RootKits galore

Discussion in 'Malware Help (A Specialist Will Reply)' started by Pete22, Dec 3, 2010.

  1. Pete22

    Pete22 Private First Class

    Hello,

    Unknown scripts running slowing down computer. I say to stop the script, but in a few minutes I get the same message again.

    Browsers freezing

    Having a hard time shutting down.

    Last night I ran malwarebytes and it found and deleted:
    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe (Security.Hik) -> Quarantined and deleted successfully.


    today avg said I had 3 copies of trojan horse Generic19.RPZ It was only able to quarentine one of the three.

    Then I noticed that that my browser has been Hijacked by Yahoo.

    So I started the read and run instructions

    ran SAS

    ran MB

    then uninstalled avg 2011

    - a good thing. Also found rements of avg 9 and avg 10 too.

    combo fix stalls after backing up the registry. tried 4 time , last time waited about an hour.

    rootrepeal ran finding lots off stuff untill it got to c:\Windows\winsxs\Manifests then it closed without finishing after a hour.

    I ran it again until it stalled. This time I took pictures (3) to show all the bad files before it closed, also at about an hour.

    Ran MGtools.

    last rr file and MGlog on next message

    Thanks for checking this out.

    Pete22
     

    Attached Files:

  2. Pete22

    Pete22 Private First Class

    The rest of the files.

    Hope I've given you enough to work with.


    Pete22
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any rootkit activity. You have a lot of leftovers from AVG, so I suggest you run their removal tool.

    Please go here and download and run the AVG Removal Tool.

    In the meantime, Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now tell me what malware issues you may still be having, if any.
     
  4. Pete22

    Pete22 Private First Class

    Hello Tim,

    Downloaded Avg remover and ran it. and

    Also downloaded AVG Identity Protection Remover and ran it.

    Ran C:\MGtools\analyse.exe


    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    done

    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    Not there

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    done

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    done

    O20 - Winlogon Notify: !SASWinLogon - Invalid registry found
    done


    ran Regedit
    It was successful.

    installed comodo antivirus instead of avg. It ran its first scan.

    It gave me these results.

    UnclassifiedMalware@24748696 C:\Users\Margery\Documents\Margery's stuff\desktop\ComboFix.exe
    Joke.Stressreducer@6032153 C:\Users\Margery\Documents\Margery's stuff\My Documents\My Downloads\Stress reliver game\stress reducers.exe
    Joke.Stressreducer@6032153 C:\Users\Margery\Documents\Margery's stuff\My Documents\My Downloads\Stress reliver game\weapon_closet.zip|stress reducers.exe
    Heur.Suspicious@22281151 C:\Users\Margery\Documents\Margery's stuff\My Documents\repair programs\Diagnose and repair\BZ\Malware\ComboFix.exe
    Heur.Suspicious@23829438 C:\Users\Margery\Documents\Margery's stuff\My Documents\repair programs\programs for getting rid of malware\ComboFix.exe
    Heur.Suspicious@22281151 C:\Users\Margery\Documents\Margery's stuff\My Documents\Utilities\Diagnose and repair\BZ\Malware\ComboFix.exe
    Win32.PSWTool.NetPass.~BAAD@2910135 C:\Users\Margery\Documents\Margery's stuff\My Documents\Utilities\Password retrieval\iepv\iepv.zip|iepv.exe
    ApplicUnsaf.Win32.PSWTool.PassView.A@48021562 C:\Users\Margery\Documents\Margery's stuff\My Documents\Utilities\Password retrieval\protected storage passwords\pspv.zip|pspv.exe
    Heur.Corrupt.PE@-1 C:\Users\Marie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U55E2V0N\avg_remover_stf_x86_2011_1165[1].exe
    Joke.Stressreducer@6032153 C:\Users\Marie\Documents\My Downloads\Stress reliver game\stress reducers.exe
    Joke.Stressreducer@6032153 C:\Users\Marie\Documents\My Downloads\Stress reliver game\weapon_closet.zip|stress reducers.exe
    Heur.Suspicious@23354895 C:\Users\Marie\Documents\stuff from desktop\EasyLink_Connect.exe
    Win32.PSWTool.NetPass.~BAAD@2910135 C:\Users\Marie\Documents\Utilities\Password retrieval\iepv\iepv.zip|iepv.exe
    ApplicUnsaf.Win32.PSWTool.PassView.A@48021562 C:\Users\Marie\Documents\Utilities\Password retrieval\protected storage passwords\pspv.zip|pspv.exe

    I think some of these are false positives. I have not told comodo what to do with them yet.

    Computer acting better. Browser is no longer hijacked. So far I have not had a slow script notice, nor crashes. Have not worked on it long though.


    What else would you like me to do?


    Thanks for your time,

    Pete22
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  6. Pete22

    Pete22 Private First Class

    Hello Tim,


    This morning I thought the computer was freezing several times. Later I heard the sound of device delete or add. So I wonder if the drivers are being messed with. The freezing could be true or it could be the mouse driver stopping or both.

    Comodo anti virus did several alerts this morning and I deleted those files.


    Still seems to shut down slowly.




    Thanks for checking my files,


    Pete22


    Edit: yes it is also freezing without the device sound.
     

    Attached Files:

    Last edited: Dec 5, 2010
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. This latest MGLogs. is incomplete. Did you stop it before it was finished?

    You need to run CCLeaner and then make sure this folder is cleaned out:
    C:\Users\Marie\AppData\Local\Temp\

    I suggest you post in the software forum for your remaining issues, as freezing could be caused by any number of reasons.

    Just to be sure, let's have you do one other thing:

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it.
    • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message
     
  8. Pete22

    Pete22 Private First Class

    Hello Tim,

    Glad to hear My logs are clean.

    I ran ccleaner and then cleaned out
    C:\Users\Marie\AppData\Local\Temp\
    C:\Users\Margery\AppData\Local\Temp\


    I ran the TDSSKiller.exe and it did not find anything.


    I did let that MGgetlog program run completely and got the message that it was done and to press any key to close the window or something like that. However, it took about 5 minutes after I started it before it did anything. I thought that was strange.


    I decided to run the MGgetlogs again just to see if it would do a complete scan. This time it started much quicker. It ran most of the way, but before it was done, suddenly the window closed without warning or message. Any ideas?


    Pete22
     
    Last edited: Dec 5, 2010
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try deleting the old version. Then download MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run the exe.
     
  10. Pete22

    Pete22 Private First Class

    I deleted the old MGtools.

    I downloaded the new file to my desktop because I could not download it to c:\ am using Vista.

    I had trouble running it and had to download it 3 times before it would run. I have included the logs. Did it run the complete program?

    Thanks for checking,

    Pete22.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, it ran to completion this time. I am not seeing any malware remaining in your logs. We can still remove some leftover junk:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Then use windows explorer to find and delete:
    C:\Users\Marie\AppData\Roaming\AVG10

    Now tell me what issues you are still having, if any.
     
    Last edited: Dec 7, 2010
  12. Pete22

    Pete22 Private First Class

    Hello Tim,

    Glad the program completely ran.

    Please check the instructions you sent me. For some reason they are mangled.

    I'll wait for your new and improved instructions. :)


    Pete22
     
  13. Pete22

    Pete22 Private First Class

    Hi Tim,

    Never mind, I figured it out.

    I did as you suggested. I was sucessful with the fixme.

    I removed the file
    C:\Users\Marie\AppData\Roaming\AVG10
    also
    C:\Users\Margery\AppData\Roaming\AVG10

    Also any files other files that I could find relating to avg.

    Bought a new mouse... that helped the driver issues.

    Still having issues with browsers refusing to close.


    Pete22.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Holy crap!! I wonder how all that happened!!! Let me try to straighten it back out. I have never seen a post get so screwy. I will re-edit it. Just let me know if you are still having any malware issues.
     
  15. Pete22

    Pete22 Private First Class

    Tim,



    Thanks for fixing your info. It really was crazy.


    My browser is hijacked again with the Yahoo search. Also get the message about the the slow script again too.

    Pete22
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  17. Pete22

    Pete22 Private First Class

    Hello Tim,

    I forgot to mention ads that used to be blocked by my browser are no longer blocked.


    To run MGtools, I turned off uac and rebooted. When it restarted, windows explorer crashed. It also said that the shell could not be started or something like that. Not sure if it related.


    Thank you again for your help.


    Pete22
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in those logs. Please re-run TDSSKiller and attach a new log. Then please let's have you do an online scan:

    eSet Online Scan.

    Do the redirects happen in all browsers? Does it happen in both user accounts?
     
  19. Pete22

    Pete22 Private First Class

    Hello Tim,

    I ran tdss, it did not find anything.

    I ran eset scan and it found some stuff.

    When I finished, comodo antivirus started a scheduled scan and it found some stuff too. So I added the text file.


    It does not appear that anything is hijacked at the moment. However, I have not had much time to check it out. I will keep testing it while I am wait for your reply.


    Pete22
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Give it a while to make sure you are not having anymore issues, then:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds