Antispyware Soft virus side effects

Discussion in 'Malware Help (A Specialist Will Reply)' started by sorvanetzsorv, Jun 2, 2010.

  1. sorvanetzsorv

    sorvanetzsorv Private E-2

    Last Thursday, I was hit by the Antispyware Soft virus. I managed to remove the visible effects of it by rebooting into the safe mode, using Malwarebytes' Anti-malware, and then doing system restore to a week ago. Then I started experiencing much more sluggish startup and shutdown, and after logging in, a number of services that are configured to start automatically did not start - there was no Internet connection, etc. This is why I came to this forum and followed all the steps in the
    READ & RUN ME FIRST. Malware Removal Guide
    It looks like ComboFix managed to find and remove this infection. I do not see any evidence of problems now, but I am not sure. Therefore, I am attaching all the logs that were generated, and would be very thankful if you could double-check that everything is clean now.

    Also, as far as I understand, if everything is clean, then I probably should do the tools clean-up - in particular, uninstalling ComboFix. Please confirm if I should do that and, if possible, point me to how to do that.

    Many thanks for your help!
     

    Attached Files:

  2. sorvanetzsorv

    sorvanetzsorv Private E-2

    Here comes the last (5th) attachment.

    Many thanks!
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is this:
    C:\Documents and Settings\rbsuser\Desktop\urdgivz8.exe

    Please use windows explorer to find and delete:
    c:\documents and settings\rbsuser\Local Settings\Application Data\mxjjmltlm
    C:\WINDOWS\Temp\ckd188.exe

    Now, making sure you have no disc emulation software running, please run this: GMER - running with a random name and attach the log from GMER.
     
  4. sorvanetzsorv

    sorvanetzsorv Private E-2

    Many thanks for your reply.

    urdgivz8.exe is actually Gmer with a random name. I tried running it before - probably around 8 times - both in regular mode and safe mode, but I cannot get the log - it freezes up my system, and I am forced to do hard reboot - this is really painful, because this is a RAID10 system, and RAID goes into the verification mode that takes many hours to complete. If there is any other way around it, I would appreciate it.

    I deleted the mxjjmltlm directory (which was empty), as you requested, but the file
    C:\WINDOWS\Temp\ckd188.exe
    is not there any more. There is another file in
    C:\WINDOWS\Temp\KC7E24.EXE
    which is identified as an OfcDog application by Trend Micro, which is my anti-virus maker. Please let me know if I should remove absolutely everything from
    C:\WINDOWS\Temp\

    Many thanks for your help and attention!
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Please download TDSSKiller to your Desktop
    * Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    * Click Start > Run and copy/paste the following bold command into Run box and hit Enter.

    "%userprofile%\Desktop\TDSSKiller.exe" -v

    * Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    * When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    And yes, you should clean out your temp folders.
     
  6. sorvanetzsorv

    sorvanetzsorv Private E-2

    Sorry about this delay - I did try to run Gmer again, and after 4 hours of running it crashed the system again. Then, after the reboot, I easily ran the TDSSKiller.exe which did not prompt me to do anything. I am attaching the log to this message.

    Many thanks for your attention!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run step 6 of the READ & RUN ME as was requested. You are making it more difficult to fix your PC since you have not followed that instruction and you have Daemon Tools running.

    After doing this, you need to rerun MGtools and attach a new log.
     
  8. sorvanetzsorv

    sorvanetzsorv Private E-2

    I apologize for my ignorance - I was under the evidently wrong assumption that since Daemon Tools were loaded at Windows start-up in my config I did not have to disable them. I now followed Step 6 to the letter - ran Defogger, and then MGtools - please see the log attached.

    Many thanks for your help!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    That is exactly why it has to be disabled. ;) Let me now show you what it was doing to totally mislead us.

    The below is part of a log collected from before you disabled Daemon Tools. Notice it stated you may have an MBR infection and that there was an unknown driver in called modules which also infers to us a possible TDSS (aka Alureon) infection
    Now below is this same part of your log after disabling Daemon Tools. Notice that everything is fine now. ;)
    TimW was spending a lot of time looking for two infections that did not exist because he just assumed you had followed all the steps in the READ & RUN ME as requested. ;)


    Are you currently having any malware problems?
     
  10. sorvanetzsorv

    sorvanetzsorv Private E-2

    Again, I am truly sorry that my ignorance caused wasted effort on your part. I am very conscious of how precious your help is and how scarce your time is. My only lame excuse is that it was absolutely unintentional and unanticipated.

    I do not experience any problems at the moment that I can attribute to malware. But I am not sure if I am done or not, and I am concerned about Gmer scans crashing my system - was it also related to Daemon Tools not being disabled? Is there anything else I should do? Is there any cleanup that needs to be done?

    Many thanks for your help and your expertise!
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I had asked you to disable disc emulation software in post #3. I mistakenly assumed that you had done that. So it is partly my fault for the false positives in your logs.

    Did you install Live Mesh?

    Your logs are clean of malware, so any additional issues might best be pursued in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  12. sorvanetzsorv

    sorvanetzsorv Private E-2

    Dear TimW,

    Many thanks for all your help, and no - there is absolutely no fault on your part. As I mentioned before, the root cause was my ignorance - I erroneously assumed that since Daemon Tools were not loaded automatically at Windows start-up, they were disabled, while in fact, the two services were still running, and I should not have skipped running Defogger - RTFM, as they say. I will make sure not to repeat this mistake in the future.

    Yes, I do have Live Mesh installed. I have found it to be quite useful, and several other computers have it installed as well. Is there a problem? Should I get rid of it? (That would be a real pity.) Please let me know.

    I will now go through the final cleanup steps - many thanks for providing them.

    I am very grateful for all your help and expertise. And all the instructions on the site are really great! If anybody else is reading this thread, they should know better than me and follow ALL the steps to the letter!
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There is no problem with Live Mesh, I just wanted to be sure that you had installed it.

    You are most welcome!! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds