Pain Removing Well Hidden Malware!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by aj10, Jun 3, 2007.

  1. aj10

    aj10 Private E-2

    Hi,

    I have gone through the read me first steps. The following problems occurred during the clean up:

    1. Panda ActiveScan could not be run due to some internet explorer problem. I've attached the screen shot of the error it gave.

    2. My Command box does not seem to be accepting common commands such as ping, netstat etc. thus it did not even recognise regedit, therefore the Getrunkeys and ShowNew did not effectively work, however I've still attached the logs. I've also attached a screenshot of the errors it gave when running Getrunkeys.

    My main problems are as follows:

    1. My ISP (Unwired Australia) continually suspends my internet service as they detect a "virus" on my computer. I have spoken to them numerous times and have established they do not run online virus scanners, however they detected an unusual amount of packets coming out of port 25 of my PC continously, therefore they think its a virus or malware.

    This could well be true as when I ran a port blocker and tried sniffing it after that, it said that port 25 was already in use.

    My firewall, (PCTools Firewall Plus) is blocking a LOT of incoming UDP packets from an address "169.254.254.1" to a broadcast address "255.255.255.255". I just want to know how to stop getting the packets.

    2. A malware overrides my windows firewall from working, when I got to turn it on, it gives an error saying Windows could not turn it on. Spybot detected this when running in safe mode, however after it was removed, it came back, along with "Hotbar" when I ran it again after a reboot. I think this issue is related to issue 1 above.

    3. The Command prompt used to accept common instructions / commands, such as ping and netstat, however these can only be run through "Start ==> Run ==> .... ". Its really odd.
     

    Attached Files:

  2. aj10

    aj10 Private E-2

    OS I'm using: WinXP, SP2

    Attached here are logs for:

    1. Spybot - the second time I ran it and found the same malware on it.
    2. GetRunKey log
    3. ShowNew log
     

    Attached Files:

  3. aj10

    aj10 Private E-2

    Attached are some screen shots to demonstrate what happens when I run GetRunKeys and also a screen shot of my firewall blocking the incoming packets from the IP address to broadcast.

    Regards

    Arjun
     

    Attached Files:

  4. aj10

    aj10 Private E-2

    Sorry, forgot to post a HJT log.
     

    Attached Files:

  5. aj10

    aj10 Private E-2

    it seemed the problem with the cmd was just the default path directory, i managed to add windows and windows/system32 to the path and run getrunkeys and show new from command. Attached are the files.

    Hope this helps out. Still cant run panda scan, dont know whats wrong with my IE.

    PS. sorry for the multiple posts.

    Thanks
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    Port 25 is typically used by SMTP. You can read more about it here:

    http://www.postcastserver.com/help/Port_25_Blocking.aspx

    Are you running anything that is sending lots of email?

    These are probably broadcast packets from your ISP. This is common used for diagnostics. See this: http://www.hamilton.ie/gavinmc/ripwave/navini_diag.html

    You have PC Tools Firewall installed. It is what disabled Windows firewall because you must never use multiple software firewalls. This is not due to malware.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You already had the Windows and system32 folders in your path. Now you have it there twice. Once at the beginning and once at the end. Delete the duplicates you added to the end of your Path.

    Many people run into problmes running the online scans. Most frequently it is an active-x settings issue or due to the fact that you are preventing it from running in your firewall or with your antivirus....etc.

    Did you knowlingly install the Crawler Toolbar stuff? It is considered adware. See this: http://vil.mcafeesecurity.com/vil/content/v_137764.htm
    I recommend uninstalling this especially if you did not install it.

    Is your copy of Spyware Doctor a paid version or a free trial? If free uninstall it it.

    You are running Ad-aware 6 Personal which is more than 3 years out of date. If you want to use Ad-Aware, you should uninstall this and download the proper version: Ad-Aware SE Personal

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_04
    Mozilla Firefox (2.0.0.2)
    Mozilla Firefox (2.0.0.3)

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O4 - HKLM\..\Run: [system] C:\WINDOWS\system32\netdd\mru\ms\mg\msi.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT
    Now reboot in normal mode

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     
  8. aj10

    aj10 Private E-2

    No there is nothing that is running that is sending lots of emails. Only using Outlook, but thats just using POP3 and an IMAP account. I am currently using a port blocker already (Analog X), however it says "Port 25 already in use". Does that mean something is using it and keeping open?

    That could be, however the IP range of my ISP is nothing like the IP address flooding me. This address starts with "169..." my ISP's address starts from 220.., but then again, the ISP should be blocking these packets if it is from an outside source, is that correct?

    I had this problem occurring before I had the fireware installed, and Spybot picked up the malware in the registry that was overiding it. I went into the registry manually and deleted it, however I ran Spybot again in safe mode and it had come back, along with "Hotbar".

    Thanks for your help.
     
    Last edited by a moderator: Jun 6, 2007
  9. aj10

    aj10 Private E-2

    I had to do this otherwise it would not allow me to run programs in the windows, or system32 directory as per the screen shot attached when trying to run GetRunKeys.bat

    I had downloaded a program, Spyware Terminator, and it had come with that. I uninstalled it a few days ago.

    free version - uninstalled already

    uninstalled already
    All steps done. Logs attached

    Things are running a lot smoother since the I had done the initial clean up from your read and run me first post. I havent had any major problems with spyware or adware, it is just this other issue of port 25 thats pressing.

    PS. I hadn't used the quote function properly in my last post, some messages are within the quote.

    Thanks
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Perhaps some application you are running. From a command prompt window enter netstat -a Post back what you get.


    What are all the below doing and why do they need to run at startup?
    O4 - HKLM\..\Run: [CostAware] C:\Program Files\NetInternals\CostAware\niIPCApp.exe
    O4 - Startup: Shortcut to YzDock.exe.lnk = D:\Program Files\Yz Dock\YzDock.exe
    O4 - Startup: Unwired Launchpad.lnk = C:\Program Files\Unwired\UwSCT.exe
    O4 - Global Startup: Grouper.lnk = D:\Program Files\Grouper\Grouper.exe
    O4 - Global Startup: Palo Alto Software Update Manager 8.0.lnk = C:\Program Files\Common Files\Palo Alto Software\8.0\PAS8_Update.exe
    O4 - Global Startup: Unwired Launchpad.lnk = C:\Program Files\Unwired\UwSCT.exe


    These are broadcast packets. They will not have the IP address of your ISP. You need to check with them if they are sending these packets and why.


    Spybot is not reporting malware. It is reporting a change from the default setting where Windows is your security center and firewall. This is not a problem. It is normal once you are using your own antivirus and firewall. Spybot is not saying that anything is wrong. It is just warning you that you are no longer set to the default settings.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It still should not be necessary to have it in the path variable more than once.
    • From a command prompt window enter regedit
    • Does the registry editor appear?
    • Now remove the duplicate entries from the end of the path.
    • Reboot (this is necessary).
    • Now again from a command prompt window enter regedit
    • Does the registry editor still appear?
    This is something they just recently started doing and we complained about it. There is a version without the addons. I see you uninstall Crawler Toolbar with Web Security Guard now!

    I fixed them for you. ;)
     
  12. aj10

    aj10 Private E-2

    I've attached the log of it. The problem with this is that my ISP reports it sends our packets at random, however long periods of time. E.g. at 8pm last night it was sending out packets for 3 hours, and then stopped and then started again at 12am for 1 hour, then they suspended my service till I called them again.


    Costaware - program that counts downloads and uploads for international and domestic traffic.
    YzDock - an Icon docking program, similar to that of the Mac menu.
    Unwired Launchpad - Program supplied by my ISP for monitoring signal strength, quality etc.
    Palo Alto Software - Business Plan Pro software updating tool, usually disabled at start up, but for the sake of the HJT log, a Normal startup was chosen to see all programs running, as instructed in your readme.
    Grouper - a video sharing program, however also usually disabled at startup.

    I read the link you provided and understood it. ISP confirmed it was a diagnostics tool checking if my modem was still there.

    No problem.
     

    Attached Files:

    Last edited: Jun 6, 2007
  13. aj10

    aj10 Private E-2

    Yes

    Removed the duplicate entries and rebooted.

    Now working again. For some reason, previously it was not recognising the SystemRoot path. This had been a problem for months until now.

    I have also attached a log of a few instances of netstat at startup. The http and smtp connections worried me as theoretically there should be no connections setup on startup, is that right?
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What are all of the below from your first log?
    Code:
      TCP    TOSSER:2912            a210-9-135-203.deploy.akamaitechnologies.com:http  ESTABLISHED
      TCP    TOSSER:2913            ar-in-f165.google.com:http  ESTABLISHED
      TCP    TOSSER:2915            ar-in-f165.google.com:http  ESTABLISHED
      TCP    TOSSER:2916            ro-in-f99.google.com:http  ESTABLISHED
      TCP    TOSSER:2932            imap-vmc.mx.aol.com:imap  TIME_WAIT
      TCP    TOSSER:2934            srv12.digitalpacific.com.au:pop3  TIME_WAIT
      TCP    TOSSER:2936            pop.secureserver.net:pop3  TIME_WAIT
      TCP    TOSSER:2938            pop.bluetie.com:pop3   TIME_WAIT
      TCP    TOSSER:2943            imap-vmc.mx.aol.com:imap  TIME_WAIT
      TCP    TOSSER:2946            srv12.digitalpacific.com.au:pop3  TIME_WAIT
      TCP    TOSSER:2948            pop.secureserver.net:pop3  TIME_WAIT
      TCP    TOSSER:2950            pop.bluetie.com:pop3   TIME_WAIT
    
    Looks like a bunch of email type connections!

    Shutdown ALL unnecessary applications, especially browsers, instant messengers, Skype, Yahoo Mail (or any other email apps), CuteFTP if running (make sure no FTP servers are running), Limewire, uTorrent (or any other P2P apps), and so on. And then tell me if these packets are still found leaving your PC. Also have you ever checked to see if this occurs after booting in safe mode.

    Have you run a netstat -a while the problem was occuring? Capture one from then?
    Have you captured any of these packets with Ethereal?

    Do you use or connect to AOL?


    Disable all of these from loading at startup! You can use HJT to permanently remove them if you never need them, or for now you can use MSconfig.



    Now please download F-Secure's BlacklightBeta
    • Download fsbl.exe and save it to the Desktop.
    • Once saved... double click fsbl.exe to install the program.
    • Click accept agreement and Click scan
    • This application may trigger a warning from your antivirus. Let the driver load. Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.
     
    Last edited: Jun 6, 2007
  15. aj10

    aj10 Private E-2

    All these connections are legit. I ran netstat while outlook was running.

    I have used TCP View and have managed to see how the program is running.

    Its now coming together. In the past I have had problems with "services.exe" where it would randomly give an error and windows would shutdown / restart.

    It seems services.exe is making connections to SMTP servers, then a http connection to a site "pm1.sjc.mccolo.com". Then all of a sudden a whole lot of smtp connections would appear. I have attached the screen shots of this. I dont know how to get rid of it as if I end the services.exe process, windows gives an error and restarts.

    It also does the same thing in Safe Mode.

    Yes, I have a tcpdump of it. I'll attach it as well.

    I have an IMAP account running through outlook for AOL.

    Disabled momentarily.

    Attached are the logs of Blacklight, some screenshots of TCPView at startup, a netstat log at startup when services.exe are making the initial connections, and also a tcpdump of when the malware is running.

    I've managed to create a rule in my firewall to block out these packets, and it seems to be working, however removal would be ideal.

    Thanks
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  17. aj10

    aj10 Private E-2

    Logs are attached. Seems to be removed, cant find any open smtp connections on tcpview. Will I be required to run Blacklight on any other users?

    Cheers
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good news! ;)

    No! You should be finished unless you have other malware issues.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  19. aj10

    aj10 Private E-2

    Great. All is well. I would like to thank you for your continuous and comprehensive help. I admire what you and others like you are doing, true professionals. If there is anything I can do to contribute in anyway, please let me know, I would be happy to give back.

    Thanks once again, hope I don't need to end up coming back to one of these forums for help in future.

    Regards

    AJ
     
    Last edited by a moderator: Jun 8, 2007
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and thanks!

    It's purely optional, but if you wish to you can PM me with an email address and I can send you PayPal info.

    Either way, surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds