Virus Problem Windows 7 64 bit

Discussion in 'Malware Help (A Specialist Will Reply)' started by FED UP, Dec 19, 2009.

  1. FED UP

    FED UP MajorGeek

    I was browsing a blog yesterday, and when i clicked a link within the blog, i got a popup window telling me "I should run a virus scan malware detected" . I didnt click the window, but tried to use task manager to terminate firefox, got it shut down (after a failed tab-reload) . I was hoping by not clicking the window i might avoid the malware infection, but it was too late . Now, whenever the system is running, things are being downloaded via Internet explorer and firefox, as evidenced by these files being deleted every time I run Ccleaner. The longer I let the system run (idle) the more files are downloaded (almost 3megs DLed during the time that Mbam ran) I ran the Vista cleaning procedure, Root Repeal and MGTools would not run due to not being 64 bit compatible. I am running Windows 7 64 bit .SAS found nothing . Mbam found nothing. I know my system is infected, i just cant find it .
    Thanks .
    Mbam log and SAS log attached
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not true. MGtools fully supports x64 and you need to run it and attach the log.

    There is nothing showing in the logs you attached other than you need to uninstall SUPERAntiSpyware and install the current version.

    What files do you think are being downloaded? Temp files are normal.
     
  3. FED UP

    FED UP MajorGeek

    Got an MGTools log - attached .

    For example, I will run CCLeaner, then I got up, never opening a browser, come back to the computer, ran CCleaner again, and theres Windows Explorer Thumbnail Cache 3,075Kb 6 files , Internet Explorer Cookies 1kb 1file, Firefox/Mozilla Internet Cache files, Firefox/Mozilla Download History, Firefox/Mozilla Cookies , Windows Explorer Recent Documents , Windows Explorer Thumbnail cache, Internet Explorer cookies, Internet Explorer Download History files .

    The number and size of files that are found increase, the longer i leave the computer sitting idle, and even though i NEVER EVEN TOUCH the computer between the CCleaner runs, many megabytes of files will be found and cleaned .
    If it is normal for internet explorer and firefox to download files when i didnt even use IE or Firefox, then I will disregard this as evidence of a virus, although i never noticed this before my incident with the popup virus window i mentioned in the first post .
     

    Attached Files:

    Last edited: Dec 21, 2009
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not appear to be malware. Try uninstalling and not running ApexDC++ 1.2.2, SoulseekNS and BitTorrent and see what happens. And if Nicotine+ (1.2.14) is a P2P program, remove it too.

    Are you referring to the JPG files that are here: C:\Users\computer\Local Settings\TEMP\
     
  5. FED UP

    FED UP MajorGeek

    Ok, I deleted the apps you suggested, went into my router and closed the ports associated with those programs (i had forwarded ports so they would run properly). I then Ran CCleaner, it removed about 10 megs of files the type of which i mentioned previously in this thred . Atfer running CCleaner, and without running ANY OTHER app (inicluding browsers) i ran SAS, which found nothing. As soon as SAS was finished running, I ran CCleaner again (and again I did not run ANY other app) and CCleaner deleted aver 6 megabytes of the same types of files. Something is causing these files to be downloaded to my computer without my authorization, and i cannot find what it is. I dont mind being rid of DC++ i only used it a couple of times and didnt like it. I do, however use Soulseek regularly, but ive never had this problem before, and have never had any problems at all with Soulseek . I just cant figure out where these files are coming from. Yesterday, I ran CCleaner, immediately got up from the computer leaving no apps running, came back maybe 2 hours later, and ran CCleaner first thing, and over 2,000 megabytes of these types of files were cleaned . I had run absolutely NO apps, In fact i was away from the computer, nobody else used the computer, yet these files are somehow being downloaded via firefox and IE . I dont know whats going on, but this was not happening until after I ran into that popup window telling me that i had a virus and needed to run an antivirus. It didnt seem to be trying to sell me one, but i did not want to click on that popup, not even the red/white 'X' . I terminated the popup using task manager . There is definitely something fishy going on here, and just cant figure out what. This cannot be normal behavior for my computer. It has NEVER done this until now . Is there some sort of port monitor application i could try to see what is causing these files to appear on my computer ?

    The files I am referring to are generally Windows Explorer Thumbnail Cache 3,075Kb 6 files , Internet Explorer Cookies 1kb 1file, Firefox/Mozilla Internet Cache files, Firefox/Mozilla Download History, Firefox/Mozilla Cookies , Windows Explorer Recent Documents , Windows Explorer Thumbnail cache, Internet Explorer cookies, Internet Explorer Download History files . Sometimes other files appear as well.
     
    Last edited: Dec 23, 2009
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Unplug the ethernet cable that goes into your PC.

    Run CCleaner and save a log to attach here later. ( you right click in the window to save a log. Call it cclog1.txt and save it where you can find it like your Desktop )

    Now reboot your PC.

    Immediately after reboot, run CCleaner again and save this second log to a new file name like cclog2.txt.

    Now plug your cable back in and attach the two logs here.
     
  7. FED UP

    FED UP MajorGeek

    Hi. Thank you for your assistance in this matter..

    I went a little further than you asked.
    I ran CCcleaner, then allowed my computer to sit idle, not running any apps.
    After about 30 minutes of sitting idle, I unplugged the cable, and ran CCleaner, generating log1 . I immediately rebooted, and did nothing more than run CCLeaner again, generating log2 . I then immediately ran CCleaner yet again, generating log3 .
    Logs are attached .
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some of the files appear to be normal. Others may just be due to things you are running. Since your logs were all clean, it does not appear to be malware. Is your PC Tools firewall setup properly? Disallow any of the previous p2p/torrent programs and close ports. The overuser of P2P and torrent programs has general publized your IP address to the whole world. Thus people may still be trying to download from you anytime your PC is turned on which is one of the reasons I said to remove all P2P and torrent programs. Also double check your firewalls to close any ports that you opened up for these programs ( i know you said you checked already).

    Also make sure that SoulSeek is not running anymore. Look for the slsk.exe process.
     
    Last edited: Dec 27, 2009
  9. FED UP

    FED UP MajorGeek

    Ok. I went into Task Manager, and can see that slsk does in fact terminate when I close the app every time . What i did was set rules within my firewall to more strictly regulate incoming data . As I stated before, I do use slsk daily, and enjoy slsk a great deal . I also use BitTorrent to a lesser extent, but cannot imagine having a computer and not using it, as I enjoy that application as well, and did also set more strict rules for incoming data via bittorrent within my firewall. I will see how these new rules effect the problems i have been having. I appreciate your time chas, thank you and happy holidays. I will report back with my findings - ill use my system normally for a few days, checking the CCleaner more often than normal to see if there is a difference . Thank you .

    Also, what do you think of using a proxy when I use Slsk or bittorrent ? I have sockschain, which creates not just a single proxy, but an entire chain of proxies which will connect applications such as slsk to the web, making it difficult for people to determine my actual IP . Once I terminate slsk or bittorrent, i can shut down sockschain, and connect directly to the net . Do you think this may be a good strategy, if in fact what you say is true, that my real IP has been broadcast to other P2P users and may be causing this problem ?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Give it a try and see if it helps. You already know our opinion on using any p2p type program. ;)


    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  11. FED UP

    FED UP MajorGeek

    I have reconfigured my security, switching from avast! a/v and pc tools firewall to the comodo internet firewall & antivirus . The firewall has given me several notifications of "unclassified malware" activity, often within windows defender . I wonder if this is overzealous hueristics or if something is really going on. I am still getting the same mysterious files, some of which i have researched and found plausible explanations for, but not all.
     
  12. FED UP

    FED UP MajorGeek

    Definition Update for Windows Defender - KB915597 (Definition 1.71.2030.0)

    Installation date: ‎1/‎13/‎2010 10:25 AM

    Installation status: Failed

    Error details: Code 80070714

    Update type: Important

    Install this update to revise the definition files used to detect spyware and other potentially unwanted software. Once you have installed this item, it cannot be removed.

    More information:
    http://www.microsoft.com/athome/security/spyware/software/about/overview.mspx

    Help and Support:
    http://go.microsoft.com/fwlink/?LinkId=52661




    Got this notice just now. I have never had an update fail.
     
  13. FED UP

    FED UP MajorGeek

    Subsequent attempts to download Update for Windows Defender are also failing.
     
  14. FED UP

    FED UP MajorGeek

    i have received notice from comodo of the following process attempting to execute, i blocked the execution after googling it and finding the following link :
    http://www.threatexpert.com/files/Uninst.exe.html


    Uninst.exe was trying to execute on my computer : should i be concerned ?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After even a week goes by after your PC had been clean, anything could have happened to your PC. After a couple weeks like in your case, you should be starting a new thread after running the cleaning process. Problems with Windows Defender not updating while no other problems exist (you did not mention any) are most likely just problems with Windows Update and should be addressed in the Software Forum. You could even be blocking the updates due to some other protection software running including your antivirus and firewall. Remember that in msg # 11 you even stated Comodo gave you problems with Windows Defender.

    You could just try manual updating: Windows Defender Definition Updates

    Probably not a problem since this is just a common uninstaller executable used by many many programs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds