Malware need help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by wendal, Aug 16, 2012.

  1. wendal

    wendal Private E-2

    Ok, thanks for reading whoever can help; it would be highly appreciated.
    My PC froze and I realised the 'working in background egg timer and cursor wouldn't stop, (have logged on to other accounts on same Windows and have not found a problem).

    I have tried ComboFix and have been unable to stop the "This machine does not have the 'Microsoft Windows recovery console' dialogue box coming up!

    I have installed Windows Recovery Console and the message still appears. What's more the drag and drop of Service Pack 2 I can't do because I can not find Service Pack 2 anywhere on the internet and the Microsoft URL is down because they no longer have it!

    Any ideas where I can locate and install Service Pack 2 so ComboFix recognises it as installed, or tell me where I can find it on my XP or the net?

    This Malware is not letting me run any browsers and is blocking the usual antiviri sites, google and so forth until I run ComboFix. Even upon completion of ComboFix and a reboot it stalls and doesnt bring up a log and I have to reboot and the problem starts again!

    I'd be grateful if ANYONE can help!

    PEACE
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. wendal

    wendal Private E-2

    Hi thanks for your reply. Here is the report if it helps...I'm still having to run ComboFix to run normal functionality of browsers and websites etc. I run the first half of it and close it as it blocks some of the processes this Malware is using to take over my system. I have ran Combofix in full; it works but upon reboot the problem persists. That is in the way described in my first post, without it realizing I actually do have Windows Recovery Console installed!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is RogueKiller really all you were able to run from Tim's link? There was much more to do/try than just RogueKiller. Be warned, do not keep randomly running Combofix, Used wrongly, it could turn your computer into a rather expensive brick.

    If you are unable to run anything in Tim's link in normal mode then try SAFE mode please.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  6. wendal

    wendal Private E-2

    Hi Kestrel, sorry thought I was supposed to upload Rogue Killer first, here are the scans was able to run all of them due to ComboFix being deployed however will take on board what you have said. Looks like HitmanPro recognized a Trojan.FakeAV "C:\WINDOWS\system32\d3d9caps.dat (Trojan.FakeAV)"

    I'm thinking I have the similar if not the same problem/s as the guy in this thread...

    http://forums.majorgeeks.com/showthread.php?t=141235

    Would anyone recommend following the steps in this thread? (i.e. uninstalling Java)

    Thanks
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No! Those steps/instructions were tailor made for that person, not you. Different computer, different fix, ay? :)

    You now need to focus on attaching the log from HitmanPro and also attach the MGlogs.zip from running MGTools.exe. THEN Tim can continue to assist you armed with all the correct materials. ;)
     
  8. wendal

    wendal Private E-2

    Here...
     

    Attached Files:

  9. wendal

    wendal Private E-2

    Thanks I'm aware of that...however I have the same file in question and the similar symptoms as this dude which is "C:\WINDOWS\system32\d3d9caps.dat", found this on my HitMan log! :cool
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yea, it's a false positive. That's why you have to be careful with certain tools, we are trained to know what it is, don't worry. ;)
     
  11. wendal

    wendal Private E-2

    "Geek it till im MHz!" :-D I'm nearly in tears over here, need the speed back! gah
    (think that's one of the slogans I saw on this site)
     
    Last edited: Aug 17, 2012
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since you have been using Combo, we will use it to remove some files:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    ClearJavaCache::
    KILLALL::
    File::
    C:\Documents and Settings\DV Customer\Local Settings\dwtmtwse.log
    C:\Documents and Settings\DV Customer\Local Settings\fqsopxrp.log
    C:\Documents and Settings\DV Customer\Local Settings\itlasalu.log
    C:\Documents and Settings\DV Customer\Local Settings\mtibeafb.log
    C:\Documents and Settings\DV Customer\Local Settings\nkpoawmx.log
    C:\Documents and Settings\DV Customer\Local Settings\ohfexhpo.log
    C:\Documents and Settings\DV Customer\Local Settings\oytkqdxm.log
    C:\Documents and Settings\DV Customer\Local Settings\rddvgsvs.log
    C:\Documents and Settings\DV Customer\Local Settings\xaqbtvkx.log
    C:\Documents and Settings\DV Customer\Local Settings\yjjfxpqo.log
    C:\Documents and Settings\All Users\Application Data\auqycojc.log
    
    Folder::
    C:\Documents and Settings\DV Customer\Local Settings\Application Data\Conduit
    C:\Documents and Settings\DV Customer\Local Settings\dhevbben
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Note: If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 31
    Java(TM) SE Runtime Environment 6 Update 1

    Now download and install:
    Java Runtime 7

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  13. wendal

    wendal Private E-2

    Thanks, will try this in a minute; I guess by this "Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!" you mean, only run it by drag and dropping the CFscript.txt I'm going to create? Well I'm pretty sure you do :). I'm going ahead with this and will hopefully have the log up in a few hours. I'm considering buying a tshirt btw, this forum is so useful so big ups to all those who run it!
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you understand the instructions. Attach the log when you are finished. ;)
     
  15. wendal

    wendal Private E-2

    Hi doesn't look like it's been fixed yet!
    I may try doing ComboFix again as it seemed to detect ZoneAlarm's Antivirus as still on; however the program had been closed, I've uninstalled ZoneAlarm, do you need a new ComboFix log? Or should I run ComboFix once me to be sure?

    I have however attached the logs, see what you can decipher from it because I'm lost now. :cry
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download The Avenger by Swandog46 to your Desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    Extract avenger.exe from the Zip file and save it to your desktop.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):


    1. Run avenger.exe by double-clicking on it.
    2. Click OK at the warning to continue to use The Avenger
    3. Do not change any of the check box options!
    4. Shut down your protection software now to avoid possible conflicts.
    5. Copy everything in the Quote box below, and paste it into the Input script here: part of The Avenger
    6. Now click the http://img33.imageshack.us/img33/9159/executeavenger.jpg button
    7. Click Yes to the prompt to confirm you want to execute.
    8. Click Yes to the Reboot now? question that will appear when The Avenger finishes running.
    9. Your PC should reboot, if not, reboot it yourself.
    10. A log file from The Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
    11. Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    You can download SP2 HERE.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  17. wendal

    wendal Private E-2

    Thanks, here are the logs, will also try dragging SP2 onto Combo to see if it can deal with the fix that way.
     

    Attached Files:

    Last edited: Aug 19, 2012
  18. wendal

    wendal Private E-2

    Hi, it's gone steps I took...

    1) Ran combofix (which I stopped halfway until it began the stage 1, stage 2, etc prompts) this allowed me to use my PC in a semi normal fashion (i.e. Firefox I think was not opening at all but managed to get Chrome to download Malware bytes which this Trojan/Virus was hindering and actually deleting. I did however rename the Mbam.exe prog file in case it wouldn't run again.

    2) Downloaded Complete Internet Repair and Checked all/most boxes
    (not sure whether this fixed it)

    3) Downloaded and ran Malware Bytes and updated; it found all of the Malware and deleted it. Ran Malware Bytes 3 times after restarting and restarting again to make sure it had gone!

    I'm now clean, thanks for your help anyway.

    Peace out.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds