Permissions Virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by TheJimmbo, Sep 26, 2011.

  1. TheJimmbo

    TheJimmbo Private E-2

    Please Help!

    I first noticed I had a virus because all my desktop icons and programs in the start menu were missing. When I try to run malwarebytes, in safe mode or not, I get a message:
    "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item."
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. TheJimmbo

    TheJimmbo Private E-2

    I downloaded and ran the unhide.exe and now when I go to start, my program folders appear, but when I click on them they all say empty. Although programs like Itunes still have a shortcut on the desktop and in the start menu, they are completely gone. I'm not even sure if I have Microsoft Word anymore. Firefox and Internet Explorer still are functional. I couldn't get ComboFix or MGtools to provide a log.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Rename Combofix.exe to s3gv701.com ensure it is on your desktop . Now try and run it again, in normal mode first and if it fails, I want you to boot into safe mode and try again.



    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    • cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    • nwktst<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    • analyse <-- this attempts to run HijackThis. Be sure to click the Accept button twice in the license agreement popup or it will just sit there and wait.
    Now look for the C:\MGlogs.zip file and attach it no matter what happened while doing the above.


    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  5. TheJimmbo

    TheJimmbo Private E-2

    Combofix stopped working the first time when it was producing the log. Here is the log from after the second time I ran combofix. Don't know if that matters..
     

    Attached Files:

  6. TheJimmbo

    TheJimmbo Private E-2

    Heres the OTL
     

    Attached Files:

  7. TheJimmbo

    TheJimmbo Private E-2

    I still cannot access programs like Microsoft Word or Itunes from the start menu or desktop icons.. However if I download a text document I can open it with Microsoft Word...?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please be warned that you would be wise to back up any important data before proceeding with the next step of attempting to fix your MBR.

    Do you have your Vista boot CD? If not:

    If you don't have your Vista disc, you can create a Recovery Environment disc for your system here:

    32bit Vista Recovery Environment

    64bit Vista Recovery Environment

    You can use ImageBurn to create the disc.

    Once the disc is created, boot into the bios and change the boot order to CD/DVD as first boot device. Put in the disc and reboot. Once in the RE, type this:
    Note the space after the exe.

    Exit out when done and boot back into normal mode. Re-run MBRCheck and attach the new log.
     
  9. TheJimmbo

    TheJimmbo Private E-2

    At the end of the burning process I got a message saying:
    Verify Failed!
    Reason: Layouts do not match
     
  10. TheJimmbo

    TheJimmbo Private E-2

    the log. sry for the dbl post
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Information I found that could help:

    • Try burning at all supported speeds.
    • Try cleaning the drive with a cleaning disc.
    • Try some better discs
    • Use a different burning program

    Any better now?
     
  12. TheJimmbo

    TheJimmbo Private E-2

    I think it might be my disc drive, I tried to burn an audio cd about a month ago and couldnt get it to finish. I'm going to burn the Vista Recovery zip on my roomates computer. So, just to verify,

    burn the whole Vista Recovery.zip
    boot in bios mode by hitting f1 or f2
    change the boot order to CD
    put the disc in my computer and reboot
    in the RE???? type Bootrec.exe /fixmbr
    boot back in normal mode ( do i have to go back into bios and change boot order?)
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Recovery Environment.

    Just do not "hit any key to boot from CD" when it asks and you should go straight into Windows...
     
  14. TheJimmbo

    TheJimmbo Private E-2

    I'm having trouble getting into the RE. I changed the boot order, put the disc in and rebooted. Windows started like it normally does.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's try the following:

    Please download aswMBR by Avast to your desktop.

    • Double-click aswMBR.exe to run it (Vista and Win7 right-click and select Run as Administrator)
    • Select No when asked Would you like to download latest Avast! virus definitions?
    • Click the [Scan] button.
      Note: This scan should only take a few seconds to complete.
    • On completion of the scan click [Save log], save it to your desktop and attach this log to your next message. (How to attach items to your post)
    • Now click the [FixMBR] button.
    • Follow the rest of the prompts.

    Reboot and rerun MBRCheck, attach its latest log. Also remember to attach your log from aswMBR.
     
  16. TheJimmbo

    TheJimmbo Private E-2

    logs
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That did not work. Have another go at following my instructions in post number 8. In the meantime I will ask colleagues about what the problem could be. Let me know how you get on.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We suspect you may be having issues because you might be just burning the ZIP file to the CD. That you are just making a data CD. Follow the instructions properly to create a bootable CD from the iso file. ;)

    (Thanks Chaslang!)
     
  19. TheJimmbo

    TheJimmbo Private E-2

    Ok, I pulled the Vista_Recovery_Disc.iso file out of the ZIP. Now in ImgBurn, do I choose "write image file to disc" or "write files/folders to disc"?
     
  20. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, TheJimmbo

    Yes
     
  21. TheJimmbo

    TheJimmbo Private E-2

    Thanks guys, don't know where Id be without ya.
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK we have dealt with the MBR infection, now let's get started on the ZeroAccess infection.

    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the Image textbox. Do not include the word Code
    Code:
    Code:
    :otl
    @Alternate Data Stream - 784 bytes -> C:\Windows\3203397148:3809022017.exe
    @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:45FE2B4E
    @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:C46995DA
    O20 - Winlogon\Notify\mifadok: DllName - (C:\Windows\system32\config\systemprofile\AppData\Local\mifadok.dll) - C:\Windows\System32\config\systemprofile\AppData\Local\mifadok.dll ()
    
    :files
    C:\Users\Owner\AppData\Local\21mn5E
    C:\ProgramData\21mn5E
    C:\Windows\$NtUninstallKB3255$
    c:\windows\3203397148
    C:\Users\Owner\AppData\Local\e6cj5tlvi1v865yfa8f352520352u236
    C:\ProgramData\e6cj5tlvi1v865yfa8f352520352u236
    C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Templates\21mn5E
    C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Templates\e6cj5tlvi1v865yfa8f352520352u236
    c:\program files\Minibar
    c:\program files\FaceSmooch Smileys
    C:\Program Files\Free Ride Games
    C:\Windows\system32\config\systemprofile\AppData\Local\mifadok.dll
      
    :reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{037039D8-8C53-43CC-95BE-198556E66531}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{037039D8-8C53-43CC-95BE-198556E66531}]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Userinit"="c:\windows\system32\userinit.exe," 
    
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  23. TheJimmbo

    TheJimmbo Private E-2

    Heres the logs. Not much has changed. I can still access my programs by opening files from their folders. Like going to one of my saved word documents, clicking on it and Microsoft Word opens. But I cannot access programs by the start menu or from the desktop. Firefox still works fine
     

    Attached Files:

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    After doing the above...

    Now we need to scan the system with this special tool.
    • Please download Junction.zip and save it to your root folder (C:\Junction.zip)
    • Unzip it and put junction.exe in the root folder (C:\junction.exe)
    • Now click Start => Run... => Copy and paste the following command in the run box and click OK:
      cmd /c junction -s c:\ >C:\log.txt
    • A command prompt window opens and also a license agreement from SysInternals will appear.
    • Accept the license agreement and the scan will begin.
    • Wait until a log file opens. Attach this C:\log.txt when it finishes (the command prompt window will close when it finishes). (How to attach items to your post)
    • NOTE: It scans your whole hard disk so if can take a long time. Be patient and don't do anything else while it is scanning.

    Run OTL again as you did in post number 4 and attach the log it creates please. Also run this:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds