Virus hidding as driver

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Maxs, Mar 19, 2012.

  1. Maxs

    Maxs Private E-2

    Hi

    Thanks in advance for working with me on this....

    I have a virus that seems to be hiding itself as a driver. I first noticed it on my task bar showing as System Restore with this file path:

    "C:\Documents and Settings\All Users\Application Data\6DSS92c31Apgjk.exe"

    I have manually deleted these, but as you will notice TDSS Killer is still picking it up along with something else.

    I am running AVG which picked up a couple of viruses, but since your instructions in the "READ ME FIRST" state to uninstall it, I have already done that and I don't have a report for that scan...all others have been attached.

    Please advise.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach logs from the below scans that were requested in the READ & RUN ME.

    • SUPERAntiSpyware
    • ComboFix
    • RootRepeal
    • MGtools
     
  3. Maxs

    Maxs Private E-2

    Sorry...see attached.
     

    Attached Files:

  4. Maxs

    Maxs Private E-2

    Forgot to tell you ComboFix will not complete scan. I've tried running it all night and it just says "Scanning..."
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a couple infected partitions added to your hard disk as noted in the below in bold red:
    Code:
    Partition Disk #0, Partition #0 
    Partition Size 11.76 GB (12,626,256,384 bytes) 
    Partition Starting Offset 32,256 bytes 
    Partition Disk #0, Partition #1 
    Partition Size 221.12 GB (237,422,223,360 bytes) 
    Partition Starting Offset 12,626,288,640 bytes 
    [B][COLOR=red]Partition Disk #0, Partition #2 [/COLOR][/B]
    [B][COLOR=red]Partition Size 10.33 MB (10,829,824 bytes) [/COLOR][/B]
    [B][COLOR=red]Partition Starting Offset 250,048,512,000 bytes [/COLOR][/B]
    [B][COLOR=red]Partition Disk #0, Partition #3 [/COLOR][/B]
    [B][COLOR=red]Partition Size 8.00 KB (8,192 bytes) [/COLOR][/B]
    [B][COLOR=red]Partition Starting Offset 250,059,341,824 bytes[/COLOR][/B] 
    Do you have your Windows XP boot CD?


    You also need to rerun TDSSKiller and have it fix the below items if still detected:
    Code:
    15:51:13.0312 1924 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
    15:51:13.0312 1924 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip 
    Are the below items you knowingly installed?
     
  6. Maxs

    Maxs Private E-2

    I have tried to fix those 2 items with TDSSKiller, but it only gives an option to "skip" or "quarantine". Quarantine doesn't seem to work, still shows up after re-scan.

    I don't have a Windows XP boot CD. Jing and myspeed are 2 apps I've been using for over a year so I hope they are safe.
     
  7. Maxs

    Maxs Private E-2

    What are my options if I don't have a windows boot cd?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make the below CD and see if you can successfully boot to the Recovery Console command prompt. Let me know your results. Once you can do this, we can continue with the next steps.

    Using ARCDC to get the Recovery Console Command Prompt
     
  9. Maxs

    Maxs Private E-2

    I will be out of town until Monday and will post my results then.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! Just get back to me when you can.
     
  11. Maxs

    Maxs Private E-2

    Ok...I have successfully burned the boot cd and tested it. Seems to work fine. There was one issue with the instructions as it mentioned to select "1" when choosing which "windows installation". However, these were my choices:

    1. H:\MiniNT
    2. H:\I386
    3. C:\WINDOWS

    I'm assuming it's "3" not "1"? Either way it seemed to work.....what shall I do next?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes 3 would be the correct choice for you.

    We are going to begin by just deleting one of the suspected problem partitions.

    Please download: gparted-live-0.12.0-5.iso (124 MB)
    Create a bootable CD for GParted. You can use ImgBurn to accomplish this.
    If you need help on how to use ImgBurn, please view this guide by dr.m -- Using ImageBurn to Burn an ISO image

    Now boot off of the newly created GParted CD.
    http://img717.imageshack.us/img717/6546/gpartedsplash01107.th.png
    You should be here...
    Press ENTER
    http://img819.imageshack.us/img819/7286/gpartedkeymaps.th.png
    By default, do not touch keymap is highlighted. Leave this setting alone and just press ENTER.
    http://img404.imageshack.us/img404/9840/gpartedlanguage.th.png
    Choose your language and press ENTER. English is default [33]
    http://img140.imageshack.us/img140/7958/gpartedgui.th.png
    Once again, at this prompt, press ENTER
    You will now be taken to the main GUI screen below
    http://img32.imageshack.us/img32/1122/gpartedo.th.png
    According to your logs, the partition that you want to delete is 8 KB
    Click the trash can icon to delete and then click Apply.
    You should now be here confirming your actions:
    http://img233.imageshack.us/img233/1533/gpartedsteps.th.png
    Now you should be here:
    http://img696.imageshack.us/img696/8471/gpartedsuccessclose.th.png
    Is boot next to your OS drive? According to your logs, your OS drive is the 221.12 GB sized partition.
    http://img194.imageshack.us/img194/7753/gpartedboot.th.png
    If boot is not next to your OS drive under Flags, right-mouse click the OS drive while in Gparted and select Manage Flags

    In the menu that pops up, place a checkmark in boot like the picture below:
    http://img196.imageshack.us/img196/3483/gpartedmanageflagsboot.th.png
    Now press the Close button to save these changes.
    Now double-click the http://img822.imageshack.us/img822/641/gpartedexit.png button.
    You should receive a small pop up like this:
    http://img88.imageshack.us/img88/8986/gpartedexitreboot.png
    Choose reboot and then press OK.


    Now reboot from the Windows XP Recovery Console CD and execute the following commands pressing ENTER after each:
    • fixmbr
    • fixboot
    • exit
    Once back in Windows...
    http://img707.imageshack.us/img707/6703/generalxpicon.gif Re-run another scan with MBRCheckand attach its latest log. (How to attach)
     
  13. Maxs

    Maxs Private E-2

    Mission accomplished...seems to be another hidden partition still there 10.33 GB. As requested, I only deleted the one 8GB. Anxiously awaiting your reply!
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You mean 10.33 MB not GB.

    8KB, This is a million times smaller. ;)

    Before doing anything with the 10.33 MB partition, I want to know how things are running right now.
     
  15. Maxs

    Maxs Private E-2

    Ahhh yes, it would be MB...that's why your helping me and not the other way around;). The firefox seems to be running a little faster...if that helps? I still have the "system restore" icon on my toolbar showing up with this file path:

    "C:\Documents and Settings\All Users\Application Data\6DSS92c31Apgjk.exe" but I've manually deleted it, as I mentioned before.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What toolbar are you referring to?


    Now let's rerun the procedure with G-Parted, but this time delete the 10.33 MB partition. And also this time after reboot, do not bother running MBRcheck. Instead do the below.

    Download the current version of TDSSkiller and rerun it. Quarantine the below if they still appear.
    Code:
    15:51:13.0312 1924 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
    15:51:13.0312 1924 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip

    Now see if you can run ComboFix as requested in the READ & RUN ME.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the c:\combfix.txt log if it ran
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  17. Maxs

    Maxs Private E-2

    Sorry, it's not a toolbar it is the taskbar to the right of the Start button where the "System Restore" icon is showing up...still!

    Anyway, attached are the log files. When I ran Combofix, it told me AVG was running, however, I had already uninstalled it a while back. Needless to say it still ran normally.

    TDSSKiller found about 7 items, but did not identify the 2 that you wanted me to quarantine as "threats", so there was no action I could take.

    When I ran MGtools an error message popped up:

    [Shell_NotifyIcon] Failed to perform desired action. Error Code: 0

    The computer seems to be running fine at this point.
     

    Attached Files:

  18. Maxs

    Maxs Private E-2

    Update.....Still have something going on. The windows internet security shield tries to pop up every once in a while, but just flashes and goes away. Something disabled my Malwarebytes (paid version).
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Combofix just deleted it. Are you sure you still have this problem?

    Uninstall your paid copy of Malwarebytes, then reboot. After reboot, reinstall and reenter your license code. Make sure you update it to current database and run a full scan.

    What is the below stuff you just put on your PC? You should not be doing anything except what we request.
    Code:
    2012-03-27 19:53 . 2007-11-21 08:38 161344 ----a-w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\UNWISE.EXE
    2012-03-27 19:53 . 2012-02-13 16:30 381 ----a-w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\unpackJars.bat
    2012-03-27 19:53 . 2012-03-27 19:53 -------- d-----w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\jre
    2012-03-27 19:53 . 2012-03-27 19:53 -------- d-----w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\resources
    2012-03-27 19:53 . 2012-03-27 19:53 -------- d-----w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\HtmlHelp
    2012-03-27 19:53 . 2012-03-27 19:53 -------- d-----w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\doe2
    2012-03-27 19:53 . 2012-02-13 16:30 74 ----a-w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Start_REScheck_CL.bat
    2012-03-27 19:53 . 2012-02-13 16:30 128 ----a-w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Start_REScheck_CL_Log_Debug.bat
    2012-03-27 19:53 . 2012-02-13 16:30 111 ----a-w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Start_REScheck_CL_Log.bat
    2012-03-27 19:53 . 2010-04-05 15:38 1642591 ----a-w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\areaCalc.exe
    2012-03-27 19:27 . 2012-03-27 19:27 -------- d-----w- c:\program files\Check

    Now download The Avenger by Swandog46, and save it to your Desktop.
    See the download links under this icon http://www.majorgeeks.com/images/dll.gif
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7 make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Mar 31, 2012
  20. Maxs

    Maxs Private E-2

    Yes...the icon is still there (quick launch)


    I have NO idea what the first 2 are and I can't find them when I search. All of the others are a program I use from the Department of Energy called REScheck....work related stuff. Unfortunately, this is my only work computer and I had to update that program recently to a newer version, however, I have NOT been downloading any other antivirus or other programs other than what you have instructed since we began.

    Neither Avenger nor myself found the file. When I ran the program an error message appeared: "Windows-No Disk Exception processing Message
    c0000013 parameters 75b6bf7c 4 75b6bf7c 75b6bf7c"



    Excel spreadsheets seem to be slow when opening and doing any work within, internet is okay...little slow. My printer keeps disconnecting and reconnecting randomly (could be a wireless thing...not sure).
     

    Attached Files:

  21. Maxs

    Maxs Private E-2

    It will not let me upload the MGlogs.zip....error says I already have in this thread?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to follow the instructions given to create a new log first.
     
  23. Maxs

    Maxs Private E-2

    Okay...seemed to work that time.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then just right click on it and select Delete.

    Also you can look for the file related to the icon in the below folder and delete it this way too.

    C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch


    Your logs are clean.
     
  25. Maxs

    Maxs Private E-2

    Found and deleted.


    Almost everything seems to be working normally. However, I am now having trouble with attachments. Every time I try to attach a file it fails the first time and usually attaches after 2 or 3 tries. Never had this happen until yesterday? (This is for regular email attachments-not here on the forum).

    Anyway, what is the next step?
     
  26. Maxs

    Maxs Private E-2

    I tried updating Malwarebytes to run a scan and it said I needed to re-start. Once the computer rebooted, a fake Adobe update popped up. Now it says my Malwarebytes hasn't been updated in 80 days?

    I think something was missed!
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A "fake" Adobe what popped up? And how do you know it is fake?

    And what happens when you update it?
     
  28. Maxs

    Maxs Private E-2

    It's a window that pops up when I reboot saying I need to update Adobe Flash and believe me...it's fake, not to mention a gateway to hell once you click on it...the virus underworld is unleashed!...Hence my thread.

    I have uninstalled Malwarebytes and reinstalled, updated and scanned, but it doesn't seem to find anything. However, it seems to have taken care of the "80 days out of date" issue. Initially when I tried to update Malwarebytes before uninstalling it completely, it kept saying it needed to reboot and after the reboot it said it needed to be updated again and again and again....I think you get my point.

    FYI, this is the 4th time I've had to deal with this parasite of a virus since Sept. 2011 (2 reformats, a trip to an apparently incompetent computer repair specialist) and now you....which I will say, the other guy did not catch the infected partitions. You've been awesome so far!...Just don't want you to think I don't appreciate the help, but at the same time...I promise you the "Adobe Flash Update" is a FAKE!
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Show me a snapshot if you can.



    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  30. Maxs

    Maxs Private E-2

    I rebooted and it did not come up this time...I will post a picture if it does.

    Worked like a charm! Computer seems to be working fine.
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then it may have been valid.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds