Questions before starting malware removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by Digibirder, Nov 17, 2010.

  1. Digibirder

    Digibirder Private First Class

    I don't want to do anything wrong whilst performing this clean-up, but I need to ask a question before continuing.

    I am working my way through the READ & RUN page and have come unstuck a little way in.

    Step 2:
    AVG is disabled and I am unable to reinstall it. When trying to launch install procedure I get a message box saying: "This operation has been cancelled due to restrictions in effect on this computer. Please contact your system administrator". So I can't get round the requirement to have one AV program running. The only one purporting to run is the fake one - Internet Security Suite.

    Step 3:
    I have disconnected the infected PC from the Internet and network for safety, so do I need to reconnect it or can I download the required tools onto a USB stick and transfer them that way to install and run them?

    I have been unable to find any version of Sun Java, new or old, so should I still go ahead and install the latest version at all?

    I'll try and progress with the other steps in the meantime.
     
  2. Digibirder

    Digibirder Private First Class

    OK, I have gone through the directions to run all the tools and have attached the appropriate logs. Throughout the tests the affected computer was disconnected from the Internet, and I downloaded all the tools onto a different machine and then moved them over via a USB stick. Please advise if the affected machine needs to be connected to the Internet to perform any of these tasks and I will run them again.

    The story is that my husband's PC has been infected with something called Internet Security Suite. He thought AVG or Windows was issuing a virus warning and when he clicked on the link it launched into action. He was taken to a webpage to buy said program and then immediately realised something was wrong. I tried to see what I could do, but the system has been totally hijacked. I tried to find the Spybot site using Google, but as soon as I clicked on the link we were directed to a porn site. I shut this down immediately and unplugged the ethernet cable.

    The cable is still unplugged, but we are getting frequent virus warnings and messages saying infected emails are being sent. The number of emails in the message increases with each warning box - this is, of course, not possible as the computer in question is not connected to the Internet or the house network. There are update messages, looking similar to the Windows Update message, saying that updates are available to fix critical system errors. I recall a similar box that appeared yesterday, just after this happened, and I was immediately suspicious as there was a spelling mistake - it said 'plese' instead of please.

    System Alert balloon tips keep appearing from the System Tray, using an icon similar to the Windows Update one.

    AVG Free appears to be disabled. I cannot access the control console to change any of its settings. I am also unable to uninstall it as indicated in some of your instructions - a message appears that says the registry is preventing uninstalling.

    I also can't access Task Manager via Ctrl+Alt+Del.

    Internet Security Suite has placed icons on the desktop, in the Quick Launch area, and in the list of Start>All Programs, just underneath the Windows Update icon. It appears in the list of programs as well, but does not appear in Add and Remove Programs. There is inevitably no uninstall option.

    One or two issues when running through the instructions.
    Step 3 (House Keeping):
    The listed entries were not present in Add/Remove Programs
    Java is not installed on the affected computer - I downloaded the latest version using a second PC, but I didn't install to the affected one. Not sure if this step was essential, as it wasn't installed anyway.

    I cannot run Combofix. Error states that AVG needs to be disabled. I cannot do this as access to the AVG control panel has been blocked. I tried to uninstall AVG, but that failed. When I looked at the details it referred to the 'installation' failing (not removal), saying that the action failed for registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: creating registry key... Access is denied.

    I'm not sure if MGTools ran correctly. A command prompt window flashed up very briefly and then disappeared and nothing else appeared to happen. The MGTools and MGLogs.zip folders were created though. Whether the attached folder is complete or not, I am not sure. It appears to contain information.

    I hope the logs are OK. Apologies if something has not worked correctly.
     

    Attached Files:

  3. Digibirder

    Digibirder Private First Class

    Update:
    I've booted into Safe Mode but still unable to uninstall AVG or access its control panel.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We will get to dealing with avg soon. I shall review your logs and we will take care of the malware first.

    I'll post back with a set of instructions as soon as possible.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I suggest you run the Official AVG Removal Tool

    Make sure you also delete any AVG folders in Program Files and Documents & Settings/Application Data directories.

    Now reboot the machine .

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Run combofix.

    Then: You need to re-run C:\MGTools.exe, let it run all the way to completion, until you see "hit any key to continue"

    Attach the C:\Mglogs.zip.
     
  6. Digibirder

    Digibirder Private First Class

    Kestrel13, thank you for the help.

    I will start by saying that I actually tried to continue with this unaided yesterday, and found some instructions on another site regarding removal of Internet Security Suite. I was so desperate and I'm sorry if this has messed things up.

    I managed to get into Task Manager by following one of the tips - hit Ctrl +Alt +Del as soon as Windows starts to load - I then managed to spot a couple of rogue processes and managed to zap them. The fake virus warnings then stopped. As I had read, I then found spurious folders in Explorer and deleted those.

    I still could not get AVG to open and could not uninstall or reinstall a new version. There is an error message saying the registry is not allowing uninstalling (or words to that effect) and the install is not allowed 'due to restrictions in effect on this computer'. The AVG removal tool will not work. The errror is: Cannot delete avgcfgx.dll: Access is denied. I have attached the log file from the attempted removal. This morning when I switched the machine on, the AVG icon had reappeared in the system tray, but when I open the user interface it says that no components are installed. I am unable to delete the AVG folders in Program Files and Documents and Settings - I get errors that files are still in use.

    Consequently, I still cannot run Combofix.

    I have managed to run TDSSKiller and MGTools and those logs are attached.

    One more thing - an icon appeared on the desktop at the time of the infection, called TempWmicBatchFile.bat. I haven't done anything with this.

    Yesterday I also took the risk of re-connecting the machine to the router. When I opened an IE page, Google would not appear and clicking the Home Page icon brought up a page where I had to enter a word code to continue. When I tried to search for something, the list of results came up, but went to incorrect pages when clicked on. As soon as I closed the browser window, there was another window underneath which was a porn site. I don't know how long that had been there, as I hadn't noticed another window open.

    The machine is now disconnected again, so I am transferring these logs by USB stick onto my computer to upload here. I hope they are OK and that I haven't messed things up.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Give me a few moments and I will post a fix for you.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :dir
      Internet Security Suite
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Tell me how things are running.
     
  9. Digibirder

    Digibirder Private First Class

    Hi Kestrel,

    Ran the latest tests and the logs are attached.

    I am still having issues with AVG. Just tried again to uninstall and got the following error, which is as before:
    Local machine: installation failed
    Installation:
    Error: Action failed for registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: creating registry key....
    Access is denied.

    However, I just re-connected the network cable and brought up IE. The Google search page opened, I entered a search term and the correct page appeared - no redirects or pop-under windows.

    So I don't know if there is anything else needed!
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We might have to remove avg manually. For now tell me (Or show me with a screenshot) what's in this folder...?

    C:\Documents and Settings\KH\Application Data\Internet Security Suite
     
  11. Digibirder

    Digibirder Private First Class

    In that folder are two files:
    cookies.sqlite
    Instructions.ini

    Think I might move over to that machine now - might make this a lot simpler! As long as it's safe to do so.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you try and run Combofix in Safe mode and see if it plays ball with us?
     
  13. Digibirder

    Digibirder Private First Class

    Nope. Still detecting AVG.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ok, I will come up with a manual removal fix for avg. In the mean time delete this folder:
    C:\Documents and Settings\KH\Application Data\Internet Security Suite
    Then after the manual removal of avg we will try running combofix again.
     
  15. Digibirder

    Digibirder Private First Class

    OK done that. Will await further instructions. I tried the AVG removal tool while I was in Safe Mode but it still failed.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    In IE, go to Tools | Manage Add Ons
    - then select Search Providers on the left. Do you see findgala.com?

    Let's try Revo Uninstaller before we resort to manual uninstallation.

    If that still does not uninstall avg THEN try the below. If Revo does work, move onto trying to run combofix. (But manually delete this if you do not run my avenger script: C:\Program Files\Internet Explorer\SET65A.tmp )

    Run Task Manager and kill any of the avg processes if present:
    • avgchsvx.exe
    • avgtray.exe

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.


    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    Now try and run Combofix.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  17. Digibirder

    Digibirder Private First Class

    I have been out all day today and I am out tomorrow too so I will have to sort this out Monday, unless I get back early enough. But it looks pretty involved so I might need plenty of time!

    Thank you very much for all your help with this. I will post again when I have worked through it.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ok, I will be here waiting. :)
     
  19. Digibirder

    Digibirder Private First Class

    OK here goes!

    findgala.com was not in the list of Search Providers in IE. Just Bing and Live Search were present.

    There were no entries related to AVG in the Revo Uninstaller window so could not run that program.

    So, moved on to Task Manager: those two entries were not in the list.

    Next step - MGtools\analyse.exe:
    (I looked through the anti-spyware programs I've installed on your instruction, but could not see any options to disable them, so I don't know if the following has worked as it should.)
    Of the list of four items in the quote box:
    O2 - BHO....etc -- the line was there but at the end said (no file) instead of the AVG reference
    O4 - HKLM ...etc -- not present
    O18 - Protocol:....etc -- not present
    O20 - Winlogon...etc -- was listed as per your instructions and presumably was fixed

    Avenger ran and log file produced and attached.

    Ran the fixME.reg file and received message that information successfully entered into registry.

    Files and folders in the bold Temp folders deleted as requested (not today's).

    Combofix gave a message that it had detected a real-time scanner operating, but this time it referenced Internet Security Suite rather than AVG. I tried to close the box, but it then stated that it could run but at a risk. I cancelled the box that appeared, as I didn't know what would happen if I did run it with the ISS being detected.

    MGtools\GetLogs.bat run and log file attached.
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Go ahead and let combofix run.

    Then:

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  21. Digibirder

    Digibirder Private First Class

    I removed Windows Messenger then moved on to running Combofix. It went through about 50 stages and then indicated that it was deleting files. Then a blue screen STOP error appeared as follows:
    Plug and Play detected an error most likely caused by a faulty driver.
    Technical information:
    STOP: 0x000000CA (0x00000004, 0x890cc030, 0x00000000, 0x00000000)

    I am just rebooting the computer and running Combofix again. I did have to install the Windows Recovery Console.
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ok, continue on. I'll be here floating about for a couple hours yet.
     
  23. Digibirder

    Digibirder Private First Class

    Right, I managed to run Combofix and it did complete, although I did get a message pop up stating that:
    PEV.exe encountered a problem and needs to close. This had the usual 'report to Microsoft' option, but I closed it down without doing so and Combofix continued. Log attached.

    Also MGlogs.zip latest log attached.
     

    Attached Files:

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    SecCenter::
    {0BCDAF4B-A88D-4BFD-914F-D2F15C01CA20}
    {2F91513F-A7E7-4CA1-B9A1-588A98C23A5D}
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Navigate to:

    C:\Qoobox\Quarantine\C\WINDOWS\system32\spool\drivers\w32x86\3\E_FATI9LE.EXE.vir rename it to disinclude the .vir extension and then move it back to its original location as follows:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Reboot the machine and install some antivirus.

    What problems remain?
     
  25. Digibirder

    Digibirder Private First Class

    OK. I copied the code and dragged the file onto Combofix icon. It ran, but this time the machine rebooted in the middle of the procedure. When it came back on the Combofix window was still active and shortly afterwards the log file was produced, which is attached.

    I renamed and moved the file as directed then ran the MGtools\GetLogs.bat and the MGlogs.zip is attached.

    One new thing happening is that Windows Security is now prompting that no anti-virus is installed and that the firewall is off. This has not been happening before while I've been running these tests. I have not yet installed any antivirus, but will do that now.

    I don't know what problems might still exist, but will keep monitoring for any further issues. I have been surfing without any issues, and Google is no longer redirecting to any dubious sites, as I've mentioned previously.
     

    Attached Files:

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, get some antivirus installed! :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  27. Digibirder

    Digibirder Private First Class

    OK - and thank you very much for this assistance.

    I have a headache now so I have switched off and will attempt this last stage at a later time. I now need to look into what anti-virus software to get - I am certainly going to get something more robust than AVG seems to be. I will look at the recommendations given elsewhere on this site.

    Boy, what a nightmare!!
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    *hands you an anadin* Safe surfing!
     
  29. Digibirder

    Digibirder Private First Class

    Thanks for the painkiller - I was quite ill last night, but I don't think it had anything to do with this performance. Probably ate something that upset me. Feeling a bit more chipper this morning.

    OK, I think I've done it all now.

    I installed the free Comodo Internet Security (AV and firewall combination), which looks to be a good program. It seems to be popping up warnings about things I don't really understand, but I expect it will settle down eventually.

    I have left SuperAntiSpyware and Malwarebytes on and will consider purchasing the full versions.

    While uninstalling Combofix, Comodo launched a few warnings, but I expected it to be the Combofix files it was detecting so I accepted them and Combofix uninstalled eventually.

    Regarding the other tools, I have uninstalled those that have an uninstall option, but can things such as the .exe files downloaded onto the desktop simply be deleted? Such as TDSSKiller.exe (and associated folders), SystemLook.exe, avenger.exe and RootRepeal.exe.

    I couldn't find HijackThis in Add/Remove programs, so presumably this didn't get installed as a standalone program.

    I ran the MGclean.bat file, but the C:\MGtools folder is still there - can I delete that?

    I went into disable and re-enable System Restore, but at some point it must already have been disabled. I enabled, disabled and re-enabled it again and it is now back on, but I wasn't prompted to reboot at any stage so I hope that has all worked.

    Do I now consider this machine to be clean?

    I am now looking at my own machine and I am going to remove AVG and get Comodo on here as well. And then batten down all possible hatches against anything of this nature happening again!!!!
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good. ;)

    Yes you can just delete them.

    Yes.

    Yes.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds