Trojans at my gate

Discussion in 'Malware Help (A Specialist Will Reply)' started by equus007, Apr 2, 2010.

  1. equus007

    equus007 Private E-2

    Did a no-no and opened and exe without scanning it and got several trojans including xp defender. Ran through the READ ME FIRST instructions without using combofix(used it before and could never get rid of it so was leery). Thought I got it so went on and soon found out I was wrong.

    Ran through the list again...here are the logs.

    Haven't been using it since then so don't know whether or not I got it.
    Any suggestions?
     

    Attached Files:

  2. equus007

    equus007 Private E-2

    still getting a redirect when using google
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the requested log from MGtools.

    Also run the below.


    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v
    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  4. equus007

    equus007 Private E-2

    Here's the MGlog I think you asked about.
    will run other tool and up log
     

    Attached Files:

  5. equus007

    equus007 Private E-2

    Sorry this is the one. The previous post was the first run through.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay TDSSkiller found and removed part of your problem.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!OR=darkred]C:\MGlogs.zip[/COLOR][/B]
    [/LIST]Make sure you tell me how things are working now!
     
  7. equus007

    equus007 Private E-2

    Here they are. Had some issues with disabling AVG9.0(grrrrrrr) but it seems to have worked

    Thanks again
    BTW my favorite binary number is 2

    running tests on redirect issue but it is still persisting
     

    Attached Files:

  8. equus007

    equus007 Private E-2

    I'm also getting a windows message that reads:

    "Generic Host Process for Win32 Services has encountered a problem and needs to close..."


    then my taskbar reverts to gray and some of the icons get fudged
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I misread your TDSSkiller log earlier. It actually said it could not fix the problem since there is no back of the infected file available. Do you have a CD that came with your PC that contains the below Nvida Optical Driver SATA

    C:\WINDOWS\system32\DRIVERS\nvgts.sys

    You need to replace this file with a clean one and there are no replacements on your hard disk. This file will have to be replace either from the Windows Recovery Console or using special tools but first you need to find a valid clean copy.
     
  10. equus007

    equus007 Private E-2

    yeah I noticed that TDSS found but could not remove/fix it. Have been searching some and saw a method on nvidia's board about a way to script this in(?) but wanted to pass this by y'all first.

    Is there a way to replace this file without the disk?
    Right now I have peerblocker stopping most of the redirects but it is annoying.

    This is an OEM install and I never had the disks. The drive was in a XPS running my OEM from DEll and then was moved to another system when the processor crashed. I think the tech that built the new box trashed the old chasis with the key sticker on it and then installed his own OEM copy on it. Since I don't have the key I don't know how to check this.

    It was at least a valid copy. I did verify the new copy when I got the new system ~2 months ago.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need a good/uninfected copy of the file and then it can possibly be replaced using TDSSkiller, ComboFix, Avenger, or the Windows Recovery Console

    It may be possible that downloading and installing updated drivers from Nvidia could even repair it but I don't know that for sure. The infection could potential block the update.
     
  12. equus007

    equus007 Private E-2

    I now have a clean copy of nvgts.sys. What next?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tell me exactly where the file is located.
     
  14. equus007

    equus007 Private E-2

    original = c:\windows\system32\drivers

    clean copy = D:\Drivers\Chipset\1526_XP32\IDE\WinXP\sata_ide
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then make sure that drive D is currently accessible before doing the below.




    Now we need to use ComboFix to copy the file to a few locations and make another backup.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    After reboot, immediately run TDSSkiller again just like previously run.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  16. equus007

    equus007 Private E-2

    here you go.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you install HitmanPro?

    Why did you run TDSSKiller 3 times (twice before running ComboFix) and once after?

    And what else have you been doing? You have a whole bunch of new infections!! Yes new. They are not related to what we have been trying to fix.
     
  18. equus007

    equus007 Private E-2

    grrrrrrr......because I am not the only one using this system.
    BRB have to go beat someone.
     
  19. equus007

    equus007 Private E-2

    Should I just start fresh with the list and new installs of all the programs?



    sorry just very angry at the moment:

    what I have been doing: going to work and spending the nights doing this and flipping around on reddit
    what she has been doing: listening to a friend on facebook about how to fix the problem and most likely downloading more stupid hidden object games.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing else but what we are asking you to do should be done on this PC. It will only make our work more difficult. Once we are either finished removing all malware ( or we give up which is rare ) you can then do what you want.


    Please follow the instructions in the below to disable CD Emulation:
    I will post another fix in a few minutes. Just do the above while I'm working on this.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you use anything like the below
    I see this file in your log which is why I'm asking. I want to be sure it is valid.
     
  22. equus007

    equus007 Private E-2

    Does not sound familiar.
    I do have several adobe products on this system but did not personally install them.
     
  23. equus007

    equus007 Private E-2

    Defogger is done
    and BTW thank you. You are very patient.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is is a legit copy? Right now it is infected and this could mean it needs to be uninstalled to clean it properly.

    The nvgts.sys file may not really be infected. It could be a problem that occurs due to using Daemon Tools which is why I just had you run Defogger.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below code box into it:
    Code:
    KILLALL::
     
    Atjob::
    Renv::
    c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl .exe
    c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray .exe
    c:\program files\ATT-SST\McciTrayApp .exe
    c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM .exe
    c:\program files\CyberLink\PowerDVD\PDVDServ .exe
    c:\program files\Microsoft Office\Office12\GrooveMonitor .exe
     
     
    DirLook::
    C:\Program Files\Common Files\System\ado
    C:\Program Files\Common Files\System\msadc
    C:\Program Files\Common Files\System\Ole DB
     
    FileLook::
    c:\windows\system32\acaptuser32.dll
     
    File::
    c:\windows\Fonts\e2nV5.com
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\8cq4r
    C:\Documents and Settings\All Users\Application Data\rq8O7YiY.dat
    C:\TDSSKiller.2.2.8.1_03.04.2010_19.01.05_log.txt
    C:\TDSSKiller.2.2.8.1_05.04.2010_17.29.05_log.txt
    C:\TDSSKiller.2.2.8.1_03.04.2010_18.45.41_log.txt
    C:\TDSSKiller.2.2.8.1_05.04.2010_17.23.28_log.txt
    C:\TDSSKiller.2.2.8.1_05.04.2010_23.29.24_log.txt
    C:\TDSSKiller.2.2.8.1_03.04.2010_18.10.35_log.txt
    C:\TDSSKiller.2.2.8.1_03.04.2010_16.14.29_log.txt
    C:\TDSSKiller.2.2.8.1_03.04.2010_00.07.24_log.txt
    C:\TDSSKiller.2.2.8.1_03.04.2010_00.08.10_log.txt
    C:\TDSSKiller.2.2.8.1_03.04.2010_00.14.20_log.txt
    C:\TDSSKiller.2.2.8.1_03.04.2010_04.39.41_log.txt
    C:\MGlogs.zip
    C:\Documents and Settings\Administrator\Local Settings\temp\bck7.tmp
     
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AtiPTA"=-
    "RemoteControl"=-
    "ATT-SST_McciTrayApp"=-
    "Adobe Acrobat Speed Launcher"=- [2009-12-22 38840]
    "Acrobat Assistant 8.0"=- [2009-12-21 640440]
    "GrooveMonitor"=-
    "Adobe ARM"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "SUPERAntiSpyware"=-
    [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\AdobeUpdater]
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now rerun TDSSKiller ( only once ).

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  25. equus007

    equus007 Private E-2

    I don't know if they are legit. Should I uninstall before using combo fix? Do you know which program the .dll links to?
     
  26. equus007

    equus007 Private E-2

    After thinking about it the only things I can for sure verify as legit on this system are my music files and my OS. In short I will (gladly) do away with just about anything that looks questionable.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For now, just follow my last instructions. If we run into problems, we will consider uninstalling some software.
     
  28. equus007

    equus007 Private E-2

    Here is what I have been able to figure out that had happened before I ran combofix.

    Several games uninstalled.
    AVG9 settings messed with*
    TDSSKiller run twice
    HitmanPro run possibly more than once
    "some sort of reg.cleaner"run
    !!!!!clicked a "do you really want to navigate away from this page" prompt on a redirect!!!!!

    *here is where you may begin to hate me if it caused any problems...I could no longer disable scans in AVG9. I have no idea how this was done but I had to uninstall it in order to run Combofix. At this point if the clean-up doesn't work I will probably just wipe the drive as I will be losing very little.
     

    Attached Files:

  29. equus007

    equus007 Private E-2

    quick question you may know the answer to as well.
    If I leave defogger on will it prevent new emulators from working as well? I do not use them and would like to find a way to prevent them from showing up without banning my daughter from the internet entirely.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not necessarily.

    You can just uninstall Daemon Tools if you don't want the emulation on your PC but your daughter probably uses it to play games without putting in the CD.

    Defogger either did not defog or TDSSKiller is having a false detection, or something else is in play the is causing the nvgts.sys to keep appearing as infected when we have replaced it with a clean copy using ComboFix.

    Let's shift gears a little. I'm going to assume you some kind of router that you use. It is not uncommon for routers to get infected. If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.

    Then reboot you PC and see if you still have problems with redirections.
     
  31. equus007

    equus007 Private E-2

    Done however still getting redirect. NAV catching it now but doing a google search for malware always gets a hit (see attached)

    In the past few days it began locking up every once in a while and then stopped starting. I finally got it started and immediately began uninstalling everything I did not personally install (I have to have this system at least functional so I can work). I also installed Norton which seems to catch some of the redirects and am now getting a different message which says msdvdr.pif ( http://www.bleepingcomputer.com/startups/msdvdr.pif-19708.html )
    can no longer run. It starts fine now. I'm assuming this is a good thing.

    The issue with the other file seems to have been cleared up and the task bar no longer grays out however that was intermittent and probably too soon to tell.

    Things Removed:

    CS3
    Illustrator
    Office 97
    A few movies
    Nexus(Game)
    Peerblocker
    Daemon Tools (ran defogger first and reactivated before uninstall)


    Will be running full NAV scan tonight.

    If you have any further ideas let me know. I will only be using this system for web browsing until I either fix this issue or reinstall OS.

    Thank you
     
  32. equus007

    equus007 Private E-2

    addendum:

    NAV removed msdvdr.pif
    system restarted and NAV detected something else and forced another restart. The log only shows the msdvdr.pif and a bunch of blocked intrusions. Still getting intrusions.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you say instrusions, I assume you are referring to incoming detections by your firewall. Is that the case? If so, that is why you are supposed to have a software firewall. ;)

    Okay now that all of that software has been uninstalled, let's see how logs look.

    Please download and run the current version of: combofix.exe

    Then rerun TDSSKiller like I prevously had you run.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )



    Now attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Apr 9, 2010
  34. equus007

    equus007 Private E-2

    Firefox now wanting to send report whenever I shut it down but otherwise functioning normally.

    Something tried to open fubar but NAV stopped it half-way while I was reading the last post. Went ahead and uninstalled it (fubar) as well before starting with combofix.

    All fresh installs of removal tools.

    edit: yes the intrusions were spotted by NAV and are coming from 2 ip's however there is at least one that is still getting through as far as I've been able to tell. I think my daughter turned off AVG9 while attempting to apply a no-cd hack which is what started all of this.
     

    Attached Files:

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    We are going to be uninstalling your old version of FireFox and installing the new version. So do the below to save bookmarks:
    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    C:\Program Files\Mozilla Firefox
    C:\documents and settings\UserAccount\Application Data\Mozilla

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).


    What IPs?


    Let's cleanup a bunch of left overs from Adobe and a few other things.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (file missing)
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    O2 - BHO: Internet Explorer Plugin - {F4F5B58A-D3A6-4F85-B3EF-5642E8937E6F} - nsfwj2.dll (file missing)
    O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
    O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    O20 - AppInit_DLLs: C:\WINDOWS\system32\acaptuser32.dll
    O20 - Winlogon Notify: gport_ - C:\WINDOWS\SYSTEM32\gport_.dll

    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Apr 9, 2010
  36. equus007

    equus007 Private E-2

    neither combofix nor mgtools seems to be working. Control panel shows cscript.cfxxe running and it started after CFscript.txt was dropped on it but blue menu screen never came up.

    MGtools came up but never began scan for reg.keys

    ip's:
    112.121.181.26
    213.163.89.106

    NAv has also removed 3 instances of Backdoor.Hack.Defender

    Still getting error report at end of Firefox session.

    I have left both MGtools.exe and CScript.cfxxe running as I know comboscript at least can really mess with a system if it goes wrong.
     
  37. equus007

    equus007 Private E-2

    System eventually froze and had to restart. Doesn't not seem to be any damage done. Only thing that I think worked was cclean

    another intrusion from:
    873hgf7xx60.com(112.121.181.26, 443)

    try same process again?
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Warnings from your firewall about blocked intrusions are not problems. They are normal. Especially after originally having a PC with infections since some hackers may know of your end address.

    Please download and use the current versions of both programs and see if they run. Make sure you shutdown Symantec or it will likely just get in the way of execution.


    Uninstall. Reboot. And then reinstall.

    MGtools should not be run until after ComboFix has finished running. They should never be run at the same time.
     
  39. equus007

    equus007 Private E-2

    Combofix and Mgtools worked.

    Was not sure if you wanted me to run the CFscript on combotools or not so I ran combofix as normal.

    Thanks
     

    Attached Files:

  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes please run the previous fix with the new version of ComboFix. Also run the new version of MGtools. Attach new logs.


    Also please run this: GMER - running with a random name and attach the log from GMER.
     
  41. equus007

    equus007 Private E-2

    all went well except system seriously slowed after gmer. Seems fine after restart.

    Mgtools did detect ip6fw(?) which it has always said was missing in the previous scans

    FF still messed up but I think it may just be the shortcut I am using...will test this next.

    Still getting redirect to Dell XPS survey give away losers

    Thanks
     

    Attached Files:

  42. equus007

    equus007 Private E-2

    combofix.txt too big for single file upload so I broke it up into 5 files
     

    Attached Files:

  43. equus007

    equus007 Private E-2

    ok make that 6 files

    lots of adobe help files deleted
     

    Attached Files:

  44. equus007

    equus007 Private E-2

    sorry bout the mess
    edit function timed out while I was trying to cut up combofix.txt

    5a.txt - 5d.txt come between combofix4.txt and combofix6.txt

    the bulk of all theses are deleted help files from Acrobat
     

    Attached Files:

    • 5a.txt
      File size:
      32.3 KB
      Views:
      1
    • 5b.txt
      File size:
      44.1 KB
      Views:
      1
    • 5c.txt
      File size:
      117.7 KB
      Views:
      0
    • 5d.txt
      File size:
      128.5 KB
      Views:
      0
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it. (If you are using Vista, please right-click and select run as administartor)
    • A blank Windows shall open with the title "SystemLook v1.0-by Jpshortstuff".
    • Copy and Paste the content of the following codebox into the main textfield under "File":
    Code:
    :filefind
    atapi.sys
    nvgts.sys 
     
    
    
    • Please Confirm everything is copied and Pasted as I have provided above
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. You can close this notepad window as the log will already be saved as SystemLook.txt on your Desktop ( if you downloaded and ran SystemLook to your Desktop as requested ).
    • Please attach this log in your next reply.
    Note: The scan may take a while from several seconds to a minute or more depending on the number of files you have and how fast your computer can perform the task.
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The ComboFix log was so large because I had it deleting stuff from Adobe which I thought were left overs. I though you said you uninstalled all of it earlier. Perhaps that was a misunderstanding. At anyrate. your installation of Adobe Acrobat 9 Pro Extended - English, Français, Deutsch was broken via the last ComboFix step and will likely need to be reinstalled but it would be best not to do this yet until we can fix your malware. The nvgts.sys file is likely the root of your problem and we will have to replace it with a good copy and this will have to be done by booting to the Recovery Console that you installed using ComboFix. We will get to this after I get the log from SystemLook.
     
  47. equus007

    equus007 Private E-2

    Norton detected Trojan.FakeAV as well ( quarantined )
     

    Attached Files:

  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay the nvgts.sys file is definitely the source of the problem and we will have to fix this by using the Windows Recovery Console that you installed when installing ComboFix. However before we can do this, I need you to do the below.

    First you need to make a copy of your backup which is here:
    d:\drivers\Chipset\1526_XP32\IDE\WinXP\sata_ide\nvgts.sys

    and put the copy so that it is located here c:\nvgts.sys

    We need to make sure this is completed properly before we can proceed so I will be asking for a new MGtools log a little further down to verify you have completed this properly.


    Now we also need to create a batch file to run from the Windows Recovery Console ( henceforth just called the RC ) which will make steps easier for you when we do get to using the RC.
    • Open notepad
    • Copy the contents of the Code Box below into the notepad window.
    • Click File -> Save As...
    • In the File name: field, type C:\grfix.txt, then click Save.
    • Close notepad
    Code:
    ren c:\windows\system32\drivers\nvgts.sys nvgts.old
    copy c:\nvgts.sys c:\windows\system32\drivers\nvgts.sys
    Now double check the C:\grfix.txt file by double clicking on it and make absolutely sure that it looks exactly like I gave above noting to maintain spacing which is why my instructions stated to copy ( typing could lead to mistakes ;) ). If it looks okay, just let me know that you have this grfix.txt file created properly.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
     
  49. equus007

    equus007 Private E-2

    accidentally ran mgtools.exe before getlogs.bat they seem to do the same thing. MGlogs1.zip was from the mgtools.exe run and the MGlogs.zip was from running getlogs.bat.

    Hope this doesn't mess it up.

    grfix.txt good to go
     

    Attached Files:

  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now we will boot into the Windows XP Recovery Console. You should print these to have on hand while offline. Also read thru all of them now to be sure you understand before starting them.
    • Restart your computer.
    • Shortly after restart and way before Windows loads, you will be prompted to choose which Operating System to start. Pay attention it flashes fast and you will only have about 1 or 2 seconds to hit a key!
    • Use the up and down arrow key to select Microsoft Windows Recovery Console that was installed with Combofix and hit enter after selecting.
    • Later you will be asked to enter which Windows installation to log onto. Type 1 and press 'Enter'.
    • At the C:\Windows prompt, type the following bolded entries, and press 'Enter' (note the space after the word batch):
    batch C:\grfix.txt

    After the above runs ( it should be quick), type in Exit and press enter and your computer shall reboot. Reboot back in to Normal Mode and run Combofix once more.

    Now also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the new c:\combofix.txt log
    • C:\MGlogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds