Mystery Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by AtariBaby, Apr 1, 2009.

  1. AtariBaby

    AtariBaby Private E-2

    I was alerted to a problem with one of cafe POS computers that the time was changing around noon every day.

    I looked into a couple of things and decided to consider malware. I then discovered that the web browser can't access any anti-virus sites, and software won't update, etc.

    Please review my logs. I did my best, in this situation where the computer's functions are extremely limited. Thank you for your help.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now let's use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    Drivers::
    Lanmanserv
    
    NetSvc::
    Lanmanserv
    
    File::
    c:\windows\system32\kwtze.dll
    
    Registry::
    [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Lanmanserv]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    You have no Java on this syste,....please download and install:
    Java Runtime 6

    Now attach the new Combo log then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
    Last edited: Apr 4, 2009
  3. AtariBaby

    AtariBaby Private E-2

    Thank you! Attached as requested.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's do this:

    First Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now download Registry Search (see the link titled RegSearch Download Link )

    • Extract the files from Regsearch.zip into a folder.
    • Doubleclick regsearch.exe to start the program.
    • See the top 3 boxes under the Enter search strings (case independen) and click Ok... option, enter the below string (use copy and past)
      • lanmanserv
    • Then click "OK".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well).
    • Attach this RegSearch.txt file.
     
    Last edited: Apr 6, 2009
  5. AtariBaby

    AtariBaby Private E-2

    Thank you! Registry edit gave a success message. Log attached.

    FYI it appears regsearch crashed after it opened the text log. Its graphics are partially drawn, program appears frozen.
     

    Attached Files:

  6. AtariBaby

    AtariBaby Private E-2

    disregard re: crash, program became responsive after I closed log file.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok....the .dll is no longer attached to the service. What issues are you still having?
     
  8. AtariBaby

    AtariBaby Private E-2

    Hi

    The time clock is still changing 1 hour every day, and sites like microsoft's home page, and anti-virus sites, are not accessible via internet explorer. I just checked and these issues are still occurring.

    Thanks
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is this with any browser? This is only on this machine that is on your network, right? Is this happening when you type the address in yourself?
     
  10. AtariBaby

    AtariBaby Private E-2

    Hi

    It is not the only machine on the network. It is attached to another POS system. These are xp computers with Adelo for Restaurants software loaded to act as cash registers. To exacerbate matters, this is all in an environment with a WRT54G giving wireless access to customers. I have however checked a feature on the router's configuration that is supposed to prohibit users from accessing each others' computers.

    The 2nd computer is showing the wrong time. I just found this out. Silly thing to overlook. I wonder if it's just a coincidence and not malware related. 2nd computer accesses websites just fine.

    I will have to install firefox on the malware computer before I can tell you if the problem is just IE or not. Should I? And yes this is occurring when I type in addresses myself: If I type in avast.com the webpage redirects to a windows live search engine result page.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, check that it does or doesnt happen with firefox.

    You could also check the time settings by going to the control panel / regional and language / customize / time.

    Now I want you to do two things:

    Run the GetRunKeys.bat and attach that to the next reply.

    Then run this:
    McAfee AVERT Stinger Conficker and report if anything is found.
     
  12. AtariBaby

    AtariBaby Private E-2

    I'm searching for getrunkeys.bat and I can't find it anywhere. :(
     
  13. AtariBaby

    AtariBaby Private E-2

    Update: Register 2 is now exhibiting infected behavior (can't access antivirus sites). Also, I guess getrunkeys.bat is part of mgtools? I will attach the getrunkeys.log ASAP.
     
  14. AtariBaby

    AtariBaby Private E-2

    also did an eset online virus scan that reported confiker files.

    McAfee app found problem.

    c:\Qoobox\Quarantine\C\Windows\system32\_kwtze_.dll.zip found the w32/confiker.worm.gen.d virus

    and deleted it.

    sorry if that wasn't word for word. the report for this program proved too difficult to retrieve.

    Edited to add: I installed firefox and was able to access anti-virus sites.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is Combo's quarantine folder.

    Is that all the McAfee tool found?
     
  16. AtariBaby

    AtariBaby Private E-2

    That is all it found.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to run Stinger on ALL computers on your network. Then apply ALL updates ( both windows and software) on these systems.

    I will have one more item for you to run:

    Copy the bold text below to notepad. Save it as fixME.bat to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to run.
    You will find two files here:
    C:\LMS1.txt and C:\LMS2.txt logs.

    Please attach them.

    Tell me what is found on your other systems as we may need to clean all of them.
     
    Last edited: Apr 9, 2009
  18. AtariBaby

    AtariBaby Private E-2

    Scanning of all computers on network is not possible, because this is a cafe offering wireless access to customers. However the computers are not workgrouped and I have the setting checked in WRT54G that supposedly prevents clients from connecting with each other.

    The POS computers are networked. I have run Stinger on Register #2 and it found nothing. However I cannot access windows update from this computer in IE. It is one of the "page not found" pages.

    Register 1 (the one that originally brought me here) is being scanned. It has a windows update notification which I will apply after Stinger scan and .bat file and report back.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now I better understand the situation. It is the two POS comps that are the problem. Good to know...and do let me know the results. ( I am wondering if your POS software is what is causing the clock issue...?).
     
  20. AtariBaby

    AtariBaby Private E-2

    Hi

    Here are the results. Stinger found nothing. It might have been a coincidence, the time thing. That does appear to be fixed. I cannot access anti-virus software or windows update on the 2nd POS.
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You don't appear to have any malware. You don't have a firewall installed that could be blocking you. Have you checked your hosts file?

    Download HostsXpert and then follow the below steps.

    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
     
  22. AtariBaby

    AtariBaby Private E-2

    I tried that, said "make read only" so I skipped that step, clicked "Restore Hosts File", closed program, still can't access windows update, any microsoft webpage, nor antivirus webpages.
     
  23. AtariBaby

    AtariBaby Private E-2

    I did a little test I read about: I could go to fsecure.com but not f-secure.com. Supposedly this is classical confiker behavior. Should I start from the "read and fun me first" instructions on this second computer, start from the beginning?
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes.....but you have me confused. Is this not the one we have been working on? Or do you have a second computer with similar issues?
     
  25. AtariBaby

    AtariBaby Private E-2

    Sorry Tim, I've been trying to make it clear in my posts, but between the two of us busy people maybe that was lost.

    I started this problem with one computer, a POS at a cafe, one of two. We'll call that the original or first computer. At some point I began reporting strange behaviors with the second computer. I tried to make that clear in each post, so please forgive me if I didn't do so.

    The first/original computer now appears to be malware free (can access anti-virus sites and microsoft updates, etc). The second computer began exhibiting both of these bad behaviors at some point. I ran the McAfee stinger program which found nothing, however I have not done "Readme and Run First" on that second machine.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK....then what you need to do is start a new thread regarding the second computer and do the R & R with the logs attached. ")

    If the first computer is now good, we need to finish it:
    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds