Author Topic: Reported threat hidden or non-existant  (Read 18835 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Reported threat hidden or non-existant
« Reply #30 on: September 12, 2010, 07:11:55 PM »
OK so it needs to be removed at the kernel level - lets now get it off your system

  • Download OTC to your desktop and run it
  • Click Yes to beginning the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.


Could you now confirm it really has gone  ;D

CarlS

  • Guest
Re: Reported threat hidden or non-existant
« Reply #31 on: September 12, 2010, 07:34:33 PM »
I ran OTC and rebooted the system per your instructions.
The threat is still there in the C:\Avenger folder.

--Carl

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Reported threat hidden or non-existant
« Reply #32 on: September 12, 2010, 09:06:59 PM »
If you could now delete the Avenger folder please

CarlS

  • Guest
Re: Reported threat hidden or non-existant
« Reply #33 on: September 12, 2010, 09:30:27 PM »
It can not be deleted.
When I select C:Avenger and press delete, a window titled "Error Deleting File or Folder" opens saying "Cannot delet nul: The parameter is incorrect".

--Carl

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Reported threat hidden or non-existant
« Reply #34 on: September 12, 2010, 09:31:43 PM »
Can you rename the nul subfolder ?

CarlS

  • Guest
Re: Reported threat hidden or non-existant
« Reply #35 on: September 12, 2010, 09:47:47 PM »
The same window opens saying "Cannot rename nul: The parameter is incorrect"

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Reported threat hidden or non-existant
« Reply #36 on: September 12, 2010, 10:08:33 PM »
OK sussed out why - that is a reserved name within 2k and as such windows will not allow you to delete it

I will have to do more investigation for a work around.  But it is not active since we deleted the control sets

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Reported threat hidden or non-existant
« Reply #37 on: September 12, 2010, 10:15:50 PM »
And as I speak I have found an old MS article about deleting reserved names lets give this a go

Type the following at either a command prompt in safe mode or from the run command

RD \\.\c:\Place here the path to the nul folder in avenger

CarlS

  • Guest
Re: Reported threat hidden or non-existant
« Reply #38 on: September 12, 2010, 10:30:07 PM »
I entered the following from the Run command:
Quote
RD \\.\c:\Avenger\knlps2\nul

A window opened saying:
Quote
Cannot find the file 'RD' (or one of its components).  Make sure the path and filename are correct and that all required libraries are available.

--Carl

CarlS

  • Guest
Re: Reported threat hidden or non-existant
« Reply #39 on: September 12, 2010, 10:59:22 PM »
For a test case, I made the following folder structure:
C:\TempFolder\TEMP

I then opened a cmd window and entered:
RD \\.\c:\TempFolder\TEMP

That worked.



I then tried:
RD \\.\c:\Avenger\knlps2\nul

The response was:
Access is denied.



I then tried:
RD \\.\c:\Avenger\knlps2

The response was:
The directory is not empty.


--Carl

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Reported threat hidden or non-existant
« Reply #40 on: September 12, 2010, 11:29:30 PM »
Back to the drawing board - more research here I feel.  Can you delete the files within the nul folder ? 

CarlS

  • Guest
Re: Reported threat hidden or non-existant
« Reply #41 on: September 12, 2010, 11:58:34 PM »
I can not see or delete anything within the nul folder.
I can only see the directory and file structure in the Avast threat report, but when I try to apply an action, Avast says it can not find the file.

Are the usr and bin folder names reserved by windows like nul?
If so, that may be complicating the situation.



--Carl - appreciating all the effort on this
« Last Edit: September 13, 2010, 12:05:54 AM by CarlS »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Reported threat hidden or non-existant
« Reply #42 on: September 13, 2010, 09:14:56 PM »
OK lets now use Combofix with the reserved name indicator and see if that can do it

Download ComboFix from one of these locations:


Link 1
Link 2


1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

Quote
KillAll::

Folder::
\\.\c:\Avenger\knlps\nul\usr\bin
\\.\c:\Avenger\knlps2\nul\usr
\\.\c:\Avenger\knlps2\nul

3. Then in the text file go to FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES

4. Save the above as CFScript.txt

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below.  This will start ComboFix again.




6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt .
« Last Edit: September 13, 2010, 09:17:04 PM by essexboy »

CarlS

  • Guest
Re: Reported threat hidden or non-existant
« Reply #43 on: September 14, 2010, 05:40:41 AM »
OK, tried that, attaching the log file.

The folder structure is still there.

--Carl

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Reported threat hidden or non-existant
« Reply #44 on: September 14, 2010, 09:21:40 PM »
One more run with Combofix to see if it will delete Avenger, after this the only other option is to remove it from outside windows either via Linux or a Bart disc

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

Quote
KillAll::

Folder::
c:\Avenger

3. Then in the text file go to FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES

4. Save the above as CFScript.txt

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below.  This will start ComboFix again.




6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt .