![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#21
|
|||
|
|||
|
Quote:
It's entirely possible, if not likely, that that's what SEP is picking up on--the reinfection. So for example, my computer has not been rebooted since the last set of logs I uploaded, and yet see the attached RK log. Is it possible the smb share I have mounted from my linux machine with ~2.4TB of data on it is reinfecting it? Or from somewhere else over my work network? |
|
#22
|
||||
|
||||
|
Quote:
Quote:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#23
|
|||
|
|||
|
I kept the rig offline (cable disconnected) for about 18 hours overnight yesterday and it was clean when I came in this morning. The most recent log is attached.
Unfortunately I have to have it online, so it's plugged in again. I'll let you know if /when it gets infected again. |
|
#24
|
||||
|
||||
|
Quote:
Now it is always possible that something on this PC is dialing out and redownloading the infection, but that seems less likely since nothing shows in the logs and your Symantec Endpoint firewall should be protecting you from this happening.... well hopefully it does unless someone has given the process permissions thru the firewall.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#25
|
|||
|
|||
|
Just ran a scan before leaving work here, and sure enough it was infected again. I've removed the offending files, but of course they'll be back.
How should I proceed? I didn't notice any exceptions I don't recognize in the firewall rules. Is it more likely to be coming from my Ubuntu server that I am mounting two shares from, or is it equally likely to be coming from any random device on my work's local network? |
| Sponsored links |
|
|
|
#26
|
||||
|
||||
|
Quote:
Navigate to the below folder: C:\Users\Jared\AppData\Roaming Create a folder ( not a file ) with the below name: service1043.exe Change the permissions of this new folder to be Read-Only, Hidden While scans may still detect this strangely named folder, let's see if it blocks the ability of the infection from creating the file. Quote:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#27
|
|||
|
|||
|
Unfortunately the service1043.exe file does not seem to exist... at least not in that location
|
|
#28
|
||||
|
||||
|
Hmmm! I wonder if it is hidden or it comes and goes? Try creating the below FOLDER name:
C:\Users\Jared\AppData\Roaming\service1043.exe If you cannot create the folder, it would mean there is a file there already using that name. The next time you see that the registry entries have appeared, do not fix them. Try running the below online scan and attach the ESET log. Using ESET's Online Scanner
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#29
|
|||
|
|||
|
Okay sooooo.... things did not go exactly as planned.
First off, I was able to create the service1043.exe directory no problem, even when roguekiller reported the threat as present. Next, I tried running ESET. It was a looooooooong scan and I ended up having to leave before it was done. While it was working, it reported Win32/PrcView as a thread, in addition to Win32/Dorkbot.D worm. I left work with it still running, and when I came in the next day my computer had BSOD'd. So I was unable to acquire a log. I reran it yesterday before leaving and it was done when I came in. There were no threats and I couldn't find any way to get a log out of it (given that there were no threads). There was a link file in some backed up data that it had quarantined, so I instructed it to delete that. Since I didn't have an ESET log for you, I ran RK and attached that log instead. As you can see service1043 was still there. I deleted it, so we'll see if it comes back tomorrow.... |
|
#30
|
||||
|
||||
|
When this problem appears, is Symantec actually detecting it? If so perhaps it is already removing something we need to see that is not showing up in scans.
However that being said, I still have to go back to the fact that this does not show up when you are not connected to your network, so I have to wonder if the problem is coming from your some other PC on your network. Do you have any files/folders shared on this PC?
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
|
#31
|
|||
|
|||
|
Quote:
Yes, I too wonder if the problem is from some other PC on the network.... I'm not sharing any folders, but I do have two samba shares mounted from an Ubuntu box. |
|
#32
|
||||
|
||||
|
Quote:
Quote:
Would need a log showing where this is found to determinie if it is real or not. Nothing related to this showed in other logs but those logs would not detect all aspects of this infection if it did exist. I would however expect that your Symantec Antivirus program would detect it. Please download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
Download SystemLook_x64 from one of the links below and save it to your Desktop. Download Mirror #1 Download Mirror #2
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#33
|
|||
|
|||
|
Quote:
Quote:
Quote:
All done, logs attached. Finds the registry entries but no files.... |
|
#34
|
||||
|
||||
|
Quote:
Now download and save a copy of combofix.exe and save it directly onto your Desktop folder. Then right click on it and select Run As Administrator. Do not disturb it by clicking in the window that opens or it may stall. After it finishes, it may reboot your PC. Attach the C:\combofix.txt log that it creates. If after running Combofix you discover none of your programs will open up because you receive the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#35
|
|||
|
|||
|
Okay, here's the log. And no, I didn't fix them prior to running this scan.
|
| Sponsored links |
|
|
|
#36
|
||||
|
||||
|
Okay the only thing Combofix showed was the below folder I had you create
Code:
2012-09-20 15:41 . 2012-09-20 15:41 -------- d-----w- c:\users\Jared\AppData\Roaming\service1043.exe Also let's do the below with ComboFix where I'm going to remove those registry keys and replace them with a dummy entry. Now we need to use ComboFix
Quote:
Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#37
|
|||
|
|||
|
Unfortunately I've been too busy working on this machine to follow the instructions in your last post.
However, I also happen to have noticed that I have seen no sign of the virus (no alerts from SEP) in over a week of continuous uptime. That hasn't happened since the infection appeared. In short, it looks to me like something we did in the last little while finally cleaned the infection permanently. What do you think? |
|
#38
|
||||
|
||||
|
Quote:
I would not think so since you still had the problem after previous fixes and you did not run the most recent one.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#39
|
|||
|
|||
|
My work network has probably roughly 1,000 PCs on it, so I can't really answer your first question.
Couldn't Windows Repair or ESET have fixed it? Unfortunately I don't remember exactly but I think the last time I saw SEP report an infection was around the time I ran those. |
|
#40
|
||||
|
||||
|
I cannot really say for sure with having seen a log but we were not able to get one. Is it possibly.... yes.
If you are not having any other malware problems, it is time to do our final steps:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
![]() |
| Tags |
| trojan, trojan.gen.2 |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Malware.trace, Trojan.agent, Trojan-dropper, Rogue anti-virus | duckfeet | Malware Removal | 8 | 07-12-10 17:01 |
| Trojan Horse Downloader.Small.DHQ, Trojan.FakeAlert, and TrojanVundo :-) good times | smssoleimani | Malware Removal | 8 | 07-30-09 09:30 |
| Trojan.Vundo.H, Trojan.Vundo, and Trojan.Agent keep coming back | Angelcape | Malware Removal | 1 | 11-28-08 16:06 |
| Re-occuring Trojans: Trojan:BHO, Trojan:adclicker, Trojan:agent | absentia | Malware Removal | 5 | 10-03-08 10:09 |
| win32/trojan downloader.ISTbar.EN trojan; win32/trojan dropper.bridge.A trojan | vlatko27 | Software | 1 | 05-27-04 08:40 |