Need Help - Malware Defense Bug

Discussion in 'Malware Help (A Specialist Will Reply)' started by Thorn, Jan 18, 2010.

  1. Thorn

    Thorn Private E-2

    Hi, my parents computer has been rent asunder by the Malware Defense bug.
    Its Windows XP 32bit Professional version.
    I was able to get SuperAnti Spyware running, MGTools, and RootRepair.

    Malwarebytes will not start, I cant uninstall it either, it freezes or refuses to load. SAS would only load via the alternate startup.

    I could not link to download the Combofix, as internet usage is limited.

    Attached are the logs for the 3 that ran. I did not have "show hidden files" on for the first SAS run, but reran a third time after doing so. I'll post all of those logs for your reference.

    I have deleted Java, AVG, and any other notable programs I could find, and ran CC cleaner as requested before running the tools I could. AVG was off of its free trial and was useless which is why I just uninstalled it.

    Thank you guys for your help.
     

    Attached Files:

  2. Thorn

    Thorn Private E-2

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you on dial up? You may as well have downloaded and run combofix because we are going to need either it or avenger for the remaining malware removal. Do the following:

    1. Please go to add/remove programs and uninstall the following softwares if found:

    • Viewpoint Manager
    • Malware Defense

    2. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    3. Download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    4. Also delete all files in the below bold folder except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\Documents and Settings\Wallace\Local Settings\TEMP

    5. Now run SUPERantispyware again after letting it update...fix all it may find and attach the log into your next reply.

    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger and also the log from SAS.

    7. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  4. Thorn

    Thorn Private E-2

    Not on dial up. I am on DSL here. I have limited connectivity in the sense that, for instance I can connect to majorgeeks or to cnet etc, but so far any attempts to connect to a legitimate antimalware/spyware site or download is met with a browser error.

    That includes Avenger as well. The link below didnt work. I cant link to the site off of a google search either.

    I did delete the 3 paths you mention on the MGTools/analyze.

    I will download Avenger and Combo from another location if I cant get the browser to work tonight.

    Thank you for your patience.
     
  5. Thorn

    Thorn Private E-2

    Good news! I was able to download from a very anchient laptop and port over Avenger and Combo fix from a flash drive. Here are the logs you requested.

    After running Avenger, I have full internet access again. I ran MGTools and deleted the Temp file as requested.

    I tried running Combo Fix after that from the desktop, but it wasnt loading right.

    Malwarebytes is runable as I was able to reinstall it, so I've included that log here as well. It found 5 additional items.

    Let me know what to do from here. Thank you!
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good evening. Looking better...
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Run RootRepeal again.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from avenger and also the log from RootRepeal.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  7. Thorn

    Thorn Private E-2

    Hey,

    Ran as directed. Running the MGtools, is giving me a process.dll application error when it gets down to the analyze.exe portion.

    Here are the 3 logs requested.

    Thank you!
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Those logs look good now.

    Let's just do this:

    Delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).

    Now I want to see if you are able to run Malware Bytes, and whether you are able to run SAS without the alternate start.

    If you are successful update each, runs scans, and fix all they find. Attach their logs into your next reply. :)
     
  9. Thorn

    Thorn Private E-2

    Malwarebytes I cant get to update, it gives me an error message. May bethe install though.

    SAS ran fine off of normal start.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.
     
  11. Thorn

    Thorn Private E-2

    Hi,

    The link for TDSSKiller does not appear to work. I've also tried it on my laptop and was not able to connect using that link either. Google searching was leading to the same link or info and was not bringing up anything either.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Loads just fine for me. Any way I have downloaded it for you and attached it here in my reply.

     

    Attached Files:

  13. Thorn

    Thorn Private E-2

    The link worked on my homecomputer. Not sure why it isnt here. Thank you for the zip file.

    TDSS didnt ask me to delete anything. Log is attached.

    Thank you.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Will Malware Bytes update now?

    Do this to get a fresh look on what's going on:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  15. Thorn

    Thorn Private E-2

    Malwarebytes still will not update. Same error message.

    MGLogs is attached below, however it still gives a process.dll error message as well.

    Should I try uninstalling/installing both of these again?
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    See error message type #4

    Using MGtools

    Yes try uninstalling Malware Bytes, reboot > run CCleaner > reinstall Malware Bytes and see how you then get on. I shall now review your logs.
     
  17. Thorn

    Thorn Private E-2

    Hi, Sorry for the delay in getting back.

    Malwarebytes still will not update. It gives a Error: 732 (12007, 0) I was able to uninstall/reinstall though which it was freezing before.

    I installed the .Net Framework...my apologies on forgetting to do that before.

    Attached is the MGLogs as requested, and it did run as normal, no process.dll error.

    One other thing to note. My USB flash drive picked up a Worm.Generic_c.ZS bug from this computer. Found it when I popped it into my clean computer at home and AVG caught it immediately.

    AVG isnt currently installed on this PC as it was out of date/trial anyway. Let me know if I should go ahead and reinstall it and run a scan.

    I take it I'll need to reformat my USB flash drive to be sure its clean?

    Thanks,

    Thomas
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Reformatting it would be an option or you can try this:

    For the external Hard Drive and a USB stick.

    Insert your flash drive before we begin. Hold down the Shift key when inserting the flash drive until Windows detects it to bypass the autorun feature. This will keep the autorun.inf from executing automatically.

    Please have all your removable storage devices ready for disinfection.

    Download Flash Disinfector by sUBs and save it to your desktop.

    • Double-click Flash_Disinfector.exe to run it.
    • Your desktop and icons may disappear. This is normal.
    • It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
    • Follow any prompts that may appear.
    • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
    • Wait until it has finished scanning and then exit the program.
    • There will be no GUI interface or log file produced.
    • Reboot your computer when done.

    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.

    Yes you can reinstall anti virus at this point. I am not seeing any reason for MBAM not being able to update. I am not seeing any malware in your logs. Be patient and I will have a word in Chaslang's ear :)

    Also delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).

     
  19. Thorn

    Thorn Private E-2

    Wow, thank you for the usb link. I'll probably just reformat mine as i only had a few of these scan softwares on it..but my mother's is probably infected as well and that would be a great tool if she doesnt want to reformat.

    AVG 9 is also having trouble connecting to download/install. (Got the initial file from cnet) I imagine the issue is the same as to why Malware wont update when attempting to connect.

    I also cannot get to avg's website.

    Do you know if there is a full AVG 9 link somewhere that skips the download wizard thingy?

    Thanks
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you able to complete this scan at all?

    You can use either Internet Explorer or Mozilla FireFox for this scan.


    • Please go here then click on: http://i280.photobucket.com/albums/kk173/Dakeyras_album2/EOLS1.gif
    • Select the option YES, I accept the Terms of Use then click on: http://i280.photobucket.com/albums/kk173/Dakeyras_album2/EOLS2.gif
    • When prompted allow the Add-On/Active X to install.
    • Make sure that the option Remove found threats is checked, and the option Scan archives is also checked.
    • Now click on Advanced Settings and select the following:
      • Scan for potentially unwanted applications
      • Scan for potentially unsafe applications
      • Enable Anti-Stealth Technology
    • Now click on: http://i280.photobucket.com/albums/kk173/Dakeyras_album2/EOLS3.gif
    • The virus signature database... will begin to download. Be patient this may take some time depending on the speed of your Internet Connection.
    • When the download is finished, the Online Scan will begin automatically.
    • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
    • When the scan completes, click List of found threats
    • Next click Export to text file and save the file to your desktop using a name such as ESETScan.txt. Attach this report to your next reply.
    • Click the <<Back button then click http://i280.photobucket.com/albums/kk173/Dakeyras_album2/EOLS4.gif
    • Attach the ESETScan.txt to your next reply.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also try this:

    Please download This Renamed Malwarebytes' Anti-Malware File and save to your desktop.

    • Right click on the renamed Malwarebytes' Anti-Malware File on your Desktop and chose Copy.
    • Next go to Start > Computer > C > Program Files.
    • Right click on the Malwarebytes' Anti-Malware Folder and click Paste.
    • Next Double click on the Malwarebytes' Anti-Malware Folder and launch the renamed file, malwarebytes should run now and update.
    • Please follow my previous instructions for running it, and post the log in your next reply.
     
  22. Thorn

    Thorn Private E-2

    I cant connect to the ESET link, its blocked like the avg webpage is.

    I'll try the Renamed shortly and let you know if it works.
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes do let me know how you got on. Your logs look clean but something seems to be hiding. We have other options to try.
     
  24. Thorn

    Thorn Private E-2

    The file overwriting for Malwarebytes in post 21 didnt work. Still giving an error on attempting to update and not connecting.

    Proxy is off, just double checked it to make sure, and the family filter is off as well.

    So not sure what is blocking just those pages and the updating.

    Thanks
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Right, well I will have to speak with Chaslang then as I am running out of options. Please be patient, he's a busy man but will get back to you about this ASAP :)
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  27. Thorn

    Thorn Private E-2

    No problem, thank you
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below may or may not be your problem but it has been an issue for some people.

    With Internet Explorer running, click Tools, Internet Options, and select the Connections tab, then click the Lan Settings button. On the Local Area Network (LAN) Settings form, put a check mark in the Automatically detect settings box. Then click OK. Then OK your way out. Then close your browser.

    Now run Malwarebytes and see if you can update.

    If you cannot update, shutdown your firewall and see if you can update. Let me know the results.
     
  29. Thorn

    Thorn Private E-2

    No luck, turned on the auto detect but still does not allow me to connect to update.

    Firewall is off as well.

    The only webpages blocked have been anything to do with things like AVG or Malwarebytes etc.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Now click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window


    Now let's flush the Java Cache
    • Click Start > Settings > Control Panel
    • Double click the Java icon (be patient, it may take a while to open)
    • Now click the General tab and under the Temporary Internet File area
    • Click the Settings button and then click the Delete Files... button.
    • In the next popup click OK.
    If you have multiple Java plugin icons in Control Panel follow the above to clear all their caches.


    Now let's flush the FireFox Cache

    To flush your FireFox Cache:
    • click Tools
    • select Options
    • select Privacy
    • in the section labeled Private Data click Clear Now
    Now let's flush the Internet Explorer Cache

    To flush your Internet Explorer Cache:
    • click Tools
    • Internet Options
    • Now on the General tab and click Delete Files and select Delete all Offline content too
    • Click OK.
    • When it finishes Click OK.
    Now run Ccleaner!



    Please download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r


    Now download Junction,zip to your Windows folder
    • Please download Junction.zip and save it to your Windows folder (i.e, C:\Windows\Junction.zip This assumes C:\ is your Windows boot drive.)
    • Now unzip it and put junction.exeinto the Windows folder (i.e., C:\Windows\junction.exe)
    • Do not try to run it right now. We will run something that uses it later.

    Now we need to reset the permissions altered by the malware on some files.
    • Download and save inhertit.exe to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!
    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.

    Now run ComboFix as instructed in the READ & RUN ME cleaning procedure. See: Windows XP Cleaning Procedure


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\combofix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  31. Thorn

    Thorn Private E-2

    I dont have Java installed currently, should I still expect to see a java icon in the control panel? Just double checking.

    Attached is the Win32 log as requested. Working on the others now.
     

    Attached Files:

  32. Thorn

    Thorn Private E-2

    Okay, ran the Fixperm as requested and it went fine. Had a few OKs to click on less than 10.

    Ran Combo Fix, and it also ran smoothly, updated, etc as it was supposed to (previous try a few days ago didnt)

    Attached is that log.

    MGTools though, I downloaded and overwrote the previous mgtools.exe, but when attempting to run it only briefly brought up the blackscreen window and then immediately closed. It did not run.

    I also checked and am still unable to connect to a website like www.avg.com
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now we need to use ComboFix again
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  34. Thorn

    Thorn Private E-2

    My apologies Kestrel, I just saw the GMER request..here is that log. Chas I'll run the combofix shortly.
     

    Attached Files:

  35. Thorn

    Thorn Private E-2

    Got everything to run okay. I can now access the previously blocked www.avg.com

    EDIT: AVG and Malwarebytes are both able to update and connect to respective servers.
     

    Attached Files:

  36. Thorn

    Thorn Private E-2

    Malwarebytes fully updated, attached log just incase you wanted it too, since it ran. Didnt find anything though I believe.
     

    Attached Files:

  37. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  38. Thorn

    Thorn Private E-2

    Thank you both for your help. Much appreciated!!
     
  39. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're very welcome :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds