trojans and BSOD's in safemode.

Discussion in 'Malware Help (A Specialist Will Reply)' started by gordo@acr.net.au, Feb 1, 2011.

  1. gordo@acr.net.au

    gordo@acr.net.au Private E-2

    Hi, A work collegue has some type of infection and I need your help to sort it out.

    I have done the steps as per the readme and have logs for SAS MWAB and MGtools, Combofix caused bsod and now it is harder to get to a normal boot.

    Sometimes it will boot normally then BSOD. I cant get access to the logs because of safemode and no netwotk, usb drive etc. As soon as I can get to them I will attach them here.

    The list found by and removed by SAS are:-
    trojan.agent/gen-nullo(micro)
    trojan.agent/gen-fakeAV(winlock)
    trojan.agent/gen-fakealert
    trojan.agent/gen-bancos

    What are the next steps.

    TIA
    Steve
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Without seeing the logs I cannot help you, so soon as you attach them we can make a start. :)
     
  3. gordo@acr.net.au

    gordo@acr.net.au Private E-2

    I've also attached a hijack log as well as SAS MBAM & MGlogs.

    No awaiting your valued assistance. :wave
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why am I not seeing any AV software on this system?

    Please boot into normal mode. If you can't do this in normal mode, do it in safe mode.

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip
     
    Last edited: Feb 1, 2011
  5. gordo@acr.net.au

    gordo@acr.net.au Private E-2

    Was running in safemode only, im guessing AGV not running? It is installed and running in normal mode. 'avg2010free'

    Successfuly added to registery.

    reboot after avenger has run in normal mode - BSOD after login 'system_service_exception'

    rebooted in safemode checking for avenger log - not there.
    try normal boot after safemode shut down -OK open explorer BSOD
    try reboot normal - BSOD irq_notlessthan_orequal_
    reboot safemode ok.

    not sure next best step??

    TIA
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your BSOD issues would be best addressed in the software forum. But let me see a new MGLogs.zip.
     
  7. gordo@acr.net.au

    gordo@acr.net.au Private E-2

    Hi Tim,
    Here is this mornings MGlogs.zip

    I have noticed that some folders in the /user/ sub folders are locked. A padlock shown on some that are accessible, some aren't with 'deny access' under security properties options i.e.
    C:\Documents and Settings\Steve\Local Settings\Temp (maybe why avenger didn't complete) ???

    TIA
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right click C:\Documents and Settings\Steve\Local Settings\Temp and choose properties. Then click on the security tab and tell me if you can add your profile to give you user permissions.

    I am currently having some issues with my computer so I will have to get back to you on further fixes. :(
     
  9. gordo@acr.net.au

    gordo@acr.net.au Private E-2

    I have removed the DENY entry, so now I have access to the temp folder and some others.

    Soz to here you too have issues, looks like it happens to the best of us ;)
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Weird ..... but I am back up and running properly. Do this while I check some things for you.

    Go to start / run / and type:
    %temp%
    delete all that it will let you remove.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is this:?
    C:\32788R22FWJFW

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is a temp folder created by ComboFix. Check the list of items cleaned up by MGclean.bat. ;)
     
  13. gordo@acr.net.au

    gordo@acr.net.au Private E-2

    yes it is. I have deleted it anyway.

    after running avenger in normal mode OK then boot to BSOD ???
    next boot to safe reboot to normal OK. - presume avenger didn't run on boot ?? no avenger log

    so i searched for following

    C:\Windows\System32\drivers\paoj.sys not found
    C:\Windows\System32\drivers\xcfmb.sys not found

    C:\Windows\SysWOW64\drivers\paoj.sys deleted
    C:\Windows\SysWOW64\drivers\xcfmb.sys deleted

    all deleted except folder OLC Logging (outlook hotmail connector log) & a 0byte txt file FXSAPIDebugLogFile.txt (delete message - file is open in windows explorer)

    ran MGtools log attached.

    cheers
    TIA
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    TimW forgot you were running a 64 bit system. Avenger will not run on 64 bit systems.

    Are you currently having any malware problems? The below files still show in your logs:
    Code:
    ----a-w   61,440 2011-02-03 01:14:53  C:\Windows\SysWOW64\drivers\imimfd.sys
    ----a-w   61,440 2011-02-02 00:02:17  C:\Windows\SysWOW64\drivers\paoj.sys
    ----a-w   61,440 2011-02-02 00:36:34  C:\Windows\SysWOW64\drivers\xcfmb.sys
     
  15. gordo@acr.net.au

    gordo@acr.net.au Private E-2

    I've deleted imimfd.sys the other two were not there.

    I'm still having BSOD issues when i shut down and reboot from normal to normal mode.

    I have to boot to safe mode, shut down, reboot normal or
    shut down reboot (not sure if this works all the time)
    as for malware well i dont know if i still have issues ???

    fresh MGtools log attached

    TIA
     

    Attached Files:

  16. gordo@acr.net.au

    gordo@acr.net.au Private E-2

    Just ran a AVG scan, not finished yet but found 'Trojan horse Agent_r.XJ in firefox.exe ??? hmmm

    not out of the woods yet.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Tell me exactly what it found. The entire path. I am not seeing any malware in your logs. But since you were able to do them in normal mode, let's have you run an online scan:

    eSet Online Scan.
     
  18. gordo@acr.net.au

    gordo@acr.net.au Private E-2

    Hi Tim, Seems to be running a little better today, booted ok this morning. (no BSOD)

    Ran eScan as suggested results attached.
     

    Attached Files:

    • ESET.txt
      File size:
      228 bytes
      Views:
      4
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, that found one thing. Keep an eye on how things are running and let me know what problems you may have. We can wait till tomorrow to do the final cleanup when we are sure you are working properly.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds