Please help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Kirkberry, Oct 1, 2009.

  1. Kirkberry

    Kirkberry Private E-2

    Hi,

    About a week ago I started to get some strange activity when on the net, e.g. google results not connecting to the correct site, websites redirecting to adverts for stopzilla. I attempted to install and run a number of free antimalware programs ( Antimalwarebytes, Spybot, Advancedcare System etc) but they would start to scan and then close down and I would not be able to reload them.

    I then came across this website and have followed the steps in the READ AND RUN ME FIRST thread.

    When I ran SAS it shut down during the scan, when attempting to reload it I received the error message 'Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item.' Nothing happened at all when I attempted the alternate start option.

    The same as above happened with MBAM.

    I then ran ComboFix. I couldn't download the Windows System Recovery Console as I wasn't connected to the net (ComboFix had rebooted the computer) and couldn't connect as all I could see was the ComboFix window and the wallpaper.

    When ComboFix scanned it found rootkit activity and needed to reboot. It asked me to note the following files:

    C:\WINDOWS\system32\drivers\gasfkyjnkvxfqr.sys
    C:\WINDOWS\system32\gasfkydltoqoob.dll
    C:\WINDOWS\system32\gasfkyrcdairr.dat
    C:\WINDOWS\system32\gasfkyskwhopqw.dll
    C:\WINDOWS\system32\gasfkyiyulbait.dat
    C:\WINDOWS\system32\gasfkylogcqlte.dll

    It then rebooted and did the same thing. After going through this loop several times I had to break the cycle by shutting ComboFix down through Task Manager. I then rebooted, started ComboFix again and it scanned and produced a log, attached below. I then installed Recovery Console manually.

    I also attach RR log and MGlogs below.

    The computer seems a little better now (issue with google sorted) but I am not too confident it is sorted and SAS still will not load. Sorry for the long post, and thank you very much in advance, any help is much appreciated.

    Cheers
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why am I not seeing any AV program installed on this system?

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now download and Run exeHelper

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Now use windows explorer to find and delete:
    c:\windows\win32k.sys

    See if you can now run SAS and MBAM. If so, attach the logs.

    Part of your problem is a lack of RAM:
    Total Physical Memory 512.00 MB
    Available Physical Memory 94.81 MB

    Now install and Anti-virus program!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * SAS and MBAM
    * C:\MGlogs.zip
     
  3. Kirkberry

    Kirkberry Private E-2

    Tim, thank you for your response. Please find attached the exeHelper and MG logs. SAS and MBAM still do not work, I get the same error message as before.

    I have downloaded and installed Comodo, I was using Avast until the problems started and it wouldn't load at which point I uninstalled and re-installed it and for some reason I seem to have uninstalled it again!

    So upgrading my RAM would help things do you think? Or is it the way the RAM is being used that is the problem?

    Cheers
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It has nothing to do with the way the ram is being used. You just need to double what you have.

    As to SAS and MBAM, have you tried totally uninstalling them and then after running CCleaner, reinstalling?

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  5. Kirkberry

    Kirkberry Private E-2

    Nice one Tim, everything is pretty much hunky dory now and SAS and MBAM are working.

    The only thing that seems odd is that having done the things in your last post and whilst working through the how to protect yourself guide I tried to install Spybot- something I'd had on the computer previously. While installing it said it could not overwrite a file, and then would not load once it had finished.

    I uninstalled Spybot thinking I would try again. I've noticed a folder C:\Program Files\Spybot- Search & Destroy that doesn't seem to have anything in when I open it but the properties says there are 2 files of around 6 MB. When I try to delete the folder it says that SybotSD.exe cannot be deleted as Access is denied. Is this something to worry about?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That folder is probably why you cant install it properly. I suggest that you post in the software forum for assistance with removing that and re-installing SpyBot.
     
  7. Kirkberry

    Kirkberry Private E-2

    OK, thank you very much for your help Tim, really appreciate it.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds