Problem with removing various trojan. malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by SalemDesign, Oct 3, 2009.

  1. SalemDesign

    SalemDesign Private E-2

    The first time I realized something was up was while installing Adobe Acrobat Pro on my Thinkpad T61 (Windows XP Pro) and it crashed (bluescreen). That's the first bluescreen I have had in a long while.

    When I restarted, I noticed that Kaspersky Internet Security 2009 had not restarted automatically. Furthermore, the normal warning that occurs if no firewall or antivirus is in place was disabled.

    And I could not restart it manually.... I uninstalled Kaspersky (Add/Remove Programs) and tried re-installing it but it would not reinstall.

    So I eventually found my way to this site and started through your cleanup process.

    For Step 2... I only every had Kaspersky for both Antivirus and software firewall. (And it wasn't working at that point).

    For Step 3
    I didn't see any Viewpoint app's in Add/Remove.

    I updated Sun Java as instructed.

    I couldn't empty the Kaspersky Quarantine folders since it wasn't running.

    I emptied the recycle bin.

    I downloaded/installed/ran CCleaner.

    Step 4
    I made system files viewable
    I set msconfig for normal startup

    Step 5
    I check Add/Remove Programs for any obvious malware (' didn't see any)

    Step 6
    I started running the Windows XP cleaning procedure

    I downloaded and ran all the tools as instructed.

    SuperAntispyware did not find anything (so I have not attached a log)

    MalwareBytes found a bunch of stuff (see attached log) and seemed to clean up most of it.

    At this point, my recollection is that MalwareBytes insisted on a reboot and following the reboot, Kaspersky started working again.

    I reran MalwareBytes and it found no malware.

    In retrospect, I should have gone directly to appying combofix...

    Instead, I tried scanning with Kaspersky. The malware went seriously nuts and Kaspersky started playing wackamole as more and more stuff got infected, including some key system files.

    I eventually rebooted manually and I did run combofix (see attached log).

    And then RootRepeal (see attached log).

    And then MGTools (see attached zip).

    Things are better than when I started the cleanup... But Kaspersky still see's infections that it cannot clean so I clearly have not removed everything.

    If you can suggest how to really get everything cleaned up, it would be appreciated.

    Thanks in advance.

    --Doug
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please do not run a scan with Kaspersky again until I have given you the all clean AND you have complete final instructions that are given once you are clean.

    We just have a little more to do before getting to final instructions.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. SalemDesign

    SalemDesign Private E-2

    Thanks for the followup.

    I started following your instructions.

    I disabled Kaspersky

    I downloaded and ran the tool for removing Windows Messenger (which seemed to proceed as expected).

    I copied your Quoted text into CFscript.txt and put it on the Desktop along with the ComboFix.exe executable.

    But when I tried dragging and dropping CFscript.txt onto ComboFix.exe, I got the following popup message:

    I figured I better check back with you and see what's going on.

    TIA,

    --Doug
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete the current copy of ComboFix.exe that is on your Desktop and download and save the new version there: combofix.exe DO NOT RUN IT or the last fix yet.

    Now download and run the new version of MGtools but do not attach a log for it right now. I will be ave you do a new scan later where I will ask for a log.


    Please download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r


    Now download Junction,zip to your Windows folder
    • Please download Junction.zip and save it to your Windows folder (i.e, C:\Windows\Junction.zip This assumes C:\ is your Windows boot drive.)
    • Now unzip it and put junction.exeinto the Windows folder (i.e., C:\Windows\junction.exe)
    • Do not try to run it right now. We will run something that uses it later.

    Now we need to reset the permissions altered by the malware on some files.
    • Download and save inhertit.exe to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!
    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.
    Now see if you can run the step with ComboFix from my previous message After running ComboFix (whether it runs or not) continue here with this message.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Now attach the below log:
    • the log from Win32kDiag
    • C:\ComboFix.txt
    • the logs from SUPERAntiSpyware and Malwarebytes if they ran
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. SalemDesign

    SalemDesign Private E-2

    OK, I turned off Kaspersky. That wasn't in your current instructions but it seemed to be necessary from your instructions earlier in this thread.

    I downloaded and ran Win32kDiag as instructed. It seemed to run (i.e. no error message) but no Win32kDiag.txt ever appeared on the Desktop and I never saw any obvious sign that it was actually running.

    C:\MGTools\fixperm.bat seemed to run, I got a number of Finish/OK popups and then the SysInternals license dialog box. I clicked OK on everything and the Command Line window eventually disappeared.

    Dropping the script file on ComboFix.exe still does not work. I get the same "don't have the appropriate permissions" popup message.

    I ran CCleaner as instructed.

    Win32kDiag never produced a log. ComboFix did not run this time and the only from when it did run (from Oct 02) is already attached to this thread. I ran MalwareBytes but it did not find anything so I won't append its log... SuperAntiSpyware has never seen anything on this machine either so no log for that.

    So all I have for you is the MGLogs.zip file. I hope that it tells you something! :)

    Thanks for continuing to help me on this.

    --Doug
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's g about this differently.

    Uninstall SUPERAntiSpyware.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\temp
    C:\Documents and Settings\Douglas Denholm\Local Settings\temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. SalemDesign

    SalemDesign Private E-2

    Given how much time this is taking, and how much effort on your part (and mine), I decided to bite the bullet and do a full factory restore. [I had all of my created work files backed up; reinstalling all the app's is a hassle but it isn't this open-ended thrashing around trying to deinfest the system.]

    My understanding is that during the factory restore everything on the C: drive is deleted as part of the restore and Win XP and all the necessary drivers are re-installed. So hopefully that should get rid of all the malware. Is that also your experience?

    Is there any scan that I can/should do to ensure there is no lingering malware still embedded somewhere?

    I really appreciate your help on this and I mean no criticism of your efforts up to now but given that I had all my work files backed up it seems like less work to "burn it down and start over."

    --Doug
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you should work thru this: How to Protect yourself from malware!

    As long as you did not have an infected Master Boot Record or a BIOS infection then yes.

    If you really want to be sure, run a full scan with a fully updated antivrus program and also do the below to be safe since all antivirus programs miss quite a lot.

    READ & RUN ME FIRST. Malware Removal Guide
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds