desperate to shake malware on my machine ("goatse?")

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nalesk, Nov 20, 2009.

  1. nalesk

    nalesk Private E-2

    hi folks

    I normally look for info on the web when I have a problem and have so far always managed to get rid of an infection on my own, but this one seems to be resisting my best efforts.
    Basically I reckon I badly need someone skilled to check out a hjt log of my box if somebody here doesnt mind taking the time to give me a hand on that one... it would be much appreciated!

    ok so my box runs win xp home (sp2) with a 2.8Gb intel pentium 4 cpu and 1 Gb (2x500 Mb) of ram
    sound : M-Audio audiophile 2496 sound card, grfx : 128Mb parhelia matrox
    storage : 1 UDMA maxtor HDD (80Gb) and 2 SATA maxtor HDD (200Gb each, striped in RAID array)

    I run Nod32 and Spybot,
    So here we go : last week, NOD noticed something when I stupidly clicked on a link sent by someone (I started contemplating a very gross picture wondering if that was even funny at all when some viral activity started manifesting itself. -uncyclopedia goatse- I think were the page where I was sent if I remember properly.
    Nod32 went red but it failed to prevent the attack.

    I tried full safe mode scans of NOD, spybot, then kaspersky but no luck. I did scoop some things and desinfected/deleted a bunch -including one called Smitfraud.
    I also tried another fix tool downloaded from a site... cant remember what though >.<
    I then used uniblue registry booster to sort out the mess and finally a good old defrag to polish the session. But evil endures...

    symptoms are :
    -autoshutdown of pc (I applied the "fix" tool from some support site and it stopped)
    -opening of random internet browser windows or tabs to adverts or blatently dodgy sites
    -more recently (and more worryingly) : disappearance of my SATA drives (they suddenly stop appearing and cant be accessed. need a shutdown + switch off PSU to find them again, then same happens again after a few minutes)
    -smss.exe issue when comp tries to switch off. (have to terminate process by hand)
    -maybe more hidden issues but I m not skilled enough to detect those (pc just doesnt feel like normal hehe)

    it d be amazing if I could find a way without having to do a total windows reinstall, especially because I think I might lose the data stored on the striped SATA drives in the process...

    can anyone help?

    Cheers:dood
     
    Last edited: Nov 20, 2009
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.

    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.


    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:

    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. nalesk

    nalesk Private E-2

    hi there

    great, so I prepared for war and religiously furbished my weapons to remove all those nasty trojans and god knows what else lurks in the dark heat of those chips down there.

    the problem is I cant go through even the first step of the process (actually that s a lie. I did manage to do C cleaner but that s about it).
    I cant uninstall java, cant install new java either, cant install superantispyware, and I stopped at that since it was already a few steps jumped. I figured I might as well get back to you for instructions.

    the reason I cant perform those tasks is that the only way I can use my pc at the moment is by using the safe mode with networking.
    each day that went by saw my normal sessions go worse and worse, to the point that now merely clicking on "my computer" or "control panel" instantly makes my pc restart. Somehow it seems that things went to the next level (worse) after I thought I succeeded in eradicating smitfraud using a tool on this provided forum. for a day or so I thought "cool, this was really easy after all". Que neni ! the next day is when the pc started restarting out of nowhere and having a big laugh at me...

    cool eh?

    Also, all operations I try to do in safe mode invariably meet the following error message : "the system administrator has set policies to prevent this installation"

    et voila!


    any suggestions?
    low level format the lot and fresh install of xp?
    wave goodbye my pride (reinstall s like rehab : for quitters eh?) as well as gigs of non backed up items (I was going to, I swear!lol) ?
    all the pics of my 10 months old daughter (that s a lot hehe)?
    booooo .. sob
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please try doing the below:

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.

    Now download and Run exeHelper

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Now download the current version of MGtools and save it to your root folder.

    Then attach the below logs:

    C:\avplog.txt - from AVPfind
    log.txt - from exeHelper
    C:\MGlogs.zip - from MGtools

    You may have to consider removing your hard drive and slaving to a very well protected computer and saving only your personal files and data. But let's see how the above work.
     
    Last edited: Nov 28, 2009
  5. nalesk

    nalesk Private E-2

    Hey Tim, thanks for your help!

    a couple of days ago, as you read up there, I mostly failed to do anything. But then I thought o well, I ll just jump a step and try the next "cleaner". so I tried and succeeded with mbam, combofix, root repeal, and then tried superantispyware once again (which worked at this point)
    here are the logs I got then.
    I tried mgtools too but it stopped progressing after the line : updating hijackthis.log
    since no prompt came up, I eventually closed the the app.

    I ran it again today after rkill.exe and exehelper.

    here are the logs!

    please let me know if you want me to post the exehelper log as well.

    I have to say that things seem better since I ran those various scans but some problems still remain :
    my pc doesnt detect my sata drives at startup
    internet browser windows still open themselves with some annoying messages (I have to go to task manager and force apps closed to get rid of it)

    Anyway, I hope it makes sense to you ...
    Thanks a lot for your help!!!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need you to attach the logs from running:
    SAS
    MBAM

    Now, you need to put ComboFix on your desktop, you can not run it from here:
    h:\cleanup xp\ComboFix.exe

    You also need to put MGTools.exe on the C:\ drive as in C:\MGTools.exe, not here:
    C:\cleanup xp\MGtools.exe

    After doing that, please try to run the MGTools.exe again and please have patience. Once it is run, attach the C:\MGLogs.zip.
     
  7. nalesk

    nalesk Private E-2

    Hi Tim

    sorry it took a couple of days. I did some progress, managed to run all scans, and after a reboot (necessary to remove the last bits of junk) my box suddenly wouldnt load windows in normal or safe mode : it kept restarting.
    Eventually I succeeded loading the "last session that worked" and I managed to re-run sas, mbam, mgtools -this time it did reach completion- and to post the logs (attached here).

    so basically I feel that something is still there because I notice the following:
    sata HD are not always found
    mouse pointer sometimes flies to the corner of the screen without reason
    unwanted browser pages open themselves
    and the worst for last : pc seems to restart itself as soon as it starts a windows session...


    anyway, here s the logs!

    thanks again for your patience

    alex

    PS : once my pc is clean (hopefully soon, but I think some evil still endures at the moment) is there a security solution you would recommend (apart from the obvious advice to not clic on links from people I dont know)?
    I used to find that NOD32 and spybot were decent, but there might be more efficient out there?
     
  8. nalesk

    nalesk Private E-2

    here they are ...
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First thing, it is a very bad idea to allow all users to have Admin. privileges!! Any malware that gets into your machine in an Admin account has total access to your entire computer.

    Please use add/remove programs to uninstall:
    Threatfire --> see the notes here: How to Protect yourself from malware!
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7

    I strongly advise you to cleanup your Desktop. Remove everything but links to run programs. Do not download and save programs here and definitely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\stu2.exe
    
    Folder::
    c:\documents and settings\All Users\Application Data\ParetoLogic
    C:\Program Files\Common Files\ParetoLogic
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now to check further, please do this:

    • Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive called "TDSSKiller.txt" please copy and paste the contents in your next reply.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  10. nalesk

    nalesk Private E-2

    Hi Tim

    thanks for taking the time mate!
    As you suggested, I uninstalled (this time successfully) the java updates as well as a couple of softwares (that previously didnt want to let themselves uninstalled). I also deleted all other user profiles, leaving only mine with admin rights and password protected.
    I also did a little tidying up on the dektop...
    Finally, TDSSKILLER didnt seem to find anything suspicious (a good thing right?).

    Oh, and I did succeed in adding this to the reg :

    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]

    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

    Here are my logs from today's cleaning session!
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. You only need to use windows explorer to find and delete:
    C:\Documents and Settings\nalesk\Local Settings\temp\MSOHTML1
    C:\Documents and Settings\nalesk\Local Settings\temp\RAR$DR00.203

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  12. nalesk

    nalesk Private E-2

    Hey Tim

    ok, I deleted C:\Documents and Settings\nalesk\Local Settings\temp\MSOHTML1
    but I failed to locate and delete C:\Documents and Settings\nalesk\Local Settings\temp\RAR$DR00.203

    I felt like my machine was ok for a day or two, but since yesterday it s been acting weird again : it stopped detecting RAID drives again, and 5mn ago windows would not let me "clic" with the mouse (only thing I could do was to ctrl alt sup and log off).

    Anyway, if the machine is clean indeed, then all I can think is that the problems I now experience are the resulting damage of malware s activity?
    In which case, the goold old reinstall seems unavoidable...

    Oh well, thanks for your help nevertheless !

    Alex
     
  13. nalesk

    nalesk Private E-2

    Hi Tim

    Since the last steps I did (after you said my pc was clean from malware) I told you that my sata drives wouldnt appear anymore.
    I forgot to mention that internet is not accessible anymore either (even though there is a connection because skype still operates, and my laptop browses the web effortlessly if I connect it to the same cable).
    The funny thing is while we were fixing the box I could use internet browsers but skype was acting weird (cutting off suddenly and disappearing from system tray). And now that internet browsers act as if my connection was not working, skype woks like a charm....

    Do you have any idea how I could get my striped sata drives to show up again so that I can backup a thing or two before making a fresh reinstall?

    I m starting to lose my marbles here >.<

    Alex
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you having the same problem using FireFox? Have you opened device manager and checked for any devices with an X or ? or ! ...?
     
  15. nalesk

    nalesk Private E-2

    Hi Tim

    I did a bit of looking around and trying different stuff and internet now works.
    I think when I cleaned up and removed software, it must have upset the port forwarding and DNS info I had. I reset it and it now works fine.

    So now the box runs smooth and fast, internet works fine too ... all I need to solve now is my sata raid array issue.

    The thing is that the BIOS doesnt detect them, and I dont see anywhere in the Bios setup anything about them... so all I can think of is a mechanical or electrical issue? I ll pop the hood and resit the cables, clean up the fans and get the power from different cables. Hopefully that will do the trick.
    If it s not that, then I dont know!

    Anyway, thanks again for taking the time, you were great help!

    Alex
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are still having problems with your sata...I suggest you post in the hardware section. And good luck!!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds