"System Check" Trojan Lingering Problems--Logs attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Disco Albino, Jan 23, 2012.

  1. Disco Albino

    Disco Albino Private E-2

    Hello--A few days ago, I got the "system check" trojan from a suspicious website--it produced a bunch of fake error messages, hid all my folders and desktop icons, and hijacked my search results.

    I have gone through the recommended cleaning procedure in the stickied thread. Combofix detected and deleted files associated with "system check".

    There are still some lingering issues, and I don't know if they are remaining malware, or just screwed up settings from the virus.

    First, since I got the virus, my desktop background has been blank (black), and still is that way.

    All my launch icons are gone. There is no little "pop-up" program menu on the top, like there is supposed to be (running Windows 7).

    Most importantly, when I click on C:\Documents and Settings, it gives an error message titled "Location is not available", saying "C:\Documents and Settings is not accessible. Access is denied". When I go into Properties and try to edit permission settings, it says "You do not have permission to view or edit this object's permission settings.". C:\System Recovery gives the same messages, and a few other folders have the little red "access denied" icon on the folder, although I can view the contents on those.

    I am running as an Administrator, and have the only user account on the computer. So I have no idea how I can get permission to access my own Documents and Settings now, since I'm the only Admin.

    I've posted all my logs. Thank you so much for your help!!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you run any temp cleaning software such as CCLeaner? If not:

    Please download and save the below tool from Grinler @ bleepingcomputer to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Now see if you can find the items that seemed to be missing?
     
  3. Disco Albino

    Disco Albino Private E-2

    Thanks. I did run CCleaner a few times. I just DL'd the program your recommended, so I'll see how that works.

    Have you had a chance to look over my logs? It would be much appreciated. I'm suspicious there still may be something in there. After posting the logs, I used a program called TDSSkiller, and it detected another high risk infection, which I of course removed with the program.

    Thanks again for the help!
     
  4. Disco Albino

    Disco Albino Private E-2

    The "unhide" program wasn't able to do anything that I can see.

    When I restart and log in, I get a message on my taskbar notifications that says a program is trying to change my search settings...I've never seen the icon that is giving me this message before.

    Edit:I uploaded my TDSSkiller and Rkill logs, hopefully someone has a chance to look over all the logs and let me know what they see
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You made a mistake by running temp cleaners. It removed the folders where your icons and program files had been moved to. Not much you can do other than re-install them.

    TDSSKiller found an issue. So please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip
     
  6. Disco Albino

    Disco Albino Private E-2

    Now when I try to run MGtools (either through MGtools.exe or getlogs.bat), it repeatedly says "access is denied" and doesn't create a log...
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please click Start, All Program, Accessories and you will see ( among other things ) a Command Prompt entry.

    • Right click the Command Prompt entry and select Run As Administrator.
      • It is critical that you run it this way.

    • If you do this properly, a command prompt window will open with a title of Administrator Command Prompt.
    • Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple/brown is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
     
  8. Disco Albino

    Disco Albino Private E-2

    Thanks again for taking the time to respond.

    I am running Admin Command Prompt. When I try GetRunKey.bat, it says "access is denied" because "this version of C:\MGtools\ltime.exe is not compatible with the version of windows you're running. Check your computer's system information to see whether you need a x86 or x64 version of the program, then contact the software publisher".

    EDIT:It also comes up with an error message in a separate window titled "unsupported 16-bit applications", saying "the program or feature '\??\C:\MGtools\ltime.exe' cannot start or run due to incompatibility with 64-bit versions of Windows"

    I am running Windows 7 64 bit BTW.

    Running ShowNew:
    "C:\MGtools\shownew
    C:\MGtools\newfiles.txt
    Access is denied.
    C:\MGtools\ffdata.txt
    Access is denied

    Running scan with ShowNew.bat

    Access is denied.
    Access is denied.
    Access is denied.
    Access is denied...."
    And so forth.

    This is pretty annoying, still can't access C:\Documents and Settings. I just want access to everything and to make sure my computer is clean of Malware, beyond that I can redo all the stuff I lost. I had my firewall off when I ran MGtools btw.

    Thanks again
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please click Start, All Program, Accessories and you will see ( among other things ) a Command Prompt entry.


    • Right click the Command Prompt entry and select Run As Administrator.
      • It is critical that you run it this way.
    • If you do this properly, a command prompt window will open with a title of Administrator Command Prompt.
    • Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple/brown is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    SN64.bat<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    GRK64.bat<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
     
    Last edited by a moderator: Jan 26, 2012
  10. Disco Albino

    Disco Albino Private E-2

    for SN64.bat:
    "C:\MGtools>sn64.bat
    C:\MGtools\newfile.txt
    Access is denied.
    C:\MGtools\ffdata.txt
    Access is denied.

    Running scan with SN64.bat

    Access is denied.
    Access is denied.
    Access is denied..."
    Etc...

    For grk64.bat:

    "C:\MGtools>grk64.bat
    C:\MGtools\runkeys.txt
    Access is denied.

    Running scan with GRK64.bat
    Access is denied.

    64 bit Windows OS found
    Access is denied."

    This is frustrating...MGtools worked fine when I did it right after all the cleaning procedures-Superantispyware, malwarebytes, combofix (which found and deleted the 'systemcheck' files) etc.

    Would running the cleaning procedure again be of any use?

    Thanks again for helping me btw
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try downloading another version of MGTools:

    Now download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run the exe and see if you can't get a new MGLogs.zip.
     
  12. Disco Albino

    Disco Albino Private E-2

    Ugh...No dice, exact same error messages when I do the procedures you gave in admin command prompt. Should I delete or uninstall the MGtools files I have right now before I DL it again? I just clicked the link you gave me and saved over the files I had.

    Sorry this is such a PITA, I really appreciate your help with this.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  14. Disco Albino

    Disco Albino Private E-2

    Here they are. Thanks
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click OTL.exe to start the program.

    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code

    Code:
    :processes
    :otl
    :files
    @Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:0B4227B4
    @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:DFC5A2B2
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.


    Tell me what malware issues you are still having, if any.
     
  16. Disco Albino

    Disco Albino Private E-2

    Hope this is the right file for the log.



    The only lingering problem I can see is that when I click C:\Documents and Settings, I get a error message titled "Location is not available", with the message reading "C:\Documents and Settings is not accessible. Access is denied."

    I get the same message for C:\System Recovery.

    I get the same little padlock icon on the C:\MSO cache, and the little lock icon next to folders in C:\System Volume Information, specifically the "SPP", "System Restore" and "Windows Backup" have the little lock icon on the folders.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Those are issues you need to address in the software forum. Otherwise, it looks like your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds