attacks from other computers

Discussion in 'Malware Help (A Specialist Will Reply)' started by CindyMT, Sep 14, 2008.

  1. CindyMT

    CindyMT Private E-2

    Hi,
    Thank-you for the repair/clean-up instructions!! :)
    I ran through them (unfortunately we had already used some of the tools), and most issues were cleared. Zone alarm still shows a serious of attempts to access from another computer. Always 7 attempts in a row from the same IP. Also single attempts from few other IP addresses.

    Combofix did not seem to run. The word "combofix" came-up with a meter that moved to the end, and that was it.

    Issues found though a day of cleaning include spyhunter, virtumonde, agent, cws, vundo, iwantsearchbar, downloader.VB.AWJ, zeroPopUpBar, component.SBSoft, malware.trace. Browsers were redirected, there were popus, slow/frozen system.

    Is there still some bug/remnant sending-out a beacon to malicious computers?
    Thanks for your time,
    Cindy
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First some questions:
    Did you at one time have PCTools Firewall installed?
    What is this : C:\Documents and Settings\Bruna\Desktop\Antispy

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Tell me if you are still getting intrusion alerts and give me the IP if you are.
     
  3. CindyMT

    CindyMT Private E-2

    Thanks for your efforts Tim! :)

    >Did you at one time have PCTools Firewall installed?

    I don't know, this is a friend's computer.

    > What is this : C:\Documents and Settings\Bruna\Desktop\Antispy

    This is just folder for her antispy/adware program links, so she can remember
    to (and easily) run them hereafter.

    > Tell me if you are still getting intrusion alerts and give me the IP if you are.

    I did all the changes, and so far I have gotten the same 7 attempts that happen simultaneously from:

    192.168.0.4

    From and to different ports.
    Thanks again,
    Cindy
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    LOL...short cut to scans...good idea.

    OK.that IP address is part of your network.....either a networked computer or a wireless device or printer....go to start / run / type "cmd" without quotes....

    when you get the dos screen type "ipconfig /all" without qoutes and note the space between ipconfig and /all.

    Tell me what is there --- esp the 192.168.0.4

    I will look at your logs after having dinner .....:) ....but I suspect that if avenger removed those items, you are probably clean.
     
  5. CindyMT

    CindyMT Private E-2

    > LOL...short cut to scans...good idea.

    Short of autoresponder messages to remind her, this is the best it gets LOL.

    >OK.that IP address is part of your network.....either a networked computer or a wireless device or printer

    Ahh..that thought had crossed my mind...momentarily.

    >....go to start / run / type "cmd" without quotes....

    >when you get the dos screen type "ipconfig /all" without qoutes and note the space between ipconfig and /all.

    >Tell me what is there --- esp the 192.168.0.4

    It's 192.168.0.5
    Default gateway + DHCP 192.168.01
    DNS 64.71.255.198, which was one of the other security alerts, blocked internet access to --from my computer

    >I will look at your logs after having dinner .....:) ....but I suspect that if avenger removed those items, you are probably clean.

    You could well be right?!?!! :)
    I have a router, and a PC networked.

    You must be in the same time zone, I am enjoying dinner also.
    Then taking this computer back to her...Have installed LogMeIn
    so can finish-up from home.

    Enjoy,
    Cindy
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If those IP addy's are part of your home network....then you can allow them....and just remember.....I nap alot...hehe.

    Will look soon.

    We can probably start some of the clean up:
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok...not much to do:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    They may no longer be there.

    After clicking Fix, exit HJT.

    Now use windows explorer to find and delete:
    C:\Documents and Settings\Bruna\Application Data\PC Tools
    C:\Documents and Settings\All Users\Application Data\PC Tools
    C:\Program Files\Common Files\PC Tools
    C:\WINDOWS\system32\drivers\pctfw2.sys

    This is all to remove the PCTools leftovers......your logs are clean.

    If you got a success message in the last post...then it is time to do our final steps:
     
  8. CindyMT

    CindyMT Private E-2

    Hi Tim, I did this, and then looked at the next message and stopped.
    Because, I see you are dealing with PCTools, and I am at my friends place,
    and realized that PCTools mades Spy Doctor, which she just installed to
    deal with this disaster.
    Do we proceed with the rest of your changes?
    Hope you're not napping LOL
    Cindy
     
  9. CindyMT

    CindyMT Private E-2

    Hi Tim, I need to clarify what "IT" was that I did, and it was re: your second-last message, here's clip:

    We can probably start some of the clean up:
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Quote:
    REGEDIT4

    [-HKEY_CURRENT_USER\Software\Kazaa]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\knight]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\

    etc...


    I did this and ran it. It did say the content was added to the registry.
    I have not done anything else, however when I tried to run Spyware Doctor(PCTools), syst crashed with blue screen. Seems we have done something to it.
    Cindy
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Unless Spyware Doctor is a paid for version....uninstall it. If they want to keep it, then don't do the fix I gave you.....(see, I should have had that nap!) :)
     
  11. CindyMT

    CindyMT Private E-2

    PS--we had another "attack" ip addres 76.114.109.119.

    The ip address here is 64.230.30.166
    wireless, no network.

    doing ipconfig in "run" the window disappears fast now, and does not stay to view the addresses.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Posted over each other...the reg fix was just to clean up combo fix stuff.....nothing else...so if spyware doc is crashing the pc...either try uninstalling or do the rest of the fix to remove all of it...run ccleaner and reboot. Then if you want it back ( I don't recommend it) it can be reinstalled.
     
  13. CindyMT

    CindyMT Private E-2


    Yes, it was paid for. But if it is no good, or something is better, we're open to whatever. Seems to keep it we will have to remove and re-install.

    Your last message seemed to conflict itself, saying the free anti-spy stuff is crap, and then saying also to keep it.

    Confused...and glad you're awake, and here :)
    Cindy
     
  14. CindyMT

    CindyMT Private E-2

    This is the sentence that contradicts itself to me:

    We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.

    If you don't recommened Spyware Doctor, what do you recommend?
    Cindy
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    not in run...you type cmd in run then in the dos box type ipconfig....
    76.114.109.119 --- comcast
    64.230.30.166 --- dsl.bell.ca
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    They do provide protection --- just not real time (you have to run them yourself when you suspect trouble)

    So you need a real time AV (one) and a real time AS.....plus backup scanners. :)
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No...that is not what I meant....most of the freeware is excellent, spyware doctor, unless paid for version, is not that effective and actually can block fixes. Since you say it is the paid for version....reinstall it. :)
     
  18. CindyMT

    CindyMT Private E-2

    oops thanks... ok, the 64. address was returned from whatismyipaddress.com
    However cmd ipconfig returns 192.168.8.100

    No idea about comcast...sounds local though.
     
  19. CindyMT

    CindyMT Private E-2

    Great! Thanks (again) :cool

    Cindy
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Any thing that starts with 192.168.1 or 0 will be your local network items.

    And you are welcome.....safe surfing. :)
     
  21. CindyMT

    CindyMT Private E-2

    Almost done your cleaning instructions....
    Combofix was not "installed", just placed on the desktop, and when attempted to use it dragging the windows file on top, it did not do what was expeted (see message below).

    When I ran the instructions below, got an error, not found.

    If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)

    Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    "%userprofile%\Desktop\combofix" /u

    Notes: The space between the combofix" and the /u, it must be there.
    This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
     
  22. CindyMT

    CindyMT Private E-2

    PS--got another two attempts...

    63.16.20.150

    Random fishing acts you think?
    C.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can look up ip addy's here:
    http://ip-lookup.net/index.php

    If you only had combo on the desk top....you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
     
  24. CindyMT

    CindyMT Private E-2

    Hi Tim:

    You're a WIZ!
    This is Bruna...Cindy's friend with all the crazzzzy computer probs.
    Thanks for your expert help....very much appreciated! bp

    You rock!!! Thanks so much for your time, expertise, & fast replies :cool
    Enjoy your well-earned zzzzzzzzzzzzzzzzzz's.
    Many thanks with gratitude,
    Cindy



     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You both are very welcome...do stay and enjoy the forums. Safe surfing....:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds