Antivirus software alert

Discussion in 'Malware Help (A Specialist Will Reply)' started by chasf, Dec 5, 2010.

  1. chasf

    chasf Private E-2

    Hello,

    I woke up my laptop a few hours ago and had a window on top of everything saying a scan just finished and my computer was infected. it was obviously not anything i had authorized or had on my computer. i closed and immediately tried to open and run Malwarebytes. It would not open. I get an error that says audiodg.exe is infected. i tried changing name to mabm and now get mabm.exe is infected. I restarted and now have a nice big window in the center of the screen that says, "Attention ! Spyware Alert... 34 serious threats have been found..." There are two buttons at the bottom to activate my antivirus software or stay unprotected. I have not selected either. in the lower right corner of my screen i have another window that has infiltration alert. Under details it says: Threat: BankerFox.A. It asks if you want to block the attack; yes or no. I have not selected either.
    When i try to run Trend Micro i get an error that says ufnavi.exe is infected. I started going thru Run and Read Me but everything i have tried is blocked by Windows Security Alert. I stopped at Step 7 since everything i had done amounted to nothing. i even tried going to Windows Features to try turning IE back on. It was blocked too - a .exe error. A Firefox browser window will open but I cannot see any pages. The error says, "Internet Explorer Warning - visiting this web site may harm..." So to sum up, everything i have tried is being blocked, even running Task Manager. I am completely out of ideas.

    I am running Windows 7 with Trend Micro and using Firefox and Thunderbird. What other system details do you need?
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.


    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post )


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.


    Then try running these instructions: Using MGtools


    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • a log from online SAS scan if you could make one
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  3. chasf

    chasf Private E-2

    Thanks for your quick reply. I was unable to download rkill.pif. The web site was not found.

    The other three will not run. when i double click to run one i get a message from Windows Security Alert that says: "Application cannot be executed. The file rkill.scr (or .com or .exe) is infected. Do you want to activate your antivirus software now?"

    After it goes away i will periodically get a Window Security Alert that says: "Windows reports that computer is infected. Antivirus software helps to protect your computer against viruses and other security threats. Click here for the scan your computer. Your system might be at risk now." Yes it has bad English:)

    Also, the window in lower right corner that last night said threat was BankerFox.A now says Win32/Nuquel.E. I'm sure they are related but thought it may help.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Rkill.pif <-- I got a 404 error for this one too.

    Try this if the other three did not work

    NOTE: If you are having problems running Rkill, try running one of these renamed copies of RKill.com:
    Did you try running the online Superantispyware scan?

    Did you try running MGTools.exe?
     
  5. chasf

    chasf Private E-2

    Ok, will try these other two options tonight. It will probably be late but i will make sure to post results before tomorrow.

    No, did not proceed down the list as I cannot access anything online and i probably made the mistake of assuming that since the rkill was blocked, so would everything else. I probably should've spent more time with it last night, but i did not.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay well just try everything I said and let me know how it goes, attach logs of you were successful, use another computer to download the tools if necessary and then transfer them onto the sick PC. Then we will take it from there. :)
     
  7. chasf

    chasf Private E-2

    Whew! it's been a fun couple of hours! eXplorer.exe did work and lots of progress after that. Attached are the logs. My internet still does not work. The error says: "The connection was reset."
     
  8. chasf

    chasf Private E-2

    Here is the MGtools log. I just realized the rkill log that i attached was from a later run. i think after rebooting after running the SAS scan. I hope this is ok. It's getting late I hope we made some progress. Thanks for looking over these items.
     
  9. chasf

    chasf Private E-2

    I should probably mention that i didn't have to run rkill after i ran MGtools.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Logs did not attach.
     
  11. chasf

    chasf Private E-2

    bummer. try this.
     

    Attached Files:

  12. chasf

    chasf Private E-2

    i forgot to click upload. :-D Here are the last two.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue, you need to use MSCONFIG to put the machine into normal start up mode.

    Java(TM) 6 Update 14 <--- Uninstall this outdated version of Java.

    If you did not deliberately set this proxy yourself then please include it in our list of HJT fixables below:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.


    Tell me, or show me with a screenshot, what is inside of the below directory:

    C:\ProgramData\{66E2F539-12B6-4870-A500-7689CDE75C5E}

    Could you please get this: crt.dat into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    log retrievable @ C:\collect.zip

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :Files
    C:\ProgramData\~0
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if

    Now run Malware Bytes as per the instructions in the Read and Run me First

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Tell me how things are running for you.
     
  14. chasf

    chasf Private E-2

    I couldn't figure out how to get crt.dat into a zip file. I searched C:\collect.zip and couldn't find any results.

    Attached is the screen shot of the directory you inquired about.
    Attached is the OTM log.
    Attached is MBAM log. I ran the quick scan and it only took about a minute and a half. Should I be concerned about the amount of time?
    I cannot find the MGlogs.zip. it is not in the directory. i'm at a loss there.


    Things are seem to be running well. I'm back online, very nice:-D ! I'm going to leave everything as is until I hear further. Thanks!
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please go to virustotal and upload the following files for analysis, and let me know the results.

    C:\windows\system32\crt.dat
     
  16. chasf

    chasf Private E-2

    I'm still unable to find the file crt.dat.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Alrighty then, seems you're good to go!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  18. chasf

    chasf Private E-2

    sounds good! i will go through these last steps. I appreciate you helping me through the process!

    Do you have any ideas on where things could've started? I run SpywareBlaster and update it about once a week. I run CCleaner about once a week and run a MBAM scan about every 10-14 days. So i'm a little disappointed that something got in here.

    do you have any other software or system recommendations virus related or overall?

    thanks again!
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No probs.

    No idea, I do not know what your surfing habits are, I do not know what types of sites you visit, what you like to download...

    Just run SUPERantispyware as well as MalwareBytes.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds