Windows XP SP3 severely infected by a devious worm/trojan/virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lovelychihuahua, Feb 22, 2011.

  1. lovelychihuahua

    lovelychihuahua Private E-2

    Hello fine folks,

    I want to start off by saying how grateful I am that such
    brilliant and seasoned professionals are willing to donate
    their considerable talents toward helping those of us that
    depend desperately upon these machines to facilitate our
    everyday lives, yet steadfastly remain mystified as to their
    inner workings.

    Having undergone my first infection, I must say that I
    appreciate the skill and talent of the person (or persons)
    who have compromised my system and am suitably impressed.

    But my praise goes out to those of you that have resisted
    the temptation to use your talent for evil, choosing instead
    to spend your free time helping idiots like me repel those
    devious little pieces of sophisticated ingenuity that ruin
    our computers (and by extension, our lives).

    I'm not just blowing smoke up your snatch...I truly
    appreciate your fight on behalf of the common man against
    those of your peers who have chosen the dark side. I
    appreciate the humor in watching an idiot flounder about in
    pain and ignorance, but God bless you for choosing to help the
    idiot instead of tormenting him (although I'm sure you laugh at
    our antics on a daily basis).

    On to it.

    I have a machine that has been severely compromised. I have
    done my best to follow the guidelines, rules and steps you
    posted for this forum. I have diligently studied and executed
    your instructions and created the correct logs to the best
    of my (severely limited) ability. Hopefully I have given you
    the tools you need to help me.

    I should start off by saying I have misplaced my original OS
    CD-Rom, and therefore will be hard-pressed to re-install XP.

    You asked that I provide a detailed account of what I did to
    allow the malware to take root, and I shall do so now.

    As stated in the subject line, I am running Windows XP SP3 on
    a Dell Inspiron 600m laptop. I am connected to the web
    wirelessly through an Intel Pro Wireless modem, using Windows
    Wireless Connection, through a Gateway 2wire router (2701HGV-8)
    and ATT broadband dsl service.

    My nightmare began about a week ago, when I decided I should try
    to get my netflix to stream live to my tv through my directv dvr.

    I encountered a program called PlayOn, which bridges the
    home network to the directv network (connected to my
    broadband router via an ethernet cable) and tells the dvr to
    treat Netflix, YouTube or any of my picture, video, or music
    files as if they were streaming from directv.

    I downloaded the trial version of PlayOn from the manufacturer's
    website, and was messing around, trying to get it to work.

    In order to do so, I had to open ports on my network to
    allow incoming connections.

    I had limited experience with this, (I know how you guys
    feel about piracy, but in the interest of full disclosure...)
    having used BitTorrent a few times to share music and video
    files.

    I opened the ports to PlayOn, then found a link in a forum (which
    tragically has been erased from my history due to repeated cache
    cleaning) that said an earlier version of PlayOn was more
    streamlined and efficient.

    It directed me to a site where I downloaded PlayOn 2.58.3190

    I have attached the instructions (playon.txt) it gave me to
    workaround the registration (I know this is not an attachment
    you asked for in the guidelines, but I thought it might be useful
    for you to look at, since I edited my registry according to its
    direction).

    I never really got PlayOn to work. It was buggy. At one point,
    I got my dvr to show the PlayOn locations in its menu, but when
    I tried to select them, the TV screen went grey with a "loading"
    process bar for a couple of minutes, then returned to the previous
    channel.

    I started messing with my firewall, both on my machine and on my
    router. I opened ports 1-16 to incoming connections on my laptop
    for PlayOn. I added the dvr to my home wireless network on my router,
    and (I'm embarrassed to say) gave it full DMZ authorization to allow
    all incoming connections. I figured it wasn't hooked up to my
    machine, so it was safe.

    Things started getting weird. My taskbar icons started disappearing,
    my system started bogging down, crashing and taking forever to shut
    down and restart. About once in every three times I tried to start up,
    it would freeze up and I would have to force shutdown by holding down
    the power key on my keyboard until the system died.

    Taskmgr.exe had several processes I hadn't noticed before, such as
    multiple permutations of svchost.exe and a huge portion of system
    resources going to apoint.exe (my touchpad software) and smss.exe.

    I tried scanning my system with AVG Free and was instructed to download
    the most current version of AVG (2011), which came with PCTuneup as a
    bundle.

    After I installed the new AVG, my system started freezing and was slower
    than ever before. Taskmgr.exe showed AVG taking up huge amounts of
    system resources, even when it was running in the background. I ran Cache
    Cleaner (v.3.3.0.1366) and then decided to run PCTuneup, since it was
    new to my system and in a free trial period. I probably made 50 changes
    to my OS with PCTuneup. One of the PCtweaks I implemented was to log me
    on automatically, rather than having to enter a password when I returned
    from standby or hibernation.

    The reason I mention this one tweak among many is that immediately
    thereafter I noticed winlogon.exe gobbling up system resources, running
    near the top in mem usage among my processes.

    Now I started hitting the forums, and I shamefully admit I paid less
    attention to the domain names than the correlation to my google search
    strings. I cannot tell you which download sites I downloaded
    ProcessExlorer, I/O Bit 360, Malwarebytes and Avira Anti-Vir from, only
    that I installed them, ran scans, looked at system processes, and tried
    to figure out what was going on. During this frenzy of activity, I
    removed PlayOn and BitTorrent and shut down the firewall permissions
    for incoming connections on both my Windows Firewall and the ATT firewall
    for my broadband connection.

    I also searched for disappearing taskbar icons as a symptom of my issues
    and found a forum thread that directed me to make a copy of explorer.exe,
    rename it explorer1.exe, and rewrite the registry to have Windows recognize
    the new app. Unfortunately, after so many cache cleanings, I have lost the
    history entry for this action and can't remember which registry entries
    I changed.

    None of the scans showed any issues except for Malwarebytes, which found
    and quarantined one memory issue and three registry issues. I have
    attached the log for this scan AS WELL AS the log from the scan I
    performed when following your guidelines on your malware removal forum
    guide. The original log is dated 2011-02-19 and the subsequent log is
    dated 2011-02-22.

    I also tried to start Windows in safe mode, but it froze up on the entry
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS\system32\DRIVERS\agp440.sys
    and still freezes at that point now.

    I noticed Avira taking massive amounts of memory and system resources,
    so I uninstalled it.

    Later, when I was following your guidelines, I was instructed to disable
    any anti-virus software but I kept running into notifications that Avira was
    active, enabled and running. However, IT WAS NOT LISTED in Add/Remove
    Programs, Windows Defender Software Explorer, taskmgr.exe, or
    Process Explorer.

    Windows Defender processes (MsMpEng.exe and MSASCUI.exe) were also hogging
    huge amounts of system resources, so I disabled Windows Defender.

    I also went to another Malware forum, techsupportforum.com, and started
    following their posting guidelines, downloading and installing DDS.scr and
    gmer.exe, before I found your forum and found it to be friendlier and more
    accessible.

    Everything I have done since then has been in accordance to your posted
    guidelines.

    whew.

    I apologize for the outrageous length of this play-by-play, but I thought
    the more information I gave you the better chance you would have helping me
    resolve this issue.

    Thank you in advance for your time and help.

    -lc
     

    Attached Files:

  2. lovelychihuahua

    lovelychihuahua Private E-2

    2nd post with last two attached logs

    Here are the final two logs.

    Thanks again,
    -lc
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.


    I also need to see the C:\MGlogs.zip from running C:\MGTools.exe
     
    Last edited: Feb 22, 2011
  4. lovelychihuahua

    lovelychihuahua Private E-2

    OK here are the logs you requested!

    Sorry I forgot to include the MGlogs .zip file. Dangit, I was trying so hard to be thorough.

    I also have one more question...my ipod was connected several times during the infection. Is it possible the virus/worm/trojan compromised my ipod as well?

    Thanks again!
    -lc
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seeing alot to do really. We can take care of some miscellaneous items and be rid of some temp files.
    Just run a full system scan afterwards with you antivirus when we are finished with the ipod plugged in.

    Uninstall the below outdated Java.

    • J2SE Runtime Environment 5.0 Update 9
    • Java(TM) 6 Update 23

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\dllcache\OLD57D.tmp
    c:\windows\system32\dllcache\OLD579.tmp
    c:\windows\system32\dllcache\OLD575.tmp
    c:\windows\system32\dllcache\OLD571.tmp
    c:\windows\system32\dllcache\OLD514.tmp
    c:\windows\system32\dllcache\OLD4AC.tmp
    c:\windows\system32\dllcache\OLD44A.tmp
    c:\windows\system32\dllcache\OLD3FF.tmp
    c:\windows\system32\dllcache\OLD37B.tmp
    c:\windows\system32\dllcache\OLD2FE.tmp
    c:\windows\system32\dllcache\OLD252.tmp
    c:\windows\system32\dllcache\OLD1A1.tmp
    c:\windows\system32\dllcache\OLD144.tmp
    c:\windows\system32\dllcache\OLDC0.tmp
    c:\windows\system32\dllcache\OLD1B.tmp
    c:\windows\system32\dllcache\OLD14.tmp
    c:\windows\system32\dllcache\OLD281.tmp
    c:\windows\system32\dllcache\SET27F.tmp
    c:\windows\system32\dllcache\OLDD.tmp
    c:\windows\system32\dllcache\OLD343.tmp
    c:\windows\system32\dllcache\OLD18C.tmp
    c:\windows\system32\dllcache\OLD188.tmp
    c:\windows\system32\dllcache\OLD184.tmp
    c:\windows\system32\dllcache\OLD180.tmp
    c:\windows\system32\dllcache\OLD17C.tmp
    c:\windows\system32\dllcache\OLD178.tmp
    c:\windows\system32\dllcache\OLD174.tmp
    c:\windows\system32\dllcache\OLD170.tmp
    c:\windows\system32\dllcache\OLDB61.tmp
    c:\windows\system32\dllcache\OLDB5C.tmp
    c:\windows\system32\dllcache\OLD4BF.tmp
    c:\windows\system32\dllcache\OLD4BC.tmp
    c:\windows\system32\dllcache\OLD4B8.tmp
    c:\windows\system32\dllcache\OLD4B5.tmp
    c:\windows\system32\dllcache\OLD48B.tmp
    c:\windows\system32\dllcache\OLD487.tmp
    c:\windows\system32\dllcache\OLD483.tmp
    c:\windows\system32\dllcache\OLD32.tmp
    c:\windows\system32\dllcache\OLD2E.tmp
    c:\windows\system32\dllcache\OLD2A.tmp
    c:\windows\system32\dllcache\OLD26.tmp
    c:\windows\system32\dllcache\OLD22.tmp
    c:\windows\system32\dllcache\OLD1E.tmp
    c:\windows\system32\dllcache\OLD1A.tmp
    c:\windows\system32\dllcache\OLD16.tmp
    c:\windows\system32\dllcache\OLD12.tmp
    c:\windows\system32\dllcache\OLDE.tmp
    c:\windows\system32\dllcache\OLDA.tmp
    c:\windows\system32\dllcache\OLD11.tmp
    c:\windows\system32\dllcache\SET1AD.tmp
    c:\windows\system32\dllcache\SETC86.tmp
    c:\windows\system32\dllcache\SETBFB.tmp
    c:\windows\system32\dllcache\SETBDC.tmp
    c:\windows\system32\dllcache\SETA74.tmp
    c:\windows\system32\dllcache\SETA6C.tmp
    c:\windows\system32\dllcache\SETA02.tmp
    c:\windows\system32\dllcache\SET543.tmp
    c:\windows\system32\dllcache\SET2E6.tmp
    c:\windows\system32\dllcache\SETA66.tmp
    c:\windows\system32\dllcache\SET144.tmp
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Tell me what malware problems remain?
     
  6. lovelychihuahua

    lovelychihuahua Private E-2

    The remaining issues are: my shutdown takes about 10 minutes, Window Security Center says Avira Anti-Vir is updated and active but I uninstalled it a while ago and it does not appear in process explorer or task manager or in the program files...Combofix also detected it and gave me two error screens about it, I uninstalled Roxio and it showed back up in process explorer during startup.

    When Combofix was running, I got a notification called PEV.cfxxe

    C:\WINDOWS\system32\atipdlxx.dll is corrupt or unreadable

    and

    C:\WINDOWS\system32\Oemdspif.dll is corrupt or unreadable

    When Combofix was generating its log, the system abruptly shut down and ran chkdsk. Should I try to track down the chkdsk log?

    After chkdsk finished, combofix tried to upload to its server and was unable to. It gave me a file to try manually, which I did, but it was also unsuccessful.

    Thanks again for your help!
    -lc
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This should do the trick.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    SecCenter::
    {AD166499-45F9-482A-A743-FDD3350758C7}
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.
    Not topic for the malware forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds