"whitesmoke" stuff, redirects, rootkits...Help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by insan_art, Dec 12, 2010.

  1. insan_art

    insan_art Private First Class

    Toshiba Satellite, Windows XPSP3, AVG Free 9.

    Howdy helpers at MajorGeeks!

    Well, I hate to be here for my own system, but things are going nuts! I believe my husband got hit by a drive-by or something while on Facebook. I first noticed a new tab come up in Firefox this evening with a weird link (never loaded all the way)... I closed it. Set the puter aside and noticed it was processing like crazy (with only thunderbird running) so I did a restart with intentions of immediately starting the Run & Read me upon restart because I was already suspicious that something was up. On restart I knew right away things were going downhill because my Windows toolbar had suddenly gone from Classic back to XP style (yet the start menu still showed as classic). When I opened Firefox my homepage had been hikacked.

    Did the Run & Read me. SAS came up clean (log is attached).

    Then the sh*t hit the fan while running MBAM - I sat there observing the scan and literally watched as this virus (or viruses?) set up shop in the background. Things started appearing on my desktop (including some "Whitesmoke" toolbar and translator crap and Google Chrome) and suddenly AVG and Windows Security were going crazy. MBAM came up with over 800 hits - I was freaking out!!!

    Hit a wall when I got to ComboFix - even though I had disabled AVG, ComboFix said I had to uninstall it to continue. I tried to uninstall AVG (several times) but I was unable to do so (it claimed it didn't have permissions to write some registry key). So, my apologies, no ComboFix log, and at this point, I've just about had it with AVG Free and their damn nag screens anyways!

    RootRepeal and MGTools ran fine.

    Please check me out! Thanks in advance. You folks do such a great service!!!!!!!!

    Also, any advice on the AVG removal issue? I already downloaded the newest AVG to replace the old one (since I thought I would be uninstalling it for ComboFix)...but now I'm re-considering other options, perhaps Avast?

    Thank you again for your help!

    EDIT: I'm sorry, it appears as though my logs didn't upload? I'll attach them to a reply (hopefully!).
     
    Last edited: Dec 12, 2010
  2. insan_art

    insan_art Private First Class

    Attaching logs. Sorry about that, not sure what happened!
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Ynezalolac"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "Hfucatebicog"=-
    
    :files
    C:\WINDOWS\csrats.dll
    C:\WINDOWS\esezoxujesazu.dll
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Uninstall AVG as it is no longer recommended by us anyway.

    I suggest you run the Official AVG Removal Tool from here
    Make sure you also delete any AVG folders in Program Files and Documents & Settings/Application Data directories.

    Tell me, or show me with a screenshot the contents of this folder:

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    Run Combofix.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!

    Yes, I use avast myself and am happy with it.
     
  4. insan_art

    insan_art Private First Class

    Kestrel, thank you so much for the super fast reply! I was so surprised by how quickly you got back to me - despite the fact you guys get more and more removal inquiries every day, you still manage to keep the response time to a minimum, and I am so grateful for that!

    Anyways:

    - Did the HJT.
    - Ran OTM, log is attached.
    - Ran TDSSKiller, log attached.
    - Ran the AVG removal tool (thanks so much for pointing that out!)
    - Screenshot of folder in question can be seen here
    - There were no files to delete in temp folders (only files from today)
    - Ran ComboFix (even though you did not specifically ask for it, log is attached anyways)
    - New MGlog is attached.

    Installed Avast. Everything seems to be super speedy now and I'm not getting any errors like I was before. The only "problem" I'm having at this point is with registering Avast? It says I need to register or it will expire in 30 days. I click the register link in the admin but it doesn't do anything. Do I need to visit their website to register it? I'm completely unfamiliar with Avast because up until now I've been a staunch AVG Free user (although my support for it has been waning for the past year or so...)

    Thanks again for all of your help!
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Delete these using windows explorer.

    c:\windows\Nniqoxewofeseduz.bin
    c:\windows\Lmabeqaluxoc.dat

    C:\Documents and Settings\Sarah Nevin\Local Settings\Application Data\{B5F66A42-3EF6-452A-A2DC-378CE6A063EA} <--- Combofix got to this folder I asked about before I had chance, so it's gone now, so that's good!

    I used to be a fan of avg too until the point where it was avg 8.0.
    The registering of avast is simple enough, locate its icon on your system tray, right click > registration information. Enter in a few details > and done. :)

    Okay, so that should be the end of it. If all is running well still, then next it will be final steps. :)
     
  6. insan_art

    insan_art Private First Class

    Hi Kestrel,

    fixME.reg was successful.

    Deleted the two files requested for deletion.

    Finally got Avast to register. Thanks! Ya, I agree, AVG started going downhill around version 8. Too bad.

    Things seem to be back to normal now AND then some - by this I mean that things are speedier than ever, and I'm guessing that must have been AVG clogging things up all this time!!

    Thanks!!!
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yea I never recommend avg now. Just verify for me that these pair of files have gone:
     
  8. insan_art

    insan_art Private First Class

    As I said in my last reply, those files were deleted, as you requested.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I wanted to be sure they did not resurface after a reboot. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds