What else can I say...HELP

Discussion in 'Malware Help (A Specialist Will Reply)' started by Kiholo, Jan 4, 2011.

  1. Kiholo

    Kiholo Private First Class

    At the recommendation of plodr in the hardware forum, I have completed the steps as described in the malware removal guide and posting results here. The original thread in HW is titled "Various BSODs"

    The system is my sister's desktop. I'm sending from my PC.

    System:
    Dell Inspirion 530.
    BIOS Revision: 1-0-16; newer ver. 1.0.18 is available but I haven't installed
    OS: Vista 64-bit
    RAM: 6GB
    Virus Protection: She had none installed...ugh!

    A few weeks ago, sister attempt to install a BUNCH of MS updates as she noticed the UPDATE reminder in the taskbar. She isn't literate just a user...so can't recall exactly what she did or what happened. All she knows is since that time, several weeks ago--first part of December, systems has been flaky. She also claims the Internet doesn't work. Her approach to fixing these problems is to power off everything and start over again...that seems to work until lately.

    I've since taken system home and been trying to resolve issues.
    - No new devices have been installed.
    - Both Windows Mem Diag Tool as well as Memory Test detected no problems.
    - System is not connected to internet via my cable modem; sister had DSL connection.

    Initially, I began posting in the hardware forum because I noted a whole slew of BSODs after I had gone thru an initial run of the malware removal guide. The BSODs just kept popping up and prevented completion of some of the tests, i.e., combofix. Also, I tried to restore the system from several of the saved files but was not successful in getting the earliest one available. So instead, got whatever version/date would go thru to completion. I believe this is somewhere in the mid-December range. I also tried to use the recovery routines to no avail due to BSODs.

    There is no antivirus protection running on the system. I have access to McAfee VSE 8.7 but have not installed it due to BSODs.

    Anyway, here are the results of SuperAntiSpyware, Malwarebytes Anti-Malware, and MGTools. ComboFix would not run due to BSODs. These routines were all run while in SAFE MODE. I was able to run CCleaner without any problems.

    Thanks in advance and I will await responses.

    Happy New Year!!!

    Blaine
     
  2. Kiholo

    Kiholo Private First Class

    Didn't see the files attached.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You have outdated Java which we will deal with later. Malware first.

    Please disable Spybot's TeaTimer.

    How to disable Spybot's TeaTimer

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner, not the registry section, simply the cleaner.

    Reboot the machine, try to run combofix now in normal mode. If you can't, don't worry, but still in normal mode do the below:

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  4. Kiholo

    Kiholo Private First Class

    Kestrel13,

    Thank you for your assistance. Here's what I did and the results:

    1. Disabled Spybot TeaTimer...
    2. Ran MGtools per instructions.
    3. Copied and ran fixME; received SUCCESS MESSAGE
    4. Downloaded/ran Avenger with script. Here's where things fell apart...did not receive message upon reboot as BSOD's struck again. Attempted several times to run in normal windows. BSODs were various types: IRQL..., System Service Exception, and no specific reason other that preventing damage to computer explanations. I was not able to locate Avenger.txt in C:
    5. Ran CCleaner.

    FYI...most of the above was done in Safe Mode vs Normal Windows. I noted that starting with TDSSKiller, you indicate specifically to run in Normal Windows.

    Could my problems be related to a hardware failure, such as a bad or failing power supply?

    Should I continue to do the other tests but in safe mode?
     
  5. Kiholo

    Kiholo Private First Class

    I just looked into the Dell and I don't have a replacement PSU which has the correct power connectors for the HDD and DVDROM. Are these PSU's proprietary/specific to Dell?

    Thanks,
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    In normal mode, run TDSSKiller and then:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Then I will have a fresh look on what is going on and know best how to proceed.
     
  7. Kiholo

    Kiholo Private First Class

    Kestrel,

    Unfortunately, the system will not allow me to boot successfully to the desktop via normal windows. I have tried several times and gotten BSODs with various explanations/causes for stopping. The last one relates to "win32K.sys" another was "ntfs.sys", but the majority are IRQL related or no reason...just system shut down to prevent damage. Tell me if those explanations are important or if you want me to keep track of them or not.

    Whenever I can get to the desktop via normal windows, i am waiting for and letting all of the startup items load as an indicator of stability...probably a wrong assumption. Anyway, sometimes, the system will load all desktop icons and other times it doesn't get that far before BSOD. They even occur right after I log on. Each time I get a BSOD, I reboot into Safe Mode which hopefully allows the software to clear/address the problem encountered. I wait until the dialog box identifying the problem appears before rebooting the machine.

    This last go around, booted in safe mode, I attempted to go into control panel to minimize the items on my startup. When I clicked on control panel, it BSOD'd with "System Service Exception". When I reboot and press F8, the option "repair computer" appears. I've gone that route and hit a dead end when I am given the log on option "Other User". There are no other users defined on this machine.

    I await further instructions.
     
  8. Kiholo

    Kiholo Private First Class

    Kestrel,

    Hooray, persistence paid off. I was able to get a stable desktop in normal windows!

    Attached are requested files and although you didn't ask for it, I attached the MBR text which I also performed.

    Thanks,

    Blaine
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Looking MUCH better! :)

    Java(TM) 6 Update 11 <--- Uninstall this outdated Java.

    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    REBOOT the machine.

    Run Ccleaner after reboot.

    Install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    How are things running?
     
  10. Kiholo

    Kiholo Private First Class

    Kestrel,

    After running TDSSkiller, things really changed. System is stable and no BSODs seen since.

    Since sending my last response, I took liberty of going back to the first set of instructions you provided and picked up with Avenger. I ran it with the previous script; only thing is I could not find the .txt file.

    Next went on to CCleaner and TDSSkiller again and it found nothing...no rootkit this time.

    Did MBRcheck and MGtools.

    Things are running smoothly right now. I was able to install McAfee VSE 8.7.0, switched the internet to my cable connection, and updated the whole thing.

    When I tried to uninstall spybot, it didn't let me...said I was missing files and need to update. So, I went thru that update process and it is now running a full scan...about halfway thru.

    When it finishes, I disable or should I uninstall Spybotwill, run Avenger again with the new script, update Java, MGtools, and CCleaner. Do I need to run ComboFix somewhere in this list of steps?

    Thanks for the reminder regarding Java.

    Blaine
     
    Last edited: Jan 6, 2011
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do not run things out of order! It complicates things for us both. You need to run everything in my instructions in post # 9 in the order I list them please, THEN attach the requested logs.
     
  12. Kiholo

    Kiholo Private First Class

    Kestrel,

    My apologies for proceeding and not awaiting your guidance. I followed items listed in your #9 email. Attached are the logs.

    Things are running fabulously...I am using the repaired computer for this response.

    Thank you to you and your colleagues who contribute to this forum for all your assistance. Whenever I am confronted with a computer problem like this, I return and will continue return to this site.

    Happy New Year!

    Best regards,

    Blaine
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    But fresh malware is present. So make sure you follow my steps exactly and in the correct order.

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :files
    C:\ProgramData\5bfKKi5.dat
    C:\Program Files (x86)\kclczgyk.txt
    C:\Program Files (x86)\cxml.txt
    C:\toayn.txt
    C:\tsvsf.txt
    C:\Windows\ikmjrnu.txt
    C:\Windows\system32\dkonk.txt
    C:\Windows\SysWOW64\dkonk.txt
    C:\Windows\System32\drivers\cgbwbgn.sys
    C:\Windows\System32\drivers\jrzqsru.sys
    C:\Windows\System32\drivers\pfds.sys
    C:\Windows\System32\drivers\ppucc.sys
    C:\Windows\System32\drivers\sszdb.sys
    C:\Windows\System32\drivers\throtifg.sys
    C:\Windows\SysWOW64\drivers\cgbwbgn.sys
    C:\Windows\SysWOW64\drivers\jrzqsru.sys
    C:\Windows\SysWOW64\drivers\pfds.sys
    C:\Windows\SysWOW64\drivers\ppucc.sys
    C:\Windows\SysWOW64\drivers\sszdb.sys
    C:\Windows\SysWOW64\drivers\throtifg.sys
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Run this GMER - running with a random name and attach it's log.

    Rename Combofix.exe to magpie.com and run it. See how you get on.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  14. Kiholo

    Kiholo Private First Class

    Kestrel,

    I followed your instructions.

    Downloaded and ran OTM with code. Log is attached.

    Ran renamed GMER and combofix but I can't find either of the logs. GMER did have two entries listed. Combofix ran to completion as well.

    MGtools ran to completion. I had to run it twice since the first try ran into UAC which had been turned on. Log is for second run after turning off UAC and reboot.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your logs look clean. I suggest you go to add/remove programs > uninstall the below:

    • McAfee Agent
    • McAfee VirusScan Enterprise
    Then reboot. Please download the McAfee Consumer Product Removal Tool

    Run this > Reboot your machine > and Run it again to get rid of remnants of McAfee.

    If we renamed Combofix and MGTools please rename them back to their original names.

    Now follow final steps and then install whatever antivirus you are going to.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  16. Kiholo

    Kiholo Private First Class

    Again, Kestrel, thank you for your assistance.

    Blaine
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds