Avast corrupted, doesnt accept reinstall (NOT A WIN32 APP), Windows CRAZY! HELP!

I’m not sure where you are at, but I’m working off of your DSS log.

We’ll hit this guy with combofix from safe mode if possible.

Delete the copy of combofix you have now, we’ll use a new “special” one. We will also run it differently.

Before we start, please ensure that system restore is turned on

After you have read the instruction for downloading this copy, please see the end of the post for instructions on how we will start combofix.

It is vitally important that combofix is renamed before it is even started to download

Please download ComboFix from Here or Here to your Desktop.

Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop

[*]If you are using Firefox, make sure that your download settings are as follows:
-Tools->Options->Main tab
-Set to “Always ask me where to Save the files”.

[*]During the download, rename Combofix to Combo-Fix as follows:

http://i266.photobucket.com/albums/ii277/sUBs_/combofix/CF_download_FF.gif

http://i266.photobucket.com/albums/ii277/sUBs_/combofix/CF_download_rename.gif

[]It is important you rename Combofix during the download, but not after.
[
]Please do not rename Combofix to other names, but only to the one indicated.
[]Close any open browsers.
[
]Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix


[*]Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause “unpredictable results”.
[*]Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don’t know how to disable it, please ask.

[*]Close any open browsers.
[*]WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
[]Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
[
]If there is no internet connection after running Combofix, then restart your computer to restore back your connection.


[*]Please post the “C:\ComboFix.txt” along with a new HijackThis log for further review.

Note: Do not mouseclick combofix’s window while it’s running. That may cause it to stall

Open a new Notepad session (Do not use a Word Processor or WordPad). Click “Format” and be certain that Word Wrap is not enabled.

Copy and paste all the text in the quote box below into Notepad.

Click File, Save as…, and set the location to your Desktop, and enter (including quotation marks) as the filename: “CFscript.txt” . Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown at the bottom of this post.

KillAll::

File::
c:\windows\system32\drivers\srosa.sys

Rootkit::
c:\windows\system32\drivers\srosa.sys

Driver::
srosa

This will start ComboFix again.Close all browser/windows first. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HJT log.

Hi guys

After a long nite and day running scans and stuff, Im back to update you before preparing for another round of scans and tasks.

Stevens solution worked great here and finally I got safe mode recovered. Thanks a bunch, DavidR. :slight_smile:

Id like to make a note about the second link as I tried it - sUBs SafeBootKeyRepair-CF.exethe link is not valid. I searched there for another link but all references to that file pointed to that same invalid link (guess they didnt redirected to new location).


Once having the safe mode back, I sticked with previous suggestions.

.: Well, I proceed like I said above but seems it didnt work, at least for Kaspersky. The KIS directory is still there. I guess Norton didnt work as well. :frowning:

Any suggestions?

.: I proceeded like Tarq57 suggested. I did at first a fast scan then after I did a complete one. However, I made a silly mistake when running the complete one… I didnt set the options ok and the log I got from it was 36M sized as it covered all scan actions and files.

Infected or suspicious files were moved all to quarantine. Attached goes the fast scan log and the HijackThis log (20080413 1437).

NOTE: Its not the first scan I do that would get files from fixing tools like ComboFix and DSS considering either infected or suspicious. All of files detected by all tools were moved to quarantine or chest. Should I get them outta there? Are they really infected or are they safe?

.: I found another thread where it was suggested to download and run Symantec Fix Tool for Beagle MO (FxBgleMO.exe), which I had previously downloaded and then I decided to run it as I had found already some variations of Beagle on previous scans (wouldnt hurt to try). The tool ran ok and the result was negative. The log goes attached.

From other thread I got suggestions from Tech, as follows:

  1. Disable System Restore and reenable it after step 3.
  2. Clean your temporary files.
  3. Schedule a boot time scanning with avast with archive scanning turned on.
  4. Use SUPERantispyware and/or Spyware Terminator to scan for spywares and trojans. If any infection is detected, better and safer is send the file to Quarantine than to simple delete than.
  5. Test your machine with anti-rootkit applications. I suggest avast! antirootkit or Trend Micro RootkitBuster.
  6. Make a HijackThis log to post here or, better, submit the RunScanner log to to on-line analysis.
  7. Immunize your system with SpywareBlaster or Windows Advanced Care.
  8. Check if you have insecure applications with Secunia Software Inspector.

.: I started to follow then and so far I performed steps 1 to 3. Avast logs goes attached plus another HijackThis log (20080414 0030).

.: I noticed some files which were not caught on previous scans (even manual ones for specific folder or file) were pointed as infected on those recent scans I performed. I dont understand how come the same file to be scanned many times and to not be detected the infection.

Example: The file I suspect to be the bad guy since the start (the key for KIS) was scanned several times and only at the last boot-time Avast scan it got detected as a rookit.

I wonder how many more scans I will have to do till busting them all and to feel safe enough to get a back up done without fearing to carry on backup infected files which were not detected after more than 1 week of effort and hard work.

Well, thats it for now. By morning Im gonna check over here again and then will go on from step 4.

I dont know if Im doing the right things here or not. If any of you have something to add or manifest about the procedures done so far and to be done ahead, please feel free to post. All help and feedback are welcomed and quite needed.

Thank you all again for your attention and efforts on trying to help, as well for your patience.

Have all a great week.

last 2 logs…

Hi there oldman

Thanks for your post… You were posting while I was finishing mine with the updates from my situation so I didnt see it till now.

About Combofix, I tried to run it from before. Actually I saw that instruction at another thread and was one the very first things I ran here. It didnt work… the log from that attempt is here:

ComboFix 08-04-08.7 - Storm 2008-04-09 11:58:50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.447 [GMT -3:00]
Running from: C:\Documents and Settings\Storm\Desktop\Combo-Fix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

Another thing is that during the scans I ran after some of them detected files from ComboFix as being infected and they were put on chest. Im not sure if thats the reason I dont see it in Control Panel for being uninstalled.

How should I uninstall it then? Deleting the folder that is?

Id like to thank you very much for your attention and support. Its very late here (past 2am), Im exhausted and needing to sleep or else Id be around for a bit more to wait for you reply.

However, Id like to invite you to read my previous post with the updates, maybe it might help or change the procedures to follow next, as well Id like to ask of you if I should proceed with the steps from Tech after performing the task you just posted me or should I stand by and wait for your reply after I post the logs from ComboFix.

Another important question… is it safe to use pc for internet the way it is now infected?

Thanks again and talk soon

Hi, just delete combofix from the desktop. It doesn’t have to be uninstalled. The combofix quarantined files are not encrypted, so other scanners will detect and remove them.

I’ve looked at what you have posted before. A lot of files have been removed. The problem with most removal tools, is they show you what has been removed, but don’t log what they scanned. Combofix logs removed files as well as recently created files and folders. It also shows some reg keys and drivers. The combofix log you posted is incomplete. Perhaps it was interupted during the writting of the log.

The remaining steps in Tech’s post are not required at this time. You have done most of them already. You are now in the manual search and destroy portion. Don’t worry, we will still use tools. It’s now a matter of going through logs and finding, if any, left overs.

As far as the internet goes, that is difficult to answer. I know you had beagle, but with out a current combofix log, I have no way of knowing if there was anything else.

The method of infections of this type does not just arriv via email. The last two I encountered came from cracked programs. One of them AVG. Sort of a special bonus I suppose.

:slight_smile: Hi ZStorm :

You asked a couple of days ago about having multiple “Updates” of Sun Java;
each “Update” is actually a new “version”. Therefore, ALL “Update(s)/
Version(s)” other than the latest SHOULD be uninstalled, to enhance the
security of a computer ( does not help IF keygens or Cracks are installed ).
To periodically check as to IF you have the latest “Version”, visit
www.javatester.org/version.html .

Hi Spiritsongs :slight_smile:

Thanks a bunch for your info. I was almost sure those Java older stuff could be uninstalled but wanted to be sure. Sun could be nice and include a batch to remove previous versions/updates when installing the latest one or at least give a notice after installing that you can do it manually. Oh well… ::slight_smile:

Im gonna get rid of that extra weight here… thanks again. :slight_smile:

Hi oldman :slight_smile:

Bad news from Brazil land… Combofix didnt work. Again. :‘( :’( :cry:

I deleted it how you said… clicked on desktop icon and delete. I installed the new one exactly like you told me to.

About the 1st log, it was incomplete cause happened for the program to be interrupted.

" … The Combo-Fix didn’t work as well (report attached) as it crashed the system after prompting it was changing my pc clock… "
(thats part of my first post on this thread)

Well, the story repeated itself once again. Same thing happened here today when I tried to run Combofix. It loads the program, opens a window saying ‘attempt to creat a System Restore Point’, ok for that part, then says its scanning and few seconds later prompts a message ‘… has changed your pc clock…’ and BOOM! comes Windows blue screen and system restarts.

From your instructions I got confused if I should run Combofix first and after to move the script file and make it run again OR if I should move the script and run it just once like that. I picked the first option, but in the end would it make any difference as it restarts the system and then I couldnt run one and next the other on a sequel?

Anyway, at both attempts to run Combofix the result was the same. The logs go attached (one for 1st run and one for 2nd with the script moved) as well a HJT one for the moment after i performed the second run and restored the AV/Firewall setups.

NOTE: Combofix doesnt run at all on safe mode. I tried twice and all it does is to show the bar loading it and nothing more happens, no window opens or anything. I checked the Task Manager and the process was there but dead. Then I had no option besides to run it on normal mode.

So, what can we do now? ??? ??? ???

PS: The idea of cutting my wrists with a spoon is becoming more vivid on my mind as days pass by… :-X

Forgot to mention… I found out and downloaded at first Combofix and DSS after reading this thread (instructions by essexboy:

http://forum.avast.com/index.php?topic=33127.msg277088;topicseen#msg277088

You think it would be the case to run DSS again? If so, should I uninstall it and install again?

The way I wanted combofix ran was with the script. But that okay, we’ll leave it for now. Yes a new DSS log would be the way to go. The copy you have will be fine to use. There will only be a main text this tme. Please post that, we may be able to see what is going on. :wink:

As I got mistaken and you said you wanted the script option only… in addition of the fact Im persistant and wouldnt hurt to try it again… ::)… I repeated the process for Combofix (deleted, downloaded, created script), got into safe mode, dragged the script and… IT WORKED!!! ;D ;D ;D ;D ;D

Attached go the logs for Combofix and HJT.

You people should see the smile on my face :wink:

Looking forward for to your feedback oldman, and never enough to say it again… THANK YOU! :slight_smile:

Good for you! Are you seeing some improvement?

Theres some kaspersky left that should be uninstalled, we can clean up any left over folder after you uninstall it.

We have a little repair work to do.

Download RenV from the link below

  1. Save it to your Desktop.

http://download.bleepingcomputer.com/sUBs/Beta/RenV.exe


<pre>
----a-w         4,752,968 2005-12-20 10:33:06  C:\Downloads\MsgPlus-362146 - 20051231 .exe
</pre>

Open a new Notepad session (Do not use a Word Processor or WordPad). Click “Format” and be certain that Word Wrap is not enabled.

Copy and paste all the text in the code box above into the new notepad

Click File, Save as…, and set the location to your Desktop, and enter (including quotation marks) as the filename: “log.txt” . Using your mouse left button, drag the new file log.txt and drop it on the RENV.exe icon as shown at the bottom of this post. You may have to click the image below to animate it.

When finished, it shall produce a new log for you. Post that log in your next reply.

Oh yeah! Lots of improvement! ;D

Just after Combofix ran I got notices for many Windows updates, mostly security ones and a special one pointed to IE7. Im not sure if you remember but since the malware started the damage here, IE7 was being called to run and if let to run would cause the system to collapse (btw, those files from C:\WINDOWS\SYSTEM32\DOWNLD\ folder which were scanned as malware were created and loaded at those times IE went crazy after infection). Security Center was also compromised and giving an error message since the infection, saying it was unavailable. After the updates download and installation, system rebooted and so I was able to check them and see they working as good as new. I dunno in the end if was ComboFix or the Windows updates the responsible for getting them fixed. System in general appears to be running as good as before the infection.

Kaspersky wasnt successfully uninstalled so far. I tried many times the [b]Kaspersky Removal Tool /b, as you can see on my previous posts, ran it as it was supposed to, the program runs but it doesnt give any message or log for the result. What I get is to see the folder KAS still on my HD. I even tried it again today before performing the next task you gave me, but still no good. :frowning:

I also tried again the Norton Removal Tool, it ran like the other times but I have no idea if it really worked or if theres still left overs of Norton here.

Performed as instructed but I got a message in the running window… “could not find C:\Downloads\MsgPlus-362146 - 20051231 .exe”… it took a bit to finish to run and gave me the log.

I found it weird and checked the HD for that path and file… they were there then what was wrong? I took a closer look and saw you typed a SPACE after the files name and before the extension. I fixed the script and ran it again. Both logs go attached. (just in case goes both).

So, whats next master? :slight_smile:

Can you tell its safe for me to use internet? Do you think the malwares I got here compromised my sensitive data as I use on regular basis internet banking?

I didn’t type the fix, I used copy and pasted it from the combofix log. It was a vundo infected file that RenV was supposted to fix. RenV now shows no infected file. However it is strange that it “fixed” itself. I’d like you to submit that file to virustotal just to be sure vundo is trying to pull a fast one on us.

When we removed the rootkit, combofix may have repaired some reg key or setting that beagle was blocking or had changed. The security updates probably helped also.

The files in the downld folder where part of the beagle infection. Some probably where calling for reinforcements.

You should be fine for the internet, just be cautious as there may be a little left. Since I don’t know what you where infected with before I was involved in this thread, I would advise you not to do any on line banking from this computer until we are finished (soon). Also you should change all your passwords from a known clean computer.

Let’s leave the other avs for the moment as they don’t be appearing to be causing any problem right now and concentrate on getting your system as clean as possible.

Please test that file, then run this little scanner.

Please download Malwarebytes’ Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
[*]Make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.
[*]If an update is found, it will download and install the latest version.
[*]Once the program has loaded, select “Perform Quick Scan”, then click Scan.
[*]The scan may take some time to finish,so please be patient.
[*]When the scan is complete, click OK, then Show Results to view the results.
[*]Make sure that everything is checked, and click Remove Selected.
[]When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
[
]The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
[*]Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Is to this file you are talking about to be submitted - C:\Downloads\MsgPlus-362146 - 20051231.exe ??

If so, the site for Virustotal I found was http://www.virustotal.com/ - hope to be the right one - and the result goes as follows:

http://www.virustotal.com/reanalisis.html?3e4e4f498ca4bf75647e2f3569cac7fc


File MsgPlus-362146_-_20051231.exe received on 06.12.2006 20:15:53 (CET)
Current status: finished
Result: 1/25 (4.00%)
Compact Compact
Print results Print results
Antivirus Version Last Update Result
AntiVir - - -
Authentium - - -
Avast - - -
AVG - - -
BitDefender - - -
CAT-QuickHeal - - -
ClamAV - - Suspect.Zip
DrWeb - - -
eTrust-InoculateIT - - -
eTrust-Vet - - -
Ewido - - -
F-Prot - - -
Fortinet - - -
Ikarus - - -
Kaspersky - - -
McAfee - - -
Microsoft - - -
NOD32v2 - - -
Norman - - -
Panda - - -
Sophos - - -
Symantec - - -
TheHacker - - -
UNA - - -
VBA32 - - -
Additional information
MD5: e9363e91044abffc8740fc6a0fe388d3
SHA1: 8991f72601620d38288c164bd4b6c41ba5347544
SHA256: f17d4388e66d0a0b3a01621d5cd38eeffdd4a05b0bbf6395a36059913faf4471
SHA512: a91654ffe4a6ceade05d94c9fffa9b0e837085e477e8ee3808b756d9207ef7d27d43d536345d090570dea09526180de04b57579bba67f0800749978f049b6476

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.


I agree its quite strange file “fixed” itself… however, is it a Vundo or not? No matter yes or no, which are the implications of it?

This new info got me a bit uptight :o … another malware?

Concerning Malwarebytes’ Anti-Malware scan, Im gonna do it first thing in the morning and as soon as its finished, Im gonna report you back.

Right now its not as late in the nite as it has been for the last week for me to check out puter and perform tasks, but for sure its not an early time. Im quite dead (you can add exhausted and drained after 8-9 days fighting these bugs day and nite). In addition, I like and want to follow up every scan at close look. At the moment, Chip & Dale (my only couple of brain cells left alive) are snoring, so would be wise to wait for the morning.

Thanks a lot and I will report you soon, first thing when I get back from Morpheus embrace.

The file loos to be okay. The type of vundo you had , when it infects a file. it add a space. It will add one space each time it gets infected. I don’t think you have anything to worry about regarding that file. I just wanted to be sure. Sorry, I thought you had the link for virustotal.

Get some rest, do the scan. Talk to you later.

Hiya oldman

MBAM scan was done and took 13 minutes. I was imagining it to take 13 hours :smiley:

Nothing but 1 adware was found. Log attached.

The scan covered something like 6% of my objects here. I was wondering if a thorough scan would be appropriated. What do you think about it?

Waiting for your feedback :slight_smile:

You can do a thourgh scan if you wish, but first we’ll clean up the tools you used. We can get them again if needed. Just don’t want to have unneccessary detections. I don’t know how long the scan will take though.

But the first thing I’d like you to do, is run combofix again. It should run from ormal windows. Please heed the instructions regarding security programs. Please post that log.

Tools clean up.

  • Click start button, run, then copy and paste the following line into the box and click ok.

Combo-Fix /u

Please download OTMoveIt by OldTimer. Save it to your desktop and double-click OTMoveIt.exe to run it, then click the Clean Up button. You may get prompted by your firewall that OTMoveIt wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will delete all the tools you have downloaded plus itself.

  • Create a new restore point

You must be logged on to an administrator account
Go to Start - All Programs - Accessories - System Tools - System Restore.
Click Create a restore point, and then click Next.
In the text box labeled Restore Point Description, type a name for this restore point , click create

  • Remove old restore points
  • Go to Start - All Programs - Accessories - system tools. Launch the Disk Cleanup tool and let it run. When it finishes a box with tabs will appear, select the more options tab. On this tab you will find a section for System Restore. If you press the Clean Up button for that section, Windows will delete all restore points except for the most recent one.

Post back and we’ll look at removing the rest of KAV.

.: Agreeded about the thorough scan. If you say it can wait for other procedures, then it is. It was just a thought of mine to run it in the mean time between an instruction and the next.

However, I have to ask you for those:

  • The link you provided comes as invalid … Error 404 - Not Found… http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

  • Admin “only exists” and shows up when I get into safe mode OR when I boot system getting to run under DOS after CD boot or something. My login options on normal mode are myself and an extra one. Theres no such option to login as Admin besides under the safe mode login or CD system boot.

By morning Im gonna run ComboFix again according to your instructions and will post the log.

I aint sure about the Admin login so to run OTMoveIt as well the link for download is not ok.

Standing by for next instructions.

an administrator account

An account with administrator rights with work. From your DSS log, if this is you, then your account will do the trick.

Storm I[/I]

Sorry about the link, it’s an old one I didn’t get rid of. Here’s the correct one. Same program, author renamed it.

Double click OTCleanIt, click the Clean Up button.

You may get prompted by your firewall that OTCleanit/OTMoveIt wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will delete all the tools you have downloaded plus itself.

If you want to run the scan and have a nap go ahead.

Dunno why but ComboFix doesnt run on normal mode. I took care of disabling Avast! On-Access Protection and Windows Firewall. Those are the only 2 security tools I have for the moment. However, happens the same old thing… when ComboFix gets at the point when it changes pcs clock, it crashes the system, blue Windows screen and reboots.

I ran it on safe mode, which was the only option. As you didnt say anything that I should delete and download again ComboFix, I used the same one I had for the last time (the one with the script added). The log goes attached.

Done.

Done.

Im gonna proceed with the rest of instructions and will post you back.