eximoussystemsearch malware?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Ghoulman, Oct 31, 2011.

  1. Ghoulman

    Ghoulman Private E-2

    Hi all.

    I've recently had what I think is some Malware infect my computer. The main symptoms are:

    1. While browsing the page is sometimes slow to load and tries to redirect me to a site containing eximoussearchsystems.com or similar.

    eximioussearchsystem.com/?search=urinary+tract+infection&subid=15&key=2813ad5f68f75ce27195&f=1

    Above is an example of this.

    2. All the anti-spyware/malware software I have tried to download and run (malwarebytes, Super Antispyware, CCleaner) install and wont open.

    Malwarebytes seems to run in the system tray and act in stopping the virus from trying to access IP addresses such as: 206.161.121.100 and 95.163.66.209. I also have ad blocker plus and noscript running within Firefox to prevent malicious things on webpages from opening/redirecting etc.

    I also tried to run tdsskiller and it found 2 threats, upon restart these threats are still there.

    Any help would be much appreciated! :)
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did MGTools not run, or Combofix?

    Have you tried to boot into safe mode to see if tools will run?
    Attach the log please and also see if you can run this:

    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  3. Ghoulman

    Ghoulman Private E-2

    Thanks for the swift response.

    I just ran MGTools, I have attached the log, and the logs of the other programs I have run.

    I will now try and start in safe mode and run the other malware software as you mentioned.
     

    Attached Files:

  4. Ghoulman

    Ghoulman Private E-2

    OK.

    I rebooted in safe mode, managed to run Super Anti-spyware, it found 1 entry of malware. It appears this has been removed now.

    Upon restart into windows again, I downloaded and ran ComboFix, it seemed to run ok.

    Malwarebytes and Super Anti-spyware still dont run in normal boot mode.

    System seems a bit better with no evidence of virus like before. Will stand by though.
     
  5. Ghoulman

    Ghoulman Private E-2

    So just to follow up.

    Web browsing seems to be quicker and I'm not getting the re-direct. Malwarebytes is still randomly blocking outgoing info from accessing certain IP addresses.
     
  6. thisisu

    thisisu Malware Consultant

    Hi, go ahead and attach the logs from running the below scans so that Kestrel13 can review them.
    • ComboFix
    • MalwareByte's Anti-Malware
    • SUPERAntiSpyware

    See: How to attach items to your post
     
  7. Ghoulman

    Ghoulman Private E-2

    Sorry about the delayed reply.

    I've attached a log from Super Anti-Spyware. Malwarebytes still wont open and run scans. The icon does sit in the system tray though.

    I also ran ComboFix but it had an issue with the anti-virus software on this computer. CA Internet Security suite. I'm reluctant to remove this as it's a work computer and it's what the office here uses. So unfortunately no log from ComboFix.

    Hope this is enough to work some solution from?

    Thanks
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would like you to let combofix run despite the warning about the antiivirus. It's not going to uninstall it or break it so don't worry. Attach the log once done.
     
  9. Ghoulman

    Ghoulman Private E-2

    I have tried to run it a few times, I let it try and do it's thing but it doesn't create a log that I can see. I have it on my desktop and would expect the log to be created there.

    When running ComboFix the window appears and runs through, then the warning about the anti virus conflict appears, I click ok.

    The warning says: "ComboFix cannot run when CA Anti-Virus is installed. It would be dangerous to continue.

    Please uninstall CA anti-virus or use another tool"

    I dont have the option to continue after that warning appears.

    Are there other tools I can try?
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    There is a zeroaaccess infection on this machine. It is stubborn to remove. Combofix has been doing great at being rid of most of it, is there absolutely no way you can temporarily uninstall the antivirus in order to get all this done? In fact, with a zeroaccess infection, usually the first thing to be compromised/broken, so would be worth uninstalling anyway! What do you want to do?
     
  11. Ghoulman

    Ghoulman Private E-2

    Ok so I gave uninstalling a go as I found the copy of the software to re-install once done.

    Ran into problems though, the software didn't want to uninstall at all. I went into Control Panel> Add/Remove programs and tried to uninstall CA security suite from there but it didn't run. No window popped up even though there was a tab in the taskbar.

    I then tried the same thing in safe mode, the program ran but as it was running through the uninstall, messages popped up saying components cannot be uninstalled. So it failed also.

    What can I try next?

    Thanks for your patience.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try Revo Uninstaller.
    Choose the option on the bottom of the list (#4). Be very careful while deleting the bolded registry items ONLY!! This software will create a system restore point for you as well prior to uninstalling a software program.
     
  13. Ghoulman

    Ghoulman Private E-2

    Ok so I managed to uninstall the Anti virus software and run ComboFix.

    It seemed to find a fair few infected files. The log is attached.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Folder::
    C:\Documents and Settings\Administrator.COMPUTER3\Local Settings\Application Data\cc316e00
    C:\windows\temp\UmxAgent31312
    C:\Documents and Settings\Administrator.COMPUTER3\Local Settings\Temp\CR_1B9B6.tmp
    C:\WINDOWS\Temp\59808883
    File::
    C:\Documents and Settings\Administrator.COMPUTER3\Local Settings\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb
    C:\WINDOWS\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb
    C:\WINDOWS\system32\c_83382.nl_
    C:\WINDOWS\assembly\GAC_MSIL\Desktop.ini
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Userinit"="c:\windows\system32\userinit.exe," 
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=""
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.





    Could you please get this: 12283112.sys into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:
    log retrievable @ C:\collect.zip




    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  15. Ghoulman

    Ghoulman Private E-2

    Hi again Kestrel.

    I've followed your instructions, attached the logs. Extras.txt didn't get created from running OTL.

    Awaiting next instructions.
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That was a kaspersky file, so now I know other similar files also belong to Kaspersky.

    Could you please get this: tskF.tmp into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:
    log retrievable @ C:\collect.zip


    MGTools did not run correctly.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    • cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    • nwktst<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    • analyse <-- this attempts to run HijackThis. Be sure to click the Accept button twice in the license agreement popup or it will just sit there and wait.
    Now look for the C:\MGlogs.zip file and attach it no matter what happened while doing the above.
     
  17. Ghoulman

    Ghoulman Private E-2

    Ran all steps except the last one, analyse. It told me access is denied.

    I've attached the MGlogs.zip as requested.

    No other errors to report.

    * edit - attached collect.zip also.
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please go to virustotal and upload the following files for analysis, and let me know the results.

    • C:\WINDOWS\system32\drivers\tskF.tmp
     
  19. Ghoulman

    Ghoulman Private E-2

    Info from file analysis is as follows:

    2 VT Community user(s) with a total of 4 reputation credit(s) say(s) this sample is goodware. 8 VT Community user(s) with a total of 8 reputation credit(s) say(s) this sample is malware.

    File name:
    tskF.tmp
    Submission date:
    2011-11-03 01:19:06 (UTC)
    Current status:
    finished
    Result:
    0/ 42 (0.0%)

    The url is below for you to check for yourself if you need to.

    http://www.virustotal.com/file-scan...e6af910e35eb9819f1a9e3363863aedfdc-1320283146
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The file is safe. You can see what Chaslang says here.

    I just had to be sure and be all squared up before we continued. Did not notice Chas's post until after we ran it through VT. OK, the infection remains but it's almost 2am for me and I desperately need to sleep. Hang in there until tomorrow, and I'll post back just as soon as possible! :)
     
  21. Ghoulman

    Ghoulman Private E-2

    Ok no problems. Only 1pm here!

    Will wait until tomorrow, thanks so much for your help so far! :)
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r


    Now we need to scan the system with this special tool.
    • Please download Junction.zip and save it to your root folder (C:\Junction.zip)
    • Unzip it and put junction.exe in the root folder (C:\junction.exe)
    • Now click Start => Run... => Copy and paste the following command in the run box and click OK:
      cmd /c junction -s c:\ >C:\log.txt
    • A command prompt window opens and also a license agreement from SysInternals will appear.
    • Accept the license agreement and the scan will begin.
    • Wait until a log file opens. Attach this C:\log.txt when it finishes (the command prompt window will close when it finishes). (How to attach items to your post)
    • NOTE: It scans your whole hard disk so if can take a long time. Be patient and don't do anything else while it is scanning.


    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code
    Code:
    Code:
    :otl
    @Alternate Data Stream - 816 bytes -> C:\WINDOWS\7221708:869175807.exe
    
    :files
    C:\WINDOWS\pcLog_2944.dat
    C:\WINDOWS\7221708
    C:\windows\0.log
      
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.


    Run OTL again as you did in post number 14, and attach the log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  23. Ghoulman

    Ghoulman Private E-2

    Kestrel.

    I managed the first step. The second step, copying this text into run "cmd /c junction -s c:\ >C:\log.txt" didn't work for some reason. A cmd window popped up for a split second and disappeared.

    Do you want me to follow the rest of the steps anyway?
     

    Attached Files:

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Oh, yes please! :)
     
  25. Ghoulman

    Ghoulman Private E-2

    On Friday, I ran OTL and copied the text into the window, it didn't run correctly the first time, it froze for a long time. I closed it and ran it again and it ran correctly but now I can't access the internet or network here at work from that computer.

    What to do next? Boss is getting shitty at me but I know this method would be better than any method he could try to fix the problem with!
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I just want to let you know that it was not the last script you ran that broke your internet connection, it is more than likely the infection that has caused it. :( I know how to remove the infection but I am still learning how to deal with the aftermath (broken internet connections) that goes along with it. I shall ask a colleague to look in on this for me. But let's just do this for now.

    • Run OTL again like you did in post # 14 and attach the log.
    • Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    This is why I always have concerns personally with fixing business computers. But as I said, it's the nature of the infection, if you take a look around the forum you will see plenty other who cannot connect with the same nasty embedded into their system as this one. Have you not got an IT department at your place of work? (I assume not as you would not be here otherwise)
     
  27. Ghoulman

    Ghoulman Private E-2

    Hi again.

    The Boss has intervened now.

    He knows "a guy" who works in IT a bit and comes in from time to time, he wouldn't pay for someone be our IT help.

    I know that we would get to the bottom of the infection given a bit of patience but the boss hasn't got any. So the computer has been taken away by "the guy" and he's going to run a windows repair to fix the networking issues.

    I don't know if any of what this guy will do will fix any of the malware troubles? I doubt it so I'm willing to pick up from where we stopped once I have the computer back with me.

    Thanks a lot for your help so far, I'll keep watching this thread. :)
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, we'll stick with you and see what happens. :)
     
  29. thisisu

    thisisu Malware Consultant

    @Kestrel13!

    Here is part of the problem, maybe the only problem as it looks like DHCP is already started:

    ImagePath should equal: "system32\drivers\ipsec.sys"

    I am not sure if a Repair Install would correct that path. From what I've read, no it won't.
     
  30. Ghoulman

    Ghoulman Private E-2

    Ok I have the machine back and have just ran OTL like you asked and also Getlogs.bat

    The logs are attached.

    IT guys said it's fixed. I'm not convinced. I tried to re-install the CA anti-virus software and it wont install, extracts but doesn't install. Kind of idles with a blank install/startup screen.
     

    Attached Files:

  31. thisisu

    thisisu Malware Consultant

    Quick question as I'm sure Kestrel13! will want to know too.

    I see they did a repair install, is the internet working now?
     
  32. Ghoulman

    Ghoulman Private E-2

    Yes, the internet and networking all work fine now.
     
  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's good to hear! :) You can ask about the issue with reinstalling CA antivirus in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds