Virus quarantined - next steps? (1/2)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Debitha, Jun 30, 2011.

  1. Debitha

    Debitha Private E-2

    Hi. I picked up a virus last night. It appears to only have hidden all my files, but I'm reluctant to assume that's the only damage. It appeared initially as though everything had been wiped - everything I had open (Opera and Firefox) closed down, all files on my desktop disappeared, everything out of my start menu disappeared, all folders initially said they were empty. Switching it to 'show hidden files' showed everything still seemed to be there, just hidden.

    I have run through your 'Read and run me first' removal guide. Super Anti-spyware quarantined 2 threats, which appear to relate to Firefox. (Tried to open it to access your site, but it wouldn't open.) I can't get Root Repeal to run. I've attached a screen cap of the error message I get when I open it.

    I run Vista on a 32 bit OS, I did have Avira Anti-virus, but as their website was redirecting to Stopzilla, it seemed they might be compromised, so I've uninstalled that and installed AVG instead.

    I left the laptop on overnight running ComboFix and when I woke up my files were back. While that's reassuring, I'm a bit worried that it just means something nastier has bedded itself in. Any assistance would be gratefully received!
     

    Attached Files:

  2. Debitha

    Debitha Private E-2

    Virus quarantined - next steps? (2/2)

    And here's the log from MGTools.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You say all that was hidden is now visible again?

    Run this just to be sure.

    Please download and save the below to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it.


    Please disable Spybot's TeaTimer.

    How to disable Spybot's TeaTimer


    Java(TM) 6 Update 22 <--- Uninstall outdated Java.


    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    AntiVirSchedulerService
    Folder::
    c:\program files\Avira
    C:\Users\Owner\AppData\Local\temp\ZGTemp
    File::
    c:\users\Owner\AppData\Local\BIT843B.tmp
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\NoExplorer]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "avgnt"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  4. Debitha

    Debitha Private E-2

    Yeah, I've opened a few documents and so on, and looked through the folders, and everything seems to be in order, but there's a definite feeling of, "It's quiet. Too quiet." So I'm going to go and work through these most excellent instructions, and will let you know how I get on.

    Thanks for coming back to me!
     
  5. Debitha

    Debitha Private E-2

    TDSSkiller will not run. I got the .exe file from your link, and have tried renaming it, as well as temporarily de-activating the AV, but it just thinks about it for a bit, then does nothing.

    Should I skip that step and move on to Combofix? Or is there anything else I can do to get it to run?
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes do the Combofix step, and then:

    Try Kaspersky Rescue CD which has had good results in the past when TDSSKiller could not be run.

    Then try TDSSKiller again and see if it will now run for you.
     
  7. Debitha

    Debitha Private E-2

    I couldn't get past the agreement page, so I ctrl-alt-deleted, which brought up a menu. I selected 'logout' and now the laptop is completely unresponsive. Hard reboot doesn't achieve anything, with or without the disk in the drive.

    Help?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What agreement page?
     
  9. Debitha

    Debitha Private E-2

    Sorry, the End User License Agreement. I booted up with the disk in. It asked what mode, etc then took me to a page where you hit 'a' (or 'c' according to their support page) to agree that they aren't liable for anything. Neither 'a' nor 'c' (or 'r' to reboot or 'p' to shutdown) did anything at all.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sigh. I am seeking advice about this. Thanks for your patience.
     
  11. Debitha

    Debitha Private E-2

    Thank you for your help. It's not your fault it went a bit wrong.

    Somehow, anytime something technological goes wrong that I can't fix myself, it is inevitably spectacularly stuffed. :eek:(
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there can you try this?

    Do you have your Vista install disc? If not:

    Vista and Win7 Recovery disc

    To run the Bootrec.exe tool, you must start Windows RE. To do this, follow these steps:

    1. Put the Windows Vista or Windows 7 installation disc in the disc drive, and then start the computer.
    2. Press a key when you are prompted.
    3. Select a language, a time, a currency, a keyboard or an input method, and then click Next.
    4. Click Repair your computer.
    5. Click the operating system that you want to repair, and then click Next.
    6. In the System Recovery Options dialog box, click Command Prompt.
    7. Type Bootrec.exe, and then press ENTER.

    Then you can do this:

    Bootrec.exe /fixmbr
     
  13. Debitha

    Debitha Private E-2

    Right. I turned the laptop on to put the recovery disk in, and it booted right up with the Kaspersky. However. It wouldn't let me use the mouse, and although I was able to use keyboard commands to get it to scan the boot sectors and hidden files, it wouldn't scan the C drive, which I assume was the actual point of the exercise.

    TDSSkiller still won't work. Also, I tried to boot the Kaspersky again to see if it would behave this time, but it will only boot normally, even with the disk in.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. Did you follow my steps in post number 12?
     
  15. Debitha

    Debitha Private E-2

    >_>

    No, because the laptop started by itself, and I thought that step was to get it started again. I'll give it a shot later today. Sorry.
     
  16. Debitha

    Debitha Private E-2

    It seems to have done its thing. I got an immediate reply, "The operation completed successfully." It didn't seem to actually do anything, though. As in, the hard drive didn't seem to engage at all. Is that right? Shall I just close the Command Prompt window and Restart?
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Does TDSSKiller now run?

    Have you completed my steps back in post number 3 from combofix onwards? If so please attach the C:\MGlogs.zip. Also attach the log from TDSSKiller if you were finally able to run it.
     
  18. Debitha

    Debitha Private E-2

    Everything seems to be working.

    TDSSkiller ran, I've attached the log, and the ones for Combofix and MGTools.

    I've loaded up Firefox and that now works. All my files seem to be in place.

    How does it look?
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Little bit more to do now.

    We need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    mailKmd
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:000000b5
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  20. Debitha

    Debitha Private E-2

    Here we go!
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  22. Debitha

    Debitha Private E-2

    *clutches laptop tearfully*

    Thank you so much. I'm re-installing anti-virus and what have you now.

    I really appreciate your help and patience!
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Aww, you are very welcome. :) Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds