Possible Failed Rootkit Removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Larceny82, Feb 11, 2012.

  1. Larceny82

    Larceny82 Private E-2

    This is from after a ComboFix run to get me online:
     

    Attached Files:

  2. Larceny82

    Larceny82 Private E-2

    This is from after I rebooted and it reverted back to it's connection-less state.
     

    Attached Files:

  3. thisisu

    thisisu Malware Consultant

    http://img205.imageshack.us/img205/4783/regeditb.gif Open Notepad and copy everything in the code box below into it.
    Code:
    Windows Registry Editor Version 5.00
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AFD]
    "NextInstance"=dword:00000001
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AFD\0000]
    "Service"="AFD"
    "Legacy"=dword:00000001
    "ConfigFlags"=dword:00000400
    "Class"="LegacyDriver"
    "ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
    "DeviceDesc"="@%systemroot%\\system32\\drivers\\afd.sys,-1000"
    "Capabilities"=dword:00000000
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AFD\0000\Control]
    "ActiveService"="AFD"
    
    • File -> Save As -> Save as type: "All Files" -> File Name: afdlegacy.reg > Save.
    Now merge this into the registry by double-clicking it.
    Let me know if the merge was successful or not.
    If not successful, let me know exactly what error message you received.
     
  4. thisisu

    thisisu Malware Consultant

    If the above merge was successful, you can continue with this next step:

    Attached is fixme2.zip
    Inside is fixme2.bat
    Run fixme2.bat
    If notepad opens and says: 1 file(s) copied.
    Close notepad and reboot Windows.

    Test internet.
     

    Attached Files:

  5. Larceny82

    Larceny82 Private E-2

    Failed, I'm attaching both logs as last time (connected to the internet after running combofix and after a reboot where it returns to its disconnected state)
     

    Attached Files:

  6. thisisu

    thisisu Malware Consultant

    Attached is a .bat file called grantperm.bat

    Extract this to the desktop.
    Run grantperm.bat by right-mouse clicking and selecting "Run as Administrator".

    Let me know if a DOS prompt window flashed quickly on the screen.
     

    Attached Files:

  7. Larceny82

    Larceny82 Private E-2

    Confirmative.
     
  8. Larceny82

    Larceny82 Private E-2

    Also, just a side note, I am still in "connected" mode at the moment. If you'd like me to do any of these steps in the "disconnected" mode, just let me know.
     
  9. thisisu

    thisisu Malware Consultant

    Now retry afdlegacy.reg. Let me know if you get an error message this time.

    You can stay in the "connected" mode.
     
  10. Larceny82

    Larceny82 Private E-2

    Yes, but it changed...
     

    Attached Files:

  11. thisisu

    thisisu Malware Consultant

  12. Larceny82

    Larceny82 Private E-2

    Attached Files:

    • FSS.txt
      File size:
      2.2 KB
      Views:
      8
  13. thisisu

    thisisu Malware Consultant

    That looks better.

    Now follow the instructions in this post: #54

    Keep me informed on what happens.

    Remember to REBOOT if you see 1 file(s) copied.
     
  14. Larceny82

    Larceny82 Private E-2

    Bat run, notepad opens with 1 file copied, reboot, no Internet [posted from phone]
     
  15. thisisu

    thisisu Malware Consultant

    Can you verify that c:\windows\system32\drivers\afd.sys is present?

    Do you have your flash drive handy? I would highly prefer that you do not run ComboFix to fix the internet anymore.
     
  16. Larceny82

    Larceny82 Private E-2

    *facepalm* nope, sure isn't. Possible quarantine file from earlier?
     
  17. thisisu

    thisisu Malware Consultant

    Do this first, I will give you some CF instructions in a bit

    Open the Device Manager

    Click the http://www.techsupportforum.com/forums/sectools/tetonbob/StartBtn.gif button. > Run - copy and paste this command in the box devmgmt.msc then click OK.

    Collapse the Network Adapters list.
    Right mouse click: NVIDIA nForce Networking Controller
    Choose "Uninstall".
    You be asked to confirm your actions, choose OK and let it uninstall.
    If it asks you if you want to delete the driver software / files too, say No.

    Now do the same exact thing with: NVIDIA nForce Networking Controller #2


    When you have done this and both NVIDIA nForce Networking Controller and NVIDIA nForce Networking Controller #2 are no longer in the Device Manager list -- Press the Scan for hardware changes button (http://img803.imageshack.us/img803/2868/scanhardware.png) or Action -> Scan for hardware changes
    Allow it to reinstall your network adapter.
    Reboot for changes to occur.
    Test internet once you have rebooted.
     
  18. Larceny82

    Larceny82 Private E-2

    Flash drive isn't handy, but if you've got patience, I've got time. I can get it tomorrow.
     
  19. Larceny82

    Larceny82 Private E-2

    Negative on Internet connection after driver uninstall/reinstall
     
  20. thisisu

    thisisu Malware Consultant

    I've got patience, but I want to use ComboFix for this next part anyways. ;)

    You do need to obtain a new copy of ComboFix though.

    http://img194.imageshack.us/img194/4930/combofix.gif Fixing items using ComboFix
    Make sure that ComboFix.exe that you downloaded while doing the READ & RUN ME is on your desktop -- but do not run it.
    If it is not on your desktop, the below will not work.
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Open Notepad and copy/paste the text in the below code box into Notepad:
    Code:
    [COLOR="DarkRed"]KillAll::[/COLOR]
    [COLOR="DarkRed"]Domains::[/COLOR]
    [COLOR="DarkRed"]FCopy::[/COLOR]
    C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16385_none_d7be98b5bfc0b4c1\afd.sys | c:\windows\system32\drivers\afd.sys
    [COLOR="DarkRed"]FileLook::[/COLOR]
    C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16385_none_d7be98b5bfc0b4c1\afd.sys
    [COLOR="DarkRed"]Folder::[/COLOR]
    c:\programdata\Spybot - Search & Destroy
    c:\program files\Spybot - Search & Destroy
    [COLOR="DarkRed"]RegLock::[/COLOR]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\AFD]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AFD]
    [COLOR="DarkRed"]RegNull::[/COLOR]
    [HKEY_USERS\S-1-5-21-1519333054-607781042-2488702932-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
    [HKEY_USERS\S-1-5-21-1519333054-607781042-2488702932-1000\Software\SecuROM\License information*]
    [COLOR="DarkRed"]Registry::[/COLOR]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\06194213.sys]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\12519724.sys]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\13472414.sys]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\33077221.sys]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\60931041.sys]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\74538679.sys]
    [COLOR="DarkRed"]Rootkit::[/COLOR]
    C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.20951_none_d864ad9ad8c98d1f\afd.sys
    
    Save this file as CFScript.txt to your desktop. So now you should have both CFScript.txt and ComboFix.exe on your desktop.
    Now use your mouse to drag CFScript.txt on top of ComboFix.exe and then release.
    http://softvisia.com/users/Night_Raven/Security/cfsdnd2.gif
    This will launch ComboFix.
    Note: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
    Allow ComboFix to update itself if prompted.
    When ComboFix finishes, a log will be produced at C:\ComboFix.txt
    Attach this log to your next message. (How to attach)


    http://img684.imageshack.us/img684/6489/aswmbr.gif Please download aswMBR to your desktop.
    • Double-click aswMBR.exe to run (Vista/7 right-click and select Run as Administrator)
    • Select No when asked "Would you like to download latest Avast! virus definitions?"
    • Click the [Scan] button.
    • On completion of the scan click [Save log], save it to your desktop and attach this log to your next message. (How to attach)

    http://img97.imageshack.us/img97/8120/fss.gif Please download Farbar Service Scanner and run it on the computer with the issue.
    • Make sure all the options are checked
    • Press "Scan".
    • It will create a log (FSS.txt) in the same directory the tool was run.
    • Please attach FSS.txt to your next message. (How to attach)
     
    Last edited: Feb 24, 2012
  21. thisisu

    thisisu Malware Consultant

    Hopefully most of our CFScript will work. You do need a new copy of ComboFix though. Yours is expired.
     
  22. Larceny82

    Larceny82 Private E-2

    Combo fix is reduced functionality mode. Requesting permission to use that mode to grant me faux Internet access to download newest files before proceeding.
     
  23. thisisu

    thisisu Malware Consultant

    May as well. Proceed ;)
     
  24. Larceny82

    Larceny82 Private E-2

    Lol! That's the spirit! Will keep you updated shortly.
     
  25. Larceny82

    Larceny82 Private E-2

    I'd also like to take this time to throw out a HUGE thanks. Either youve got the same goofy work schedule or you're really dedicated to this gig. Either way I greatly appreciate it.
     
  26. thisisu

    thisisu Malware Consultant

    Both :-D
     
  27. Larceny82

    Larceny82 Private E-2

    After running combo fix, Internet was restored but all programs were reporting "cannot execute this program because it is trying to use a file that has been marked for deletion". After reboot, we're back where we started: no connection, no afd.sys file in the drivers folder.
     
  28. thisisu

    thisisu Malware Consultant

    I need to see the 3 requested logs to see what happened / what comboFix changed.
     
  29. Larceny82

    Larceny82 Private E-2

    Copy that, I'll run the other 2 when I get home tonight and post the results as soon as I can.
     
  30. Larceny82

    Larceny82 Private E-2

    I apologize for the delay. I'm resisting all urges to run the fix me and the grantpermissions and the afdlegacy, etc. picking up a new flash drive tomorrow then it's a matter of finding a computer to upload results. :)
     
  31. Larceny82

    Larceny82 Private E-2

    Oh. My. Word...I can't believe I had a brain-fart last that long. I created another Ubuntu live CD and reinstalled Ubuntu, so now I will have Internet access at will so it won't take me ages to get stuff uploaded to you. :-o *facepalm* Anyway, here are the documents you requested from the scan over a week ago.
     

    Attached Files:

  32. thisisu

    thisisu Malware Consultant

    Quick question, are you running scans with SAS or MBAM on your own?
     
  33. Larceny82

    Larceny82 Private E-2

    The only thing I've run since that was a quick test to see if combo fix would get me connected.
     
  34. thisisu

    thisisu Malware Consultant

    Are you using the paid versions of SAS or MBAM?
     
  35. thisisu

    thisisu Malware Consultant

    I may have missed this earlier but you should not be running SAS on your own unless requested to.

    This may be what keeps quarantining afd.sys and other internet related drivers.

    For good measure, please uninstall SAS, MBAM, and Spybot - Search & Destroy and leave them uninstalled for the remainder of malware removal.

    Reboot your PC after you have uninstalled all 3 of these.

    Now download a NEW ComboFix.exe from here. Place it on your desktop.

    http://img194.imageshack.us/img194/4930/combofix.gif Fixing items using ComboFix
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Open Notepad and copy/paste the text in the below code box into Notepad:
    Code:
    [COLOR="DarkRed"]KillAll::[/COLOR]
    [COLOR="DarkRed"]ClearJavaCache::[/COLOR]
    [COLOR="DarkRed"]Driver::[/COLOR]
    SASDIFSV
    SASKUTIL
    !SASCORE
    [COLOR="DarkRed"]File::[/COLOR]
    c:\windows\system32\dds_trash_log.cmd
    [COLOR="DarkRed"]Folder::[/COLOR]
    c:\program files\SUPERAntiSpyware
    c:\windows\$NtUninstallKB41664$
    [COLOR="DarkRed"]MIA::[/COLOR]
    c:\Windows\system32\drivers\afd.sys
    c:\Windows\system32\drivers\netbt.sys
    c:\Windows\system32\drivers\tcpip.sys
    c:\Windows\system32\drivers\tdx.sys
    c:\Windows\system32\drivers\nsiproxy.sys
    
    Save this file as CFScript.txt to your desktop. So now you should have both CFScript.txt and ComboFix.exe on your desktop.
    Now use your mouse to drag CFScript.txt on top of ComboFix.exe and then release.
    http://softvisia.com/users/Night_Raven/Security/cfsdnd2.gif
    This will launch ComboFix.
    Note: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
    Allow ComboFix to update itself if prompted.
    When ComboFix finishes, a log will be produced at C:\ComboFix.txt
    Attach this log to your next message. (How to attach)

    http://img17.imageshack.us/img17/3214/baticonvista7.gif Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)
     
  36. Larceny82

    Larceny82 Private E-2

    Copy that. I'm at work now, but with a working edition of Ubuntu, you'll have these shortly after I get home tonight.
     
  37. Larceny82

    Larceny82 Private E-2

    Do you recommend using standard Control Panel Add/Remove Programs? Because I've also used Revo Uninstaller in the past...
     
  38. thisisu

    thisisu Malware Consultant

    I typically just use the standard Control Panel for most applications. If I encounter any difficulties then I may use Revo Uninstaller.
     
  39. Larceny82

    Larceny82 Private E-2

    Okay, I'll get those uninstalled and get the new logs up tonight.
     
  40. Larceny82

    Larceny82 Private E-2

    Newest Logs, definitely seemed to run smoother. Internet in general seems to be running smoother too.
     

    Attached Files:

  41. thisisu

    thisisu Malware Consultant

    Latest logs are clean. :)
    I guess it was one of those 3 security applications after all.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis if it present
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work through the below link:
    Be safe :)
     
  42. Larceny82

    Larceny82 Private E-2

    I can't thank you enough and I apologize for all the delays in the process!

    Yes sir! :major
     
  43. thisisu

    thisisu Malware Consultant

    You're welcome and no problem ;)
     
  44. Larceny82

    Larceny82 Private E-2

    Didn't think I'd be back so soon...so since my last post, I went to work, came home played Portal, slept, played Portal, went to work, booted into Ubunto to watch TV, booted into windows, downloaded and installed Microsoft Security Essentials and a .NET framework as well as Avast!, rebooted and can't log in to Windows completely. As windows loads, the entire thing freezes. Safe mode loads fine however.
     
  45. thisisu

    thisisu Malware Consultant

    Hi,

    It may be a problem with both MSE and Avast trying to load while in Normal Mode.

    You should uninstall both for testing purposes and see if that helps.

    By the way, you should only have one Antivirus installed, uninstall the rest. There are more details about why in the Read and Run Me First thread.
     
  46. Larceny82

    Larceny82 Private E-2

    You were exactly correct. I loaded safe mode, uninstalled avast and the computer booted right up. Thanks again.!
     
  47. thisisu

    thisisu Malware Consultant

    :cool You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds