    abri
     
  9. chasgreghall

    chasgreghall Private E-2

    I did step 1). I had to use cmd and attrib -h to get to the hidden files. My computer will not connect to my wireless network at home anymore. I guess we deleted something that was necessary. I will run ATF at work on Monday.

    Once we get everything done, I will redo my wireless.
     
  10. abri

    abri MajorGeek

    Hi chasgreghall,

    What we deleted was malware. You can return to a restore point directly prior to those instructions and see if you internet wireless connection comes back. Then we can delete the same files one at a time and see which caused the problem.

    It would help me alot to see the Avenger log from that post and a fresh MGlogs.zip.

    abri
     
  11. chasgreghall

    chasgreghall Private E-2

    I deleted the files and folder mentioned. I don't know what they were.
    Everything worked but Avenger. The program worked, but the script gave me an error on the last three lines.

    Looks like we are making great progress. CCleaner is working !!

    I won't take my computer home anymore. That way I can avoid reboots.
     

    Attached Files:

  12. abri

    abri MajorGeek

    Hi chasgreghall,
    I don't see any further malware. How is your computer working? Are you still without a wireless connection? Is there a resident antivirus program running?
    abri
     
  13. chasgreghall

    chasgreghall Private E-2

    You guys have been wonderful. Where is the "donate" button. I haven't tried the wireless yet because I didn't take it home. I still can't get itunes to run, even if I uninstall and install. Everything else seems fine.
     
  14. chasgreghall

    chasgreghall Private E-2

    And, panda is my resident program and it is not running. when i tried to start it, i got the good old "not a win32 program" message.
     
  15. abri

    abri MajorGeek

    Hi chasgreghall,

    Before you run off to the Software Forum, I want to post you the final cleanup instructions which will remove all the logs and tools we used. If you want to keep HijackThis and its backups, there is an instruction for doing this at the bottom of the following box.


    abri
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The infection you had is known for breaking AV programs. Uninstall Panda, reboot, and then reinstall and see if things work afterwards.
     
    Last edited: May 21, 2008
  17. chasgreghall

    chasgreghall Private E-2

    Thank you all for everything. Panda is working now. I will take care of the scraps that are left. Go ahead and close the tread if you want.
     
  18. abri

    abri MajorGeek

    You're welcome from both of us. Good luck with your computer.
    abri
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds