Jacked with crap

Discussion in 'Malware Help (A Specialist Will Reply)' started by shiftlessatol, Oct 27, 2010.

Thread Status:
Not open for further replies.
  1. shiftlessatol

    shiftlessatol Private E-2

    i've run [combofix]->Safemode twice both times it indicates MBR infection and Rootkit activity

    also ran [Smitfraudfix, Rougefix, SDfix]-> Safemode, 4 offline scanners, hardware diagnostics ALL PASS

    i'm still getting porn popups on IE and windows updates is totally inaccessible

    there's no additional processes running that would indicate the ie hacks are coming from, HiJackThis! didn't indicate any suspicious files, and the popups are coming from svchosts(one of about 7)

    here's the combofix & MGtools logs let me know if i've forgotten a step

    xp home sp3
    Kaspersky 2010

    Recovery Console won't load from hd0
    ran from setup disk => fixmbr

    kl1.sys
    TDI.sys
    both of these load after MUP.sys (usually mup is the last file to load on SM)

    -dave-
     

    Attached Files:

  2. shiftlessatol

    shiftlessatol Private E-2

    Progress!

    ::fixmbr has resulted in no more MBR infection notifications or Rootkit activity via CF
     
  3. shiftlessatol

    shiftlessatol Private E-2

    New CF report (Post-fixmbr)
     

    Attached Files:

  4. shiftlessatol

    shiftlessatol Private E-2

    just checked and i have windows updates back - no porn pops so far...
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    I see you have two antivirus installed?

    • Norton AntiVirus Parent MSI
    • Norton AntiVirus SYMLT MSI
    • Kaspersky Anti-Virus 2010

    You must uninstall one of them now.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    SecCenter::
    {4055920F-2E99-48A8-A270-4243D2B8F242}
    {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Things still running okay?
     
  6. shiftlessatol

    shiftlessatol Private E-2

    it's just some old registries, i haven't run the norton removal yet, i'm about finished with cleaners, after NRT i'll do this process you've posted, and reply - probably later in the morning maybe in a few depending on the cleaners...

    thanks!
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK. :) I'll be about sometime later on in the day.
     
  8. shiftlessatol

    shiftlessatol Private E-2

    I'm currently finishing your instructions - Logs will be posted soon
     
  9. shiftlessatol

    shiftlessatol Private E-2

    Here are the files you requested
     

    Attached Files:

    Last edited: Oct 28, 2010
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You attached the Combo script, not the log from running it. But it is in your MGLogs.zip. So just hang on until Kes can get to you when she gets off work.
     
  11. shiftlessatol

    shiftlessatol Private E-2

    my bad, she didn't actually request it, but i went ahead and threw it in cause CF generated it

    Thanks!
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete the below files using windows explorer.

    • c:\windows\system32\SET28A.tmp
    • c:\windows\system32\SET28E.tmp
    • c:\windows\system32\SET28F.tmp
    • c:\windows\system32\SET28B.tmp
    • c:\windows\system32\SET291.tmp
    • c:\windows\system32\SET290.tmp
    • c:\windows\system32\SET295.tmp
    • c:\windows\system32\SET296.tmp
    • c:\windows\system32\SET297.tmp

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know how the machine is running!
     
  13. shiftlessatol

    shiftlessatol Private E-2

    The machine is running great, just finished with cleaners & defrags. the only problem currently is the inability to access symantec.com, other AV sites are fine, and if that's the only site she can't get to it should be fine on account of she'll never need to access, i'm running your last posts instructions now....
     
  14. shiftlessatol

    shiftlessatol Private E-2

    there were several other SET###.tmp files, should i keep them or delete them also?
     
  15. shiftlessatol

    shiftlessatol Private E-2

    Weird, so the first time TDSS ran, it showed 3 threats, i clicked next, the log indicated that i skipped them, so i ran it again, the first log is gone, and the second and third time it didn't indicate there to be threats?

    so i may have jacked the results but i've included the two logs it gave
     

    Attached Files:

    Last edited by a moderator: Oct 28, 2010
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete them.

    Now your last MGlogs.zip was incomplete. I need you to do this again making sure you let it run to completion.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  17. shiftlessatol

    shiftlessatol Private E-2

    correct! sorry

    they're deletred
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Get rid of these too:

    • C:\Program Files\Internet Explorer\en-US\SET1E9.tmp
    • C:\Program Files\Internet Explorer\en-US\SET1EB.tmp

    Everything still running well?
     
  19. shiftlessatol

    shiftlessatol Private E-2

    ok, it's all good, i found them on the log and deleted them manually, so they're gone now (the three it found in the first log)
     
  20. shiftlessatol

    shiftlessatol Private E-2

    gotten Rid of

    running smooth, i'm trying Symantec now......=> still fail, should i reboot after these deletions?
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Great!

    If we renamed combofix, rename it back to it's original name ---> combofix.exe
    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  22. shiftlessatol

    shiftlessatol Private E-2

    Uninstalled and cleaned,

    rebooted => success
    symantec.com => fail, but i don't care, cause she's never going to need to access that site.

    i'll try resetting the zone again and see if it rectifies - do you have paypal?
     
  23. shiftlessatol

    shiftlessatol Private E-2

    i discovered it's in the routing - maybe the DNS server i set using DNS Jumper has it jacked, i'm going to remove them to see if i can access it attached is the tracert
     

    Attached Files:

  24. shiftlessatol

    shiftlessatol Private E-2

    sure enough, there's a DNS server that is down or something kinda neat!

    thanks again
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Any luck?
     
  26. shiftlessatol

    shiftlessatol Private E-2

    yes, this post was intended to indicate that it was fixed

    Thanks
     
  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome!
     
  28. shiftlessatol

    shiftlessatol Private E-2

    Auto run issues with CD drive, and VPN tunnel problems. i've corrected most of the registry entries and used Tweaks UI for autoruns = > no change

    i'm going to do some hands on work with the machine tomorrow and i'll update you with what i've come up with. i fear that i may have removed a driver that was required by Cisco's worthless VPN client. anyway keep an eye on this thread still and give any ideas you might have for solutions on correcting these two problems

    thanks
     
  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry but any outstanding issues that are obviously not malware related will have to be resolved in other area's of the forum. :) Best of luck!
     
  30. shiftlessatol

    shiftlessatol Private E-2

    lol, so you're not sure then, because they worked prior to the infection and even during the infection, only after the infection (the removal of) did these two things stop working, but that's fine, i'll figure it out

    thanks
     
  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I only have time for malware removal, that is why the software forum exists. ;) I volunteer all my free time to helping people like you who have problems like this, which I responded to by the way.

    Jacked with Crap v2
     
  32. shiftlessatol

    shiftlessatol Private E-2

    yes you did, and you helped immensely

    BTW the fix for the above post extraction issues is as follows::

    VPN traffic was to remove the DNS from the Advanced properties on the NIC used by VPN Client

    right click > Properties > TCP/IP v4 > Advanced > DNS > Deleted Entry
    Also
    CMD >

    route delete xxx.xxx.xxx.0
    xxx.xxx.xxx.0 = Default network. will be your gateway Ip address ending with 0 instead of what is posted)

    Autoplay issue,

    Autofix.exe provided by Microsoft
     
  33. shiftlessatol

    shiftlessatol Private E-2

    Thanks again to Kestrel13! for your assistance with malware removal
     
  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome. :)
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds