Malware removal, please help.

Discussion in 'Malware Help (A Specialist Will Reply)' started by pyro1975, Apr 7, 2010.

  1. pyro1975

    pyro1975 Private E-2

    Hi all, hope someone clever can help,

    Just yesterday I was on google images search when I started to get various pop-ups. So I immediately ran an Avira scan and it picked up Zpack/XPack trojans, which I moved to the quarantine.
    So I then ran the READ & RUN ME FIRST. Malware Removal Guide from Step 1 onwards without omitting any steps, however;
    1) SAS; ran a complete system scan and removal of detected items. Log attached.
    2) Ran MalwareBytes quick scan. Removed detected items, Log attached.
    3) Ran combofix.exe. However, on opening the file I got the message "not safe to continue when the combofix package has been compromised. You may be infected with a file patching virus 'Virut' " went on to step 4
    4) Ran RootRepeal, log attached
    5) Ran MGtools, log attached. However I had a message saying that a .dll was missing so the scan finished prematurely, something to do with Microsoft.Net framework not being installed, which It is/was some time ago, since I'm running Catalyst Control Centre.

    Edit: tried to upload RootRepeal log, says it's 1.2MB, which is larger than allowed?!

    Since the infection, a number of .exes don't work, such as Word/Powerpoint and now Catalyst Control Centre won't launch, and some games. Others such as Firefox and Adobe seem to work fine.
    I fully expect a grim prognosis, but any help is most welcome.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's do this:

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner! Now make sure these folders are cleaned out:
    C:\WINDOWS\Temp\
    C:\Documents and Settings\m\Local Settings\Temp\

    Now re-download ComboFIx and see if it will run.
    If it does not, go to start / run / and type:
    sfc /scannow --> have your xp cd handy and run it at least twice.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. pyro1975

    pyro1975 Private E-2

    First of all, many thanks for your reply TimW, much appreciated.

    So i...
    turned off Avira

    ran avenger.exe from the desktop no problem, log attached.

    ran Ccleaner no problem.

    downloaded ComboFix to desktop ; however when run still get the "not safe to continue the combofix package has been compromised. You may be infected with a file patching virus 'Virut' " message.

    so typed sfc /scannow in start / run /; ran twice, not much happened but what looked like a cmd window came up for a second then closed.

    ran C:\MGtools\GetLogs.bat file no problem, still had the same message saying that a .dll was missing; log attached.

    to update the orig. post, when I said a number of .exes don't work, since the infection and the first run of the Malware Removal Guide, they are actually missing, such as Word/Powerpoint.exe, but others seem to remain untouched. Don't know if this is because of the infection or something i did in the clean-up.

    Anyhow your help is most welcome.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry to give you the bad news but you will have to do a total clean reinstall.

    I can see the reason for your problems. Your logs show that your Windows Operating system files have become infected by a Virut infection and there is no known reliable fix for this. In addition there are many many other infected files. We could spend a lot of time trying to remove this infection, but odds are that it will not work because the nature of the infection has so many executable system files infected that as soon as we fix one file, other files that are infected will almost immediately or upon the next reboot, just reinfect the files. In addition, your PC would still basically be unreliable/untrustworthy even if we manage to fix the infected files that we can see since there could be many more that we are not seeing.

    The safest thing for you to do is backup your personal data immediately since your PC could possibly become unbootable at any point in time. Do not back up any executable files. This includes programs that you have downloaded since any of them could be infected. Anything you may have already backed up that is an executable type file (things you downloaded to install programs....etc) are most likely infected and will cause you to be reinfected if you reuse these files.

    Once you backup, you need to format partitions and reinstall Windows and all other software especially your protection software. Then install all updates for all software. DO NOT reinstall from any executable file backups you made while this PC was infected or you will just be reinstalling the infection.
     
  5. pyro1975

    pyro1975 Private E-2

    TimW,

    Thanks again for your response, even if the news is grim..

    Anyhow, before I go ahead with the reinstall of Windows one question:
    I would like to transfer my word and power-point files over to a USB stick before i reinstall. My USB stick has an autorun feature (i.e. an .exe) which, if I plug in, will pick up the infection and thus just pass the infection on to the next install of Windows?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If your thumb drive has an autorun.inf, I would use another computer to format that thumb drive first, removing the autorun feature. Then you should be safe. It may be wiser to copy to a dvd.
     
  7. pyro1975

    pyro1975 Private E-2

    TimW,

    Yes that's what I'll do then, copy my important .docs over to a DVD and I'll go ahead and reinstall xp.

    Many thanks for your help, most appreciated. See you all on the other side..
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome....and for future use, this is a good way to protect against autorun type infections:
    AutoEater.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds