RogueAV, rootkit, bluescreen...

Discussion in 'Malware Help (A Specialist Will Reply)' started by duckfeet, Dec 6, 2009.

  1. duckfeet

    duckfeet Corporal

    My friend asked me to look at her computer, as it wouldn't even boot up, it would start, desktop would come up, then all the pop-up's started, and it would kick into bluescreen with errors...I couldn't download anything of course, so I put the required scans on USB flash drive, couldn't get to msconfig. It stalled halfway thru superantispyware scan, back to bluescreen again...so I ran malwarebytes and it made it thru scan, and then I ran combofix and it seemed o.k., and by then the constant popups and rogue AV seemed gone...so at this point I could finally go to msconfig, and of course it *wasn't* in normal startup, so I put it in normal startup and continued w/root repeal and mgtools...and since I had to run some of the stuff backwards--like ccleaner, and the java updates, I was hoping you could look at this...

    I have run combofix, MBAM, and SAS again in normal mode...but since I had updated them before I ran them on USB, and since they found so much horrible stuff, I figured I better post the originals...the second scans came up clean...I'm worried about the rootkit and trojan droppers and hoped you could look at this...

    Thankyou in advance, as before you have helped me so much...
     

    Attached Files:

  2. duckfeet

    duckfeet Corporal

    And the rootrepeal log...
     

    Attached Files:

    • rr.txt
      File size:
      43.2 KB
      Views:
      5
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there Duckfeet :)

    Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      c:\windows\System32\drivers\25cf2bb7.sys
    • At the upload site, click once inside the window next to Browse.
    • Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
    • Next click Submit file
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

    Then do the same for the below file and also let me know the results:

     
  4. duckfeet

    duckfeet Corporal

    Hi Kestrel::wave

    The first one wouldn't come up, here is the second one, it came up clean...

    http://virusscan.jotti.org/en/scanresult/00e326737e79893a4d406bc267ec693a769efbfa

    I have to say that this computer has gotten progressively worse since I first posted. No more popups or Rogue AV, but all kinds of other problems. I can no longer run Malwarebytes. Superantispyware bogs down in the middle. Very very slow booting up, several blue screens...I've tried some of the online scans, some go thru, others, like Panda and Kaspersky, stop in the middle of downloads...etc., etc. Tried to run chkdsk from Norton disk, and it stops every time, on section 4.

    Well, just wanted you to know that it's gotten a bit grimmer. I wasn't sure if I was supposed to keep trying different scans, or what...

    Standing by here, sure appreciate your help: you'all have bailed me out before when it seemed hopeless
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's try other online scanners then, and if that doesn't work I'll have you zip it and I'll examine the file.

    1. Try any of the below online scanners for the file you couldn't scan at jotti.


    Virus.org

    Kaspersky

    Virus Chief



    2. Avira AntiVir Personal - Free Antivirus is the anti virus that is installed and being used now, so we have some remnants of Symantec to kill off which could be the cause of some instability. I see nothing actually installed now from symantec, but there are items that remain from an incomplete uninstallation.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    Symantec Lic NetConnect service 
    
    File::
    c:\program files\Common Files\Symantec Shared
    c:\documents and settings\All Users\Application Data\Symantec
    
    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    3. Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log.

    4. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    5. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now! :)
     
  6. duckfeet

    duckfeet Corporal

    1) I think that first file has disappeared, or I caught it in one of the earlier scans that I thought wouldn't finish...in any case, I tried to find it for the online scanners, and searched for it myself, and couldn't see it.

    2) First time I dragged CFscript.txt to ComboFix it started and then the same blue screen came up...I started laptop back up, and the second time I dragged CFscript.txt over it, it went all the way thru, then on the reboot, it started chkdsk, saying "the volume is dirty," but it finally finished, so CF did complete, I will include this.

    3) The SAS online scan started fine, and then stopped in the middle saying it had an error, and stopped, the same as the SuperAntispyware I had tried to run from this laptop. So that scan failed.

    4) MGlogs.zip included.

    Honestly, it's still seems like something is very wrong...what w/the constant blue screens, also the stopping of programs with errors, particularly Avira, SAS, and Malwarebytes...

    Thankyou again for your time and patience...
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing any malware in the logs. Hmmm Let's do this:

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    
    KILLALL::
    
    RegLock::
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
    @Denied: (Full) (Everyone)
    "scansk"=hex(0):be,f9,5b,dd,c5,38,b6,eb,80,91,9a,96,dd,2f,04,8d,b0,7f,a7,41,2d,
       80,8b,89,6e,5e,e5,2f,61,e8,c5,af,2b,9a,aa,56,6a,18,d5,86,00,00,00,00,00,00,\
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ac812391-b2fe-444f-b790-e803f85a3d69}]
    @Denied: (Full) (Everyone)
    "Model"=dword:000000ec
    "Therad"=dword:0000001e
    "MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
       38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Next... (and hopefully it will allow us to)

    Scan your computer with the ESET FREE Online Virus Scan

    • Click the ESET Online Scanner button.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
    • Double click on the esetsmartinstaller_enu.exe icon on your desktop.
    • Place a check mark next to YES, I accept the Terms of Use.
    • Click the Start button.
    • Accept any security warnings from your browser.
    • Leave the check mark next to Remove found threats and place a check next to Scan archives.
    • Click the Start button.
    • ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click List of found threats.
    • Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.
    • Click the <<Back button then click Finish.
    In your next reply please include the ESET Online Scan Log and the log from running combofix
     
  8. duckfeet

    duckfeet Corporal

    Hi Kestrel:

    Not much good news here, I'm afraid. Keeps giving me problems, ever since this thing got all the malware, just hasn't worked right.

    1) After moving CFscript to Combofix, it updated and began scan, somewhere in the scan, it quit and brought up blue screen, w/ Bad_Pool_Header. I will try again, but wanted you to know this...I looked in "C:" drive and it does appear to have left a log, which I'll include.

    2) I went to ESET online scan, and it tried, but at the endo of getting updates, it failed, and said: "Cannot get update, is proxy configured?"

    Now, when I try to boot up Chrome Browser, it also says "Enabling Proxy..." But I have no proxy setup, so I don't know what that is about.

    Also, constant errors with Avira, giving me MS messages like "AVG.nt cannot be started. Exception in module Avgnt.exe..." and various other errors and problems.

    It is very slow to boot--and I had added ram during all this, but it didn't seem to help much.

    Very slow to boot up, but it will boot, and browsers do work...Thank you so much for your hellp
     

    Attached Files:

  9. duckfeet

    duckfeet Corporal

    I tried the CFscript thing again, and again it failed, but this time during CF update, and brought up *this* interesting error message: "the contents of the ComboFix package have been compromised...please download a fresh copy from BleepingComputer... NOTE: You may be infected with a file patching virus 'Virut.'"

    Well, I guess I'll try and download CF again and try this again...don't know if any of this helps or not...I do thankyou for the help...
     
  10. duckfeet

    duckfeet Corporal

    Well, redownload worked, but lots of error msgs, little windows would pop up saying things like "application corrupt," and also browser keeps shutting down...but combofix went all the way thru, here is log...
     

    Attached Files:

    • log.txt
      File size:
      10.2 KB
      Views:
      5
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It does not look to us like this computer is infected with Virut. In fact I am not seeing anything much in the logs. I feel like you should uninstall Avira since you are having so many issues with it and do a clean installation of it afterwards, but let me confer with Chaslang before we do anything. Thanks for your patience. I appreciate it. :)
     
  12. duckfeet

    duckfeet Corporal

    I'd already tried that once, and it still doesn't work correctly. Very very slow booting up, malwarebytes won't run at all, even after fresh download, now same with superantispyware, and chkdsk won't complete either.

    I do appreciate the time and trouble you are taking with this. Seems so weird, since it all began w/the malware, and there was so much malware on it, that I just sort of presumed, that, like other times, on other computers, it would start working better once malware was removed.

    However it pans out, thankyou for your help!
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Right, I've spoken to Chaslang who has given us something to do next:

    1. Please ensure that you now download a fresh copy of combofix and make sure that it is directly on the desktop where we need it to be run from.

    2. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    Driver::
    ffg0f4a
    25cf2bb7.sys
    
    File::
    C:\WINDOWS\system32\drivers\ffg0f4a.sys 
    C:\WINDOWS\system32\drivers\25cf2bb7.sys
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    3.
    • Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter ( the quotes are required).
    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive called "TDSSKiller.txt" please attach this log to your next reply.

    4. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix. and also the log from TDSSKiller

    5. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  14. duckfeet

    duckfeet Corporal

    Good morning! Went to sleep worrying about this, and woke up the same. So glad you haven't given up on me yet, as this thing seem so cursed. But anyway, I did what you suggested. Even tho I had Avira turned off, it kept wanting to "interfere," but I know you wanted me to just follow instructions, so I kept at it:

    1)ComboFix: while running, first error msg, before it even began to run thru, was an "application corrupt" window, which I ignored. Next error msg, before rebooting--which I've seen before--was "PEV.cfxxe has encountered a problem and has to close. Finally, after rebooting, Avira kept popping back up, saying it was encountering malware...and I just kept closing the Avira windows, and let CF continue. Log included.

    2) While running TDSSK, came up with "Freeware implementation of Reg.exe encountered a problem and has to close. Log included.

    3)MGtools mentioned several files it couldn't access and stuff, while running, but I ignored it. Log included.

    Didn't know if you wanted me to re-install Avira or not. I will upload this first, since I'm worried I might loose these logs if I start checking computer to see if runs better, then I'll edit post, let you know how it's running...

    Again, I thank you and Chaslang both. Really appreciate this...
     

    Attached Files:

  15. duckfeet

    duckfeet Corporal

    (Sigh) Still same stuff, Kestrel: Tried running Malwarebytes, came up with error code 703...before that it was error code 722. Avira keeps giving *it's* error message, so I uninstalled it completely, but now I have trouble downloading new version, as it balks or goes to same old blue screen "PFN_List_Corrupt. Also tried running ESET online scan, as you'd suggested in earlier post, and same thing happens: it gets all the way to the end of updates, then at 99% of "Downloading Virus Signature Database," it stops, saying "Cannot get update, is proxy configured?"

    No proxy that I know of. Sorry this is turning into such a pain...I am grateful you've tried so hard...let me know what else I could do, or if it's time to throw in the towel, or whatever you think. I'm willing if you are, to try whatever you think...

    I'll stand by on any more attempts to download Avira: I do have Microsoft Security Essentials set up, downloaded, and I"ll run that if you think I should...

    Thankyou so much...
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    One of us will get back to you ASAP but I'd rather I had Chaslang's final word on the matter, thanks for your patience duckfeet :)
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Duckfeet we are not seeing any malware in the logs. I can only suggest that regarding the BSOD's and Avira and any other issues with the machine that you post in the software forum :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  18. duckfeet

    duckfeet Corporal

    I'll see what my friend wants to do: probably reformat, but in any case, I do thank you for your help!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds