Russian hacker problems...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by samuk1000, Mar 15, 2010.

  1. samuk1000

    samuk1000 Private E-2

    A hacker attacked my PC last week. All my website html files had malicious code entered. I performed the cleaning process. I thought I was clean, so I disabled/reenabled Sys Res. I'm now getting hangups on startup with programs like starteak using 99% CPU. Nasty viruses/trojans/rootkits. Will try to attach all .txt files.
     

    Attached Files:

  2. samuk1000

    samuk1000 Private E-2

    additional attachments.
    I ended up doing two scans of SAS/MBAM in the end hence two attached.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!
    I can however see what else needs to be done in the way of cleaning any malware that does remain on the machine itself. I'll look over your logs and get back with a response shortly. :)
     
  4. samuk1000

    samuk1000 Private E-2

    Thank you. I have since done uninstalled many programs that could be malicious or illegit and done another malwarebytes scan. I note also that combofix created a "my computer" icon and copies of various folders but that seems to have gone now. It is very difficult for me to get online. Firefox and Seamonkey both crashing. I have just managed to get on with Seamonkey.

    I am quite scared about identity theft and the maliciousness of the attacks, especially to my websites, which were reinputting the malicious code seemingly in real time and preventing a launch of a product I was releasing.

    Finally, I also enclose the root repeal log (yesterday) and a hijack this log (at time of writing). I could not get online to upload the root repeal and also it got caught in the endless loop (there is a thread talking about running root repeal for 15 hours by someone else).

    I believe the hackers/virus distibutors are Russian because I remember a very strange and bizarre Russian "strange news" site popping up literally out of nowhere in internet explorer about a week ago and I followed a few links which lead pretty much nowhere, wondering where the sites had popped up from.

    Thanks in advance for your help.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks for attaching the Rootrepeal log. But do not run anything or attach anything else unless I request it. :) I did not ask for a HJT log

    Let's get started:

    1. Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode, if you haven't done so already.

    2. Please download http://noahdfear.net/downloads/HelpAsst_mebroot_fix.exe by noahdfear and save it to your Desktop.

    • Double click HelpAsst_mebroot_fix.exe to run the tool.
    • When the tool completes it will inform you HelpAssistant was successfully removed, or it may require a reboot. DO NOT reboot at this point if it tells you this. Do the below first.
    • With Windows Explorer, navigate to the C:\MGtools folder and double click on mbrfix.bat ( If not sure how to use Windows Explorer, you can optionally click Start > Run and enter C:\MGtools\mbrfix.bat into the run box and click OK. ) This will run quickly flashing a black screen in front of you too fast to read.
    • NOW REBOOT!

    After reboot continue with the below:

    3. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    msconfig should not be running at start up so please fix this as well.
    After clicking Fix exit HJT.


    4. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    Driver::
    nprdnpm
    
    DirLook::
    C:\Baskets
    C:\{ed902d57-ac1b-405a-9026-b6f25799d38e}
    
    File::
    C:\WINDOWS\system32\msirbt32.exe
    C:\Documents and Settings\Sam\My Documents\~WRL1201.tmp
    C:\Documents and Settings\Sam\My Documents\~WRL1522.tmp
    C:\WINDOWS\TEMP\$$$dq3e
    C:\WINDWS\TEMP\$67we.$
    C:\WINDOWS\TEMP\77.tmp
    C:\Documents and Settings\Sam\Local Settings\temp\NPJs.dll 
    C:\Documents and Settings\Sam\Local Settings\temp\Cab78.tmp
    C:\Documents and Settings\Sam\Local Settings\temp\Tar79.tmp
    C:\Documents and Settings\Sam\Local Settings\temp\TLHg2zLi.htm.part
    C:\Documents and Settings\Sam\Local Settings\temp\REV8.tmp
    C:\Documents and Settings\Sam\Local Settings\temp\CFG10.tmp
    C:\Documents and Settings\Sam\Local Settings\temp\cfg18.tmp    
    C:\Documents and Settings\Sam\Local Settings\temp\cfg1a.tmp     
    C:\Documents and Settings\Sam\Local Settings\temp\cfg1f.tmp     
    C:\Documents and Settings\Sam\Local Settings\temp\cfg21.tmp     
    C:\Documents and Settings\Sam\Local Settings\temp\cfge.tmp      
    C:\Documents and Settings\Sam\Local Settings\temp\csj54.tmp 
    c:\windows\system32\drivers\laxgne.sys
    
    Folder::
    C:\Documents and Settings\Sam\Local Settings\temp\is-0QI7V.tmp
    C:\Documents and Settings\Sam\Local Settings\temp\IS-1H6OL.TMP             
    C:\Documents and Settings\Sam\Local Settings\temp\IS-8RG4S.TMP                
    C:\Documents and Settings\Sam\Local Settings\temp\IS-E7H54.TMP                
    C:\Documents and Settings\Sam\Local Settings\temp\IS-FMKII.TMP               
    C:\Documents and Settings\Sam\Local Settings\temp\IS-S2KF2.TMP                
    C:\Documents and Settings\Sam\Local Settings\temp\ISP2B.TMP                  
    C:\Documents and Settings\Sam\Local Settings\temp\ISS11F.TMP
    C:\Documents and Settings\Sam\Local Settings\temp\Rar$DR01.453
    C:\Documents and Settings\HelpAssistant
    
    Registry::
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{145B29F4-A56B-4b90-BBAC-45784EBEBBB7}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    5. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    7. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
    Last edited: Mar 16, 2010
  6. samuk1000

    samuk1000 Private E-2

    Unable to run first instruction (Help_Asst...) Some strange characters came up in the shell window and then windows error:

    Rest of actions carried out. Logs attached.

    In C:\Documents and Settings\Sam\Local Settings\TEMP
    C:\WINDOWS\Temp there were three files that could not be deleted, including yesterdays (dated yesterday). That was the only other issue.

    Things seem to be running better since I uninstalled a lot of uneccessary software. Internet browsers continue to regularly crash (eg firefox, seamonkey). I deleted filezilla (FTP software) because it was crashing and giving strange requests.

    Another strange thing was that I was using PC tools firewall and it detected a network which it doesn't normally do.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Damn! Do you happen to have your XP CD? let me know and in the mean time I am going to seek advice regarding this.
     
  8. samuk1000

    samuk1000 Private E-2

    Hi I don't have it as I bought this machine off a friend.
    I do have a Chinese version of Windows XP CD for another machine.
    This was one of the worst hacks I've experienced ever.
    I believe it came from two Russian popups with "Barnum and Bailey/"weird news" pics which got my curiosity.
    I had no idea going on an odd site could allow trojans and so forth.
    After I got infected I left my machine on all day, so basically my whole hard drive could have been explored, including passport pics etc. DOH!
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's try this:

    GMER's MBR.exe

    • Double click on the MBR.exe file to run it.
    • A log will be produced & saved to the desktop, called MBR.log.
    • Rename this log. Attach this log to your next message.


    Then run the below instructions.
    Click Start > Run and copy & paste the following text in the code box into the Run box and then click OK. You must copy and paste or type in this exactly. The quotes must be exactly as shown and there is a space before the -f
    Code:
    
         "%userprofile%\desktop\mbr.exe" -f
    
    Now double click on the mbr.exe file and attach the new mbr.log

    Now we need to use ComboFix again
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Folder::
    C:\Documents and Settings\HelpAssistant
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix. and the other logs that I asked for.
     
  10. samuk1000

    samuk1000 Private E-2

    I'm not sure how long it takes to get infected from a site which has the malicious script. Do you know?

    Here are the attachments. Amazingly fast response times, thank you.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Could be instantaneous... our main concern now is removing the infection.

    We have work to do, and although it might be frustrating, rest assured, my aim is to get your machine clean, I may have to seek advice at times too, but I won't abandon you.

    Complete as many of the steps as you can, if something doesn't work, just note it down to later tell me and continue on with the rest of the fix.


    1. We need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    NetSvc::
    {281D9357-D0A6-490B-AA6A84090F8993DF} 
    
    FileLook::
    c:\windows\system32\dllcache\tcpip.sys
    c:\windows\system32\drivers\tcpip.sys
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    2. Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      c:\windows\system32\dllcache\tcpip.sys
    • At the upload site, click once inside the window next to Browse.
    • Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
    • Next click Submit file
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

    Then do the same for the below file and also let me know the results:

    Code:
    c:\windows\system32\drivers\tcpip.sys

    Now let's try this again:

    3. Please download http://noahdfear.net/downloads/HelpAsst/HelpAsst_mebroot_fix.exe and save it to your desktop.
    Close out all other open programs and windows.
    Double click the file to run it and follow any prompts.
    If the tool detects an mbr infection, please allow it to run mbr -f and shutdown your computer.
    Upon restarting, please wait about 5 minutes, click Start>Run and type the following bolded command in the quote box, then hit Enter.



    Make sure you leave a space between helpasst and -mbrt !
    When it completes, a log will open.
    Please post the contents of that log.

    *In the event the tool does not detect an mbr infection and completes, click Start>Run and type the following bolded command, then hit Enter.



    Now, please do the Start>Run>mbr -f command a second time.
    Now shut down the computer (do not restart, but shut it down), wait a few minutes then start it back up.
    Give it about 5 minutes, then click Start>Run and type the following bolded command, then hit Enter.



    Make sure you leave a space between helpasst and -mbrt !
    When it completes, a log will open.
    Please post the contents of that log.

    4. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix. and the other logs that I asked for as well as the results from jotti.

    5. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  12. samuk1000

    samuk1000 Private E-2

    The main problem encountered was Combofix failing to continue running after it restarted, but on a second run was fine.

    In addition, StarTEAK.exe being a CPU hog taking out the CPU to 100%. This stops being the case by killing the process, but tends not to happen in the first place without virus activity in my experience.

    topic.sys at both locations brought ZERO/20 malware reports back.

    helpasst logs 1 and 2 attached.

    MGtools attached.

    Thanks again.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's finally nailed it. :) Your logs look good!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. samuk1000

    samuk1000 Private E-2

    Many thanks Kestrel, do you have a buy beer link? Or should I donate to the site if I want to?
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome! :)

    LOL @ buy beer. I gotta go pour it tonight at work!

    We do not take donations per se, however you can if you wish purchase yourself some geekwear (see red bolded link below) :major

    J!NX
     
  16. samuk1000

    samuk1000 Private E-2

    Reopened thread...

    Unfortunately, I got another malware attack, seemingly in the same vein as the previous, hence reopening the thread. This time, it got to the point I could not open a single program, not even "right click, properties" without the app failing to start and getting a dwwin.exe error.

    Finally I managed to run cmd.exe through the taskbar on startup and run combofix through shell. It ran process 49 only and I got back enough functionality to run removeitpro v. 8. The computer seems "cleaner" but is by no means clean I think.

    For example, running superantispyware or combofix causes the computer to shut down to a blue error screen asking for a restart and stating windows has closed to prevent further harm being done to the computer.

    I attach what files I can to this post, but I cannot run a lot of the antimalware tools as stated, eg malwarebytes, sas, combofix, rootrepeal.

    So I attach removitultra, the cbfix which did work, hjthis.
     
  17. samuk1000

    samuk1000 Private E-2

    Sorry. Mbam, hjthis, rmultra8
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Oh my :( What happened since the last time I declared you all clean? Ideally you should have started a new thread anyway, but we will continue on now.

    This report is a false positive anyway:
    Pev.exe is safe, and it's part of combofix.

    Now, without seeing at least logs from MGTools I am not going to be able to help you. I also want to try and get a combofix log.

    Rename Combofix.exe to Kestrel.com and rename MGTool.exe to 123.com and see how you get along with that. If you cannot manage this in normal mode, then do try safe mode.
     
  19. samuk1000

    samuk1000 Private E-2

    Combofix crashed system again (as Kestrel.com)
    As follows (blue screen).

    fasttx2k_2.sys

    PAGE_FAULT_IN_NEW_PAGE_AREA

    Technical details
    STOP 0x00000050
    (0xA709CS75,00000001,B09D0899,00000000

    ***fasttx2k_2.sys
    base at B0924000
    Datestamp 3f306b36

    MGtools attached.

    What happened was I was online and running a couple of softwares and suddenly a popup appeared as a window saying "personal settings" in a blank window, everything slowed and then nothing worked anymore- everything giving a dwwin.exe error. I managed to access shell by running task manager (CTL,ALT,DEL) before all startup items loaded and run a combofix, but this only carried out number 49 scan. SAS and MWB crashing as soon as finding trojans/viruses. CBfix crashes windows as it is preparing to scan.

    Noticed a couple of processes which seem to crop up when malware is running on machine - *.pif and CATCHME.tmp don't know what these are.

    Safe mode crashes to the blue screen before getting in to windows.
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not a problem. And ...

    Catchme is not a problem, it is just part of gmer/combofix and other tools.

    Going through your logs now
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Why are you using this computer without running anti virus?? I believe you were using avast at one stage. In my final steps was a link to how to protect yourself from malware, and that included reference to a list of recommended.

    Before I give you final steps this time, you should install some AV and a third party firewall. Because if you come seeking malware removal assistance again, you could be refused help if not protected.

    2. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    3. I had asked you to rename combofix to kestrel.com not Kestrel.com.exe. Please rename it exactly as I suggested.

    4. What exactly is this file on your desktop?

    5. What do you know about this small file? Do the properties of it reveal anything?

    6.Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      C:\WINDOWS\system32\admparsed.exe
    • At the upload site, click once inside the window next to Browse.
    • Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
    • Next click Submit file
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

    Then do the same for the below file and also let me know the results:

    Code:
    C:\WINDOWS\system32\bfvf.bxo

    7. Could you please get this: admparsed.exe into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    log retrievable @ C:\collect.zip

    8. Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    9. Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    10. Now try and run kestrel.com (combofix) again, if not in normal mode then try again in safe mode.

    11. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from avenger and hopefully you were successful with CF this time. Also let me know the jotti results and attach the collect.zip.

    12. Let me know how things are running, please.
     
  22. samuk1000

    samuk1000 Private E-2

    I am using RemoveitUltrav8 for AV
    I will reinstall PCTools Firewall Plus- I uninstalled it because it was crashing system when I had the previous malware

    Check

    Check

    I did this already. Still crashed the system.

    4. What exactly is this file on your desktop?

    MGTools renamed.

    When I opened this in notepad--C:\{ed902d57-ac1b-405a-9026-b6f25799d38e} it says the following in notepad:

    "Gootkit lock file. dont remove, please"
     
    Last edited by a moderator: Mar 26, 2010
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks for answering all my questions. But I cannot assist you until you attach the requested logs and jotti results.

    and please delete the renamed MGTools program from your Desktop. You don't need it anymore and it does not belong on your Desktop anyway.
     
    Last edited by a moderator: Mar 26, 2010
  24. samuk1000

    samuk1000 Private E-2

    Sorry Kestrel, I did not mean to post the above until I had finished. Phew. Kestrel.com worked a treat. It detected rootkit activity and shut down to the error screen, but worked on reboot and log is attached.​

    This thing was not allowing me access to jotti and many other sites such as google and basically causing a bunch of stress. I ordered a new computer this week anyway as this is getting old. But I won't let those f**kers win. At least not with your kind help.

    I am using RemoveitUltrav8 for AV
    I will reinstall PCTools Firewall Plus- I uninstalled it because it was crashing system when I had the previous malware

    Check

    Check

    I did this already. Still crashed the system.

    4. What exactly is this file on your desktop?

    MGTools renamed.

    When I opened this in notepad--C:\{ed902d57-ac1b-405a-9026-b6f25799d38e} it says the following in notepad:

    "Gootkit lock file. dont remove, please"



    Then do the same for the below file and also let me know the results:

    Code:
    C:\WINDOWS\system32\bfvf.bxo
    [/quote]

    RESULTS:

    C:\WINDOWS\system32\admparsed.exe - <strong>nasty</strong>
    File size: 44032 bytes
    Filetype: PE32 executable for MS Windows (GUI) Intel 80386 32-bit
    MD5: 017308b7027ebfe8e4f2206434086bc4
    SHA1: e4c3fd2a9eb9329ea8d14478417c014e2e3687d2

    [ArcaVir]
    2010-03-26 Found nothing
    [F-Secure Anti-Virus]
    2010-03-26 Trojan-Spy:W32/Zbot.PLI
    [A-Squared]
    2010-03-26 Found nothing
    [G DATA]
    2010-03-26 Found nothing
    [Avast! antivirus]
    2010-03-26 Found nothing
    [Ikarus]
    2010-03-26 Found nothing
    [Grisoft AVG Anti-Virus]
    2010-03-26 SHeur3.MNT
    [Kaspersky Anti-Virus]
    2010-03-26 Found nothing
    [Avira AntiVir]
    2010-03-26 Found nothing
    [ESET NOD32]
    2010-03-26 Win32/Kryptik.DFO
    [Softwin BitDefender]
    2010-03-26 Found nothing
    [Panda Antivirus]
    2010-03-26 Found nothing
    [ClamAV]
    2010-03-26 Found nothing
    [Quick Heal]
    2010-03-26 Found nothing
    [CPsecure]
    2010-03-26 Found nothing
    [Sophos]
    2010-03-26 Mal/FakeAV-BT
    [Dr.Web]
    2010-03-26 Found nothing
    [VirusBlokAda VBA32]
    2010-03-24 Found nothing
    [Frisk F-Prot Antivirus]
    2010-03-26 Found nothing
    [VirusBuster]
    2010-03-26 Found nothing


    C:\WINDOWS\system32\bfvf.bxo - <strong>also nasty</strong>
    File size: 28160 bytes
    Filetype: PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bit
    MD5: 37a421521b3818fbe6c5d8282bc9e2bc
    SHA1: 7577da27ae73682bb407a4efa1c099e8fb8d0136


    [ArcaVir]
    2010-03-26 Found nothing
    [F-Secure Anti-Virus]
    2010-03-26 Trojan.Win32.Agent.douf
    [A-Squared]
    2010-03-26 Trojan.Win32.Agent!IK
    [G DATA]
    2010-03-26 Found nothing
    [Avast! antivirus]
    2010-03-26 Found nothing
    [Ikarus]
    2010-03-26 Trojan.Win32.Agent
    [Grisoft AVG Anti-Virus]
    2010-03-26 Agent2.AMUV
    [Kaspersky Anti-Virus]
    2010-03-26 Trojan.Win32.Agent.douf
    [Avira AntiVir]
    2010-03-26 Found nothing
    [ESET NOD32]
    2010-03-26 Win32/Oficla.EZ
    [Softwin BitDefender]
    2010-03-26 Found nothing
    [Panda Antivirus]
    2010-03-26 Trj/Downloader.MDW
    [ClamAV]
    2010-03-26 Found nothing
    [Quick Heal]
    2010-03-26 Found nothing
    [CPsecure]
    Scanning, please wait...
    [Sophos]
    2010-03-26 Mal/Oficla-A
    [Dr.Web]
    2010-03-26 Trojan.Oficla.32
    [VirusBlokAda VBA32]
    2010-03-24 Found nothing
    [Frisk F-Prot Antivirus]
    2010-03-26 Found nothing
    [VirusBuster]
    2010-03-26 Found nothing

    collect.zip attached.

    avenger.txt attached

    Check


    See above done - YES. This is a powerful tool.

    .zips attached

    Smooth so far. Browser functionality seems back. Overall feel smoother.



    RemoveItPro Ultra 8 (is this OK as AV?)

    Will reinstall PCTools Firewall Plus. Last time I accepted Malware processes and got screwed though.

    ***I think the avenger ran OK but because Removeit found "cleanup.exe" to run on startup, I disallowed it, then realised it was probably avenger and ran it again, by which time it had deleted the files anyway.
     

    Attached Files:

  25. samuk1000

    samuk1000 Private E-2

    admparsed.zip

    admparsed.zip included in collect.zip


    After I examined the properties of the C:\{letters} small file, RemoveitPro found a Win32.Unknown.Random.X virus on object c:\windows\system32\cmd.exe
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    NOTE: I recommend you uninstall this immediately. I don't recommend any InCode Solutions software as they are notorious for false detections and constantly indite valid programs to be malware. The frequently even declare valid Microsoft files to be problems. This software is not properly tested.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: admparsed.zip

    See what I mean! This is the Windows Command Prompt program.
     
  28. samuk1000

    samuk1000 Private E-2

    Thanks done. Will go back to avast + PCtools firewall +
     
  29. samuk1000

    samuk1000 Private E-2

    Am going with sygate not PCT.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sygate was discontinued years ago and really does not provide adequate firewall features these days since it has not been updated in many years.
     
  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ok here's a fix. Please in future be very cautious about how you surf and where you surf to. I would also like to point out that the "stumble upon" toolbar and features can also land you in trouble as you do not know where the heck you are going to.

    1. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O4 - HKLM\..\Run: [syncman] c:\windows\system32\wuaucldt.exe

    After clicking Fix exit HJT.

    2. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Fcopy::
    C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\atapi.sys | C:\WINDOWS\system32\drivers\atapi.sys
    
    FireFox::
    FF - prefs.js: keyword.URL - hxxp://www.ask.com/web?&o=13795&l=dis&q=
    
    File::
    C:\WINDOWS\system32\admparsed.exe 
    C:\WINDOWS\system32\bfvf.bxo
    c:\windows\system32\wuaucldt.exe
    C:\{ed902d57-ac1b-405a-9026-b6f25799d38e}  
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "syncman"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    3. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  32. samuk1000

    samuk1000 Private E-2

    Re: Russian hacker problems...latest logs

    Hi Kestrel,

    Here are my latest logs.

    Sam
     

    Attached Files:

  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Those logs look good now Sam. Please rename kestrel.com back to combofix.exe otherwise final steps will not go smoothly.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  34. samuk1000

    samuk1000 Private E-2

    Thanks. There were about 30 files came up as containing security risks/viruses on the Avast scan I ran today. Some of them were combofix quarantined filed, but others were files sitting in folders on the computer. Do you know how to extract a log to notepad from Avast free edition?
     
  35. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    avast.jpg

    Open up avast by double clicking it's bubble in the system tray, choose the type of scan you want > click on more details > at the bottom of "more details" when that expands click on "settings" which will bring up the scan settings dialogue box. Click on "report file" and select generate report file. Enter a file name, and choose the file type. Plain Text (ANSI).

    Ok that, start your scan, and at the end of it, it should give you the option to view the report. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds