[help req] infected system - cleaned, ready for analysis

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by gracious27, Aug 27, 2008.

  1. gracious27

    gracious27 Private E-2

    hello,

    yesterday my system got what i've best seen described as the 'antivirus xp 2008' bug.

    symptoms:

    • antivirus xp 2008 pop-up (EULA)
    • white destop and warning message w/ virtumundo and privacyremover.M64 warnings
    • windows firewall not active warning (via pop-up and tray notifier)
    • unable to connect to certain sites (e.g. majorgeeks.com) or update malware utilities

    i've gone through the general cleaning steps outlined on your site and things are much better now. i would like to kindly ask for your assistance though in making sure that i have a clean system and also to answer just a few questions.

    1. in researching this bug on your site i see that there is a specific treatment for smitfraud which one of the scans identified - does this warrant further steps on my part, or does everything appear ok?
    2. prior to beginning your cleaning process, symantec identified joke.blusod - does this require further attention?
    3. i am concerned about the security of sensitive data on my system - do i have any reason to be concerned that this data has or could be compromised? even after receiving a clean bill of health from you?

    the only symptom i've witnessed since running READ & RUN ME FIRST is when using the 'control-c' shortcut or right clicking for the context menu. either brings up a symantec installer dialog about 1 in 3 times.

    thanks in advance for your assistance!

    p.s. i was unable to update malwarebytes or sas prior to scanning (due to the bug preventing a connection). should i do that now and scan again?
     

    Attached Files:

  2. gracious27

    gracious27 Private E-2

    remaining logs...
     

    Attached Files:

  3. gracious27

    gracious27 Private E-2

    it looks like avg free vaulted about ten items in a scan this morning that i didn't catch earlier.

    screen grab attached.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only problems I see are that you don't have any java installed. You can download it and install it from here: Java Runtime 6

    You are running both Symantec and AVG. You need to uninstall one of them!

    And I want you to do this:
    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    DirLook::
    C:\System32
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Please attach the new log from Combo and also tell me how things are running.
     
  5. gracious27

    gracious27 Private E-2

    hi tim,

    thanks so much for helping!

    done.

    symantec lost that battle! the installation actually got hosed and wouldn't load properly after getting this bug. its officially uninstalled now.

    when dropping the .txt file to combofix i get the following windows dialog error: 327882R2FWJFW\hidec.exe "windows cannot access the specified device, path, or file. you may not have the appropriate permissions to access the item."

    using escape gets me passed the dialog and combofix runs, but i'm wondering if the above error is part of the infection? i stopped avg, etc. prior to running combofix.

    new log attached.

    regarding status, i've intentionally stayed off this machine until i got word back from you. here's what i've noticed this morning:
    • symantec got corrupted by this bug
    • avg quarantined another half dozen or so items in this mornings scheduled scan (screen cap attached)
    • avg resident shield alerted me of a hideexec.ev file being accessed from system restore (screen cap attached)
    • ccleaner has numerous registry references to some of the items removed during the READ ME/RUN cleaning
    • when rebooting (after uninstalling symantec), the system automatically shut down again as it neared completion of its boot cycle. it then booted properly
    • there is an avg tray icon telling me scans are running even though they're not. i've seen another post recently that mentions this as well.
    • avg updated once this a.m., but failed when trying again just moments ago. i assume this to be on avg's end as i verified this to also be an issue on the non-infected machine i'm currently writing from.
    • ie resets itself as my default browser rather than FF

    that's all i've got so far.

    avg's updates this morning included new def's for new fraudload, etc. variants today and i'm wondering, as i've seen this referenced during cleanup, if that's part of my problems here.

    i appreciate your time, thanks again for helping!
     

    Attached Files:

    Last edited: Aug 28, 2008
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Somehow between your last post and this one, you have gotten infected .....Please re-run SAS, MWB's and run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file as well as the SAS and MWB's logs.
     
  7. gracious27

    gracious27 Private E-2

    hello,

    new logs are attached below.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Wherever those items that AVG picked up came from, I don't know. But your logs are clean.

    Just for the halibut, please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure you get a success message, then if so:

    If you are not having any other malware problems, it is time to do our final steps:


    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below

      * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combo-fix folder from combofix.

    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    12. After doing the above, you should work thru the below link:

     
  9. gracious27

    gracious27 Private E-2

    i really appreciate all your time on this tim. i know you guys are volunteering and it means a ton to me.

    everything seems to be a-ok now.

    i followed the steps in your last post including the 'how to protect yourself...' guide and am now surfing on a pw protected restricted user account, behind an online armor fw, using avg, sas (will purchase), spywareblaster and spybot - all as recommended. (although i've gone blue in the face from reading all this stuff the last few days...i think i got it right though :)

    i do have one last question for you if i can borrow just another minute of your time. i understand that what i got infected with is perhaps just scamware, but i did want to ask again about the integrity of sensitive data on this machine. do i have anything to worry about regarding the possibility of private data, tax info, etc. being compromised in any way?

    thanks again and take care!
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes it is a malware scam.....but it can be rather insidious....but not to the point of stealing sensitive data.....:)
     
  11. gracious27

    gracious27 Private E-2

    ok, good...i'll sleep better now :zzz

    have a great weekend!
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome....sleep well. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds