MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infestation

Discussion in 'Malware Help (A Specialist Will Reply)' started by Morbii, Aug 9, 2013.

  1. Morbii

    Morbii Private E-2

    Hi all,

    About a week to a week and a half ago I went to download a file from IE and I was informed that it was infected with a virus and could not download. I didn't think much of it until yesterday when the same thing happened and I quickly realized it was for ANY file I tried to download.

    I did plenty of scans, looked at various help sites (including this one), and finally installed Avast. Avast found and cleaned up some Sirefef viruses at these locations: (c:\windows\assembly\GAC-32\desktop.ini and c:\windows\assembly\GAC-64\desktop.ini).

    However, this did not fix IE. In addition, I ran MBRCheck (whose logs I will include in a subsequent post if possible), and for both my drives I got the message "MBR Code Faked!". So, I began thinking I had something in my MBR as well.

    Anyway, I followed all of the instructions (see attached logs) and did not clean anything, despite being tempted.

    From what I can tell, RogueKiller found something (presumably still left behind from Sirefef?) and even opened a browser here: http://www.adlice.com/zeroaccess-removal-with-roguekiller/

    In addition, it seems that Hitman Pro may have identified why MSSE no longer works. Via research, I'm also pretty certain that IE won't let me download files simply because MSSE does not work (it reports that they are all infected). I used Chrome for all downloading.

    Other random possible symptoms I've seen are reboot slowdown, Window Positioning being forgotten (mostly for Outlook), and some programs being asked to be added to the firewall after a reboot that have already definitely been added before (Some Epson software for my printer asked me once for private and then public on a second reboot).

    If I have to reinstall Windows, I will. I would really, really like to not have to do that, though.

    Thanks in advance for all of your time and effort and please see the attached logs.

    Thank you,
    Anthony
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [SERVICE][ZeroAccess] HKLM\[...]\CCSet\[...]\Services : ???etadpug ("C:\Program Files (x86)\Google\Desktop\Install\{773bcb97-41f6-52ed-da06-f2bea5d272e2}\ \...\???ﯹ๛\{773bcb97-41f6-52ed-da06-f2bea5d272e2}\GoogleUpdate.exe" < [x]) -> FOUND
    • [SERVICE][ZeroAccess] HKLM\[...]\CS001\[...]\Services : ???etadpug ("C:\Program Files (x86)\Google\Desktop\Install\{773bcb97-41f6-52ed-da06-f2bea5d272e2}\ \...\???ﯹ๛\{773bcb97-41f6-52ed-da06-f2bea5d272e2}\GoogleUpdate.exe" < [x]) -> FOUND
    • [SERVICE][ZeroAccess] HKLM\[...]\CS002\[...]\Services : ???etadpug ("C:\Program Files (x86)\Google\Desktop\Install\{773bcb97-41f6-52ed-da06-f2bea5d272e2}\ \...\???ﯹ๛\{773bcb97-41f6-52ed-da06-f2bea5d272e2}\GoogleUpdate.exe" < [x]) -> FOUND
    • [HID SVC][Hidden from API] HKLM\[...]\CCSet\[...]\Services : . e () -> FOUND
    • [HID SVC][Hidden from API] HKLM\[...]\CS001\[...]\Services : . e () -> FOUND
    • [HID SVC][Hidden from API] HKLM\[...]\CS002\[...]\Services : . e () -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.

    ...and the same for items on the file/folder tab please...

    • [ZeroAccess][Junction] MpClient.dll : C:\Program Files\Microsoft Security Client\MpClient.dll >> \systemroot\system32\config [-] --> FOUND
    • [ZeroAccess][Junction] MpRTP.dll : C:\Program Files\Microsoft Security Client\MpRTP.dll >> \systemroot\system32\config [-] --> FOUND
    • [ZeroAccess][Junction] MpSvc.dll : C:\Program Files\Microsoft Security Client\MpSvc.dll >> \systemroot\system32\config [-] --> FOUND
    • [ZeroAccess][Junction] MsMpEng.exe : C:\Program Files\Microsoft Security Client\MsMpEng.exe >> \systemroot\system32\config [-] --> FOUND
    • [ZeroAccess][Junction] NisIpsPlugin.dll : C:\Program Files\Microsoft Security Client\NisIpsPlugin.dll >> \systemroot\system32\config [-] --> FOUND
    • [ZeroAccess][Junction] NisLog.dll : C:\Program Files\Microsoft Security Client\NisLog.dll >> \systemroot\system32\config [-] --> FOUND
    • [ZeroAccess][Junction] NisSrv.exe : C:\Program Files\Microsoft Security Client\NisSrv.exe >> \systemroot\system32\config [-] --> FOUND
    • [ZeroAccess][Folder] Install : C:\Users\Anthony\AppData\Local\Google\Desktop\Install [-] --> FOUND

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Please save the work in your browsers before proceeding.
    • Double-click JRT.exe to run (Vista/7 right-click and select Run as Administrator)
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Please attach JRT.txt to your next message. (See: HOW TO: Attach Items To Your Post )


    Rescan with RogueKiller (just a scan) and attach the log please.
     
  3. Morbii

    Morbii Private E-2

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    RK seems to have claimed to not be able to delete at least one thing. However, the good news is that on a reboot I can download from IE again.

    Attaching RK log and my MBRCheck log I promised in the first post (in case you want it).

    Running JRT now.
     

    Attached Files:

  4. Morbii

    Morbii Private E-2

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    JRT logs attached.
     

    Attached Files:

    • JRT.txt
      File size:
      10 KB
      Views:
      7
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    Do you have your Windows 7 boot CD/DVD?
     
  6. Morbii

    Morbii Private E-2

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    I have a Windows 7 DVD, yes. I assume it will work on boot. It's an OEM disc, though (which I imagine doesn't mean much other than the labels).
     
  7. Morbii

    Morbii Private E-2

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    BTW, I ran RogueKiller again after the reboot, and it reported nothing in regards to the items that it said it couldn't delete. I can run it again and send a log if you like (if that's what you're worried about).
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    This is what I am concerned about, the findings of the MBRCheck log:

    When you run it today, does it still report faked MBR codes?
     
  9. Morbii

    Morbii Private E-2

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    Yes, still reports faked codes :(. What's next?
     
  10. Morbii

    Morbii Private E-2

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    I also wanted to point out two things:
    1. I don't boot from the second drive that also lists having a fake MBR.
    2. I am using a RAID1 (striped) configuration for my first drive and a RAID0 (mirrored) configuration for my second drive. So, the boot situation is not completely normal.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    I think what MBRCheck is reporting are false positives. I will verify this to be sure, but you say everything is running nicely?
     
  12. Morbii

    Morbii Private E-2

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    Yeah, things seem to be smooth. When I booted this morning it DID seem to take way longer than normal, but that could also just be an overly cautious sense of paranoia -- I also have Avast still running, which hasn't been installed in the past, but the "longer than normal" seemed to be pre-desktop, which is why I brought it up. I also wasn't present during the majority of the boot, but I did note that there wasn't a Windows update or anything, so that wouldn't have been the cause. In short, I started a boot and went to the other room and when I came back I expected it to be up.

    All the non-could-be-something-else problems seem to have gone away.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    Can you run this as a one last thing to do please?

    http://img827.imageshack.us/img827/1263/frst.gif For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  14. Morbii

    Morbii Private E-2

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    Had some fun and games getting it to recognize my HD (needed the RAID drivers), but got it working. Turns out the RAID drivers were already on my USB drive, too.

    Anyway, see attached. The folder it mentions in relation to ZeroAccess does seem to have sub-folders. I did not delete it yet.

    The subfolders seem to be two folders deep that don't appear to have a name and a third folder whose name appears to be "...". Doing a Get-ChildItem -r in Powershell puts it in what appears to be an infinite loop.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now re run FRST again - just a scan and attach new log please and explain how things are running.
     

    Attached Files:

  16. Morbii

    Morbii Private E-2

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    Logs attached.

    Things seem to be running smoothly. The only "normal" thing I haven't resumed doing is leaving my computer running when I'm not using it (just in case there's something else on here). I will also probably (begrudgingly) turn on UAC when we're done here if you think that will help me avoid this situation in the future.
     

    Attached Files:

  17. Morbii

    Morbii Private E-2

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    It's probably nothing, but I figured I'd bring it up, just in case.

    In sharepoint (work), some submenus in HTML dropdown menus stopped appearing in IE for me. It worked in chrome. I turned on compatibility mode, and they started working again.

    Due to that last part, I think it's ok, but just in case there's a known issue affecting stuff like that.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    Looks good now. :) I don't know about the drop down menu's, you can ask about that in the software forum. Ready for final steps?
     
  19. Morbii

    Morbii Private E-2

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    Yep!
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  21. Morbii

    Morbii Private E-2

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    Thank you very much!

    BTW, is there a place to donate, say, $10? I'd rather donate cash as support than purchase stuff I won't use through a third party :)
     
    Last edited: Aug 15, 2013
  22. Morbii

    Morbii Private E-2

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    You know, also, I cannot get Windows backup to successfully run. I'm not sure yet that it's malware, but this is the error I get:

    The backup was not successful. The error is: Windows Backup failed while trying to read from the shadow copy on one of the volumes being backed up. Please check in the event logs for any relevant errors. (0x81000037).

    I know this can happen for numerous reasons. I basically deleted all my backups and restore points and went to create a fresh one, and now I can't. If this isn't something you can help with, I'll try googling more. I've found some stuff so far.
     
  23. Morbii

    Morbii Private E-2

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    Scratch that last message. I disabled MSSE real time scan and it worked. You'd think after 3 years they'd figure out a way to make their own software deliverables not interfere with one another in such a crucial way and/or come up with real options/error messages to users as to what happened. This isn't the first time I've had Windows Backup fail and have to figure out why.
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: MSSE no longer works; IE can't download; susp/known viruses and maybe MBR infesta

    Glad you got it sorted. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds