Think I have malware and can't remove it

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sp8eu, Oct 4, 2011.

  1. sp8eu

    sp8eu Private E-2

    Hi,

    Last night I downloaded some shareware which clearly wasn't actually legit.

    On startig my machine this morning, at boot I got a SPTD.sys BSOD and the system rebooted.
    I went into safe mode and renamed the file and finally got into my machine.

    I thought all was fine and that this file was corrupt, however, during the day I have installed 2 legit bits of software and when i attemp to run them I get a message that starts "windows cannot access the specified device path or file...". Ok so, I think i have a problem.

    I downloaded malware bytes, installed and started to run this....2 seconds in and it shuts down for no reason. Attempt to run this again and I get "windows cannot access the specified device path or file..." again.

    Tried safe mode - no success. I have found that if i set my malwarebytes security setting for my user to be full access, but then when i run it again, i get the same issue (closes then reattempt to load it an the "windows cannot access.." message).

    Full system scan using AVG completes in 1 second - definately not right.

    Older apps seem to run fine though - games, windows.

    I've tried to kill off processes in the taskbar with no different to the malwarebytes issue.

    PLEASE HELP! It seems new S/W I install gets it's dir security settings changed, even in safe mode.

    i don't really want to wipe the drive and start again if i can help it.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. sp8eu

    sp8eu Private E-2

    Thanks TimW.

    Done as much as I can, started to scan using super anti syware once installed and as Malarebytes did, it closed after about 5 seconds then trying to reopen get the same error ("windows cannot access the specified device path or file...". )
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you run ComboFix or MGTools?
     
  5. sp8eu

    sp8eu Private E-2

    MGtools has created a zip.

    combfix I believe is currently installed windows recovery console...it just came back saying "you are infected with Rootkit.ZeroAccess". It's done something and now says it needs to reboot....hopefully will be back after this *fingers crossed*
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download and run Win32kDiag per the below instructions:

    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log

    C:\win32kdiag.exe -f -r



    Now download Junction,zip to your Windows folder

    • Please download Junction.zip and save it to your Windows folder (i.e, C:\Windows\Junction.zip This assumes C:\ is your Windows boot drive.)
    • Now unzip it and put junction.exeinto the Windows folder (i.e., C:\Windows\junction.exe)
    • Do not try to run it right now. We will run something that uses it later.

    Now we need to reset the permissions altered by the malware on some files.

    • Download and save inhertit.exe to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!

    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.

    And one more scanning tool I want to use to collect more information is OTL per the below.

    Please download OTL by Old Timer to your desktop.
    See the download links under this icon: http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif

    1. Double-click OTL.exe to run (Vista and Win7 right click and select Run as Administrator)
    2. When OTL opens, change the Output (at the top-right portion of the program) to Minimal Output.
    3. Put check-marks in LOP Check and Purity Check.
    4. Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.



    • When the scan is complete, two logs entitled OTL.txt and Extras.txt will be created on your desktop.
    • Attach both of these logs to your next message.
     
  7. sp8eu

    sp8eu Private E-2

    When I try the first step I get:

    ------

    Starting up...
    Running from: C:\win32kdiag.exe
    Log file at : C:\Documents and Settings\Stan\Desktop\Win32kDiag.txt
    Removing all found mount points.
    Attempting to reset file permissions.
    WARNING: Could not get backup privileges!
    Searching 'C:\WINDOWS'...

    Cannot access: C:\WINDOWS\system32\MRT.exe
    Attempting to restore permissions of : C:\WINDOWS\system32\MRT.exe

    Finished! Press any key to exit...
    ------

    Doing the other steps now.
     
  8. sp8eu

    sp8eu Private E-2

    Fix perm just pops up a "windows script host" box:
    'There is not script engine for file extension ".vbs".'
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please ATTACH your logs. :major
     
  10. sp8eu

    sp8eu Private E-2

    My apologies.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did ComboFix finish and can you get me the log as well as the C:\MGLogs.zip?
     
  12. sp8eu

    sp8eu Private E-2

    I can't seem to locate the log for combobox. Can I rerun it or is there a usual path it is created in?
     

    Attached Files:

  13. sp8eu

    sp8eu Private E-2

    Sorry, combofix log might be this one, please let me know if not.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    ComboFix should be on your desktop, which I am not seeing there. Please download it to your desktop and run it:
    ComboFix

    You need to run CCLeaner and delete as much as you can in this folder:
    C:\Documents and Settings\Stu\Local Settings\Temp\
     
  15. sp8eu

    sp8eu Private E-2

    attahced is the combofix.txt file. I can't see the link for CCLeaner on the "Read me First" page. I will need to run that part in the morning.

    Thanks for your help thus far.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That removed a few things. You can find CCleaner HERE.

    Tell me what issues you are still having, if any. ;)
     
  17. sp8eu

    sp8eu Private E-2

    Thanks Tim, had to shutdown last night. So far, so good, Malwarebytes/superantispyware aren't shutting down quickly now and running scans to check stuff.

    Thanks for your help. Will let you know if I find anything (I know some folders still seem to be set with specific security permissions so I can't run them) but I can fix this.

    Keep you posted and thanks again.
     
  18. sp8eu

    sp8eu Private E-2

    So far so good, I've had to reinstall some stuff, but apparent from that all looks good. Many thanks for your help.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. And you are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0


    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds