Need help with crypt trojan horse

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jchag1718, Jan 21, 2012.

  1. jchag1718

    jchag1718 Private E-2

    Comp: Dell Dimension 2350, 2.3 GHz Pentium, 1 GB Ram

    OS: Windows Home XP; Serv Pack 3

    I have dealt successfully with infections in the past, but this nasty bogger takes the cake.

    Processes tried: Boot in Safe Mode; Run rkill and TDsskill; then follow up with Malewarebytes and AVG full scan.

    Results: Infections were found and deleted each time, but they came back.

    The system is now so bad that I cannot connect to the internet. Pretty much the same symptoms as user: GretalsADog in his post "trojan horse crypt.anvh & no internet connection". With one exception: I cannot upload anything to the machine with a jump drive. It will not recognize them. It says they need to formatted, which I know is not true.

    I was able to get critical info off of the desktop onto my laptop by using my Mp3 player. So thats where I am now. I am in the process of completing the RUN and READ ME first. It is slow going because I am having to shuffle data and programs between the Laptop and Desktop to complete everything.

    I have already run MGtools.exe and have the MG.zip file ready. Many thanks.

    Jeff
     
    Last edited: Jan 21, 2012
  2. jchag1718

    jchag1718 Private E-2

    Here is the MGlog.zip file.
     
    Last edited by a moderator: Jan 22, 2012
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your MGLog zip is either corrupt or damaged. I will remove it and ask you to run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    C:\MGlogs.zip
     
  4. jchag1718

    jchag1718 Private E-2

    Thanks for the reply Tim. I will try and get to it today. Forgive me if I'm traveling at a snails pace, but I do shift work. So I'm not at home all the time. Thanks.

    Jeff
     
  5. jchag1718

    jchag1718 Private E-2

    I figured out the problem with the MGlog.zip file. It appears my Mp3 player was corrupting it somehow. Ported them over to the laptop unzipped and then zipped the files. I can now get it to open and close normally on my laptop. Also when I ran MGgetlogs.bat I received this message in a window that popped up:

    ProcessDll.exe

    Application has generated an exception that could not be handled.
    Process id= 0xd50 (3408), Thread id= 0xff4 (4084)
    Click OK to terminate
    Click Cancel to debug

    I clicked OK and the .bat file finished running.

    Thanks.

    Jeff
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you missing desktop icons and missing program files in your start menu? If so:

    Please download and save the below tool from Grinler @ bleepingcomputer to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Now see if you can find the items that seemed to be missing?

    Anything else that is still missing could be found here:
    C:\Documents and Settings\Jeffrey Chagnard\Local Settings\TEMP\smtmp\

    You have a faked partition. We will need to use your XP install disc to clean it up. But first:

    Now download The Avenger by Swandog46 to your Desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    Extract avenger.exe from the Zip file and save it to your desktop.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    1. Run avenger.exe by double-clicking on it.
    2. Click OK at the warning to continue to use The Avenger
    3. Do not change any of the check box options!
    4. Shut down your protection software now to avoid possible conflicts.
    5. Copy everything in the Quote box below, and paste it into the Input script here: part of The Avenger
    6. Now click the http://img33.imageshack.us/img33/9159/executeavenger.jpg button
    7. Click Yes to the prompt to confirm you want to execute.
    8. Click Yes to the Reboot now? question that will appear when The Avenger finishes running.
    9. Your PC should reboot, if not, reboot it yourself.
    10. A log file from The Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
    11. Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Now:

    Preferably from a clean computer, I need you to download: gparted-live-0.11.0-7.iso (114 MB)
    Create a bootable CD for GParted. You can use ImgBurn to accomplish this.
    If you need help on how to use ImgBurn, please view this guide by dr.m -- Using ImageBurn to Burn an ISO image

    Now boot off of the newly created GParted CD.
    http://img717.imageshack.us/img717/6546/gpartedsplash01107.th.png
    You should be here...
    Press ENTER
    http://img819.imageshack.us/img819/7286/gpartedkeymaps.th.png
    By default, do not touch keymap is highlighted. Leave this setting alone and just press ENTER.
    http://img404.imageshack.us/img404/9840/gpartedlanguage.th.png
    Choose your language and press ENTER. English is default [33]
    http://img140.imageshack.us/img140/7958/gpartedgui.th.png
    Once again, at this prompt, press ENTER
    You will now be taken to the main GUI screen below
    http://img32.imageshack.us/img32/1122/gpartedo.th.png
    According to your logs, the partition that you want to delete is 1.32 MiB (1,381,888 bytes)
    Click the trash can icon to delete and then click Apply.
    You should now be here confirming your actions:
    http://img233.imageshack.us/img233/1533/gpartedsteps.th.png
    Now you should be here:
    http://img696.imageshack.us/img696/8471/gpartedsuccessclose.th.png
    Is boot next to your OS drive? According to your logs, your OS drive is the 111.73 GB sized partition.
    http://img194.imageshack.us/img194/7753/gpartedboot.th.png
    If boot is not next to your OS drive under Flags, right-mouse click the OS drive while in Gparted and select Manage Flags

    In the menu that pops up, place a checkmark in boot like the picture below:
    http://img196.imageshack.us/img196/3483/gpartedmanageflagsboot.th.png
    Now press the Close button to save these changes.
    Now double-click the http://img822.imageshack.us/img822/641/gpartedexit.png button.
    You should receive a small pop up like this:
    http://img88.imageshack.us/img88/8986/gpartedexitreboot.png
    Choose reboot and then press OK.


    Now reboot from the Windows XP Recovery Console CD and execute the following commands pressing ENTER after each:

    • fixmbr
    • fixboot
    • exit
    Once back in Windows...
    http://img707.imageshack.us/img707/6703/generalxpicon.gif Re-run another scan with MBRCheckand attach its latest log. (How to attach)

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  7. jchag1718

    jchag1718 Private E-2

    Ok. Got all of that completed with all the attachments below. The computer still runs slow and cannot connect to the internet. It just sits there says acquiring network address and it never does. It boots up normal and I can run programs. Its just extremely slow w/o internet. When I ran MGgetlogs I still got the same error, but with different Process and Thread id's.

    ProcessDll.exe

    The application has generated an exception that could not be handled.

    Process id=0xa2c (2604), Thread id=0x96c (2412)

    Click OK to terminate
    Click Cancel to debug

    I clicked OK and let MGgetlogs finish. I hope this helps. Thanks again.

    Jeff
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download afd.zip

    Extract afd.reg to your desktop.
    Then double-click afd.reg and allow it to merge into the registry.
    Let me know if you received a successful message or not before proceeding.
     
    Last edited by a moderator: Jan 24, 2012
  9. jchag1718

    jchag1718 Private E-2

    Thanks. I'm at work today. I should be able to get to it sometime tomorrow.
     
  10. jchag1718

    jchag1718 Private E-2

    Okay. It was successfully added to the registry.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is your internet connection back up and running?

    In the meantime, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip
     
  12. jchag1718

    jchag1718 Private E-2

    Sorry. No go. Internet still not up. I will run MGtools and post the zip file.
     
  13. jchag1718

    jchag1718 Private E-2

    Ok. Here's the MGlogs.zip file. Still getting the ProcessDll.exe error with these id's:

    Process id=0xe9c (3740), Thread id=0x674 (1652)


    Thanks.
     

    Attached Files:

    Last edited: Jan 25, 2012
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attached is afd.zip

    Inside is:
    • afd.reg
    • fixme+restart.bat

    Extract both files to the infected computer's desktop.

    First double-click afd.reg and allow it to merge into the registry. You should receive a successful message.

    Now reboot your PC.

    Once you have rebooted...

    Test your internet, If it still is not working, run the fixme+restart.bat file by double-clicking it.
    Your PC will reboot again. Once you are back in Windows, test your internet again.

    If it still does not work, attach the fixme_results.txt file the .bat file created.

    AFD.zip
     
  15. jchag1718

    jchag1718 Private E-2

    Still no internet after afd.reg and reboot. On to the next step. fixme+restart.bat
     
  16. jchag1718

    jchag1718 Private E-2

    Okay. Still no internet. Here are the .txt files that were created. Thanks.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That should have done it. Please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip
     
  18. jchag1718

    jchag1718 Private E-2

    Okay. Running Getlogs.bat.
     
  19. jchag1718

    jchag1718 Private E-2

    Okay. Here's the .zip file. I just completed running. Thanks.
     

    Attached Files:

  20. jchag1718

    jchag1718 Private E-2

    Tim,

    I took it upon myself to start over from square one. It seemed things were just going 'round and 'round. I wanted to make sure I didn't miss something. I started the RUN and README first process all over again. I completed all of the steps up until the cleaning part for Windows XP. I was able to run SuperSpyware, Malware Antibytes, Combofix.exe and MGTools.exe. I could not get RootRepeal.exe to run. It wouldn't initialize. I have attached the logs from the four that I was able to run. I have my internet back and everythings seems to be running well. Note: Combofix reported that I had a deep seated rootkit in the tcp/ip.sys. Combofix ran twice and rebooted twice on its own. So I believe that took care of it. I guess you will be able to confirm that in the log files attached. Many, many Thanks! Let's hope the system stays stable for a couple of days and then we will really know.

    Jeff
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, Combo did what was our next step, which was to replace the AFD file that was missing. I will give you the final clean up if all is working now.

     
  22. jchag1718

    jchag1718 Private E-2

    Okay. That sounds great. I'm back at work today. So I probably won't get to it until tomorrow. Thanks again.

    Jeff
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    When you get back to it:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  24. jchag1718

    jchag1718 Private E-2

    Tim,

    The system has been stable for the past couple of days with no additional problems. I completed the instructions in your last post to finish the cleaning process. Everything is running well. I cannot thank you and Major Geeks enough. I have been successful in the past handling infections, but this one really took the cake. Nasty little booger. Thanks for your time, effort, patience and diligence.

    Sincerely,

    Jeff C. :celebrate
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing, my friend. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds