Trojan TDSS & Virtumonde- Some of the scans do not run...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Fernando Magallanes, Jun 6, 2009.

  1. Fernando Magallanes

    Fernando Magallanes Private E-2

    Hello good people,

    So, I recently found this out by running Ad-Aware. At first Virttumonde came out, but I believe I got rid of it by erasing some stuff (perhaps not, but hey). Then it was that Ad-aware found the notorious TDSS.

    All this time Spybot has not started. My Google searches are redirected to some Chinese Museum or some other site, I keep getting this weird google installer mishap, yet I'm not running any installer. And a Dr. "Something" also has appeared every now and then failing to run/install.

    Following the instructions to create the logs:

    -SAS worked, did it twice because I do not know if Teatimer was running the first time (I ended up uninstalling Spybot).

    -MB - It worked the first time, but I did not save the log, as it was mentioned that I could return to the log after the reboot. Well, after the reboot the program does not want to start. I even tried to uninstall it to do it all over again, and not even the uninstaller wants to run. It is a sad day for this little program. I do know it found 27 bad objects.:booger

    -Combofix - The icon is laughing at me at the desktop, since it doesn't want to run. I get up to the "Are you sure you want to trust this program and run it" dialog box, then nada.

    -MG - worked!

    If I've failed to mention anything, or if I have not done a step, pleasee let me know. Many, many thanks

    FM
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The logs are always saved. Please attach it. You can find it here:
    Code:
    "C:\Documents and Settings\Mariela\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\"
    Jun  6 2009        4148  "mbam-log-2009-06-06 (01-15-54).txt"
    You MUST shutdown all other security software as instructed before you run ComboFix. Shut down Ad-Aware's Ad-Watch and Symantec software and then try running ComboFix again. Then attach the C:\combofix.txt log.

    Continue on with the below no matter whether you can run ComboFix or not.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jun 7, 2009
  3. Fernando Magallanes

    Fernando Magallanes Private E-2

    Hello and thanks chaslang!

    Ok, I found the MB log, it is attached. ComboFix did not start (I even uninstalled Norton, in part also because it was out of date and was asking me for more $ for new definitions... I want to change my Anti-Virus program anyways, any suggestions other than Norton?) And Ad-Aware's Ad-watch was shut down...

    Well I will continue now with the rest of the instructions and will inform as soon as I am done. Just wanted to put that out of the way.

    Cheers!

    FM
     

    Attached Files:

  4. Fernando Magallanes

    Fernando Magallanes Private E-2

    Hey chaslang,
    Everything went well, save for the Combofix which as reported before did not want to start. Attached are the 2 logs (Avenger and new MG).

    Will await your comments.

    cheers!

    FM
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Alright now re-run (one at a time) SUPERAntiSpyware and Malwarebytes. Make sure you UPDATE them first. Then run a new scan and fix what they find. If they find anything for you to fix, immediately reboot after fixing. Then attach new logs.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    After clicking Fix, exit HJT.


    How things are working?
     
  6. Fernando Magallanes

    Fernando Magallanes Private E-2

    Hey Chaslang,

    Things are working much better, I see improvement! It still worries me that both SAS & MB still find some threats and infections; yet I can see its close now.

    Attached are the logs, many thanks again.

    FM
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The reason for running them again was to finish cleaning things up since I expected a few stranglers to be hiding after other steps were completed. As long as they are coming up clean now, you are okay.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  8. Fernando Magallanes

    Fernando Magallanes Private E-2

    Many thanks Chaslang. I did all the steps, and downloaded Comodo AntiVirus...

    Just a side note, this happened after trying to delete ComboFix - both the Antivirus and SAS are blocking some kind of trojan, perhaps the same one? I did everything, even the Restore disable/enable. Should I worry?

    Cheers!

    FM
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    You are most likely referring to either something to do with C:\Windows\nircmd.exe or C:\Windows\pev.exe (I'm just guessing because you were not specific). If so these are not problems. They are just programs used by ComboFix and many other tools. If you are referring to something else, you will have to tell me exactly what or attach a log.
     
  10. Fernando Magallanes

    Fernando Magallanes Private E-2

    Hey Chaslang,
    Well, I've attaced the log of SAS. It did not find anything, but my Anti-Virus (COMODO 3.9 Internet Security) is finding random things. I would've included a log from COMODO, but I cannot find it as a txt file. Should I run something else or am I freaking out here?:confused

    Cheers

    FM
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Like what? Be specific and give full path file names and names of the infections it thinks it is finding.

    Comodo's documentation may explain how to get a log. It may not be so straight forward. See around page 67+ in the below

    http://personalfirewall.comodo.com/Comodo_Internet_Security_User_Guide.pdf
     
    Last edited: Jun 19, 2009
  12. Fernando Magallanes

    Fernando Magallanes Private E-2

    Would this work? Is a print screen of what the antivirus has found and taken action upon... JPGs...\

    They have all the info, locations and dates...

    FM
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see if we can figure out what that file is. Put a copy of the c:\windows\system32\pm.exe file into a ZIP file and attach it here for me to look at.


    If you don't know how to ZIP a file, you can do the below.

    Click Start, Run, and copy and paste the below into the run box and then click OK.

    %systemdrive%\MGTools\zip "%systemdrive%\collect.zip" C:\Windows\system32\pm.exe

    Then attach the C:\collect.zip file to your next message.
     
    Last edited: Jun 21, 2009
  14. Fernando Magallanes

    Fernando Magallanes Private E-2

    Hi Chaslang,
    thanks, I tried to do the run and pasted %systemdrive%\MGTools\zip "%systemdrive%\collect.zip" C:\Windows\system32\pm.exe but it did not created the zip file in the C:\

    Also, I manually went searching for the pm.exe file, it is no longer there...

    Ohh well, its running great now, if anything happens I will inform. many thanks!

    cheers!

    FM
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds