Windows Vista Malware Removal Complete Failure

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Menaceofri, Jul 9, 2011.

  1. Menaceofri

    Menaceofri Private E-2

    Got kicked after i typed up a very long post and now its gone.. Followed windows Vista fix guide got nowhere Tried windows 7 malware removal. The issue is with my laptop shut down the primary problems but still getting google redirects empty start bar and hidden files all over the place System is very much still infected.

    1.SAS failed to install, Portable crashes after 5000 scans (2 threats) Skipped
    2.MBAM installed updated crashes after 25 seconds no scans made (afterwards it seems to be deleted as i have to install it and update it again to re run it) Skipped
    3.Combofx Get an alert about a Virut possible and contaminated file, deleted downloaded from place it mentioned same thing, try launching again it launches but hangs on scanning (let go for over an hour) Deleted redownloaded same results.
    4. Skipped rootrepeal as i'm running vista 64 bit
    5. Running MGTOOLS After getting an error about a missing file it continues to search for different things will post when it finishes or fails...Shortly after agreeing to the hijackthis acceptance Something kept opening a compose mail Window, as nothing in the guide refers to this i would close to, never got a scan completed finish on MGTOOLS it simply close and no log file exists where it should be.. Attempting to run it again but i believe this is enough information to get the ball rolling, Again no log files exist for any of the scans as they couldnt finish. Hoping for help in a big way ~Menace
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you tried running the scans in safe mode?

    Please download and save the below tool from Grinler @ bleepingcomputer to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Now see if you can find the items that seemed to be missing?

    Now try to run this:
    TDSSkiller - How to run

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator


    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif


    * Double-click on the Rkill desktop icon to run the tool.
    * If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    * A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    * If not, delete the file, then download and use the one provided in Link 2.
    * If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    * Do not reboot until instructed.

    If you are having problems running Rkill, you can download iExplore.exe or eXplorer.exe, which are renamed copies of Rkill.com, and try them instead.

    Try to at least get me an MGLogs.zip.
     
  3. Menaceofri

    Menaceofri Private E-2

    Previous to this Post i did tried to use tdsskiller and nothing happens when i clikc it, ive tried probably 10 different downloads of it, which makes me feel it is a patching virus (also why all of my other programs close) I have tried all steps in safemode and normal mode with the same results.

    RKill ran and terminated one process which was mbamgui.exe plus its svchost.exe will try mgtools again and hopefully get you that log.

    Also unhide seemed to work but due to a failed guide on the vista fix i think my shortcuts were all deleted (it had me clear my temp folder) Aslong as i get the rest of this virus gone I can worry about the little stuff at a later date. post in 5 when the mgtools finishes.
     
    Last edited: Jul 9, 2011
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you shouldn't have run any temp cleaning software. Sigh. Get me an MGLogs.zip otherwise I will only be able to give you links to cleaning discs that you could create and try to get them to work.
     
  5. Menaceofri

    Menaceofri Private E-2

    Same result i'll switch it over to safe mode and try running rkill and mgtools again it simply closes after getting the system information which i assume is very close to the end.

    Are cd's the only way to fix this issue after this point? I've read about dr webs livecd or whatever and was going to try that however i cannot write the bootable as a dvd (nero wont let me) and unfortunately thats all i have.

    I can live without the start bar, not being able to run most of my programs or google searches just makes thing difficult as that is basically my internet browsing computer

    UPDATE* Safe mode returned much worse results for RKILL, blue screen errored and automatic shutdown of the system, didnt have time to read the cause
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your Vista install cd? We may need to have you boot into the Recovery Environment and do a:
    bootrec.exe /fixmbr
     
    Last edited: Jul 9, 2011
  7. Menaceofri

    Menaceofri Private E-2

    Unfortunately not its my roomates computer it is one of those that came preloaded with windows but with no cd's or anything. He bought it before he went to iraq in '07 or so.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have another computer you can use to create a Recovery disc?
     
  9. Menaceofri

    Menaceofri Private E-2

    I have this computer but it uses windows xp not vista. and the two computers in the living room are windows 7. It can burn but i assume those bootable cd's will also have to be cd's and i cant burn them on a dvd also. Do you feel a livecd by dr web would solve my issues? I'm assuming its a virut that i'm infected with based on all of the applications crashing. But i know little about these infections.
     
  10. Menaceofri

    Menaceofri Private E-2

    Im not sure how big the file should be if it was logged properly, this seems excessively small but i did find a logs file on my computer it just wasnt where i thought it would be. let me know if this helps.

    EDIT: I'm not sure how helpful this will be, i've never seen a prompt that actually said it was finished, maybe the other programs are doing something similar and just closing for some reason rather than telling me? Wishful thinking :x
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please go to C:\MGTools\analyse.exe and run it(Note: if using Vista, don't double click, use right click and select Run As Administrator). I want to see that log.

    I am not finding much in your logs, but let's do this:
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now see if you can get any of the other scans to run.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  12. Menaceofri

    Menaceofri Private E-2

    Again had everything all typed up and it decided not to post /sigh
    Avenger.exe gave back a log of deleting everything can attach if you like, Have started running all of the other scans again
    1.Analyze.exe gives an error that it cannot find the file or that i dont have permission to use it (am using run as admin)
    2.TDSKILLER same result doesnt open up, have used the same file on this unaffected pc and it opens just fine.
    3. MBAM
    4.Combofix
    5.MGTOOLS

    Will post results on the other scans when they happen (this is to let you know i am actively working on it).
     
  13. Menaceofri

    Menaceofri Private E-2

    Okay well i cannot edit that one any longer
    RKill KilledAdobe Reader 9.0 and its associated driver
    MBAM Actually ran this time Quickscan 170,000 Items Scanned 0 infections
    SuperAnti Spyware Installs now updated No memory items no registry scanned 5000 items Locked up, Skipping
    Combofix At stage 4 PEV.CFXXE stopped working (it has never gotten as far as stages previously) After a half hour of 0 activity I checked computer Completely frozen, Cannot do anything with computer hard shutdown required (last output from it was completed stage_16 Will rerun it see if I get different results. This time it froze after completed stage 2, again computer completely unresponsive, Skipping
    Attempted to delete MGTools Folder to get a fresh install however i dont have permissions even though i am administrator.. Will run mgtools again and post the log when i have it.
     
  14. Menaceofri

    Menaceofri Private E-2

    The only two that finished and found anything (combo logs didnt finish)
     

    Attached Files:

  15. Menaceofri

    Menaceofri Private E-2

    Now its freezing before even giving combofix a half hearted try, browserdefender is shooting all tons of errors and explorer continually crashes and i'm not using the computer to do anything. How could i go about fixing this outside of malware removal without the documentation for a clean format?
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Without having the installation cd, you are going to be stuck. I can give you a link for doing a repair install, but you would first be advised to backup your files and data. You may need to try to find a cd that you can borrow of the same version as what you have installed.
    http://www.vistax64.com/tutorials/88236-repair-install-vista.html

    In the meantime:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  17. Menaceofri

    Menaceofri Private E-2

    So I was able to actually watch MGTOOLS this time, analyze.exe access denied, attempting to gather system restore information access denied then crash a second lags. Heres are the logs from MBRCheck and MGTOOLS Anything i can do about the access denied bit or is that part of this virus? Also the avenger sucessfully deleted all of those.
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have an MBR infection and we need to be able to get into the Recovery Environment to fix it. You will need to create a disc to access the RE. The links for creating such a disc have been removed. So you need to find a Vista install disc. See if you can borrow one. If you can:

    To run the Bootrec.exe tool, you must start Windows RE. To do this, follow these steps:

    1. Put the Windows Vista or Windows 7 installation disc in the disc drive, and then start the computer.
    2. Press a key when you are prompted.
    3. Select a language, a time, a currency, a keyboard or an input method, and then click Next.
    4. Click Repair your computer.
    5. Click the operating system that you want to repair, and then click Next.
    6. In the System Recovery Options dialog box, click Command Prompt.
    7. Type Bootrec.exe /fixmbr, and then press ENTER.

    Exit out and re-run MBRCheck.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    *** Please print these instructions ***

    1. Download Hiren's BootCD Iso to the desktop of a clean computer.
    2. Extract the zipped HirensBootCD.zip to your desktop.
    3. Open the extracted HirensBootCD folder and extract the zipped HirensBootCD.iso.
    4. Double click the BurnToCD.cmd bat file contained in the HirensBootCD folder. This will launch BurnCDCC.
    5. Insert a blank CD in your drive.
    6. Press Start. This will burn the image to disc. After it has completed...
    7. Restart your sick computer and boot from the HBCD you created.
    o If your PC is not booting from the CD, you need to change the boot order:
    + Restart your PC
    + As soon as you get an image, press the Setup key. This is usually F2, F10, F12 or Del. On some machines the key can also be a different one. It should, however, be stated on the screen which key is the setup key.
    + Once you enter the computer's BIOS, use the arrow keys and tab key to move between elements. Press enter to select an item to change.
    + Navigate to the tab, where you can set the boot order. It should be called Boot or Boot order
    + The tab should now show your current boot order.
    + If the CD-drive is not at the top, please navigate to the CD-Rom drive with the keys arrows. Then move it to the top of the list. The keys for switching boot position are usually + to move up and - to move down. However they can be different, but they should be stated in the help, so that you can find them easily.
    + Once the CD-drive is on top of the boot order, navigate to Exit and select Exit saving changes.
    o Your PC should now boot from your CD.
    o Click to select any options that are required to start the computer from the CD-ROM drive if you are prompted.
    8. When the CD boots choose "DOS BootCD".
    http://noahdfear.net/10.2_startup.gif
    At the Hiren's BootCD main menu, select Next and hit Enter.
    http://noahdfear.net/main_menu.gif
    At the second menu select 1 MBR (Master Boot Record)Tools
    http://noahdfear.net/menu2.gif
    In the list of MBR Tools select 1 MBR Work 1.08
    http://noahdfear.net/mbr_tool.gif
    This screen will show the hard drive configuration.
    http://noahdfear.net/mbr_tool_fix.gif
    Type 5 to Install standard MBR code then hit Enter
    Type 1 to select Standard then hit Enter
    Type Y then hit Enter to confirm
    Type E then hit Enter to exit
    Press Ctrl+Alt+Del to restart the machine
     
  20. Menaceofri

    Menaceofri Private E-2

    sorry it took me a few days to get a cd to do this, i did what you said im not sure it actually did anything however. You didnt actually say what to do after this either. All of the steps of this last section were pretty instant. Couldnt do the one previous as i do not have access to a vista cd.

    Guessing what i was supposed to do i ran mbr check again and it said windows xp mbr code detected, instead of the infection bit. which is weird because its windows xp... but thats better than an infection lol. Whats the next step, or is a vista cd still my only option?
     
  21. Menaceofri

    Menaceofri Private E-2

    Running combofix almost immediately gave me an update that my computer is infected with rootkit.zero.access! or something like that, really tired but ill let you know if combo fix is frozen when i wake up :x
     
  22. Menaceofri

    Menaceofri Private E-2

    After that error it gave me another couldnt locate exact match need to do an intense search or something like that. at some point during the night combo fix froze again. The google redirect portion of my problem seems to be gone, not sure how to replicate the other problems to see if they still persist or not.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip
     
  24. Menaceofri

    Menaceofri Private E-2

    here is the two you wanted most recently. I can also run tdsskiller. it find one but it cant cure it so i quaranteend it.
     

    Attached Files:

  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. However, if you want to fix the MBR to reflect the Vista install, we have found a new link for creating a Recovery Environment disc (choose your version re: 32 or 64 bit ):

    http://digiex.net/downloads/downloa...6-windows-vista-32-bit-x86-recovery-disc.html
    http://digiex.net/downloads/downloa...7-windows-vista-64-bit-x64-recovery-disc.html

    To run the Bootrec.exe tool, you must start Windows RE. To do this, follow these steps:
    1. Put the Windows Vista or Windows 7 installation disc in the disc drive, and then start the computer.
    2. Press a key when you are prompted.
    3. Select a language, a time, a currency, a keyboard or an input method, and then click Next.
    4. Click Repair your computer.
    5. Click the operating system that you want to repair, and then click Next.
    6. In the System Recovery Options dialog box, click Command Prompt.
    7. Type Bootrec.exe /fixmbr
    and then press ENTER.
     
  26. Menaceofri

    Menaceofri Private E-2

    I dont think that part matters thanks for all of your help you can close this thread or delete it or whatever you guys do. :) Computer is working as good as an old computer can be expected to :)
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds