Rootkit, Rogue.Pal.spyware, HijackStartme

Discussion in 'Malware Help (A Specialist Will Reply)' started by duckfeet, Jul 25, 2010.

  1. duckfeet

    duckfeet Corporal

    This has been a mess. When I try to open applications, whether I doubleclick or hit 'open' it still opens up a "/Windows cannot openthis file...needs to know what program created it..." so I've tried all kinds of things to run scans: safe mode didn't work, but by renaming them with the extension '.com' most of them worked, more or less, but everything is bogged down and running slow, and whenever it reboots, it gets worse. It took forever just to get into msconfig, as going to 'Run' and hitting run, it too brought up the dialog, but I finally got it to go....

    I had to run combofix from a disk, but I drug it onto desktop and can run it again if needed...Combofix did need to reboot, saying it found 'rootkit activity' I managed to get MGTools to work...I could *not* get RootRepeal to run. I did get it downloaded and unzipped, and of course the Windows dialog box kept saying it couldn't open it, so I changed it from .exe to .com, and it would start to run, then get bogged down in "Files Initializing, please wait" and then go on to tell me I was 'low on virtual memory' and I'd wait...and wait...and wait...,

    So I'll keep trying to run RootRepeal the rest of the night, but I guess I better go ahead and post this miserable stuff in case you have any ideas or think I should try another rootkit scan...as always, thankyou...I have friends who bring me their tired worthless old computers with all their grandkids' pictures when they are lousy with malware, but you guys usually manage to find a way...this time it looks hopeless..

    I removed one of the two AV programs, set the files the way I'm supposed to, uninstalled ask.com and some other junk...ran ccleaner...pretty much finally got everything to go except RootRepeal...
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Part of your problem is that you need to, at least, double your RAM:
    Code:
    Total Physical Memory    512.00 MB    
    Available Physical Memory    188.93 MB
    Please put ComboFix directly on your desktop, not here:
    Running from: J:\combofix.com

    Do you know what these are:
    c:\windows\is-7MDG5.exe
    c:\windows\is-7MDG5.lst
    c:\windows\is-7mdg5.msg
    If you don't, leave them in the below fix. If you do and they are OK, remove them from the fix.

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 5

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. duckfeet

    duckfeet Corporal

    HijackThis worked good, got success message on Regedit...Avenger rebooted, but then when desktop started to come up, the same nasty Windows pop-up saying "Windows cannot open this file..." etc. Desktop finally booted, and I was able to find the Avenger text file, and run the MGLogs bat file....things were running better, but same thing happens, where when I reboot, I can open no application, because of the windows file extension thing...unless I change them to ".com", sometimes that works...I also had done a search before on here, and found the webpage that showed me how to get around that by downloading 'rkill.com and rkill.scr' and stuff...but it's just temporary, and files go back to being all screwy after reboot...

    Anyway, it seems to be getting better, and I'm including the two logs you asked for, and hope there is some way to fix this...thankyou so much for help, as always...

    EDIT: Whoops, had forgotten to uninstall J2SE--just did that and rebooted...popup still happens... :-(
     

    Attached Files:

    Last edited: Jul 25, 2010
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    My bad. First, let's see if we can get your .exe files to work. Go to this site and scroll down to the ninth file fix:
    http://www.dougknox.com/xp/file_assoc.htm

    Tell me exactly what the message is on start up.

    Now let's fix my fix....

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip
     
  5. duckfeet

    duckfeet Corporal

    Got 9th tool down (xp exe) file unzipped and merged w/registry succesfully, then ran Avenger o.k., then rebooted...only message was "Windows cannot open this file
    file: cleanup.exe" and then went on with the usual options, selced a program or use web service...same thing happens when I click on the Windows Security Alerts, in Startup area, except it brings up: Windows Cannot open this file...file: rundll32.exe...

    So still no 'exe' fix working apparently...

    Enclosed are logs u requested...
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    AAARRGGHHH!!

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    I think you will need to post in the software forum for your other issues, but lets do the above and see where we are.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip
     
  7. duckfeet

    duckfeet Corporal

    Here you go, Tim...
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok. At this point I am not seeing any malware in your logs. Your other issues should be pursued in the software forum.

    You can try going to start / run / type:
    sfc /scannow and have your OS disc handy.

    Since you are not having any malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  9. duckfeet

    duckfeet Corporal

    Cleaned up, and I'll try scannow and do some searches, post in software on the 'exe' thing...thankyou for all your help!
     
  10. duckfeet

    duckfeet Corporal

    Scannow did the trick! Seems to be working fine now Tim...once again: thankyou all so much for what you do!
     
  11. duckfeet

    duckfeet Corporal

    Ahhh...*Bad* news...everything kept running slower and slower, and just obviously some problem...then since it was time, I went ahead and ran the MS Security Essentials Scan...which took forever...and found three more bad malware...unfortunately, for the life of me I can't figure away to get a text log out of this AV, so I had to do a screen shot of what it removed: Program: Win32/RegCure and Trojan.Win32/Rundis.gen...and it deleted them...doesn't seem to be log...screenshot shows them tho...

    I won't do anything else until I hear from you...glad to start over or whatever you think....
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only one I see in that screen shot that I can make out is exeHelper.com. It is not malware. If you wish to run both SAS and MBAM again, I will be happy to check those logs.
     
  13. duckfeet

    duckfeet Corporal

    I'll try to upload the MSE jpeg fileagain, since it looked legit trojan, plus I got mbam w/some new stuff, an SAS log and I went ahead and looked at the alternative scans you'all recommended, and I went ahead and ran the Kasperksi scan, since it had caught a trojan before. I know some of them are just false catches, and some are MGTools that are still on here...but some sure look like bonafide malware...Kasperski took forever, but they were bad what it caught...plus at least on it I could get a normal log...

    Thanks for all your help, Tim...I didn't want this to keep going on either, but it just kept running worse and worse, so hopefully you can discover something in here...I'll be standing by
     

    Attached Files:

  14. duckfeet

    duckfeet Corporal

    I had run a spybot S&D yesterday, and they also found malware...I don't know if you want or need this report, but since they found zlob and some other stuff, I'll send it...
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The screen shot does me no good since different scanners have different names for malware. I would need to know the path to the file that it is reporting as bad.

    Download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Then run the .exe file.
     
  16. duckfeet

    duckfeet Corporal

    Here you are! :)
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer to find and delete:
    C:\WINDOWS\system32\drivers\utexmtm2.sys

    Reboot and tell me what issues you are having.
     
  18. duckfeet

    duckfeet Corporal

    Removed file...rebooted...very slow at first, but I attribute that as you indicated, to only 1/2 gb of ram...

    Right now working good, actually, I'm just gunshy, but it seems o.k....do you think maybe we got it? If so, I appreciate your patience with this...does seem to be working good now...
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes to the RAM. Adding more would be very helpful for your system. But the main thing to do is to follow the suggestions in the How to Protect yourself thread and keep all your AV and AS software updated.

    I usually only run my AS software when I suspect trouble, but then I don't do a lot of surfing past MG"s, so you would need to figure out how often you might need to run it, such as weekly or bi-weekly.

    And you are very welcome.





    Support MajorGeeks!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds