Zbot 4 infection?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by AJW, Feb 5, 2010.

  1. AJW

    AJW Private E-2

    Hi there on Tuesday my computer started to act a little oddly Norton informed me it had blocked Zbot from accessing the internet. Shortly after firefox could not connect to goggle and ended up in an infinite loop being directed between goggle.com and goggle.co.uk.
    None of my anti malware software could connect to the internet to update and attempts to search for anti malware software timed out or got redirected.
    My windows folder contains a file called sdra64.exe which leads me to believe its Zbot version 4.

    I have tried to follow all the steps in the sticky but because my pc’s acting so strangely I had problems with Superantispyware.

    I will post the logs in a minute from the infected pc.
     
  2. AJW

    AJW Private E-2

    I can’t find a logfile for the Superantispyware scan I ran what is the default location for it please?
     
  3. AJW

    AJW Private E-2

    Sorry about posting log files as txt here they are as attachments
     

    Attached Files:

  4. AJW

    AJW Private E-2

    the last 2
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please go to Add/Remove programs and uninstall the following software:

    • J2SE Runtime Environment 5.0 Update 1


    2. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.


    3. Use Windows Explorer to locate and delete the below bold folder:

    4. Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.


    5. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix. and TDSSKiller.

    7. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  7. AJW

    AJW Private E-2

    Kestrel I’m afraid I have a confession to make when I got impatient after a couple of days with out a reply and started playing around on my own looking at people that had similar problems.
    The steps I took were running DDS and Malwarebytes again which this time found and delegated about 40 items for some reason my inability to update anti virus software was rectified as was firefoxes and IE’s inability to log on to Google. I updated all my anti spyware programs and ran them they found a few more items that I delegated but I am still left with occasional Google redirects primarily to the following sites “Shopperdo,http://pharmastores.com/sleep.htm,Anoneweb,Safecompare.com”

    The registry values you asked me to delete with MGtools had already been delegated I did al the rest but ****ed up running TDSSkiller by double clicking it instead of running it as you directed.

    Sorry Kestrel I have managed to screw up quite a bit I really appreciate the time and effort you’re putting into this and promise to try and follow instructions better in future.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry, I work nights at a pub and weekends are busy for me, I don't often get home until 1am.

    You should never follow advice given to someone else in another thread, each computer is different and therefore so is the fix. You could damage your system by following fixes built for someone else. Just a heads up for the future.
    Which perhaps proves the fix you followed for someone else didn't work properly ;)

    I need to get a fresh look on how things are, so:

    • Run Combofix again and attach the log it creates.
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  9. AJW

    AJW Private E-2

    I appreciate the help Kesrel and didn’t mean to be ungracious.
    System seams to be running fine now after running TDSSkiller it caught and deleted something but id still appreciate an all clear before I consider using on-line banking or anything.
    One last question what was the primary infection was it Zbot?
    Second last question I used a usb memory stick to transfer programs to the infected PC in the early stages do I need to run Malwarebytes on that I guess I do?
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The worst problem was the infected atapi.sys file caused by the TDSS Rootkit. TDSSKiller cured the problem.

    What is this file for?

    Did you fix the 017 lines from my fix in post #6?

    You need to use HJT to fix this line:
    You can scan with MBAM or SAS with your flashdrive plugged in, and you can also try this:

    Insert your flash drive before we begin. Hold down the Shift key when inserting the flash drive until Windows detects it to bypass the autorun feature. This will keep the autorun.inf from executing automatically.

    Please have all your removable storage devices ready for disinfection.

    Download Flash Disinfector by sUBs and save it to your desktop.
    • Double-click Flash_Disinfector.exe to run it.
    • Your desktop and icons may disappear. This is normal.
    • It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
    • Follow any prompts that may appear.
    • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
    • Wait until it has finished scanning and then exit the program.
    • There will be no GUI interface or log file produced.
    • Reboot your computer when done.

    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.
     
  11. AJW

    AJW Private E-2

    File Saver is a program for recovering deleted files I have never used it so took the opportunity to delete it.

    The 017 lines had been deleted by one of the malware scans and weren't there when I ran hijack this last time.

    O15 - Trusted Zone: *.musicmatch.com
    I have now removed.

    I’m going to delete old system restore points and create a new one then I’m done right?

    Thanks for your help Kestrel.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes you're all done now :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds