Possibly still infected

Discussion in 'Malware Help (A Specialist Will Reply)' started by abz1nthe, Dec 29, 2009.

  1. abz1nthe

    abz1nthe Command Sergeant Major

    I want to make definite sure this computer is clean now as I believe it is the culprit in bringing a nasty mail spam bot onto our network which really wreaked some havoc for the School District I work for. It pretty much spammed emails out to the world until we were on virtually every major DNS blacklist. Still waiting to be de-listed on a couple -_-

    Thank much appreciated :)

    -A
     

    Attached Files:

  2. abz1nthe

    abz1nthe Command Sergeant Major

    attached additional log
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you knowingly install WinPCAP on this PC? If so, you will have to reinstall it AFTER we finish all cleanup since ComboFix broke it. While WinPCAP is a legit application used to perform packet capturing, it can be used by malware too.

    Did you knowingly setup Microsoft Remote Desktop Connection to run at Startup? See below
    c:\documents and settings\Administrator\Start Menu\Programs\Startup\
    Remote Desktop Connection.lnk - c:\windows\system32\mstsc.exe [2004-8-4 677888]

    You need to delete MGtools from the below location as this is not where we asked you to download to or run it from:
    C:\Documents and Settings\User\Desktop\Allison's AV\MGtools.exe


    The below are out of date and security risks. You should uninstall and update as requested in the READ & RUN ME.
    Java(TM) 6 Update 5
    Mozilla Firefox (3.0)

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    After clicking Fix, exit HJT.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. abz1nthe

    abz1nthe Command Sergeant Major

    Heya Chas thanks for the help.

    I honestly didn't notice any issues with the computer even before the cleanup but I knew it was infected based on the fact I saw it spamming SMTP traffic about 50 instances a second in the logs of my SonicWall. It has no popups or sluggish issues which I thought was weird.

    Attached are the logs

    Thanks again!

    -A
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not answer my questions about WinPCAP or the Remote Desktop Connection software.

    Also you did not tell me how things are working now.

    The below file failed to delete:
    c:\windows\SYSTEM32\DRIVERS\LTEPSGGR.SYS

    Can you see this file? If so right click on it and select Properties and look at the Version tab information to see if you can determine what it is and who it belongs too. If there is no version info and you can see the file, have it scanned at the below link and report what is found:

    http://www.virustotal.com/
     
  6. abz1nthe

    abz1nthe Command Sergeant Major

    Hi Chas sorry was kinda hectic at work that day so I skimmed it.

    1.) Yes I am aware RDC was set in startup as we run a terminal server/RDP environment.

    2.)No, WinPCAP was not used on this pc.

    As mentioned previously I never even noticed that it was infected as it showed no signs of sluggishness or popups and didn't affect access and configurations that I could notice.


    c:\windows\SYSTEM32\DRIVERS\LTEPSGGR.SYS isn't showing a version tab and when I try to move the file over to my flash drive and/or delete it says "Cannot delete Itepsggr: Cannot read from the source file or disk". I am still hesitant to put this computer back online until I know for sure it is clean. Last thing I need is to have our WAN IP blacklisted by the world again :(

    Thank ya much!!

    -A
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    NOTE: RE your PM. We respond to threads in queue order which you should know. Our procedures are mentioned in this sticky: Don't Bump! It Only Hurts You!!! Also as stated in other stickies, we rarely will respond to PMs. Most PMs that are related to normal operatons or malware removal in the forum are just ignored since all threads are answered and they are answered in queue order.

    I did not ask you to move or to delete the file. Since ComboFix could not so easily delete it (it is in use) there is no way you could move or delete it manually. You could putting a copy into a zip file and attaching here. That is assuming that you can ZIP it. It could block you.

    Otherwise you will have try doing the above in safe mode to see if it will work or you will have to boot to the Recovery Console and rename the file to something like LTEPSGGR.SYS.BAD and then reboot back normally and see if it cause any problems to normal operation. Then ZIP the renamed file and attach it here.
     
  8. abz1nthe

    abz1nthe Command Sergeant Major


    Hi Chas,

    They reason I was trying to move the file was because I didn't want to put this computer back onto my network and have it create more problems. However, I did as you requested and when I uploaded the file the page said:

    0 bytes size received / Se ha recibido un archivo vacio

    I am going to try your other suggestion later on today when I have time.

    Thanks!

    -Adam
     
  9. abz1nthe

    abz1nthe Command Sergeant Major

    So I was able to boot in through recovery console and rename the file. Everything loaded up fine and attached is that file.


    thanks again Chas you are a life saver!!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  11. abz1nthe

    abz1nthe Command Sergeant Major

    I was able to delete the file and on a restart it did not respawn :)

    Thanks!
     
  12. abz1nthe

    abz1nthe Command Sergeant Major

    Bah just putting that pc online for that 2 minute period of uploading that file it spammed out to the world (unknowingly to me) and again our district is blacklisted from sending any emails to the outside world :(
     
  13. abz1nthe

    abz1nthe Command Sergeant Major

    I am just going to completely wipe this computer.

    Thanks for trying Chas.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If you have not wipe it yet, you may want to just try installing the current version of ComboFix and running it and attaching a new log. You were out of date of the last run and it ran in reduced functionality mode. There could be a couple leftovers that still needed removing.
     
  15. abz1nthe

    abz1nthe Command Sergeant Major

    I think just for sanity sake I am going to wipe it lol Unleashed demon spawn on my network got put on every major DNS blacklist which is so hard to get off after the second time. Still battling those companies to take us off there list :p

    Thanks again though!

    -Adam
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Sometimes this is the most secure way to know a PC is really 100% clean. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds