Malware Infection - Am I in the clear now?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by MadDogg80, Jan 2, 2010.

  1. MadDogg80

    MadDogg80 Private E-2

    First off I'd like to say thanks chaslang and everyone else here. I've been running McAfee security software for four years now and until the events of the last 12 hours I didn't realize how vulnerable it is.

    While browsing a gaming forum last night (which by all indications was trustworthy) my browser bogged down after clicking on a thread. My browser bogs down occasionally sometimes and I thought nothing of it and stepped away from the computer for a moment. I returned to find numerous warning from McAfee about trojans being quarantined and attempted registry changes. I followed the prompts, blocked all the changes and deleted the quarantined viruses. I'd previously only seen trojan prompts from McAfee while browsing a handful of times over the years as I'm usually very careful where I browse. I had certainly never seen anything of this magnitude. I assumed McAfee had done it's job though and it was late so I shut down and went to bed.

    Logged in this morning to a complete disaster. I was overwhelmed with suspicious looking Spyware Alerts and warnings from Internet Security 2010, my desktop background went black, McAfee started detecting and quaranting a couple more trojans (HTML/FakeAV, Artemis etc.). I followed some direction from the McAfee website and tried to disable System Restore but it was no longer present under My Computer, Properties. It appeared that the malware had stripped my Admin priveledges? When trying to run a virus scan thru McAfee it would find a couple things, get to 80% and then I'd wind up with the dreaded blue screen of death.

    I didn't click any of the bogus warnings and started doing some digging to find some solutions which eventually led me here thankfully. This was quite a task as links from google searches were now sending me to rubbish websites.

    Wow, my apologies for the ranting wall of text :-o

    I performed all of the steps found in the sticky thread READ & RUN ME FIRST and was amazed at how much stuff the cleanup programs found that McAfee didn't. Also noticed thru this that my Java software wasn't up to date (won't make that mistake again ;))

    Anyhoo my computer appears to be working perfectly fine again now (a bit faster than normal actually). However the log files, particullarly the last three (RootRepeal, ComboFix, MGTools) are a bit foreign to me and I just want to be sure that my computer is completely clean.

    If someone could look over my log files and let me know if I'm in the clear it would be much appreciated. And again a big thanks to everyone that runs this forum, lots of excellent resources and information here!
     

    Attached Files:

  2. MadDogg80

    MadDogg80 Private E-2

    And here is the MGTools log file.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Seems like the scans took care of most issues, just a little remains to be done.

    1. I strongly advise you to cleanup your Desktop.

    • C:\Documents and Settings\Mike\Desktop

    Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.


    2. The version of Mozilla Firefox you are using is:

    3.5.6 is latest, so you should update.

    3. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    • O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Documents and Settings\Mike\My Documents\partypokernet.exe (file missing)
    • O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Documents and Settings\Mike\My Documents\partypokernet.exe (file missing)

    After clicking Fix exit HJT.


    4. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    Driver::
    AIBQQMCW
    
    File::
    c:\windows\system32\aibqqmcw.zcd 
    c:\windows\system32\drivers\wuytl.sys
    c:\windows\temp\mcmsc_rjynnrbdzwwnetp
    
    Folder::
    c:\documents and settings\All Users\Application Data\Viewpoint
    c:\documents and settings\Mike\Local Settings\Application Data\jqrqdk
    c:\windows\temp\mcmsc_rjynnrbdzwwnetp
    
    Registry::
    [-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\AIBQQMCW]
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    5. Also delete all files in the below bold folder except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\WINDOWS\TEMP

    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now! :)
     
  4. MadDogg80

    MadDogg80 Private E-2

    Thank you so much for the help Kestrel13!

    I still seem to be running fine on my end however I logged into my wife's profile (User Profile=Michelle) and there appear to be some lingering issues there. Her desktop background is grayed out and I'm unable to change it (within the list of selectable backgrounds it says critical_warning). There is also a small yellow phone icon in the bottom right Taskbar called Intel Modem Event Monitor which doesn't appear to do anything but she claims it was never there before performing the cleanup. Do I need to run MalwareBytes, Combofix etc. while logged into her profile as well?

    I did do some housecleaning on my desktop as you suggested (letting it clutter up is a very bad habit of mine). I also started to uninstall a few unneeded programs and then realized I probably shouldn't be doing that yet. I apologize for any unnecessary clutter in my next logs. :-o

    I haven't used Firefox in a long time, but have updated and plan to use it as my primary web browser going forward.

    I was able to run steps 3, 4 and 6 without any problems. I went into my C:\WINDOWS\temp folder and there were only three files there, none of which could be deleted. One of the files was Perflib_Perfdata_664.dat and the other two were mcmsc_XXXXX files (not sure if those are of any significance).

    Anyhoo thanks again for all your help! Here are the new logs from Combofix and MGtools.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    RegLock::
    [HKEY_USERS\S-1-5-21-2108532852-844249745-1793510146-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
    @Denied: (Full) (LocalSystem)
    @SACL=
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    The logs for your account are clean :)

    You can follow my final steps below and then run the R&R for your wife's account. You can remain in this thread to do so.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  6. MadDogg80

    MadDogg80 Private E-2

    Thanks for the quick reply!

    I'm going through the final steps right now and seem to be having a problem uninstalling combofix. I've inputted the text in the Run command line exactly as shown

    "%userprofile%\Desktop\combofix" /u

    But it doesn't seem to be uninstalling combofix and just performs another combofix scan. Combofix is still on my desktop after the scan has completed. I've attached the log from the scan that just completed.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try using
    If that doesn't work then simply locate the following and delete:


    • ComboFix.exe file
    • C:\ComboFix folder
    • C:\QooBox folder
    • C:\WINDOWS\nircmd.exe
    • C:\combofix.txt
    • C:\ComboFix-quarantined-files.txt logs that was created.
     
  8. MadDogg80

    MadDogg80 Private E-2

    Thanks! Typing /uninstall instead did the trick!

    I'll finish working through the final steps and then move over to my wife's user profile and go through the cleaning process in the R & R again and post the logs once I've finished.

    Thanks again!
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK! I'll be here waiting :)
     
  10. MadDogg80

    MadDogg80 Private E-2

    Ok I've finished running all of the cleanup procedures while logged into my wife's profile. SAS and MBAM each found and deleted a few more things.

    On the first run of Combofix I got a blue screen of death while it was preparing the log, but ran it a second time without any problems.

    Here are the first four logs.
     

    Attached Files:

  11. MadDogg80

    MadDogg80 Private E-2

    And the final log file for MGTools.

    Fingers crossed that all this nasty stuff is close to being cleared up now.

    And again a HUGE HUGE thank you for all of your help!
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your wife's logs are also clean! :) The scans took care of what malware there was. You can again follow final steps now.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. MadDogg80

    MadDogg80 Private E-2

    Thank You, Thank You, Thank You!!!

    I had never had a major malware problem before and was very worried at first. All of you guys here are awesome I'm so glad I stumbled upon Major Geeks!

    My PC hasn't been running this quickly in a couple years. It shuts down and restarts nearly as quickly as the first week I got it (who knows how long some of this junk had been buried where McAfee couldn't see it).

    I'm seeing a few things I can do to prevent something like this happening in the future and hopefully I won't need to use this section of the forum again (fingers crossed).

    Once again, THANK YOU!!!!
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds