Laptop Duqu malware help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by EcoGeek, Jan 26, 2012.

  1. EcoGeek

    EcoGeek Private E-2

    Just recently my laptop receive blue screen indicating stack overflow in kernel which it never did before. Upon rebooting, some of my malware, spyware programs would not load and those that did had real protection checked off. WinPatrol did not load at all even when I went into the folder and clicked on the application. Received blue screen again with stack overflow. Rebooted and all my system restore points were erased. In folder options all options to hide windows system files and operating system were unchecked.

    I went into safe mode and ran all the anti virus programs and maleware programs and everything checked out ok except Avira found a hidden file it could not read. Ran that file through SAS and Virustotal online scan and it checked out fine.

    I rebooted into normal mode and everything was fine. I shutdown the computer and the next day when I rebooted it would not reboot into normal mode. The window screen came up but the anti virus and anti malware programs would not load.

    Reference Embedded OpenType Font Heap Overflow Vulnerability - CVE-2009-0231 http://technet.microsoft.com/en-us/security/bulletin/ms09-029

    http://***********.com/business/news/2011/11/microsoft-fails-to-patch-duqu-but-fixes-critical-hole-in-windows-tcpip-stack.ars

    "Duqu-based attacks could allow attackers to run arbitrary code in kernel mode, allowing them to install programs; view, change or delete data; or create new accounts with full user rights. But Microsoft is still developing a permanent fix to the software, which will be included in either a future monthly update or an out-of-band patch, if it is ready earlier. "

    I have Windows 7 Ultimate 32bit with Avira Pro, SAS Pro, Malewarebytes Pro, Spybot, Spywareblaster, Windows Defender, WinPatrol Pro with Firefox browser. Windows 7 has all of the latest Microsoft security updates installed.

    Could there be an unknown installed program or maybe windows kernel is compromised. Could there be new accounts with full user rights hidden embedded somewhere? Changes to my security policies?

    I notice a lot of outbound traffic from system on TCP and UDP now to ps.mshome.net betbios-ssn, netbios-dgm, netbios-ns TCP/ip

    Begin scan in 'C:\Windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.1.7601.17514_none_b7c78d327d35e10e\'
    C:\Windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.1.7601.17514_none_b7c78d327d35e10e\t2embed.dll
    [WARNING] The file could not be opened!

    I could not open, copy or delete this file. message stated I did not have admin rights. I was in admin mode.


    Any help or suggestions will be appreciated.

    Thanks
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis logs are of very little use these days which is why are instructions state not to post them.

    Please follow the instructions in the below link in Normal Boot mode if possible:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Too many!!!
    I suggest that you uninstall Spybot, Windows Defender and WinPatrol.

    And then choose whether you prefer SAS or Malwarebytes. I would stick with Malwarebytes. And uninstall SAS
     
    Last edited: Jan 26, 2012
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oh and just an FYI, you are not supposed to have permission to delete this. It a system owned file and you should not be touching it. It is not a problem.
     
  5. EcoGeek

    EcoGeek Private E-2

    Ok, very frustrating. :-(
    I could not shutdown my laptop clicking on the windows shutdown button. It just sat there. The lights on my wireless router were flicking very fast and the laptop wireless light was solid so I waited and waited finally disconnected the router to shut down the laptop and actually had to hold down the turnoff key for the laptop to shutdown.

    I then plug the wireless router back in and turned on the laptop. The laptop would load the windows screen but hung when attempting to load the antivirus and malware programs. It just sat there with the wireless connector light solid green with just the rotating windows circle sitting there and the active lights flicking again on my router. I waited and waited. So I disconnect the router again and rebooted in safe mode with networking, turning the router back on.

    I disabled all anti virus software but combofix said Avira was still running on desktop. It was not loaded. Taskmanager did not show Avira running. All the avira services were stopped. Procexp showed no avira processes or programs running. So I continued on anyway. So all these programs were run in safe mode networking on. Spybot Winpatrol were uninstalled.

    Rootrepeal would not run as a memory exception error message initiated

    Thanks
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It appears that you are not having malware problems. All of your logs are clean.
     
  7. EcoGeek

    EcoGeek Private E-2

    Ok Thanks for your speedy reply and all your help. I wonder what caused BSOD twice on overstack in one day and why there are connectivity issues. We had severe power outages over the past few days. Maybe, the problem is with my router or memory issue as event viewer shows. It's that Avira hidden file message that threw me off and the security bulletin.

    IP_ICS_IPV6_LOG_CONFIG_IPV6_STACK_FAILED

    IP_DNS_PROXY_LOG_ALLOCATION_FAILED">

    Opps,
    Hmmm,
    Windows Search Service Details: The content index catalog is corrupt.
    The index cannot be initialized.

    I might have a windows or a hard disk issue with corrupted files.
    After now looking in event viewer with 15 error messages that occurred over last few days. Should have checked there first. Sorry for taking up your time.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds