Need Maleware Removal Help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by uncleseano, Aug 26, 2011.

  1. uncleseano

    uncleseano Private E-2

    Heya, I read through the things to do first topic and did all the unsual, unistalling java/disable virtual drives etc...

    Now down to the nitty gritty, where do I start? I bascially have something that malewarebytes stops from connecting to some IP address and every now and then a folder with a random name is created in my INternet Temp folder and tries to run something called 'setup'. Comodo blocks it tho.

    This morning I noticed the program was an svchost that tried to connect to an IP in romania. I disabled one of the svchost, the one that was running 500,000k of memory and noticed the maleware bytes 'pop-ups' dissapeared.

    Idears guys? I really want this thing gone
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the requested logs from doing the Read and Run First instructions:
    SAS
    MBAM
    RootRepeal -- if it runs
    ComboFix
    C:\MGLogs.zip
     
  3. uncleseano

    uncleseano Private E-2

    Sorry that posted without the info, I didnt do the rootseeker ive a 64bit system and combo fix just wouldnt start up properly. I kept on seeing stuff like 'grep.3xe has stopped working' amoung other processes that combo would use failing. Also I got this 'cannot rename combo fix'. All anti virsus/firewalls etc offline. But this problem has shown itself with a few programs since the infection.

    Please help :cry
     

    Attached Files:

    • mbam.txt
      File size:
      899 bytes
      Views:
      4
    • SAS.zip
      File size:
      580 bytes
      Views:
      3
  4. uncleseano

    uncleseano Private E-2

    Forgot the mgtools one, here..
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your MGLog.zip was virtually empty. Did you get any error messages when you ran it? Please do the following:

    Please click Start, All Program, Accessories and you will see ( among other things ) a Command Prompt entry.

    • Right click the Command Prompt entry and select Run As Administrator.
      • It is critical that you run it this way.
    • If you do this properly, a command prompt window will open with a title of Administrator Command Prompt.
    • Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple/brown is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GRK64 <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    SN64 <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.

    Now attach the new C:\MGLogs.zip
     
  6. uncleseano

    uncleseano Private E-2

    I've downloaded mgtools twice now and both times I run the .exe it creates the mgtools folder but i doesnt contain GRK64 or SN64. Any idears?

    By the way thanks for this, you're a champ
     
  7. uncleseano

    uncleseano Private E-2

    I've disabled everything, scanners etc and UAC and when I run as admin is only ever creates a temp file and 2 logs, no .bats files. Here is the pic of command I get attached
     

    Attached Files:

    • cmd.jpg
      cmd.jpg
      File size:
      91.2 KB
      Views:
      3
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download OTL by Old Timer and save it to your Desktop.

    See the download links under this icon [​IMG]

    1. Double click OTL.exe to run OTL (Vista and Win7 right click and select Run as Administrator)
    2. When OTL opens, change the Output (at the top-right portion of the program) to Minimal Output
    3. Put check-marks in LOP Check and Purity Check
    4. Now click the [​IMG] button.


    When the scan is complete, a file entitled OTL.txt will be created on your Desktop. There will be another file called Extras.
    Attach these logs to your next message. (See: HOW TO: Attach Items To Your Post )
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please try it again now. There was a problem with the last file. I just updated it. Download and run the new MGtools See if it makes the MGlogs.zip file now. Thanks!
     
  10. uncleseano

    uncleseano Private E-2

    ok the new mgtools.exe worked grand, here are the logs, do I still need to do oldtimer then?
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, it may prove useful since you could not run ComboFix.

    Also two more thins.

    1. You said you disable virtual drives but I see Daemon Tools running.
    2. Why do I see two instances of ping.exe running? What are you pinging and why would it be always running and why two instances?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I see that you are running ping with the below options. Are you running these manually or part of some other program/game? Why?


    "C:\Windows\SysWOW64\ping.exe" -g no -t 3 -o http://revalati0n-startup.com:8344/ -u sdrkuqykq -p fibkxml

    C:\Windows\SysWOW64\ping.exe 127.0.0.1 -t


    Code:
    REVALATI0N-STARTUP.COM - Geo Information
    IP Address: [URL="http://cqcounter.com/traceroute/?query=178.162.224.229"][COLOR=#000099]178.162.224.229[/COLOR][/URL]   [URL="http://cqcounter.com/traceroute/?query=184.82.193.155"][COLOR=#000099]184.82.193.155[/COLOR][/URL]   
    Host: revalati0n-startup.com
    Location: [IMG]http://n1.dlcache.com/flags/us.gif[/IMG] US, United States
    City: Scranton, PA 18501
    Organization: RAZÃO DIGITAL c/o Network Operations Center, Inc.
    ISP: NetDirect
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    More questions:
    1. Your IP shows that you are in Ireland. Is that correct?
    2. Why are you using DNS server addresses in Sterling, Virginia, USA?
    3. And why are you pinging that address in Pennsylvania?
    [edit] Ah! I just notice you are using Comodo and those DNS severs are for comodo secure DNS. Put the pinging question remains.
     
  14. uncleseano

    uncleseano Private E-2

    I don't really know what those two ping.exe are, they werent always there even tho i've had comodo for ages now. As for daemontools sorry my bad. Its Running but the drives are disable. Doing the scans again to see if it interfered.

    Yeah I'm in Ireland, windy and cold. Oh joy.
    Attached below is the oldtimer log
     

    Attached Files:

    • OTL.Txt
      File size:
      80.9 KB
      Views:
      4
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click OTL.exe to start the program.

    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code

    Code:
    :processes
    :files
    @Alternate Data Stream - 487 bytes -> C:\ProgramData\TEMP:05EE1EEF
    @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:C0EC8D57
    @Alternate Data Stream - 1124 bytes -> C:\Users\Seán\AppData\Local\Temp:pYsQuHJIHNfoEkQqaQb6sQpVwDK
    @Alternate Data Stream - 1124 bytes -> C:\ProgramData\Microsoft:jYIikL2QpDCskA7z52zDN0V
    @Alternate Data Stream - 1090 bytes -> C:\ProgramData\Microsoft:hpZA7W0IwgHSK1nhyXYXrbz
    @Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:A4C20950
    
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:

    • C:\MGlogs.zip
    • OTL log

    Make sure you tell me how things are working now!
     
  16. uncleseano

    uncleseano Private E-2

    thanks for all the help and speedy replies, you are total champs...

    mgtools get logs returns an error that says
    'Freeware implementaion of REG.EXE has stopped working, but I thinks that's normal is it?

    It also says that AAM Updates Nofifier Application, grep.exe and vfind.exe, zip.exe have stopped working during the getlogs.bat run
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me how things are running.

    Just to cover all bases, let's have you do one more thing:

    Go to the below link and follow the instructions for running TDSSKiller from Kaspersky

    Be sure to attach your log from TDSSKiller

    Please also download MBRCheck to your desktop.

    See the download links under this icon [​IMG]

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  18. uncleseano

    uncleseano Private E-2

    ok so here are those logs, pretty promising. TDSSkiller found a dodgey rootkit and cured it and it seems to have done the trick. mbam isnt reading the computer trying to reach that random serbian IP anymore and the sound stutter seems to have stopped.

    Gonna give it a day tho before I'm totally happy
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Very good!! :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0


    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  20. uncleseano

    uncleseano Private E-2

    Yeah looks like the malware is gone, problem is I think the sound stuttering is to do with my computer. The crashes are happening still, just had one when trying to play a game that's really low in spec. Its the same sound 'lag' sort of, then gets more intence until the comp either freezes or BSOD on me. Is there anyway to check is the CPU or other hardware mnight be on the way out?
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That's a topic best suited for the software or hardware forum. ;)
     
  22. uncleseano

    uncleseano Private E-2

    hah! ok thanks for all your help. you've been great. have a good Tim. I can sleep happier now tonight :cool
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds