Malware Problems. Run all from R&R but problem still here.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Maglarnet, Jan 20, 2010.

  1. Maglarnet

    Maglarnet Private E-2

    It started while instaling a program from unsecured source (my friend give it to my to try:mad)

    My AV (symantec endpoint protection) detected during instalation something called "Bacdoor.Tidserv!inf" and Packed.Generic265.

    AV deleted Packed.Generic265 but Backdoor.Tidserv!inf didnt it just said pending for analysis for a long time.I aborted installation and run full scan. Again it found Packed.Generic265 and Bacdoor.Tidserv!inf and then BSOD!

    Backdoor.Tidserv!inf....file infected: atapi.sys
    Packed.Generic265......file infected:OLDE.tmp (I deleted this file manualy)
    Runtime erorr started to apear with erorr code 0x00000002

    I read somewhere that combofix could fix atapi.sys so i run it. It fixed runetime error but not Backdoor.Tidserv!inf.

    Now after runing all from R&R I get every 5-10 min hacktool.rootkit which is deleted by AV and AV blocks somekind of email spam which apparently i am trying to send (which i'm not).

    Here are logs that are requested from R&R
    (I am sorry if i misspeled something english is not my first language)

    Thank you very much for all help that you can provide.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please disable Utorrent from running at start up whilst we are removing malware. :)

    2. Please go to add/remove programs and uninstall the following software:

    • Java(TM) 6 Update 17

    3. Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      c:\windows\system32\drivers\PCASp50q.sys
    • At the upload site, click once inside the window next to Browse.
    • Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
    • Next click Submit file
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

    Then do the same for the below file and also let me know the results:

    Code:
    c:\windows\system32\drivers\nfeunc.sys
    4. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Fcopy::
    C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys | C:\WINDOWS\system32\drivers\atapi.sys
    
    Driver::
    KGootkit
    
    File::
    c:\windows\system32\drivers\KGootkit.sys
    c:\windows\system32\drivers\str.sys
    C:\gkvc.exe
    C:\tpjcj.exe
    
    RegLock::
    [HKEY_USERS\S-1-5-21-507921405-1993962763-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
    @Denied: (Full) (LocalSystem)
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    5. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    7. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. Maglarnet

    Maglarnet Private E-2

    First of all THANK YOU for replying!

    This is what I did and what happend.

    1. Disabled Utorent

    2.uninstalled java

    3.went to jotti, scaned file c:\windows\system32\drivers\PCASp50q.sys

    here is link: http://virusscan.jotti.org/en/scanr...22a3/e97e2adf736c3a4b485d44e06d6e3c51916254de

    tryed to scan file c:\windows\system32\drivers\nfeunc.sys

    it said: File not found Please verify the correct file name was given.
    (I tryed numerous times same thing)

    4. run Combofix as instructed. Message during stage 4 popuped from symantec. Something like "symantec temper protection" , and it blocked something ( I disabled AV and SUPERAntiSpyware before runing combofix)
    Log in attachment

    5. rebooted and installed java from link provided

    6.run GetLogs.bat in mgtools folder. log provided in atachment.

    Yesterday when i turned pc on symantec found 4 threats. 2 backdoor (quarantined) and 2 hacktool (deleted), after that things are ok, no BSOD or any other kind of crashing, running smoothly I would even dare to say faster than before, BUT still i get from symantec popup that i am tryng to send somekind of spam emails to some crazy emails adresses. ( i am not sending anything I dont even have outlook configured). Still after doing what you said I get that popup (few popuped as I was typing this) . Sometime is just one but sometime is like 15 of them.

    THANKS again for all your help!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\drivers\PCASp50q.sys
    c:\windows\system32\drivers\nfeunc.sys
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    2. Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    3. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix. and TDSSKiller

    4. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. Maglarnet

    Maglarnet Private E-2

    Thanks again!:)

    I have done everything you said had no problems, except while running combofix AV popuped again but this time I managed to write down message.

    SYMANTEC TEMPER PROTECTION

    Target: c:/Program Files/Symantec/Symantec Endpoint protection/Rtvscan.exe
    Event info: Terminate process
    Action taken: Blocked
    Actor process: C:combofix/PVcfxx (PID1808)

    Had no other problems, no popups for now.

    Logs provided in attachments.

    Cheers!
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    2. SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      iaStor.sys
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    3. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from avenger. and also the log from systemlook.

    4. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
    Last edited: Jan 24, 2010
  7. Maglarnet

    Maglarnet Private E-2

    Thank you sooo much, my pc is running and jumping like a new one! You are a real expert!

    No popups, everything great.

    I understood to post log from system look so here it is.

    SystemLook v1.0 by jpshortstuff (11.01.10)
    Log created at 12:44 on 25/01/2010 by User (Administrator - Elevation successful)

    ========== filefind ==========

    Searching for "iaStor.sys"
    No files found.

    -=End Of File=-

    To be honest I didnt expect this amount of expertise, I thought it will be like this; run this,run that, yeah, you need to format your hard drive.:cry
    You made everything so simple.
    I cant thank you enough, you are a real savior!!!

    (just in case i misunderstood, SystemLook log is also in attachment)
     

    Attached Files:

    Last edited: Jan 25, 2010
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're very welcome :)

    Now just do this - use Windows Explorer to locate and delete the below bold file. If it doesn't go away quietly then please let me know and we'll do it another way.

    If it deleted away okay then you can follow the steps below:

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  9. Maglarnet

    Maglarnet Private E-2

    I deleted that file with no problems, everything is working great.:)

    Thank you very much thousand times!
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Surf safely :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds