Still have malware problems after the readme

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by crazybutable, Sep 27, 2011.

  1. crazybutable

    crazybutable Private E-2

    I have some questions at the end of this post, but here is my story.

    On Friday my computer (Windows XP) started making a series of beeps, then suddenly a popup from Microsoft Security Essentials showed up saying "MSE is not running because the service is stopped [etc.]" Trying to start the service gave me a "Access denied" error and a hex code. Could not run windows update, it said the website did not exist. Nothing in the hosts file to redirect traffic. My computer locked up and I reset it.

    I booted into safe mode and downloaded microsoft's standalone scanner (Microsoft Support Emergency Response Tool). A full scan found a trojan and a trojan dropper (sorry I didn't write down which one.)

    After reboot, MSE seemed to start okay, but as I was getting ready to run Windows Update it got that error again. Windows update still didn't run. I did a bing search (I was still in IE) to try to find this page and got redirected to a page full of ads.

    A google search on firefox got me here. I started reading the read me and kept getting OUTLOOK.EXE errors and the computer would stop responding. I needed to get some work done on Saturday so I disconnected all four drives in my computer, picked up a brand new hard drive, and installed linux on it.

    On Sunday I disconnected the linux drive and re-connected my windows boot drive (but not the others) to get a file off it. I completely forgot that I had those other three drives disconnected.

    Later that day I started working my way through the readme. I uninstalled java entirely from my computer, I checked all of the add remove programs entries, and made sure that I didn't have any disk emulation software installed. I then downloaded all of the tools. This took a very long time because the computer would freeze up and I had to hard reset it with the reset button. During this time, opening task manager would cause the computer to lock up.

    1. SuperANTISpyware: I got it installed and running okay. Performed the first full scan and it crashed (as in, suddenly the program was just gone) as it was scanning processes. Then the computer froze up again. On restart, I could not start the program, and had to use the alternate start. Did a second scan, trying a quick scan instead, and got the same result.

    2. I installed Malwarebytes, but immediately when I tried to run it it said that I didn't have permission to run that program. I checked the permissions, and Everyone had full control, but there was a "special permissions" line and the effective permissions were that everyone was denied access. So I created a special entry for my user account giving my user account full control and execute permissions on the process. Then I was able to get it to run. But it got just a few seconds into the scan and was forcibly terminated.

    3. I ran Combofix from the desktop. It tried to install the windows recovery console. The network was acting very flaky and the install failed. I continued, and ComboFix popped up a message saying that I had a rootkit: Rootkit.ZeroAccess, and that the rootkit was in my TCP/IP stack and was "particularly difficult" to remove. Then after some more thinking it popped up another Rootkit popup. Then I went to the store and when I came back 2 hours later the computer was hung. (It never displayed stage_1, stage_2, etc.)

    I reset the machine and ran it again. This time it booted much faster and was more responsive. Combofix was able to download and install the windows recovery console, and then it was able to complete the entire scan successfully.

    4. I rebooted and tried running root repeal but it stayed stuck in the initializing screen for several hours. I rebooted (after combofix I was able to reboot using the start menu instead of the reset switch) and tried again and it still did not work.

    5. I ran MGtools and it appeared to work fine.


    So, am I clean? I don't know how to read these log files to know for sure. Although my machine is more responsive I'm still experiencing some network flakiness.

    Also, what do I do with the 3 drives I forgot to connect to my machine? Should I reconnect them and run the Readme process from the top?

    Re: Logs: SAS left no log. Malwarebytes is back to being un-runnable because of permission problems. Root repealer never got far enough to generate a log.

    Thank you kindly for your help and time.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What do you mean by this?

    Your logs look good, but let's double check something:

    Go to the below link and follow the instructions for running TDSSKiller from Kaspersky

    Be sure to attach your log from TDSSKiller

    Please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  3. crazybutable

    crazybutable Private E-2

    I'm not sure how to describe the network flakiness. My network is usually reliable, works like a rock, if a bit slow. I have an ancient router in the mix and that will occasionally up and die, requiring a plug-unplug kind of thing. Ever since I got this virus my network has been acting... flaky. Losing connection with the outside world, downloads go super slow, then everything will be fine again, then suddenly I have no network connection.

    Another problem is that I still cannot connect to Windows Update using IE.

    Another symptom is that when I reboot, there is a pause, a long, long pause, far longer than what I'm accustomed to seeing, between the "welcome to windows" screen and the "choose an account" screen. About 20-30 seconds.

    Attached is my log of TDSKiller. When I tried to run the MBR scanner, it locked up my computer. I took a picture of the screen but I can't upload the picture right now so I'll type it out.

    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows XP Professional
    Windows Informaion: Service Pack 3 (build 2600)
    Logical Drives Mask: 0x0000000c

    \\.C: --> \\.\PhysicalDrive0 at offset 0x00000000'00007e00 (NTFS)

    Size Device Name MBR
    -------------------------------------------------------------------
    69 GB \\.\PhysicalDrive0 [cursor sat here]

    The cursor just sat there blinking. I let it go for 5-10 minutes before I hit printscreen to take a picture of it. Then when I clicked on the start menu the whole machine locked up.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me have you try one other things, just to be sure:


    • Please download a ZeroAccess Removal Tool (By Webroot)to your desktop.
    • Double click on it to run it (If running Vista or Windows 7, right click on it and select "Run as an Administrator")
    • Type y and press enter to run the scan .
    • Hit any key to exit once it has finished it's scan.
    • Attach the log which will be in the same location as you ran the tool from. (Should be desktop)
    And to try to fix your "flaky" network issues:
    Please download Winsock 1.2

    http://i1111.photobucket.com/albums/h479/MysticalMagpie/winsockXP.png

    Use it to try and fix the broken internet connection.
     
    Last edited: Sep 28, 2011
  5. crazybutable

    crazybutable Private E-2

    Here is my log file.

    I can now run windows update, and I haven't seen any network weirdness since I ran that program and rebooted. Thank you so much!

    My next question is, what do I do with the other three disks? I used to have them connected to my computer but right now they are not connected. Should I connect and scan them one at a time? Which program should I use to scan them?
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Connect each one at a time and run both SAS and MBAM on each. Then please run :

    Go to the below link and follow the instructions for running TDSSKiller from Kaspersky

    Be sure to attach your log from TDSSKiller

    Please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Attach both SAS and MBAM logs as well as the logs from TDSKiller and MBRCheck. Use three posts. One for each drive.
     
  7. crazybutable

    crazybutable Private E-2

    I am connecting each drive and doing a full scan (so it rescans the C Drive).

    Can I be doing anything else with my computer while these scans are going on? The MAB one takes forever.

    Also of note, I still can't get MBR check to run successfully. It crashes before it is finished. I tried booting off a linux recovery CD to peek at the MBR but I guess I don't really know what I'm looking for. fdisk says I have one windows NTFS partition, although it also says I have around 14k unallocated 512 byte sectors, which is odd because I remember using up all of the space on the disk when I formatted it.

    Anyway here are the results from drive E. Currently scanning drive L.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That drive looks good.
     
  9. crazybutable

    crazybutable Private E-2

    Drive L. Again, MBR check locks up when running it.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That drive seems fine also.
     
  11. crazybutable

    crazybutable Private E-2

    Here are the logs from Drive F.

    I just noticed that MBRcheck was leaving behind text files this whole time. I've been running it from the desktop and my desktop is rather... cluttered.

    I've included the MBRcheck file for the most recent run, I can upload the others.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks like that drive is clean as well. Are you having any malware issues?
     
  13. crazybutable

    crazybutable Private E-2

    No, it looks like I'm all clean. Thanks!
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0


    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds