Artemis!20B937399785 trojan virus & Generic PUP .z!gx

Discussion in 'Malware Help (A Specialist Will Reply)' started by arvin1, Nov 3, 2011.

  1. arvin1

    arvin1 Private E-2

    Hey there,

    Thanks for taking the time to help me out, i have been going nuts trying to sort this out.

    Basically about 4 or 5 days ago my McAfee antivirus software has detected a trojan virus Artemis!20B937399785 an item name of SAFARI.exe that is located in C:/program files (x86)\safari\bin. It also detected a Potentionally Unwanted Program (PUP) Generic PUP .z!gx. McAfee will find and quarantine both these programs, whereby i will delete these files from the computer however everytime i reboot my laptop the virus and PUP reappear and i can't seem to get rid of it. Attached are my log files.

    Just fyi if u need, i have a laptop running windows 7 64 bit. thanks so much for your help and i'm sorry if i have left any information out, please let me know and i will be of any assitance thanks :)
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  3. arvin1

    arvin1 Private E-2

    I've run both programs with no problems. I had turned my computer off when i went to bed and restarted it in the morning then run these scans. Attached are the log files.

    Thanks!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    C:\Users\Arvin\AppData\Local\28050
    C:\Users\Arvin\AppData\Local\{2C7BFCDC-81C6-4EA0-9B28-7F399C2CFDAF}
    C:\Users\Arvin\AppData\Local\{5A0F2A2E-FE18-4AE7-9945-7B977AA32F4F}
    C:\Users\Arvin\AppData\Local\{5F07C2DD-B23E-478C-92D7-9A42B8823320}
    C:\Users\Arvin\AppData\Local\{8214897E-480E-4433-BEDF-F5602268BA19}
    C:\Users\Arvin\AppData\Local\{B9CC0ECE-6B83-4F90-B81C-0A406FCA0B69}
    C:\Users\Arvin\AppData\Local\{CBFA9D2D-9DF6-4C30-B12A-4CCEC8D10C3E}
    Folder::
    C:\Program Files (x86)\Safari
    c:\program files (x86)\google chrome
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!

    Is your antivirus still complaining?
     
  5. arvin1

    arvin1 Private E-2

    I've created the 2 scripts and run the 2 programs, attached are the logs.

    As far as my computer health goes it seems to be working just fine, although McAfee keeps finding these trojans.

    thanks
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Where now?
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete the below folders and then tell me where exactly mcafee is still finding threats.

    C:\Users\Arvin\AppData\Local\28050
    C:\Users\Arvin\AppData\Local\{2C7BFCDC-81C6-4EA0-9B28-7F399C2CFDAF}
    C:\Users\Arvin\AppData\Local\{5A0F2A2E-FE18-4AE7-9945-7B977AA32F4F}
    C:\Users\Arvin\AppData\Local\{5F07C2DD-B23E-478C-92D7-9A42B8823320}
    C:\Users\Arvin\AppData\Local\{8214897E-480E-4433-BEDF-F5602268BA19}
    C:\Users\Arvin\AppData\Local\{B9CC0ECE-6B83-4F90-B81C-0A406FCA0B69}
    C:\Users\Arvin\AppData\Local\{CBFA9D2D-9DF6-4C30-B12A-4CCEC8D10C3E}
    C:\Program Files (x86)\Safari
    c:\program files (x86)\google chrome
     
  8. arvin1

    arvin1 Private E-2

    In the past when i did run McAfee to quarantine and delete the infected files on my computer then performed a restart, it will still continue to find the artemis trojan in the programfiles (x86)\ safari folder. I will now delete the files you posted up, perform a restart and perform a full system scan with McAfee and Malware bytes to determine whether the malware is still in my system, does this sound like a good idea? I won't perform the restart and scan until i get your a- okay :)

    thanks
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, go ahead and do what you proposed to do! :)
     
  10. arvin1

    arvin1 Private E-2

    I have successfully deleted all the files you have told me except for OS (C:) \ Program Files (x86) \ Google Chrome, whenever i try it says The action can't be completed because the folder or a file in it is open in another program Close the folder or file and try again. What should i do? i've tried closing my google chrome browser and then deleting the file but that didn't work.

    Also in my programs list i have a file called XNotes, Mozilla Firefox, Opera and Internet Explorer, i believe these files to be of a malicious nature as well as i don't have any of those programs installed, only got chrome as my main browser. What action should be taken about these files??

    Thanks
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    None yet!!



    Sorry! I thought Google Chrome was NOT installed as I was not seeing it in the list of installed programs in one of your logs. Can you just uninstall Chrome, (and use IE or install another broswer for now) rescan with Macfee... see if it finds anything. Let me know the result. Then reinstall Chrome and rescan again.
     
  12. arvin1

    arvin1 Private E-2

    i have uninstalled google chrome from my system and still i am unable to delete the google chrome folder in programs files (x86). i checked McAfee thinking that it may have quarantined something in that file causing in to be unremovable, but the artemis virus was found in the safari folder. i found under my PUP section of McAfee that the Generic PUP .z!gx was quarantined from the internet explorer folder, i'm currently using internet explorer from anohter computer.

    How do i go about removing the Google chrome file??

    thanks
     
  13. arvin1

    arvin1 Private E-2

    i found the problem and i deleted the file, proceeding to complete the other steps :)

    Thanks
     
  14. arvin1

    arvin1 Private E-2

    I've just run malwarebytes full scan and it found 5 different infected objects, i removed them and the computer has just restarted my computer, so far so good. My cpu is being chewed up anymore, i hadn't realized but in my task manager it said that chrome.exe was using close to 100% of my cpu and i had never stopped and thought that that was the cause of the trojan and not chrome itself! so far that isn't happening. However XNotes.exe is still creating an autorun registry on every startup, somehow i still feel that the system isnt clean...

    what are the next possible steps? should i redo all of the malware removal procedures again??

    thanks
     
  15. arvin1

    arvin1 Private E-2

    My cpu is NOT being chewed up anymore, i hadn't realized but in my task manager it said that chrome.exe was using close to 100% of my cpu and i had never stopped and thought that this was the cause of the trojan and not google chrome itself!
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, so let's rerun Malware Bytes. Attach the new log.

    Then:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  17. arvin1

    arvin1 Private E-2

    I've run malwarebytes and mgtools as requested, after malware had quarantined and removed the infections, it asked to restart the computer, i chose to restart later as this virus seems to regenerate on startup i then ran mgtools. Should i restart my computer now?

    thanks
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O4 - HKLM\..\Run: [XNotes] C:\Program Files (x86)\XNotes\XNotes.exe
    • O4 - Startup: Cleaner.lnk = C:\Program Files (x86)\Cleaner\Cleaner.exe

    After clicking Fix exit HJT.


    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Folder::
    C:\Program Files (x86)\XNotes
    C:\Program Files (x86)\Cleaner
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "XNotes"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  19. arvin1

    arvin1 Private E-2

    I have followed the instructions exactly, i still haven't restarted the computer since malwarebytes has asked, what should i do restart the computer or not? Attached are my log files for the two programs. Thank you

    Cheers
     

    Attached Files:

  20. arvin1

    arvin1 Private E-2

    Also the computer is running smoothly, my cpu is being chewed up however i haven't performed a restart yet to see if the virus have been redownloaded and generated ..
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes do a reboot and then let me know how things are running for you today. :)
     
  22. arvin1

    arvin1 Private E-2

    Wow i suck at typing, my bad rolleyes ! haha my cpu isn't being chewed up and still haven't restarted the computer yet thanks :)

    ahh i hadn't seen you post back, restarting machine now and will post regarding system performance and if the virus/trojan/bitcoin miner/malware has regenrated!

    cheers
     
  23. arvin1

    arvin1 Private E-2

    Hey kestrel,

    Just restarted the computer, seems to be running fine, used autoruns just to check if Xnotes.exe was running and there is no registry auto run for it, which is a really good sign im thinking :D hopefully the malware has been removed, gonna scan with malwarebytes, then McAfee just to doubly confirm, shall hopefully post up the good news to you soon that my computer is malware free.

    Thanks!
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Post the (hopefully good) news!! :) Let me know.
     
  25. arvin1

    arvin1 Private E-2

    Good news bro!! :) :-D

    the computer is clean, the files stopped regenrating and there is no more registry entry created for xnotes. Also both malwarebytes and McAfee aren't finidng the virus!! thanks so much for your help on this matter, really appreciate it!!

    As far as the programs i downloaded on the computer, mgtools and combo fix etc, can i get rid of them or should i leave them on the computer?

    Thanks again
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent news. ;)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds