win32/patched.fs & fr virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by amberH, Apr 9, 2011.

  1. amberH

    amberH Private E-2

    Hello,
    I have a win32/patched.fs. and fr virus.
    I'm running AVG (was 2009 - updated to 2011 last night).
    My system is running XP Media Centre Edition 2002 SP 3.

    I've googled extensively, but the only successful fixes I've found are specific to each user - their doesn't seem to be a generic fix.

    Steps I've followed based on your site instructions:

    1. Uninstalled MyWay Search Assistant
    2.Removed all versions of Java - installed version 6 update 24.
    3. Ran CCleaner on both user accounts
    4. Adjusted folder settings so hidden files, extensions & system files are visible
    5. Changed MSConfig to Normal Startup
    6.Ran SAS - (no malware found - this is because I had ran SAS & MalwareBytes before beginning the steps on your site - I went back and reran to ensure I had every step covered off). I've attached both logs - I'm not sure if it's relevant what was found the first time or not.
    7. Ran MalwareBytes (had ran 3 times total - all 3 logs attached)
    8. Ran ComboFix (was forced to uninstall AVG in order for this to run) - uninstall said it was successful, but ComboFix won't run - it says AVG is still installed, and must be uninstalled before the tool can be run.
    9. Ran Root Repeal - it finished, but at the end displayed the error message "Root repear error: Error - on - disk corruption detected - run chkdsk!" Logs attached.
    10. Ran MGTools - log attached

    * had to rename not just the MB exe file in order for it to run, but also SAS & ComboFix

    Thanks for your help!

    Amber
     

    Attached Files:

  2. amberH

    amberH Private E-2

    Here are the rest of the attachments.

    Amber
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I suspect a Ramnit infection, but let's see what happens.

    Ask Toolbar <--- Uninstall this.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    • F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Program Files\tyyiagyl“RÌ”Ëeierinpe.exe\eierinpe.exe,
    • O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    • O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
    • O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
    • O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
    • O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    • O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
    • O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    • O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    • O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    • O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} (Java Plug-in 1.4.2_03) -
    • O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.5.0_06) -
    • O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} (Java Plug-in 1.5.0_09) -
    • O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.5.0_11) -
    • O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.6.0_01) -
    • O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} (Java Plug-in 1.6.0_22) -
    • O20 - Winlogon Notify: avgrsstarter - Invalid registry found

    After clicking Fix exit HJT.


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    
    :reg
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Userinit"="c:\windows\system32\userinit.exe," 
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    
    :files
    C:\Documents and Settings\All Users\Application Data\106v50l53jpe0d87ue1i
    C:\Program Files\tmp
    C:\Program Files\tyyiagyl“RÌ”Ëeierinpe.exe
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run this and attach the results.

    Using ESET's Online Scanner

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  5. amberH

    amberH Private E-2

    Thanks for your help!

    I uninstalled the Ask Toolbar.

    AVG is still uninstalled - I haven't reinstalled since ComboFix asked me to uninstall. So currently there is no antivirus, and no active antimalware program.

    Ran HijackThis and fixed all files you listed.

    While running OTM, received the message:OTM: OTm.EXE - corrupt File: The file or directory C:\Documents and Settings\Jack\Local Settings\Temp\WEReb92.dir00\firefoxexe.hdmp is corrupt an dunreadable. Please run the Chkdsk utility.
    I got it several times.
    I've attached the OTM log.

    Ran CCleaner.

    Ran ESET's online scanner. Log attached.

    Ran GetLogs.bat - log attached.

    Cheers,
    Amber
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Another two ESET scans please, back to back, and attch the logs.
     
  7. amberH

    amberH Private E-2

    Oh oh!
    Last night I turned the computer off.
    When I turned it on this morning, it won't boot into Windows.
    I get the following:

    STOP: c000021a {fatal system error}
    The Windows Logon Process system process terminated unexpectedly with a status of 0X0000005 (0X0000000 0X0000000).
    The system has been shut down.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then until you are back up and running, I cannot help you :( You would be better off posting in the software forum about this new issue :) Then return here.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like your infected system files may have been deleted. You will need to boot into the Recovery Console and replace the C:\WINDOWS\system32\winlogon.exe file which is probably now missing.
     
  10. amberH

    amberH Private E-2

    Can I just replace this file by copying from an XP disk?

    And if so, does it have to be the exact same version (Media Centre 2002 SP3) ?

    Thanks!

    Amber
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is what I was saying. You need to do it from the Recovery Console.

    Yes this would be best otherwise you could have an outdated version, but any version will be better than none.
     
  12. amberH

    amberH Private E-2

    I'm assuming other critical files were removed in the malware cleanup.
    Now the PC will boot again, but in regular mode or safe mode - as soon as Windows starts up I get an error:

    Windows Explorer has encountered a problem and needs to close.
    If I click 'Don't send error report' - I never get any further - Windows never finished loading.


    Amber
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your C:\Windows\explorer.exe file could still be infected. It would be a good idea to boot to the Recovery Console and replace it with a clean copy too.


    Then boot up Windows and try running the below.

    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.
     
  14. amberH

    amberH Private E-2

    Okay! I ended up doing an in-place Windows reinstall - without losing any data.
    It seems to have resolved most issues.

    I ran ESET twice more.
    The log from the first time is attached.
    The 2nd time it was clean, and there was no log.

    Thanks :)
    Amber
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excellent. Looks like you caught the Ramnit infection before it spread too far to be able to fix.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds