Multiple virus attacking computer speed, smitfraud and trojans.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by smssoleimani, Jul 12, 2010.

  1. smssoleimani

    smssoleimani Private First Class

    Hello,

    after dealing with spontaneous and random computer slowness for a day or two i decided to run a few virus scans to see if a virus could be flooding my cpu usage. and there it was, viruses! i believe it must have happened from when my kids were on the internet one day. im usually careful, but kids, nsm.

    well i went through the read & run as directed and all went well (the process) except for RootRepeal. It was scanning fine, but when it finished a error window popped open and it said:

    RootRepeal Error

    "Exception Address: 0x004eca19"

    it also created created a log on its own and placed it on the desktop titled "RootRepeal_crash_######'s"

    not sure what happened but rather than not saying anything or not posting the RootRepeal log i will attach this error log. in addition to the log it created, it also placed two files on my desktop..settings.dat and RootRepeal.dmp, no icons, and cannot open....weird.

    thank you for your assistance, requested logs are attached.

    -steve solo
     

    Attached Files:

  2. smssoleimani

    smssoleimani Private First Class

    here is the RootRepeal crash log i mentioned the program created on its own after it gave me a error after the scan. its attached.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is an extremely bad idea to allow all users to have Admin. privileges!! Once malware enters your system on an account with Admin. privileges, it has free reign for the whole system. I strongly suggest you only have one Admin. account and all others be changed to limited.

    Fortunately, the scans took care of the malware, at least on this user account. You need to run SAS and MBAM on each user account.

    Attach any logs that show malware for each user account and make sure to identify the account.
     
  4. smssoleimani

    smssoleimani Private First Class

    ok i changed every other account except for "dad" to limited and ran MBAM and SAS. every account had some type of virus, some had the same viruses, and some with different viruses or a different number of them. i will post all the logs from the 3 accounts tested, so 6 logs. i will put the remaining logs in a reply following this one.

    a few problems i noticed...on every account on boot up, once i reach the desktop a few annoying things open that are not in the startup folder. but even more serious the task bar is, for most startups, frozen.. for example i would try to move my cursor there to click start or SAS from the task bar and i would get the time clock cursor. so a temp work-a-round i would ctrl-alt-delete and end process explorer.exe and new task explorer.exe and then it would work.

    edit: also when i log into any account Kodak EasyShare software shows up with an error asking to send to ms, im on admin account now trying to uninstall through add/remove...not working, i click remove and nothing happens..at all.

    in this post i attached accounts justin and andrew's mbam and sas logs, next one contains mikes.

    -steve solo
     
    Last edited: Jul 14, 2010
  5. smssoleimani

    smssoleimani Private First Class

    and here are mikes mbam and sas logs.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I see that each account had virtually the exact same infections.

    If you are now back in the one Admin account, please re-run ComboFix and then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  7. smssoleimani

    smssoleimani Private First Class

    alright i've attached the combo log as well as the mglogs.zip.

    along with the issue with uninstalling kodak, i tried to run ccleaner again and i recieved this error:

    "Microsoft Visual C++ Runtime Library

    Runtime Error!

    program: C:\Program Files\CCleaner\CCleaner.exe

    R6002
    -floating point supported not loaded"

    and then the porgram just closes after hitting ok.

    -steve
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am confused. You want to remove Kodak EasyShare software? Does nothing happen when you try to uninstall it from the add/remove programs list? And why do you have a user account with that name and with Admin. privileges?

    We can try to remove the Kodak files:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    KodakDigitalDisplayService
    
    File::
    c:\Program Files\Kodak\Digital Display\KodakDigitalDisplaySoftware.exe
    c:\Program Files\Kodak\Digital Display\OrbKodakLauncher\DllStartupService.exe
    c:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    c:\documents and settings\All Users\Application Data\ArcSoft\kodak-printcreations-22-080812-oem\acforall.dll
    
    Folder::
    C:\Program Files\Kodak
    
    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\Kodak\\Digital Display\\KodakDigitalDisplaySoftware.exe"=-
    "c:\\Program Files\\Kodak\\Digital Display\\OrbKodakLauncher\\DllStartupService.exe"=-
    "c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=-
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Otherwise, your logs are clean. I suggest that you post in the software forum for your remaining issues.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  9. smssoleimani

    smssoleimani Private First Class

    im not following when you said "And why do you have a user account with that name and with Admin. privileges?" if what your talking about is the user accounts, there is only one admin, the rest are now limited. what name? and what privileges?

    and yes when on any account if i try to uninstall it just doesn't do anything. i click remove in add/remove programs and it blinks, but nothing happens.

    was the root repeal issue something to be concerned about?

    combofix report:

    combofix said this at one point when it was running:

    System file is infected !! attempting to restore
    "C:\WINDOWS\system32\userinit.exe"

    combofix started to delete a bunch of files, the kodak ones.

    the system file infected message came back in combofix but this time with a ton more consecutively, each with a different file! diskpart, diskperf, dllhost, dmremote, dplaysvr, dpnsvr, dpvsetup, fsquirt, gpupdate, ipconfig, imapi, sooo many, all infected?!??!! its like every file in system32 is infected! it seems to be going through files in alphabetical order form a-z.

    is this bad, it looks bad.

    after the system32\[filename] it became system32\Com\[filename], then \npp, then \oobe, \Restore, etc.



    i attached the combo fix log. please help, im worried now from all of the infected!! messages.
     

    Attached Files:

  10. smssoleimani

    smssoleimani Private First Class

    ahh mbam and sas are still detecting viruses during scans!
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to attach the SAS and MBAM scan logs.

    What I meant about users is this:
    Code:
    Users on this computer:
    Is Admin? | Username
    ------------------
       Yes    | Administrator
              | Andrew
       Yes    | Dad
              | Guest
              | HelpAssistant (Disabled)
              | Justin & Andrew
       Yes    | kodak[COLOR=DarkRed] <----- this account[/COLOR]
       Yes    | LogMeInRemoteUser
              | Mike
    What has happened in the last day or so? It would appear as though you picked up a very nasty bit of malware.

    Do you have your OS disc?

    Please go back to the Read and Run First instructions and download a new copy of Combofix and run it and get me the above logs as well as the new Combo log and a new MGLogs.zip
     
  12. smssoleimani

    smssoleimani Private First Class

    thats strange, i've never seen this kodak admin before. how do we get rid of such a thing, it doesn't show up under users in control panel and it doesn't even show when i boot up, only shows dad, justin, andrew, mike.

    honestly for the past week all i did was run scans and follow your instructions. nothing else.

    i do not have the OS disk.

    attached i have the newest sas and mbam logs, as well as the mglogs.zip. in the post immediately following this i have a few screen shots of errors i've been seeing randomly.
     

    Attached Files:

  13. smssoleimani

    smssoleimani Private First Class

    3 screen shots:

    1. on login from bootup i get this message from windows security alert asking to block or unblock "windows explorer."

    2. combofix - a parasite is trying to attach! what the hell?!?

    3. and this weird NSIS error i've never seen before and have no idea what its complaining about.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Combo is still detecting many of your system files to be infected. We could try replacing them, but the danger is that we will not get them all and it will just continue to spread again. At this point, your best bet is to backup all your personal data and files ( do not back up exe. files ) and do a complete reformat and clean install.

    Do you have a recovery partition? If not, you will need to find ./ borrow a copy of your OS. You should have your install code somewhere on the back of the computer.
     
  15. smssoleimani

    smssoleimani Private First Class

    FOUND ONE!!

    it says:

    operating system
    already installed on your computer
    re installation cd
    Microsoft windows xp home edition
    including service pack 1a
    dell

    hope this will work, its a magenta purple like color.

    how do i go through doing this, and os repairs do not remove data right? so all files and pictures, music will still be there, its just the system files that are replaced, right?
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    NO. Doing a repair install will not remove the malware. You need to backup your personal files and then once that is done ( either to a cd or thumb drive ) you need to reformat your hard drive and do a clean installation.

    I suggest that you post in the software forum if you are unsure about how to proceed. :(
     
  17. smssoleimani

    smssoleimani Private First Class

    i see.

    when it comes to applications how can i back that up so once i do the reinstall i can just move them over from a thumb drive back to pc. would it work? or would i have to reinstall everything? i know pictures and things it easily just a move and move back. but does that also work with apps?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, that doesn't work with applications. You would need to reinstall your apps. You would also need to add user accounts and do all the updates again. It is a large amount of effort, but sadly, about your only choice.
     
  19. smssoleimani

    smssoleimani Private First Class

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, that would be a good choice for you to be able to backup pictures and data files to a cd. ;) But you can not use this to backup apps!!
     
  21. smssoleimani

    smssoleimani Private First Class

    would it be possible to remove all other accounts, leaving just dad and debug his account and re add new accounts later?
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Again, no. There are too many corrupt files to be able to "debug". You need to do a reformat and a clean install. :(
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds