query - Dr. Guarder and special removal procedures?

Discussion in 'Malware Help (A Specialist Will Reply)' started by THE Bimbo, Mar 17, 2010.

  1. THE Bimbo

    THE Bimbo Private E-2

    Hi,

    one of our machines at the office has been hammered with virii / malware late this afternoon just before we packed up for the day,

    one of the popups claimed to be "Dr. Guarder", which disabled AVG, Malwarebytes and Spybot SD, and then installed things like porn.net and a few others, while continually claiming to be "helping" (like the mother-in-law from hell)

    i isolated the system and will be slugging away at it tomorrow morning when i go in, i can just plug it into a caddy, recover the doc's and blow away the hdd but i do like to beat these damn things - it's good practice for when an important system gets nailed,

    i was just wondering if anyone knew anything about "Dr Guarder" and if i need to do anything special to kill it?
    (could not find much at all on google)

    thanks,
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. THE Bimbo

    THE Bimbo Private E-2

    thanks for that,
    i have printed that out and the supplementary guides it links onto,

    i have been following the instructions and i got past ccleaner and msconfig, and into the actual OS guide,
    but nothing else wanted to run,
    so i moved onto the guide (which i left next to the unit at work) telling me what to do when everything else fails,
    and everything on that is failing too,

    so i have no logs to upload yet,

    to this point nothing will keep running, not even MGtools,

    every tool either fails to run entirely, or locks up within 60 seconds and (simultaneous with the lock-up) the keyboard and mouse get disabled,
    forcing a reboot and it seems to me the malware is repairing itself at the reboot,

    having had nothing run i have left the machine running the AVG repair bootable CD overnight, (my boss wanted to see something happening) though my results with that CD have been mixed in the past.
    that CD will detect many virii, and delete them if i tell it to, but it does not repair the OS (XXPro in this case)

    I will report back here in 24 hours, :major
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Have you tried running what scans you can in safe mode if normal mode is proving difficult/impossible?

    If push comes to shove, just make sure you have the tools in the correct location as specified in the R&R, then at the very least rename combofix to kestrel.com and rename MGTools.exe to 123.com, THEN see if they will run. If you are still having difficulty then try this out:



    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.


    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post )


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.


    Then try running these instructions: Using MGtools


    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • a log from online SAS scan if you could make one
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  5. THE Bimbo

    THE Bimbo Private E-2

    many apologies for the delay, the system has sat in the corner whimpering for much of the week, with bits and pieces being done to it (and the odd kick when it was down) whenever time permitted or one of us passed it by


    the boss insisted on running AVG Rescue from CD,
    the AVG CD found and removed VB.VIH, VUNDO.KV, SHEUR3.GCA,
    WIN32/ALUREON, ROOTKIT-AGENT.EG and GENERIC17.EMX


    i was still having trouble losing keyboard and mouse control,
    i ran the rkill / exe helper tools (as sugested here), we were still losing control,
    perhaps the system was turning off USB, because we plugged in a PS2 Keyboard and Mouse and that solved that.

    exe helper then found sdra64.exe

    and then the boss tried to follow the printouts of the step-by-step guides here,
    and managed to do a few things back to front,

    as, quite likely, so did i.

    at the end

    SAS i was unable to save a log for,
    it found c:/windows/system32/lowsec
    local.ds, user.ds,user.ds.dll

    rebooted

    mbam still refused to update, and refused to browse to any page on the mbam site,
    but the unupdated version would run,
    it found and removed 22 objects,
    including rogue dr guard, rootkits, dns changers, trojan downloaders and fake alerts

    rebooted

    THEN we could update mbam,
    so we did and rerun it and it found another 14 objects,
    including a different rootkit and malware packers,

    rebooted

    third scan found 3 copies of A0157677.dll (another malware packer)

    rebooted

    AVG SBS resident found 2 copies of twopya.exe, ??
    AVG SBS scan then found another copy of sdra64.exe ???

    after removing those
    rebooted
    and a full AVG scan found only tracking cookies
    a full mbam scan found only a tracking cookie
    Spybot SD found nothing
    SAS found nothing

    so it looks like this machine had rootkits, inside rootkits, inside rootkits...

    seeing we have the machine back under control (but still isolated) is it likely we still have anything onbaord?
    what tool/s would you like me to run for you to be able to check the logs?
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hopefully you are okay now, and I should have noticed before from your first post, however:

     
  7. THE Bimbo

    THE Bimbo Private E-2

    ah, not to worry, there's no business data on any of our desktop boxes, that would be suicidal after all,
    they're all simple workstations,

    (we have over 1,400 desktops, maintained by 4 techs - policy is minimal restrictions on users, they're not "locked down" - much as i would prefer to lock them down, we simply dont.)

    all databases and so on are stored on a HDD raid array on one of the servers, all the desktop boxes ever hold is the application installations, any personal data the user wants local, and the O/S.

    and we are in australia, rules here are a little different, all help i solicit is treated as "given as a gift with no warranty" and thus acting upon such solicited advice is accepted as "at my own risk", even if i phone IBM or Toshiba and they tell me to do something that destroys the data, it's "tough luck"! (and i have, and they have!)


    I do a lot of data recoveries here, on the rare occaisions someone brings me a machine that does have critical data, (which is usually the daughters birthday party photo's or similar) the very first thing i do is boot to a CD/DVD and create a backup image of the drive, and a seperate backup image of all files.
    That allows me to attempt a variety of data recovery and/or op sys repair solutions - because if one fails i can restore the image and try another (which i do).
    and if all else fails i have the raw files that i can burn to DVD for the end user.


    When it comes to this sort of issue, (multiple virii), Life is generally much simpler for the user if i can recover a system from an infection, rather than wipe and rebuild. (It takes me 3 minutes to wipe and restore, but the user then loses all their customisations and the complaining i get to listen to when i wipe ...aiyaiyai...)


    this system is not important, and its misfortune is being taken advantage of as a test bed to practice virii removal and op sys repair.

    under the simple caveat that there is nothing of importance on the drive and anything that goes wrong is entirely my fault, can you help?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well this is the problem you see, your boss wanted to do one thing and I wanted you to follow my instructions. Bear with me while I confer with a colleague. :)
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then attach the log from MBAM and the log from exe helper and from AVPfind
    Also download and run combofix as per the instructions in the R&R. Attach the log it creates ---> C:\combofix.txt
    Then do the same for MGTools and attach the log from running it ---> C:\Mglogs.zip
     
  10. THE Bimbo

    THE Bimbo Private E-2

    Apologies for delay, so many people away over easter i have had no time to look at anything, the system is sitting under my desk, unplugged,
    as it has for two weeks now

    attached are logs for
    avp, exehelper, combo fix and mgtools

    will upload mbam logs immediately
     

    Attached Files:

  11. THE Bimbo

    THE Bimbo Private E-2

    as explained one log from the base install, when the system would not allow us to update mbam, (11-33-43)

    and the log from when we could finally update mbam and re-ran same, (11-50-02)

    thank you
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. AVG 8.5 <--- Is now out of date, you can either upgrade to version 9 or switch to another AV.

    2. There has been an update to Malware Bytes since you were last here so now in normal mode if possible and not safe mode, I would like for you to open up the program > update > re-scan > fix all it finds > and attach the log it creates into your next reply here.

    3. I see SUPERantispyware was run on 23rd march, the log is retrievable here, I would like for you to also attach that.


    4. You did not run combofix, you ran SDFix. Combofix is on your desktop and I will instruct you to run it again further down.

    5. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    6. Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    7. Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.


    8. Please go to Add/Remove programs and uninstall the following software:

    1. J2SE Runtime Environment 5.0 Update 6
    2. Java(TM) 6 Update 3
    3. Java(TM) 6 Update 5
    4. Java(TM) 6 Update 7

    9. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    10. Now I want you to run combofix as per the instructions in the Read and Run Me First Procedures.

    11. Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    12. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds