Residual Traces of Infection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by RastaJon, Aug 20, 2014.

  1. RastaJon

    RastaJon Private E-2

    Hi,

    I'v been cleaning a friends computer of quite a lot of infections. I have removed most of the malware but i'm sure there is some traces left behind.

    Please find the logs attached.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O1 - Hosts: 54.204.28.26 ajakpekbmnkgnjbpajgkdhimcbeoocam
    • O3 - Toolbar: (no name) - {41564952-412D-5637-00A7-7A786E7484D7} - (no file)
    • O4 - HKCU\..\Run: [IhizErye] regsvr32.exe "
    • O4 - HKLM\..\Policies\Explorer\Run: [81324703] C:\PROGRA~3\msdfvu.exe
    • O9 - Extra button: (no name) - {4BEEA052-726D-4A6E-B65D-A6BD07C263F3} - (no file)
    • O9 - Extra 'Tools' menuitem: About nurago web meter - {4BEEA052-726D-4A6E-B65D-A6BD07C263F3} - (no file)
    • O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
    After clicking Fix exit HJT.



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :reg
    [-HKU\S-1-5-21-61326812-3260373432-3726041123-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\AppDataLow\Software\Conduit]
    [-HKU\S-1-5-21-61326812-3260373432-3726041123-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\AppDataLow\Software\Smartbar]
    [-HKU\S-1-5-21-61326812-3260373432-3726041123-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [-HKU\S-1-5-21-61326812-3260373432-3726041123-1001\Software\AppDataLow\Software\Conduit]
    [-HKU\S-1-5-21-61326812-3260373432-3726041123-1001\Software\AppDataLow\Software\Smartbar]
    [-HKU\S-1-5-21-61326812-3260373432-3726041123-1001\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    
    :Files
    C:\PROGRA~3\msdfvu.exe
    C:\$RECYCLE.BIN\S-1-5-21-61326812-3260373432-3726041123-1000\$RZ8MWRR.exe
    C:\Users\Tez\AppData\Local\alkyqyva.log
    C:\Users\Tez\AppData\Local\aobumajl.log
    C:\Users\Tez\AppData\Local\aofihiqe.log
    C:\Users\Tez\AppData\Local\bffifaql.log
    C:\Users\Tez\AppData\Local\cwitwhcg.log
    C:\Users\Tez\AppData\Local\cwvmsisr.log
    C:\Users\Tez\AppData\Local\dnaaoiwo.log
    C:\Users\Tez\AppData\Local\enssmpai.log
    C:\Users\Tez\AppData\Local\huqifvnv.log
    C:\Users\Tez\AppData\Local\IconCache.db
    C:\Users\Tez\AppData\Local\jdlaobwy.log
    C:\Users\Tez\AppData\Local\jnhcrury.log
    C:\Users\Tez\AppData\Local\lvfwbdbf.log
    C:\Users\Tez\AppData\Local\ncarwerw.log
    C:\Users\Tez\AppData\Local\ndbpieuo.log
    C:\Users\Tez\AppData\Local\pkumgmxd.log
    C:\Users\Tez\AppData\Local\saexifdu.log
    C:\Users\Tez\AppData\Local\vrbtxasi.log
    C:\Users\Tez\AppData\Local\xgknxahb.log
    C:\ProgramData\npgpkrqm.log
    
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    Empty your recycle bin.


    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!

     
  3. RastaJon

    RastaJon Private E-2

    Hey, thanks for the quick response.

    Running HijackThis I encountered an unexpected error:
    Am I right in assuming these steps are a manual way of removing what HitMan would of? Just curious, as I am wanting to learn more about malware fighting.

    Please find the logs attached.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I was wrong about the trial expiring with Hitman, there are 28 days remaining. (My fix is attempting to remove the items it did show, though.)



    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program

    MGTools did not run correctly. Please run it again this time ensuring protection software is disabled, that you indeed ran it as admin, and that UAC is disabled. Then attach the new MGlogs.zip please.
     
  5. RastaJon

    RastaJon Private E-2

    HostsXpert throw the following error when I attempt to restore the MS hosts file:
    In response to:
    I'v just realized Avira was in fact running, I had checked the system tray previously and it was not there (it still in not). When I try to open Avira i get the message:

    Should I stop the services AntiVirSchdulerService, AntiVirService, AntiVirWebService and Avira.OE.ServiceHost in Task Manager to run MGTools?
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Commands
    [resethosts]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    Uninstall Avira please and try MGTools.exe again.

    Let me know how you get on.
     
  7. RastaJon

    RastaJon Private E-2

    OK,

    So I tried to uninstall Avira and received an error saying it could not uninstall. I have attached the log file it gave me.

    I have IObit Uninstaller which has found 828 Avira items to delete using the powerful scan tool.

    Shall I use this to remove it?

    Also OTM gave the same error as HostsXpert. Could it be Avira stopping us modifying the hosts file?
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  9. RastaJon

    RastaJon Private E-2

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yep, go for it. :major
     
  11. RastaJon

    RastaJon Private E-2

    After a 612Mb download I have ran into a snag, the removal tool requires to be burnt to a CD/USB and booted from. I currently do not have physical access to the box.

    I have been using LogMeIn Rescue to perform the cleaning remotely. It gives me full access to Windows as well as letting me reboot in safe mode etc but i cannot control the client without windows being loaded as LogMeIn runs as a service.

    I can get access to the machine maybe tomorrow, but id like to resolve this remotely if possible, as its quite a drive away from me.

    If you tell me this is the only way, then so be it. But is there another angle we can approach this from?
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Go ahead and use iobit uninstaller and let me know how that goes....
     
  13. RastaJon

    RastaJon Private E-2

    OK,

    So i ran the force uninstall and Avira has disapeared from IObit and Windows Add/Remove Programs.

    But the C:\Program Files(86)\Avira folder is still present and the avguard.exe, Avira.OE.ServiceHost.exe and avshadow.exe processes are still running.

    If I try to run Avira from the desktop shortcut or the .exe i get the message
    After rebooting i got a window from OTM saying hosts has been reset on boot, so there's that.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Why are you trying to run it after uninstalling it? :confused

    I wanted it uninstalled so that MGTools could run, as you know. How is that going?
     
  15. RastaJon

    RastaJon Private E-2

    After "uninstalling" it, I noticed that the processes were still running and the file system seemed to be in place. I then wondered if the program was still runnable or part deleted so i thought id try and launch it, to test. This is when I received the program is blocked message.

    It seems to me that Avira is running, but the malware has removed my permissions to use or modify it in any way by using group policies. There is only one Windows account on this machine.

    I have tried to end the processes from task manager to stop it running but I get an access denied message.
     
  16. RastaJon

    RastaJon Private E-2

    I've finally managed to kill Avira,

    I had to boot into safe mode and disable the Avira services through services.msc. Now when I reboot there are no Avira processes running.

    I have re ran MGTools (in safe mode) and attached the logs. Is there any way to reset Windows group policies to default values?n
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So you were still unable to run MGTools in normal mode??

    I am not seeing anything else in that last set of logs anyway. How are things running?

    Are you able to reinstall Avira? If having troubles let me know. I think it may be broken left right and centre, I think thanks to iobit.
     
  18. RastaJon

    RastaJon Private E-2

    Once I had deleted the remaining parts of Avira. I reinstalled it no problem, once it was installed the program launched, updated the scanned the system. It found no infection.

    After a reboot I was back to being blocked out from it. Receiving the
    message any time I try to run it.

    If i try to uninstall it using windows programs and features i get the message.
    As far as i can tell there is currently no infection, but that wont last if i cant run an AV. I'm going to remove Avira again and try MSE to see if that has permission to function.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm, yes, do indeed install MSSE and let me know if you are able to run it.
     
  20. RastaJon

    RastaJon Private E-2

    I rebooted into safe mode and Avira uninstalled with no issues. MSSE installed with no problems. I have run a full scan which found no malware. Then rebooted 3 times to test, MSSE has run every time without issue.

    I did a scan with Hitman and MBam just to reassure myself that all infections have been cleared. Both returned no results.

    It's been a strange journey, I have never encountered malware using these tactics before. But I am happy, if you are, to call this machine clean. MSSE seems to work around the restrictions placed on Avira and all scans have returned no results.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I think avira just went a bit "iffy" is all. I'm glad Microsoft Security Essentials is playing nicely with your machine. It's what I use personally.

    I suggest you surf around for a day or so and then come back to me and post about how things are running, any problems etc...
     
  22. RastaJon

    RastaJon Private E-2

    Will do, thanks for all your help.

    On a side note, can you recommend any books or courses on malware removal? I am keen to study the subject and would like to eventually get myself to the point were I can analyze logs and create fixes confidently and independently. :major

    Many thanks again.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


    Becoming A Malware Forum Helper


    Unfortunately we are too busy to offer training to anyone who is not already a recognized expert. There are a few websites that provide training rooms. The process can take awhile to complete since there is a lot to learn and the people training you are doing it in their free time. Make sure that you are serious about wanting to spend the time to learn and have the time to perform malware removal this because it takes a strong committment. Check out the below sites:

    BootCamp

    Geek U!

    What the Tech Classroom

    BleepingComputer Malware Removal Training Program
     
  24. RastaJon

    RastaJon Private E-2

    Thanks Tim, exactly what I was looking for.
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Explain how things are running RastaJohn. It's been a few days now. I need to give you final steps to follow if all is still well. ;)
     
  26. RastaJon

    RastaJon Private E-2

    Hey Kestrel,
    My friend has been using the machine since we last spoke, and has reported no issues. MSSE is running everytime and all seems well.

    I kinda jumped the gun, and permormed the final steps the last time i had access to the machine. :-o I felt it was worth doing before I let my friend loose with it.

    Thanks again for all your help. You guys, as always, have been great. I have just been accepted into SWI Boot Camp. Inspired by the work you guys do here, so maybe, in few months/years i'll be in a position to pay it forward to the next guy eager to learn.:major
     
  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Glad the computer is running nicely. Enjoy your studies. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds