I think I picked up malware on a web ad ...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by HelpMeRt66, Jan 16, 2010.

  1. HelpMeRt66

    HelpMeRt66 Private E-2

    I think I picked up malware on a web ad ...

    though I didn't click it the ad. MS Defender warned me but it seems it or another one got thru that & AVG :(

    I performed the "READ & RUN ME FIRST. Malware Removal Guide"

    See the attached logs
    hijackthis

    to save time I ran & included these logs
    GMER (scan only, would only run in safe mode)
    Malware Byte (found 2 items it removed)
     

    Attached Files:

  2. HelpMeRt66

    HelpMeRt66 Private E-2

    After a little Malware Byte cleanup, I was able to run GMER in regular mode & it found rootkits. Here's the report
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    To save time you could have also attached the other requested logs from the R&R. Also, we didn't request a HJT log. :) Yes you have a rootkit. Could I please see logs from running:

    • ComboFix <--- C:\combofix.txt
    • MGTools <--- C:\MGlogs.zip

    also: You need to open up MBAM > let it update > re scan > and fix all it finds. attach the log.

    Thanks
    Kes13!
     
    Last edited: Jan 17, 2010
  4. HelpMeRt66

    HelpMeRt66 Private E-2

    Sorry, I missed running a few things :(

    And Sorry I figured no harm in running hijackthis incase it helped you and saved us a few days

    I was able to run a more up to date malware bytes

    FYI I had to rename SUPERAntiSpyware to get setup to run & then I could only run it in safe mode. You may want to revise your procedures, for others. I can't find the log (I searched on the file name) but I recall it only found 48 cookies & removed them, nothing else was found

    ComboFox wouldn't run in reg or safe mode even with renaming it. No error, program just vanished

    I couldn't run RootRepeal in reg or safe mode, Win's gives a low on memory error then RootRepeal locks up
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    The below is not malware.

    After clicking Fix exit HJT.

    2. Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    3. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\WINDOWS\TEMP
    • C:\Documents and Settings\Stacie\Local Settings\TEMP
    4. Now I want to see if combofix will run at this stage. Download a fresh copy to your desktop, double click it to run it, and if successful attach the C:\combofix.txt log that it creates.

    5. Run GMER again.

    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    7. Also attach the logs from Avenger, combofix (if you were successful) and GMER.

    8. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
    Last edited: Jan 18, 2010
  6. HelpMeRt66

    HelpMeRt66 Private E-2

    Incase it's of any value, I believe SUPERAntiSpyware is giving me a small window ~2x3" on the bottom right but it's only white with a red X on the top left

    Also I've noticed in Task Manager iexplorer.exe keeps running after I terminate it & the malware's terminating Firefox after a while.

    I ran the HJT fix while they were all terminated though I imagine I could have removed that setting in uTorrent to disable startup. I terminated uTorrent so it's not running

    I'll terminate that iexplorer before I run other steps to be safe that it doesn't interfere

    after running avenger & rebooting I"m getting "Windows Explorer has encountered a problems & needs to close, I click don't send & it keeps poping back up so

    I'll continue with it open asking send/dont send

    My PC locked up deleting those temp files & upon rebooting I got a window "Critical Sytem Warning! The file you have tried to open has been detected as

    infected by virus & blocked to protect your PC"

    ComboFix still won't run (no error just disapears) as FF is still doing after a while though they're both running in task manager as a process, just not as

    an application so I just can't access them. Same with GMER

    I tried running ComboFix & Gmer in safe mode, explorer wasn't running, I think it said it couldn't be found so that made it tricky. ComboFix woudln't run

    (same as before), GMER gave me "GMER device error. \\.\aujasnk: The system cannot find the file specified" then c:\windows\system32\config\system: The

    process Cannot access the file because it is being used by another process" & more errors & wouldn't run

    Also each time I reboot I see there's a windows update to be installed but I have updates set to manual so I think the malwares trying to get me to to that but I don't do the install
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Please download SystemLook from the below link and save it to your Desktop.
    Download Mirror

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :file
      C:\WINDOWS\System32\drivers\{0DC900CD-20B4-4A92-BA79-AA5C133950F9}.sys
      C:\WINDOWS\System32\drivers\Vp9079C62.sys
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    How are things running now?
     
  8. HelpMeRt66

    HelpMeRt66 Private E-2

    sorry i forgot to mention I ran avenger, I gave you the log, Oops I didn't see the new things to do, I'll get on it :)
     
    Last edited: Jan 19, 2010
  9. HelpMeRt66

    HelpMeRt66 Private E-2

    ok, it's doing better, AVG was disabled & seems ok now

    I got ComboFix to run but it seems stuck in stage 7 scan. It says whole process takes ~10-20 mins & it's been ~35-40 mins. I'll let it go longer, thoughts?

    then I'll run GMER scan only after that incase you want those
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      C:\WINDOWS\System32\drivers\{0DC900CD-20B4-4A92-BA79-AA5C133950F9}.sys
    • At the upload site, click once inside the window next to Browse.
    • Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
    • Next click Submit file
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

    Then do the same for the below files and also let me know the results:

    Code:
    C:\WINDOWS\System32\drivers\Vp9079C62.sys
    Now Run GMER - running with a random name

    • When the scan is complete, click Save and save the log onto your Desktop where it should be easy for you to find.
    • Attach the log to your next message.
     
  11. HelpMeRt66

    HelpMeRt66 Private E-2

    Attached Files:

    • GMER.txt
      File size:
      699 bytes
      Views:
      4
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    May have to send you to software forum if your issues with firefox persist after further malware removal, but let's see what happens after completing this:

    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from avenger

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running.
     
  13. HelpMeRt66

    HelpMeRt66 Private E-2

    many Thanks again!

    Does that window with X problem sound familiar for SUPERAntiSpyware?

    or is that just not working right for me?

    It seems IE & FF are behaving now

    Hopefully it's all ok now & you don't see anything :)
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Take a screenshot of it for me?
     
  15. HelpMeRt66

    HelpMeRt66 Private E-2

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.
     
  17. HelpMeRt66

    HelpMeRt66 Private E-2

    Thanks again

    FYI That white Super box is low priority vs cleaning up PC

    From my mentioned scans, MS Defender found & seemed to hang trying to remove

    Trojan Alureon.BF C:\System Volume Information\_restore{74E520FE-3AAA-4BBB-A12B-FD9FEF5FBE6E}\RP3\A0002181.dll
    Trojan Alureon.DA C:\System Volume Information\_restore{74E520FE-3AAA-4BBB-A12B-FD9FEF5FBE6E}\RP3\A0002180.dll

    After rebooting & checking those directories don't exist

    AVG found & moved to vault

    "C:\Documents and Settings\Stacie\Local Settings\Temp\Av-test.txt";"Virus identified EICAR_Test";"Moved to Virus Vault"

    It seems TDSSKiller didn't find anything, no log file, here's the screen ouput

    "TDSS rootkit removing tool, Kaspersky Lab, 2010
    version 2.2.2 Jan 13 2010 08:42:25

    Scanning Services ...

    Scanning Kernel memory ...

    Completed

    Results:
    Memory objects infected / cured / cured on reboot: 0 / 0 / 0
    Registry objects infected / cured / cured on reboot: 0 / 0 / 0
    File objects infected / cured / cured on reboot: 0 / 0 / 0

    Press any key to continue . . ."
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    But in the post with the screenshot, there was something found in system32, Finding something in system restore is fine as we will flush it out when we do final steps. I am just worried about the rootkit typed file in your sys32. Is that still being found?
     
  19. HelpMeRt66

    HelpMeRt66 Private E-2

    Yes, but as the image indicates it removed those succesfully.

    Anything you want me to do next or does it seem all cleaned up? It seem to be behaving well
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    My apologies, I was having a braindead moment.
    Yes, I would like for you to run RootRepeal - do not run on 64 bit systems and attach the log from doing so into your next reply please. :)
     
  21. HelpMeRt66

    HelpMeRt66 Private E-2

    When I run RootRepeal, I still get that low on memory error then things lock up.

    Does that usually eat up a lot of memory?

    Anything else we can use that doesn't eat up memory (though it has 1 G of real RAM)
     
  22. HelpMeRt66

    HelpMeRt66 Private E-2

    ok, malware Byte is finding something, says it removes it but doesn't seem to be or it comes back?

    The the attached GMER, image & malware Byte log (weird)
     

    Attached Files:

  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It is merely finding files from running combofix, it is nothing to worry about.
     
    Last edited: Jan 20, 2010
  24. HelpMeRt66

    HelpMeRt66 Private E-2

    I'm not sure things are ok, I keep finding things in malware bytes, it removes them then 1-2 hours later there's another new one.

    You mentioned that combofix directory is fine, then why when I look in it does it have an image of all the PC drives?

    That seems strange. Is that causeing Root Repeal to recurse directories that never end & it eats up memory?

    Why is RootRepeal not running? Maybe a virus or malware?

    Also now in regular boot mode I'm getting a blue screen & Kernel_Stack_inpage_error Stop 0x00000077

    :(
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    C:\123Combo456Fix\Combo-Fix.sys (Malware.Trace) -> Quarantined and deleted successfully.

    Part of combofix!

    Does MS Defender detect any more malware?


    I will have to ask Chaslang regarding the PC Drives strange images.

    RR only seems to run on 50% of machines.
     
  26. HelpMeRt66

    HelpMeRt66 Private E-2

    Also ask about that blue screen error when i boot in regular mode & ask abotu the GMER error, after that It opens & scans for ~12 seconds. I thought it usually scans longer then you click scan for a full scan. I'm doing full scans to see if it's ok now (will take a while). thanks
     
  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I have some information for you from Chaslang and another fix. Bear with me and i'll post in a little while
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Uninstall SUPERantispyware to fix the box you are talking about and seeing with the red cross.

    2. Delete the C:\123Combo456Fix folder that you created yourself. It showed up in the logs in message # 13. Doing things we don't ask to do, invariably leads to problems which is why our instructions say don't do anything on your own.

    3.
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    4. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from avenger, and let us know how things are running now.
     
  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    also make sure you delete the below before running those steps if you havent already started:
    This is why you have a folder with a similar name.
     
  30. HelpMeRt66

    HelpMeRt66 Private E-2

    Sorry for the delay, I didn't get the notify email that there was a post & the PC was behaving much better.

    ok & deleted this

    C:\Documents and Settings\Stacie\Desktop\123Combo456Fix.exe

    & the folder also. As mentioned that wouldn't run before so that's why I had renaming it, incase that helped

    I know I shouldn't have but before removing SUPERAntiSpyware I ran a scan & let it remove the following that you were also addressing, sorry

    Trojan.Agent/Gen-Alureon
    HKU\.DEFAULT\Software\h8srt
    HKU\S-1-5-19\Software\h8srt
    HKU\S-1-5-20\Software\h8srt
    HKU\S-1-5-21-776561741-1960408961-725345543-1004\Software\h8srt
    HKU\S-1-5-18\Software\h8srt

    FYI I'm having a problem with net connection being lost at times breifly on all PC's on this router, could this be caused by the malware?

    See the attached event viewer loggings
     

    Attached Files:

  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now...
    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from avenger.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  32. HelpMeRt66

    HelpMeRt66 Private E-2

    Thank you so much! Things have seemed fine for a long while as mentioned besides the loss of connection at times briefly.

    Any idea on that? could malware have caused that? I've tried 4 routers :(
     

    Attached Files:

  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run Ccleaner. (not the registry part)

    You are running an outdated version of avg. latest version is 9. You can either choose to upgrade to 9 or opt for something else from our reccommended list which will be included in a link at the end of my final steps (scroll down to section two, antivirus)

    Any remianing issues will have to be worked out in another forum, eg: software or networking.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  34. HelpMeRt66

    HelpMeRt66 Private E-2

    Thanks, AVG is still updating it's virus database & running properly though I'll update it to the latest version. Take Care!
     
  35. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Surf safely :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds