Trojan and other diseases

Discussion in 'Malware Help (A Specialist Will Reply)' started by damgreg, Aug 4, 2009.

  1. damgreg

    damgreg Private E-2

    Good morning!

    A couple days ago, my 10 yr old son decided to try and find a key code on the internet for his Call of Duty game (he lost the original code). He downloaded something, but it sure wasn't a code!

    I have AVG Free on my machine and it just went crazy with alerts. It appeared that I had multiple problems, the most obvious of which was Protection System. I ran multiple full scans, but to no avail. I looked up Protection System on the web and discovered it is actually malware. I found an anti-spyware program called StopZilla, which said it can remove Protection System. This was true, but a bunch of other problems remained. In fact after that my machine didn't and still won't connect to any anti-virus sites for definitions updates (I downloaded updates for the scans on another machine and transfered by jump-drive to my infected desktop). The machine runs slow.

    At this point, I went looking and found Major Geeks. I have followed the "Windows XP Cleaning Procedure" to the letter. All the scans ran fine except Combofix. Running it gave me the following Error message:

    "!!ALERT!! It is NOT SAFE to continue!

    The contents of the Combofix package has been compromised. Please download a fresh copy from:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    Note: you may be infected with a file patching virus "Virut" "

    I press "OK" and the Combofix.exe icon disappeared. So, I downloaded a fresh copy of Combofix on another uninfected laptop. I transfered it to my infected desktop by jump-drive, but when I ran it I got the same Error message.

    I have attached all the logs as instructed. Any help you can give me would be appreciated, as I am now contemplating a re-format of my hard drives.

    My deepest, heartfelt thanks for all your help.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The first thing I want you to do is to backup all your personal data and files to a cd.

    Please refrain from making any changes to your system (updating Windows, installing applications, removing files, etc.) from now on as it might prolong handling your log and make the job for both of us more difficult.

    Now download The Avenger by Swandog469, and save it to your Desktop (if need be, download on a different computer and transfer via cd).

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please double-click the RootRepeal.exe previously downloaded.

    * Select File then Scan
    * On the Select Drives form select drive [ insert drive infected here ] by "ticking" the box for drive [insert drive here] and click OK
    * When the scan is complete - highlight each of the following file(s) (one at a time if more then one is listed) by left clicking it. Then use right mouse click and select the Wipe File option only for each file.
    c:\documents and settings\grigoris\grigoris.exe
    c:\documents and settings\grigoris\reader_s.exe
    c:\windows\temp\0603ce18-6a55-4f8e-9185-5dab6e8fa2f7.tmp
    c:\documents and settings\grigoris\application data\pridl\pridl.exe
    C:\Documents and Settings\Greg\Local Settings\Temp\IXP000.TMP\sys
    c:\documents and settings\grigoris\local settings\temp\plugtmp-11\s
    * After Wiping all files, immediately reboot your pc!

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    -
    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip
     
  3. damgreg

    damgreg Private E-2

    Tim,

    First of all THANKS for helping! I'm not sure why you guys do this, but its absolutely brilliant that you do. When we're done, just tell me where to make a donation and consider it done.

    Unfortunately, I didn't get very far:

    I have 2 hard-drives - C:\ I use for programs & files, F:\ for backup. I wasn't sure, so I checked both for the RootRepeal scan. From your file list, only the following came up:

    1. c:\documents and settings\grigoris\reader_s.exe
    2. c:\Documents and Settings\Greg\Local Settings\Temp\IXP000.TMP\sys
    3. c:\documents and settings\grigoris\local settings\temp\plugtmp-11\s

    On 1. & 3. the Wipe File produced a RootRepeal Error:

    "Invalid path!"

    On 2. the right-click would not allow the Wipe File option (it was lite gray), just Force Delete.

    So what's next?:confused Thanks in advance for help.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You continue on with my instructions.
     
  5. damgreg

    damgreg Private E-2

    Thanks for clarifying instructions.

    I have the following notes to report while attempting to complete all steps in your instructions:

    1. HijackThis did not produce the following two lines:

    O4 - HKUS\S-1-5-18\..\Run: [pridl] "C:\Documents and Settings\Grigoris\Application Data\pridl\pridl.exe"

    61A847B5BBF72811329B385672FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310 (User 'SYSTEM')

    The other two lines were checked and Fixed as per instructions.

    2. I DID get a success message re: adding fixMe.reg to the registry.

    3. When running Getlogs.bat, I got the following error:

    ProcessDll.exe - Application Error

    The application failed to initialize properly (0xc000007b). Click OK to terminate the application


    Upon clicking "OK", no MGlogs.zip popped up on the desktop, so this log is not attached.

    The log avenger.txt is attached for your review.

    THANKS once again for hangin' with me on this.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    My bad...let's do it again.
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Please use this link and go to Error message #4 to fix the MGTools error:
    Using MGtools

    Attach the new logs:
    C:\MGLogs.zip
    C:\Avenger.txt
     
  7. damgreg

    damgreg Private E-2

    Thanks Tim,

    No problem with the avenger. avenger.txt is attached. I ran dotnetfx.exe and then tried to run GetLogs.bat again, but still resulted in the same ProcessDll.exe - Application Error:

    "The application failed to initialize properly (0xc000007b). Click on OK to terminate the application."

    :cry

    What say you now, wise one?
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you saying that you do now have Microsoft Netframework installed? If you clicked ok to continue, then you probably did get a new log....so just attach the C:\MGLogs.zip.
     
  9. damgreg

    damgreg Private E-2

    I checked my Currently Installed Programs and I have the following:

    Microsoft .Net Framework 1.1
    Microsoft .Net Framework 1.1 Hotfix (KB928366)
    Microsoft .Net Framework 2.0 Service Pack 1
    Microsoft .Net Framework 3.0

    I searched all files and folders and found a MGLogs.zip. It's attached.

    Sorry, I'm doin' the best that I can:zzz. Thanks for helping.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    IMPORTANT NOTE: Some if not many, of your Windows system files are infected. And many other non-Windows files could also be infected. Even if we attempt to fix these problems (which may not be easy to do unless you have an original Windows XP SP3 bootable CD), your system may be unreliable and untrustworthy.You may need to reinstall this system.

    Your logs show that your Windows Operating system files have become infected and there is no known reliable fix for this. In addition there are many many other infected files. We could spend a lot of time trying to remove this infection, but odds are that it will not work because the nature of the infection has so many executable system files infected that as soon as we fix one file, other files that are infected will almost immediately or upon the next reboot, just reinfect the files. In addition, your PC would still basically be unreliable/untrustworthy even if we manage to fix the infected files that we can see since there could be many more that we are not seeing.

    The safest thing for you to do is backup your personal data immediately since your PC could possible become unbootable at any point in time. Do not back up any executable files. This includes programs that you have downloaded since any of them could be infected.

    Once you backup, you need to perform a total reinstall of Windows and all other necessary software. DO NOT reinstall from any executable files you backed up because they are most likely infected.
     
  11. damgreg

    damgreg Private E-2

    Tim,

    Thanks for trying...I had a feeling this was where we were going to end up.

    I have two more questions for you:

    I have used the Windows Backup utility to backup my desktop, documents, pictures and music to my second hard-drive. If I re-format my C: drive (which contains all programmes and the OS), then re-install Windows, will by backup set on the other hard-drive be safe to restore?

    Once I finally get this mess sorted out, what anti-virus and malware protection programmes should I install to stay safe? I was running FREE AGV, but it appears that wasn't good enough.

    Again, thanks for the help...:cry
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds