Adlice forum

General Category => Malware removal help => Topic started by: Louis Lata on June 19, 2017, 05:32:20 PM

Title: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Louis Lata on June 19, 2017, 05:32:20 PM
Rogue Killer has been able to detect Adw.Yelloader, ntuserlitelist, dataup, and svcvmx but upon reboot they are all still there and svcvmx continues to clone itself and eat up my memory, any advice?

Edit : Added RogueKiller JSON report.
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Curson on June 19, 2017, 05:41:36 PM
Hi Louis,

Welcome to Adlice.com Forum and thanks for supporting our product.

Please download Farbar Recovery Scan Tool (x64) (http://download.bleepingcomputer.com/farbar/FRST64.exe) and save it to your Desktop.
Regards.
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Louis Lata on June 20, 2017, 12:55:11 AM
FRST  & Addition
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Curson on June 20, 2017, 01:00:04 PM
Hi Louis,

Please uninstall TeamViewer if you haven't installed it.

Download attached fixlist.txt file and save it to the Desktop.
NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system !

Run FRST and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please attach it to your reply. A file using the Date_Time.zip notation should have been created, please attach it as well.

How is your computer running ?

Regards.
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Louis Lata on June 21, 2017, 06:01:19 PM
Computer seems to be running fine i don't see any of the  programs running found in the ntuserlitelist folder (Dataup,svcvmx,retool,winscr), But the ntuserlitelist  folder is still there (AppData\Local\ntuserlitelist).
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Curson on June 21, 2017, 06:31:40 PM
Hi Louis,

The infection is not completely gone.

Download attached fixlist.txt file and save it to the Desktop.
NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system !

Run FRST and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please attach it to your reply.

Regards.
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Louis Lata on July 01, 2017, 12:46:40 AM
Here is the Fixlog
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Curson on July 02, 2017, 09:50:02 AM
Hi Louis,

It's still here. We are going to use another method.

Please restart your system in Safe Mode with Networking (https://support.microsoft.com/en-us/help/12376/windows-10-start-your-pc-in-safe-mode).

Download attached fixlist.txt file and save it to the Desktop.
NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system !

Run FRST and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please attach it to your reply.

Regards.
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Louis Lata on July 03, 2017, 05:19:40 PM
Fixlog
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Curson on July 03, 2017, 05:40:13 PM
Hi Louis,

It was a long time since I saw such resistant malware.
Could you please generate new FRST.txt and Addition.txt reports ?

Regards.
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Louis Lata on July 03, 2017, 07:50:18 PM
Here is the new Addition and FRST.

Thanks
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Curson on July 03, 2017, 08:47:25 PM
Hi Louis,

Let's give Safe Mode another try.
Please restart your system in Safe Mode with Networking (https://support.microsoft.com/en-us/help/12376/windows-10-start-your-pc-in-safe-mode).

Download attached fixlist.txt file and save it to the Desktop.
NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system !

Run FRST and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please attach it to your reply.

Regards.
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Louis Lata on July 03, 2017, 09:15:30 PM
New Fixlog
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Curson on July 03, 2017, 09:34:02 PM
Hi Louis,

It seems that FRST is unable to set proper permissions on some files / registry keys.
I must speak to the developper of the tool before proceding any further.
Please attach the contents of TDSSKiller.[Version]_[Date]_[Time]_log.txt found in your root directory (typically C:\) in your next reply.

Regards.
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Louis Lata on July 03, 2017, 09:57:24 PM
Everytime i click it i get a error says, Resource is in use
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Curson on July 03, 2017, 10:25:59 PM
Hi Louis,

I think the malware is preventing TDSSKiller kernel-mode driver to launch. Let's try another tool.
Please follow the instruction in shadowwar post (https://forums.malwarebytes.com/topic/198907-requested-resource-is-in-use-error-unable-to-start-malwarebytes/) and attach MBAR log with your next reply.

Regards.
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Louis Lata on July 04, 2017, 03:38:06 AM
Mbar log
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Curson on July 05, 2017, 10:05:44 AM
Hi Louis,

The tool removed some troublesome keys.
Could you please generate a fresh FRST log ?

Regards.
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Louis Lata on July 07, 2017, 05:07:21 AM
FRST Log and Addition if needed
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Curson on July 08, 2017, 11:24:43 AM
Hi Louis,

The malware is still present.
A new build of MBAR should take care of it.

Please download MBAR 1.09.4.1001 (https://malwarebytes.app.box.com/s/h72aj6mp6rkshh7lk0u7msx810wz75jl), then follow the instructions in shadowwar post and attach the reports with your next reply.
Please make sure to hit the "Update" button to update MBAR databases.

Regards.
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Louis Lata on July 09, 2017, 03:04:49 AM
Hi im having a problem completing the scan, it freezes and stops responding also the amount of malware it has detected is extremely high.
Attached is a screen shot
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Curson on July 09, 2017, 06:16:57 PM
Hi Louis,

Does the software unfreeze when waiting long enough ?
This infection drops many files, so it's not unusual for MBAR to detect such an amount of malware.

Regards.
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Louis Lata on July 13, 2017, 06:16:13 AM
Hi sorry for the late reply, the longest i waited was about 2 hours and with no success of responding
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Curson on July 13, 2017, 10:52:39 AM
Hi Louis,

Don't worry about the late reply, it's no big deal.
There is definitely a bug with this version of MBAR. Could you please download this one (https://downloads.malwarebytes.com/file/mbar/) and try again ?
Please make sure to hit the "Update" button to update MBAR databases before launching the scan.

Regards.
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Louis Lata on July 13, 2017, 04:21:28 PM
Hi i was able to get a full scan and cleanup overnight attached is the mbar log
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Curson on July 13, 2017, 04:52:38 PM
Hi Louis,

It seems that MBAR was able to kill the rootkit.
Could you please redo a FRST scan ?

Regards.
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Louis Lata on July 13, 2017, 08:40:56 PM
FRST log attached
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Curson on July 13, 2017, 10:06:54 PM
Hi Louis,

The log confirms that the infection is gone. Your system is now clean.
You can remove MBAR, FRST and related files/folders.

Regards.
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Louis Lata on July 14, 2017, 12:15:38 AM
Great! thanks so much, you guys are Awesome!
Title: Re: ntuserlitelist,SVCVMX Found but not removed after reboot
Post by: Curson on July 14, 2017, 12:25:49 AM
Hi Louis,

You are welcome. Thanks for the kind words.
I'm glad we were able to help you.

Regards.