torjan help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by mglogs, Sep 23, 2011.

  1. mglogs

    mglogs Private E-2

    my younger brother ran Microsoft_Office_2010_crack_by_ViKiNG.zip

    which was found on ...........

    i dont think it worked however it did install some sort of trojan. im not sure which one. but its blocked the virus scan from running. and keeps redirecting webpages to corkingsearchsystem.com

    -tried norton antivirus and it says unspecified error.
    -when i try to start malwarebytes it says "windows cannot access the specified device, path, or file. you may not have the appropriate permission to access the item"
    -when i try to use microsoft security essentials it says access is denied, gives me error code 0x80070005
    -i tried running rkill but it only runs once and half way through terminates. trying to run it for the 2nd time it gives error ""windows cannot access the specified device, path, or file. you may not have the appropriate permission to access the item"
    -combofix wont even install.
    -mbr check worked and the file is attached
    -mgtools worked and file is attached.
    please help!

    a similar thread @ http://forums.majorgeeks.com/showthread.php?p=1667545
     

    Attached Files:

    Last edited by a moderator: Sep 23, 2011
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I trust you have removed the cracked software.

    Your Newfiles log is virtually empty, so let's try this:

    Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  3. mglogs

    mglogs Private E-2

    both logs are attached.

    also i was reading other forms and it might be a zero access rrokit thing ...
     

    Attached Files:

  4. mglogs

    mglogs Private E-2

    and nothing got cracked, the keygen thing completely disappeared
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    So far I am not seeing any malware in your logs. Do this: ( Make sure MGTools is on the C: drive as C:\MGTools )

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.
    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.

    But first disable TeaTimer!!

    Please Disable Spybot's TeaTimer --> Should have been done as per the R&R instructions!

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!
     
    Last edited: Sep 24, 2011
  6. mglogs

    mglogs Private E-2

    did everything you said and no errors. i saw another post about a zero access rootkit and ran those steps and that has seemed to fix it. it did find a sever rootkit infection. everything seems to be running normally except malware bytes wont start. when i try to start malwarebytes it says "windows cannot access the specified device, path, or file. you may not have the appropriate permission to access the item" and when i try to use microsoft security essentials it says access is denied, gives me error code 0x80070005.

    also now when i start my computer it gives me this window:

    Please select the operating system to start:

    Microsoft Windows Recovery Console
    do not select this [debugger enabled]
    Microsoft Windows XP Home Eddition

    Use the up and down arrow keys to move the highlight
    Press ENTER to choose.

    Any idea on how i can get rid of that?

    also thank you for all your help!!
     
  7. mglogs

    mglogs Private E-2

    now when ever i try to open any microsoft office document it says

    "You may be encoutering this message because an anti-virus program is not allowing the file to open. This can be caused by one of two conditions. Either the anti-virus program needs to be updated (due to a compability problem with this application) or there is a virus in the file but the anti-virus program cannot properly remove or process the virus it has found."

    which is odd because it was working just fine before.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Uninstall your AV program as well as MBAM. Run CCLeaner to remove any leftovers. Download and reinstall the two programs and see if they will run.

    I still need you to follow my last instructions and get me the two new logs.
     
  9. mglogs

    mglogs Private E-2

    here you go...also where do i get CCLeaner
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That was not what I asked you to run. You can get CCLeaner HERE.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.
    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.

    You also still have TeaTimer running!! Please disable it via my last instructions.
     
  11. mglogs

    mglogs Private E-2

    there were no error msgs . do you want the newfiles.txt and the other one
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes.
     
  13. mglogs

    mglogs Private E-2

    attached
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look good. What malware issues are you still having, if any?
     
  15. mglogs

    mglogs Private E-2

    none at this point. i did delete and reinstall norton and now everything seems fine. when i open ms office docs it does give me a pop up sayin "the command cannot be performed because a dialog box is open. click okm and then close open dialog boxes to continue" after clicking ok it works but just an annoyance but i can live with it. other than that everything seems good. thank you
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You might want to discuss the Office issue in the software forums. Good to know everything else is running good, and you are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0


    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds