Malware - Stops apps from starting

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kamkar1, Oct 23, 2010.

  1. kamkar1

    kamkar1 Private E-2

    I am again trying to fix my son's computer. eeehhh :-o

    Anyway, I have followed the instruction provided.
    AVG 2011 reports:
    trojan horse backdoor.generic12.cjbk
    C:\32788R22FWJFW\CMD.CFXXE vaulted
    CCleaner completed no issue
    Superantispyware stops after 5 minutes, see log
    Malwarebytes anti-malware does no launch. Instruction to change setting for GPedit.msc not working. gpedit.msc is not found from the run command.
    combofix will not install.
    Rootrepeal.txt attached
    MGtool log attached

    - Firewall installed but does not launch
    - 3 memory stick used one way of another, I think all are infected, would like to save data.

    Thank you for your reply.
    jk
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. You are using an out of date version of MGTools.

    As to your flash drives:
    For the external Hard Drive and a USB stick.

    Insert your flash drive before you begin. Hold down the Shift key when inserting the flash drive until Windows detects it to bypass the autorun feature. This will keep the autorun.inf from executing automatically.

    Please have all your removable storage devices ready for disinfection.

    Download Flash Disinfector by sUBs and save it to your desktop.

    * Double-click Flash_Disinfector.exe to run it.
    * Your desktop and icons may disappear. This is normal.
    * It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
    * Follow any prompts that may appear.
    * The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
    * Wait until it has finished scanning and then exit the program.
    * There will be no GUI interface or log file produced.
    * Reboot your computer when done.

    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.

    Now please do this online scan:
    eSet Online Scan.

    Now download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Please run the exe and attach the new C:\MGLogs.zip. Make sure you do the agreement to run HJT.
     
  3. kamkar1

    kamkar1 Private E-2

    Hi,

    Cleaned the memory sticks, the only response was "done", so I am assuming it's over.
    I also deleted the AVG files so, it does not interfere / confuse me, I'll install after all of this is over.

    In regard to ESETScan scan, completed with four viruses found, see attached file.

    In regard to MGtool, downloaded ew version, see attached result.

    Finally, I still can not run the Superantispyware & Malwarebytes, tells me I do not have appropriate permission.

    Waiting for next instructions ..
    regards,
    jk
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download and Run exeHelper

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Now try to run both SAS and MBAM.

    Your MGLogs.zip is corrupted so please try to attach it again.
     
  5. kamkar1

    kamkar1 Private E-2

    As instructed ..

    1- Exehelper was downloaded,clean execution, see attached file.
    2- installed SAS was not functional, removed from control panel
    3- Manual SAS was run, found a trojan.dropper\svcHost-fake2.
    it terminates prematurely after about 5 minutes.
    4- Installed MGMtool directory was deleted to prevent log corruption
    installed fresh copy in C:\, zip file was stored on C:\ - see attached file
    following error messages were presented to viewer:
    State - Checking DNS server with nslookup
    error message- the ordinal 1108 could not be located in the dynamic link library wsock32.dll
    state - checking routes
    error message- the procedure entry point getnetbyname could not be located in the dynamic link library mswsock.dll

    Waiting for instructions
    jk
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Something is still wrong with the MGLogs.zip. It will not open and the size is wrong. Let's try it again by running the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  7. kamkar1

    kamkar1 Private E-2

    You are correct, I ran the log, the new file is > 90K and active, see attached MGtool. Just hopeI have the correct version of MGtool
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it.
    • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message
     
  9. kamkar1

    kamkar1 Private E-2

    Hello,
    Downloaded and ran scan, see attached.
    waiting for instructions
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good, that found the culprit. Tell me what issues you may still be having, if any.
     
  11. kamkar1

    kamkar1 Private E-2

    hi,
    (Little history - before I contact major geeks, I re-installed the operating system from D drive 3 time- full recover no data was retained), still the virus cames back. Thought this was due to memory sticks. )

    Okay coming back to tdsskiller solution ....
    I am not sure if this is over. here is a brief of what took place..
    No memory stick or cd were used in the following operations.

    I rebooted, window update took over. After about 88 downloads and installation I removed installed online armor, superantispyware since they were not functional.

    After re-installation (from hard drive) of both online armor, and antispyware I found out again they are not functional. Re-ran tdsskiller and found two infections, attempted to clean and tried the process three times. If I read the report correctly, As an admin I have no permission to clean or delete the file. see attached.

    Finally, I am not sure why this is coming back. I am beggining to wonder if it resides in other partitions (D) system restore or LINUX partition. Just to make sure I turnd the computer off (not reboot) after tdsskiller delete. looks like it leaves traces behind that we have not cleaned.

    waiting for your reply...

    One last thing, I saw another forum that was having trouble with MSWSOCK.DLL AND wsock32.DLL. I have seen the same foot print on my computer.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-run TDDSKiller again and let's see if it finds anything else. Do you have a link to the other forum where this problem is occurring?
     
  13. kamkar1

    kamkar1 Private E-2

    Hi,
    ran tdsskiller multiple times finds the same two files but does not have permission to clean or delete, Tdsskiller recommends skip, I on the hand selected delete. After reboot re-ran tdskiller found the same threat.

    Here is thelink you asked for:
    http://forums.majorgeeks.com/showthread.php?t=225178

    regards
    jk
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTM by Old Timer and save it to your Desktop.




    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\WINDOWS\system32\drivers\vbma180d.sys
    C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
    :Reg
    [-HKLM\SYSTEM\ControlSet001\services\bcm4sbxp] 
    [-HKLM\SYSTEM\ControlSet002\services\bcm4sbxp] 
    [-HKLM\SYSTEM\ControlSet001\services\vbma180d] 
    [-HKLM\SYSTEM\ControlSet002\services\vbma180d]
    :Commands
    [purity]
    [ResetHosts]
    [createrestorepoint]
    [emptytemp]
    [start explorer]
    [Reboot]

    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.
     
  15. kamkar1

    kamkar1 Private E-2

    Good Morning,

    Completed OTM download, and ran as Owner with Admin privileges.
    Copied content of CODE: under the yellow area, and pressed Move it!.

    1- OTM, disappeared from the desktop and did not return.
    2- Rebooted the system and OTM was no longer available for execution, no privileges.
    3- Downloaded the OTM again to Desktop OTM(2), recopied CODES and pressed MoveIt!.
    1- OTM did not come back, and no messages.
    2- There were two folders under C:\OTM neither one had any contents.

    I re-ran tdsskiller and copied the content again, not sure it helps.

    regards
    jk
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now re-run TDSSKiller. Then attach the below logs:

    * C:\Avenger.txt
    * TDSSKiller log.

    Make sure you tell me how things are working now!
     
  17. kamkar1

    kamkar1 Private E-2

    Hi,

    Looks like my messaage from 10/31 did not get posted. Sorry for the late reply.
    10/31/10
    Avenger was installed, it would go through the process after reboot, no text message. Malware still active
    11/1/10
    - ran Tdsskiller to idenitfy registry numbers, and manually deleted infected registrys
    - rebooted to ubuntu and deleted both drivers
    - rebooted in windows and ran Avenger, it worked. after reboot I for a second I saw windows NT login screen and it rebooted again. This time I saw normal XP login screen and signed on.
    - ran Avenger again, and I saw the Vdma180.sys back on.


    Observation: No memory sticks used, wireless was off, and no ethernet connection. There seems to be another application seeding.

    Waiting for instructions ..
    jk
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you now run the C:\MGTools.exe and get me the log ( C:\MGLogs.zip)?
     
  19. kamkar1

    kamkar1 Private E-2

    Hello MGTool data attached.
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now download and install an Anti-virus program!!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  21. kamkar1

    kamkar1 Private E-2

    hi,
    ran Avenger, it did not produce any text file after reboot.
    re-ran for confirmation and same result. No text fileafter reboot.

    I decided to use regedit to delete registry for Vdma180, boot up into linux and deleted giine, and remaining drivers lited in Avenger note section.
    rebooted, and installed AVe2011, and online amor.
    Avg installed but online Armor failed to install and somehow the malware stopped all operation.
    No file to report.

    removed AVG, and online Armor
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach a new MGLogs.zip.
     
  23. kamkar1

    kamkar1 Private E-2

    Hi,

    Attached please find mgtool you requested. Malware still active.
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  25. kamkar1

    kamkar1 Private E-2

    hello tim,

    attached please find MGtool file, Avenger did not leave a text file at stat up.
    tried 3 time.
    jk
     

    Attached Files:

  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try using Combo. Put it on your desktop but do not run it.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    smxqd
    gtqau
    datd
    
    File::
    C:\hyxdjhwb.txt
    C:\rgueg.txt
    C:\ryzwcjxl.txt
    C:\ypjvpcp.txt
    C:\WINDOWS\tnmaeb.txt
    C:\WINDOWS\system32\drivers\datd.sys
    C:\WINDOWS\system32\drivers\gtqau.sys
    C:\WINDOWS\system32\drivers\smxqd.sys
    C:\WINDOWS\system32\uqllvcyb.sys
    C:\WINDOWS\system32\vbma180d.sys
    C:\WINDOWS\system32\zoca.sys
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  27. kamkar1

    kamkar1 Private E-2

    hi,

    Combofix was downloaded fresh from MG website on desktop.
    Notepad was created on desktop, see attahced.
    drag and drop CFscript.txt on combofix icon, combofix had no response. It processed the data and stopped. No data file was created as C:\combofix.txt was not created.
    MGtool was ran, file was stored on C:/Mgtool.zip see attached.

    Two additional files were created dated 11/6 and MG upload found errors during upload for your review.
     

    Attached Files:

  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What happens if you try to manually remove those files? Are you able to do that?
     
  29. kamkar1

    kamkar1 Private E-2

    hi,
    manually deleted all files - no difficulty, see attached mgtool log.
    also tried Combix, no data file. Malware still active.
     

    Attached Files:

  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please re-run TDSSKiller and have it cure/fix anything it finds. Attach the new log.
     
  31. kamkar1

    kamkar1 Private E-2

    Do you think its time to format?

    jk
     

    Attached Files:

  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is consistently in your logs:
    svchost (\\.\globalroot\Device\svchost.exe\svchost.exe)

    We have no methods to remove this, so I am afraid that we will need to do a clean install. I hate to give up, but it is probably the safest thing to do at this point. You can save your personal data and files to a cd. Then you will need to reformat and do a clean install. Make sure that once you are back up and fully protected to scan the cd before transferring the info back to the system.
     
  33. kamkar1

    kamkar1 Private E-2

    Last edited by a moderator: Nov 7, 2010
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds