System Fix, iExplore, Combofix problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by DrRobin, Dec 6, 2011.

  1. DrRobin

    DrRobin Private E-2

    Hi,

    I have managed to get System Fix on my PC. I run Avira and saw a couple of virus warnings,the next thing is it had System Fix, apart from Outlook running I wasn't doing anything and I had previously removed any junk emails using a pop checker. I ran iExplore.exe from Bleeping Computer and I already had Malware Bytes installed.

    After several tries iExplore and MBAM removed all of the viruses they could find, but I still had a problem with browser re-direct.

    I downloaded unhide and ran this as well, which restored my icons and menus.

    I downloaded TDSSKiller, but this fails to run. I then saw some notes about Combofix and how this can detect rootkit virus so downloaded it and ran it.

    The first time it went through it mentioned that MS System Revory wasn't installed so I installed that and then it displayed two dialog boxes one said

    Combofix - ZeroAccess
    You are infected with Rootkit.ZeroAccess! It has inserted itself into the tcp/ip stack. This is a particularly difficult infection.


    It then ran some more and another dialog pop up

    ROOTKIT

    Rootkit is detected

    Be patient as this may take some moments.


    The program continued to run and then after some time the hard disk access stopped and finally the PC just locked up, first no keys would work, but the mouse would, then the mouse stopped working, probably after about 40 mins from first starting Combofix.

    I ran it a couple of more times, but didn't see the error messages and about 10 minutes after the hard disk stops it crashes. I see Combofix unpack and then a command window opens saying

    ------------------------------------------------------
    Please wait.
    Combofix is preparing to run.

    Attempting to creat a new System Restore Point
    ------------------------------------------------------

    And then another window pops up with progress bars saying it is backing up the registry.

    Then the command window clears and displays
    ------------------------------------------------------
    Scanning for infected files...
    This typically doesn't take more than 10 minutes
    However, scan times for badly infected machines may easily double
    ------------------------------------------------------

    The hard disk lights for around 20 minutes and it is after this the PC freezes.

    I just thought I have mapped network drives, perhaps Combofix is trying to scan those and failing? I have also turned Avira off, but Combofix still comes up with the warning, perhaps I should un-install?


    I think it still has the same virus. All of these tests were mostly run in Normal mode but with no Internet connection. Should I have run these in Safe Mode?

    I had tried a System Restore after getting rid of System Fix, but this either didn't run in the first place or when the PC re-booted, System Restore said nothing had changed and the restore had failed.

    Any suggestions would be gratefully received.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Now please we will try using two tools designed especially for this kind of infection.

    • Download AntiZeroAccess to Desktop
    • Also download and save this >> ESETSirefefRemover to your Desktop
    • Now double click on AntiZeroAccess to run it (If running Vista or Windows 7, right click on it and select "Run as an Administrator")
      • Type y and press enter to run the scan
      • Please attach the AntiZeroAccess_Log.txt log to your next message. This file is saved in the same location as AntiZeroAccess program.

    • Now run the Win32/Sirefef tool while in Normal Mode and follow the prompts as directed

    Now download and run MGtools ( from the READ & RUN ME ) and run it as per the below instructions and attach the MGlogs.zip file that is requested.

    Using MGtools
     
  3. DrRobin

    DrRobin Private E-2

    Hi,

    Thanks for the suggestions.


    I decided to run another scan, my PC rebooted, but then complained it was missing Hal.dll. After booting from an NTFS cd I couldn't get any further so had to put the Windows CD in and perform a restore.

    It did this and now the PC boots but it says the Registry is corrupt. The registry folder has entries but they are all .SAV

    When I ran Combofix it made a back up of the registry but I don't know where it put it or how to restore. Any suggestions would be welcome as I can't proceed with your suggestions until I can get it booting back into Windows.

    Robin
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please post in the software forum for additional assistance. Once you are back up and running, return to this thread. ;)
     
  5. DrRobin

    DrRobin Private E-2

    Hi,

    I have my machine back on, a combination of an NTFS boot disk and a repair install.

    I still have the browser redirect, antizero says it's all clear, ESETSirefef runs but doesn't find anything.

    MGTools doesn't run, it complains of 'find' not been available.

    IExplore.exe now doesn't run correctly, it gets so far through and crashes.

    Combofix also doesn't run, it complains about been run in compatibility mode, which is not set.

    I also can't start Task Manager, there are at last two DLLs missing, I can probably put these in from another XP PC.

    Any suggestions would be gratefully received?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    See if you can do the following:

    Go to the below link and follow the instructions for running TDSSKiller from Kaspersky

    Be sure to attach your log from TDSSKiller

    Please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  7. DrRobin

    DrRobin Private E-2

    Hi Tim,

    Thanks for your help. I couldn't run TDSSKiller when booting from the C drive, it just didn't do anything.

    I did run MBRCheck and it found an MBR virus, non standard hash key. I have saved the log file and as soon as my PC has finished restoring my virus scanner I will post it.

    I did have an idea, I have an NTFS boot/utility disk, it boots the PC from the CDROM and gives a limited set of tools. TDSSKiller ran under this and it found a rootkit virus, which it removed. I didn't make a note of which one but when I rebooted and reran TDSSKiller, it said everything was okay. I also reran MBRCheck and it didn't find anything. Combo fix wouldn't run under this and neither did MBRCheck but TDSSKiller seems to have done the trick.


    I still can't run Combo fix, it complains about Compatibility mode, but non of the other scanners seem to find anything. Does this mean I have now got rid of all of the problems or should I be able to run Combo fix and get a log file?
    My browser now doesn't redirect on a Google search and all of the excess hard disk activity seems to have stopped.

    Regards

    Robin
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It sounds as though you may have cracked it. I would still like to see the log from running MBRCheck and if you could, a log from running MGtools --> C:\MGLogs.zip.
     
  9. DrRobin

    DrRobin Private E-2

    Hi Tim,

    I am not sure if it is cracked or not. I can't get MGtools to run and unfortunately the window closes before I can see anything.

    Combo fix doesn't run, it complains of been in 'Compatibility Mode'.

    IExplore.exe (RKill) doesn't run correctly either, it seems to either complain about not been able to access something or just closes.

    I am also trying to re-install my Virus Scanner (Antivir), but it unpacks everything and then crashes whilst it runs a soft compatibility test.

    Not sure if you can recommend a good virus scanner/firewall?

    Anyway, I have managed to get my MBR file off the machine and attached.

    Regards

    Robin
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your MBRCheck log was garbage. But you stated that when you ran it, it didn't find any problems with your MBR. And that other scans were coming up clean. I can only assume that you are having system issues and you may need to pursue this in the software forum.

    What OS are you using?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds