8+ different viruses over 2 weeks... rootkit?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by blueflame678, Dec 30, 2010.

  1. blueflame678

    blueflame678 Private E-2

    On 12/16 my computer was infected while someone was on here using Google Chrome. Ever since then, my antivirus has picked up new threats every day or two on my computer. Each time I uninstall viruses and trojans, I seem to get new ones shortly. I was using AVG, Avira, Microsoft Security Essentials, and Malwarebytes. After following the directions to only keep one anti-virus I removed AVG.

    I have spent all day today going through the directions and trying to fix my computer. I was unable to run combofix, but the rest of the directions I have followed (upgraded Java, got logs, used CCleaner, etc.) I am left wondering if I maybe have a rootkit buried deep in my system that keeps trying to install new viruses/trojans all the time.

    In case this helps, here is a history of identified threats below.

    History of Viruses that were identified which my various softwares quarantined/deleted:
    Win32/Kryptik.IHR on 11/20/2010 [had this a while back]
    Win32/Bredolab.AC on 12/16/2010
    Win32/Bredolab.AC on 12/17/2010
    Trojan Horse Generic20.ATDB on 12/21/2010
    Spy.Agent.blsy on 12/22/2010
    Trash.Gen on 12/22/2010
    Drop.Softomat.AN on 12/22/2010
    Fake.SpyPro.67 on 12/23/2010

    Exploit:Java/CVE-2009-3867.BW on 12/29/2010
    Exploit:Java/ByteVerify on 12/29/2010
    Exploit:Java/CVE-2008-5353.FJ on 12/29/2010
    Exploit:Java/CVE-2009-3867.ER on 12/29/2010
    TrojanDownloader:Java/OpenConnection.AX on 12/29/2010
    Exploit:Java/CVE-2010-0830.W on 12/29/2010
    Exploit:Java/CVE-2009-3867.BY on 12/29/2010

    Malware Bytes detected multiple Trojan Banker files over the past week (in logs)
     

    Attached Files:

  2. blueflame678

    blueflame678 Private E-2

    2 more MBAM logs
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Then you stil have too antivirus programs installed which is not acceptable. Microsoft even warned you about this when you installed it. You must immediately uninstall either MSE or Avira and then reboot.

    What exactly happens when you run it? Problems could be due to having multiple antivirus programs installed and running.

    Do you know what the below folders are for? What is in them?
    Code:
    "C:\WINDOWS\system32\"
    5005          Sep 29 2010              "5005"
    5006          Oct  4 2010              "5006"
    
    You have a bunch of left overs from uninstalled security programs to cleanup along with a few other minor items to remove.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-unins...MTArMS1GMTBNMTBEKzE"&"prod=90"&"ver=10.0.1187

    After clicking Fix, exit HJT.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    I still would like to see if you can get ComboFix to run now after having only one antivirus progam installed and also after shutting your AV down.
     
  4. blueflame678

    blueflame678 Private E-2

    Have not had computer access for a while, but catching up with your directions.

    1. Ok I removed MSE and rebooted.

    2. I went into folder 5005 and found
    C:\WINDOWS\system32\5005\install.rdf
    C:\WINDOWS\system32\5005\components\AcroFF.txt

    I double clicked it and got instantly hit with Avira
    The file 'C:\WINDOWS\system32\5005\components\AcroFF.dll'
    contained a virus or unwanted program 'TR/Spy.Agent.bnal' [trojan]

    5006 has
    C:\WINDOWS\system32\5006\install.rdf
    C:\WINDOWS\system32\5006\chrome.manifest
    C:\WINDOWS\system32\5006\components\AcroFF.txt


    Will work through the other steps now.
     
  5. blueflame678

    blueflame678 Private E-2

    Logs attached. Looks like I still have the virus buried in my computer. So I have had this since September? All of my personal files/accounts I must assume then are compromised.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure why you say this. What problems are you currently having? Your logs appear to be clean (other than what we already fixed) and the file 'C:\WINDOWS\system32\5005\components\AcroFF.dll' that Avira called a trojan appears to just be a FireFox addon for Adobe Acrobat.
     
    Last edited by a moderator: Jan 25, 2011
  7. blueflame678

    blueflame678 Private E-2

    Ah ok, I did not realize the file is ok and that Avira was giving me false message. How do you know this is not a virus?

    When I tried to run ComboFix it just froze my computer -- I left it untouched for 2 hours and it hung on the screen 'this should normally take 10 minutes but could be longer...' and I could move my mouse but nothing on my computer was clickable
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Online scans of the file have never shown it to be a problem.

    Okay. But his does not mean you have an infection. ComboFix sometimes has compatibility issues with some PCs or software/drivers that may be running.

    So what malware problems are you still actually experiencing if any?
     
  9. blueflame678

    blueflame678 Private E-2

    I guess I am all settled then! THANK YOU !
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. blueflame678

    blueflame678 Private E-2

    I don't think I am fully fixed. I have not been using this computer much because I am worried I still have infected files buried deep. Just ran Malwarebytes:

    Files Infected:
    c:\WINDOWS\system32\srvblck2.tmp (Malware.Trace) -> No action taken.
    c:\WINDOWS\system32\acroiehelpe.txt (Malware.Trace) -> No action taken.

    Any ideas?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you fix these with MBAM?? The above shows you took no action. Run a new scan and make sure you fix them before saving a log and attach the new log. Then reboot and run a new scan to make sure these do not come back. Let me know the result.

    Also to be safe, I want to run a couple other scans to make sure nothing else is hiding.

    Please run this GMER - running with a random name and attach the GMER log.

    Also run this Using ESET's Online Scanner and attach the log from ESET.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7 make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. blueflame678

    blueflame678 Private E-2

    I tried running GMER in safemode and in normal mode. Both times when I went to save the log file, the program went to unresponding and then then my computer froze. Any ideas? It bothers me that GMER won't run, and ComboFix wouldn't run either when we tried before... something is blocking them?

    ESET found nothing and provided no log.

    Will run MGTools and Avenger.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay finish these steps and attach the new logs so we can think about what our next steps will be.
     
  15. blueflame678

    blueflame678 Private E-2

    Ran Malware bytes and fixed the problems specified. Ran Avenger and MG Tools. logs attached.

    Thank you for your continued help, means a lot to me.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please try running GMER and also ComboFix in safe boot mode. Let me know exactly what happens if the do not run. Rename the GMER and ComboFix executable files to a random name ( like g123.exe and cf123.exe ) to see if it helps. Attach logs if they do run.


    Also try running the below in normal boot mode.


    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  17. blueflame678

    blueflame678 Private E-2

    Tried in safe mode and I de-activated Avira. I tried to run Combofix and it kept telling me that Avira was not de-activated. I ran Combofix anyways and it froze. GMER also froze. Is there a way to for sure disable Avira in safe mode other than de-activating and closing the program? Not sure why that did not work. I also used random file names on CF and GMER.

    Attached is the TDSS report.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstalling it and cleaning up any left overs ( which is not always that easy ) may work. Do not that quite often we actually have to use ComboFix to remove left overs from security programs that they DO NOT cleanup for themselves when uninstalled. Since you told it to run anyway ( which it should allow ) and it froze and also GMER is also freezing, you have some other issue at hand and it may not even be malware.
    • If you try to run a full antivirus scan on your PC, does it freeze?
    • If you use Malwarebytes and select Perform Full Scan rather then Quick Scan, does it freeze?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds