Is it a MALWARE/SPYWARE?

Discussion in 'Malware Help (A Specialist Will Reply)' started by ONEEYEMAN, Jan 19, 2008.

  1. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi, ALL,
    Very recently my Windows XP machine started to behave very strange.
    It started continuosly working with the Web.

    The little "2 computers" icon in the bottom right corner is always lit. My guess is that somewhere along the line some bad program was downloaded which opened the private socket and started communication with some site.

    Or is my assumption wrong?

    I ran SpyBot on it, but it didn't find anything. I didn't performed any other test from the "Sticky..." thread yet. I just want to confirm that I really have the malware/spyware on my PC.

    Thank you.
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi


    Yes if the Network icons are perminently lit, which is showing traffic on your network, then you must suspect as one cause Malware, so to really know if this is the case the full READ ME, will need to be run as sadly no one application like Spybot, will highlight every malware.

    Another cause of perminent connection is that your running p2p software.
     
  3. ONEEYEMAN

    ONEEYEMAN Corporal

    Halo,
    I'm running McAffee Virus Scan and Firewall.
    Unfortunately, when I tried to clean "quarantine" folder, I got a firewall pop-up saying that I can't delete those files.
    And then the Windows message box pops-up saying that M$ can't delete the files, make sure that the disk is not full or write-protected.

    How to go around this issue? This is one of the first steps in the "READ ME" thread...

    Thank you.
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    HI

    Can you boot into safe mode and delete the quarantine folder to McAfee? if not the malware found is quarantined so ok for now, just continue onto the next step, it maybe that we need to see the logs you can get, as some malwares block many various operations from working like delelting from various areas, to being able to download anti-malware scanners etc.

    But do continue on and if at any stage you cannot do a section, do as you already have done tell us what step and what the problem was.
     
  5. ONEEYEMAN

    ONEEYEMAN Corporal

    Ok, some good news first ;)
    I booted up in a safe mode and was able successfully delete the files from the "quarantine" folder.
    Now some not so good news :(
    On the "Read Me First" page for the "Windows XP" http://forums.majorgeeks.com/showthread.php?t=139313, there is a not enough info.
    Step 2:
    However, it does not say if I should re-instate it or do it at the end of the process. This is especially helpful for people that will do as read the instruction.

    Is it possible to drop some note there?

    Thank you.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When your PC reboots after running ComboFix, all of the programs you stop will just automatically start as usual.
     
  7. ONEEYEMAN

    ONEEYEMAN Corporal

    Like I said, it would be nice if it was mentioned on the "Read Me First" page somewhere.
    And thank you for your help so far.
     
  8. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi,
    I ran ComboFix with a success.
    I ran an AVG according to the HOW-TO. But when I tried to save the report it didn't produce any. Is this OK?
    I am going to run MGTools now, and get back to you.

    Also, I got the message that AVG is protecting my system. However, I got a McAffee firewall and antivirus installed. Should I kill (uninstall) AVG and let the McAffee do the job.

    Thank you for the help so far.

    [EDIT]
    Also, I have a dual-boot system - Windows and Linux. It has 4 partitions: 1 Windows (NTFS), 1 ext2, 1swap and 1 ext3. Are they going to be fine after scans?
    [/EDIT]

    [EDIT 2]
    OK, MGTools just finished running. The problem is not yet visible, but I didn't reboot yet. I'm going to attach the logs for review.
    [/EDIT]
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sometimes this happens when first installed. After a reboot, it may work properly. Don't worry about it now.

    AVG Antispyware is a different kind of protection than McAfee is giving you. Also note that after the 15 day trial, AVG AS will no longer provide any protection unless you purchase it.


    What do you mean by fine? Are you referring to malware free or something else? These scans will have no effect on other partitions.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Administrator\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  10. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi,
    When I ran "analyze.exe", I got following buttons/choices:

    1. Do a system scan and save a log file.
    2. Do a system scan only.
    3. View the list of backups.
    4. Open the Misc Tools section.
    5. Open Online HijackThis QuickStart.
    6. None of the above, just start the program.

    Which option should I choose? There is no "Do a system scan only" choice....

    Thank you.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excuse me????? Please look at option 2 in your own list.
     
  12. ONEEYEMAN

    ONEEYEMAN Corporal

    Yes, I'm sorry. I guess it was too late.

    Now, I followed the procedure and currently the icons are not even blinking.
    I'm attaching the file you requested.

    However, I got a problem during the run of "Avenger".

    McAffee VirsusScan window popped up with the following message:

    Message: Virsu Scan Alert!
    Date and Time: 1/27/2008 12:28:10 AM
    Pathname: C:\Avenger\burito1bd6-201c.sys
    Detected As: W32/Nuwar.sys
    State: Move failed (Clean failed)

    Since it happened after reboot and the file were not present, I simply deleted the message from the virus scan. I hope I did the right thing... :)

    Thank you.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    McAfee was attempting to block the cleanup that we were doing. Pretty poor timing. They should have blocked the malware from getting on your PC in the first place not the fixes we were doing. ;) At anyrate it looks like the fix worked in spite of McAfee.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  14. ONEEYEMAN

    ONEEYEMAN Corporal

    No, it looks clean so far.
    I was just wondering about this: What if this program open some sockets or port on my PC? Is this procedure closed/removed them?
    Because someone else might try to use it...

    I'll wait for your responce before finishing up.

    Thank you.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    No this procedure does not check for this. You would have to do that on your own.
     
  16. ONEEYEMAN

    ONEEYEMAN Corporal

    I started SpyBot, updated it, and started scan.
    It finished with "No threats found".

    However, VirusScan popped up again. The message says:

    Message: VirusScan Alert!
    Date and Time: 1/27/2008 1:10:44 PM
    Pathname: C:\System Volume Information\_restore{F1E37CCD-2791-4374-A680-D7B975A1C2C3}\RP171
    Detected As: W32/Nuwar.sys
    State: Move failed (Clean failed)

    File name is A0041129.sys.

    Should I: clean file, delete file, move file, remove message, close window?

    Thank you.
     
  17. ONEEYEMAN

    ONEEYEMAN Corporal

    Do you know how to do this? And how to check if this is the case?

    Thank you.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to complete the instructions I gave you in message # 13. I did not ask you to run any other scans. You need to complete those steps first.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  20. ONEEYEMAN

    ONEEYEMAN Corporal



    1. After finishing up, I tried to get the Windows Update from the site.
      It gave me that I need the "Update for Windows XP (KB898461)" and "Windows Genuine Advantage Validation Tool (KB892130)". However, when I click "Download and Install Now" it reported that the install failed for both updates.
      Then I got redirected to the "Your results" page. There was a lfollowing message "Problem: Please check your update history for a description."
      When I clicked on the link I got the message: "You have not yet installed updates from this website or by turning on automatic updating on your computer. To select and install updates now, go to our Home page."

      I think that the firewall blocks the installation of updates. How do I enable the installation?

      Thank you.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must make sure that you are not blocking the process in your McAfee Firewall. You try disabling your firewall as a test to see if it is the cause of your problems. MS Windows Update is notorious for causing people issues with getting updates.
     
  22. ONEEYEMAN

    ONEEYEMAN Corporal

    I just tried disabling the firewall, and got the same responce.
    What else might be wrong?

    Thank you.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Could be a variety of problems with MS update and issues on your PC. I suggest you post in the Software Forum where they can attempt to help you with this.

    You could give the below a try first to see if it helps:

    Fixing Windows Update Problems (Win 2K and XP)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds