Besieged by Virtual Vermin

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lohengrin, Aug 29, 2011.

  1. Lohengrin

    Lohengrin Private E-2

    Hello potential saviors, I have a few problems on my hands:

    1. Google redirection problem on all browsers.

    2. CPU usage constantly at 50%+ even when there is hardly anything open and running.

    3. Computer on restart becomes unresponsive and forces a manual restart.

    4. For some reason, manage attachments doesn't work, even with pop-up blocker off. This is what the error log in firefox says: Security Error: Content at googleads.g.doubleclick.netmay not load data from http://forums.majorgeeks.com/showthread.php?t=165974.

    5. Programs like malwarebytes, superantispyware, avira antivir, and advancedsystemcare do not work. During a scan, these programs crash and then I'm unable to access them, and get the error message: "Windows cannot access this file.... blah blah blah... or you may not have the permissions... blah." The exception to this is avira antivir, as the scan doesn't crash, it simply doesn't do anything if you click on the option.
    ------

    So, I have tried some things this website suggested:

    I ran TDDSKiller and it fortunately found that I have a Rootkit.Win32.ZAccess.c on my hands, but was unable to cure it.

    Then, I also ran MBRCheck, and this is the result:

    I also ran MGTools, but I can't attach the zip file as manage attachments doesn't seem to be working.
     

    Attached Files:

    Last edited by a moderator: Aug 29, 2011
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Were you able to run Combofix?

    See this, please.

    You need to take a look at this.

    HOW TO: Attach Items To Your Post
     
  3. Lohengrin

    Lohengrin Private E-2

    I did read those how-to-attach instructions but, like I said, even when I disable the popup blocker, nothing popups when I click on “manage attachments.”

    And yes, I did manage to run Combofix. It detected the rootkit zero access and then asked for a reboot. The computer froze during this and I had to manually restart it. When I logged on again, Combofix immediately started up again, completed all of its stages, deleted some files, and automatically restarted the computer.

    As a result, the google redirection problem and the restart freeze issue has been fixed, but I'm still getting 50%+ CPU usage when hardly anything is running.

    Oh and, after running combofix, I am now able to run malware bytes, which found these four infections:

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\Name\Local Settings\Application Data\gau.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> Not selected for removal.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Still getting the abnormally high CPU usage though.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then you need to try using a different browser first. If that really doesn't help you attach the logs I want then you can upload them to www.mediafire.com and give me the sharing link. You said you were able to run Malware Bytes so please attach (or upload) that log too, and what about SUPERantispyware? Attach/or upload the logs from Combofix and MGTools too please.
     
  5. Lohengrin

    Lohengrin Private E-2

    Alright, using Chrome now.

    Malwarebytes, MGtools, and Combofix logs are attached (I uninstalled Superantispyware, so don't know if it works or not)

    About the combofix log, the first time I ran the program it did not produce a log, so this log you see here is based on the second run.

    And...... it seems that after the second Combofix run, CPU usage is now normal, but perhaps the logs show some lingering issue?

    Let me know,

    ~Thanks
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, there are definately lingering issues. :(

    c:\program files\iPod\bin\iPodService.exe is infected so I suggest uninstalling Itunes and then you can reinstall after we are done here.

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      nvsvc32.exe 
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt



    Now we need to use ComboFix sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\Temp\{E9C1E0AC-C9B2-4c85-94DE-9C1518918D02}.tlb
    C:\WINDOWS\system32\drivers\11995438.sys
    C:\WINDOWS\system32\drivers\tsk2B.tmp
    c:\windows\006265_.tmp
    C:\Documents and Settings\All Users\Start Menu\desktop.ini
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
    C:\Documents and Settings\Default User\Start Menu\Programs\Startup\desktop.ini
    C:\WINDOWS\assembly\GAC_MSIL\Desktop.ini
    C:\WINDOWS\assembly\GAC_MSIL\Desktop(3).ini
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.



    Please go to virustotal and upload the following files for analysis, and let me know the results.

    • C:\windows\system32\c_51525.nl_


    Could you please get this: c_51525.nl_ into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    log retrievable @ C:\collect.zip


    Please re run TDSSKiller and attach the new log.

    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  7. Lohengrin

    Lohengrin Private E-2

    When I got back on the computer, Avira detected Virus or unwanted program 'RKIT/ZAccess.c.1 [trojan]'
    detected in file 'C:\System Volume Information\_restore{AA651E87-4D36-4B53-8AB8-04195AEE187D}\RP6\A0001616.dll.
    Action performed: Deny access

    It repeated this action about 7 times, until finally I banished it: Avira moved it to Quarantine: 'C:\System Volume Information\_restore{AA651E87-4D36-4B53-8AB8-04195AEE187D}\RP6\A0001616.dll'
    contained a virus or unwanted program 'RKIT/ZAccess.c.1' [trojan]
    Action(s) taken:
    The file was moved to the quarantine directory under the name '4c79eb66.qua'.

    -Uninstalled ITunes
    -Systemlook and Combofix logs attached
    -For the virustotal analysis, 21/44 programs detected an infection in c_51525.nl_
    -TDSSKiller log attached
     

    Attached Files:

  8. Lohengrin

    Lohengrin Private E-2

    And the rest of the logs, below.

    None of the problems I have been having before have come back thus far.

    EDIT: I made a post before this, and it requires moderator approval. Why doesn't this one? ;o
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good, but let's just do this.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\windows\system32\c_51525.nl_
    C:\WINDOWS\pchealth\helpctr\binaries\pchsvc(3).dll
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know if things are still running well.
     
  10. Lohengrin

    Lohengrin Private E-2

    Things are running well, albeit with some malware detections from avira every now and then.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Such as..? Can you give file and file path? :)
     
  12. Lohengrin

    Lohengrin Private E-2

    Here are some of them, in the attached file.

    All of them have been quarantined, I think, but who knows, there might be some problem.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, the stuff being detected in system restore is not a problem, it will be trapped in there until we have you follow final instructions. However some of the other detections had me a little worried.

    Let's do this.


    Run this and attach the results.

    Using ESET's Online Scanner
     
  14. Lohengrin

    Lohengrin Private E-2

    Here are the results of the ESET scan
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you please run another avira scan and attach the results?
     
  16. Lohengrin

    Lohengrin Private E-2

    Hello guys, I'm back, unfortunately.

    Thanks for the help last time, and I'm appearing once more to make sure if my computer has been successfully cleaned.

    I recently encountered the problem of the svchost process exponentially hogging up CPU power until the computer was inoperable. I then ran all of the programs in the sticky thread and it appears this issue has been resolved. BTW, I'm running windows xp.

    But if someone could check the logs to see if I'm right, it would be appreciated.

    Thanks,
     

    Attached Files:

  17. Lohengrin

    Lohengrin Private E-2

    Have to double post to get the rest of the logs attached:
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Why on earth did we not wrap up properly last time? You just left the thread dangling. You must always see it through to completion please!! :)

    Re run TDSSKiller and attach the new log. Also you forgot to run MGTools.exe in order to produce a MGLogs.zip? Please attach that too.
     
  19. Lohengrin

    Lohengrin Private E-2

    Heh, yes, I'll see it through this time.

    Here they are:
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete this folder: C:\Documents and Settings\Administrator\Local Settings\Application Data\Ilivid Player

    Go back to the Read and Run me First and download the CURRENT MGTools.exe, let it overwrite the old, run the new and attach the C:\MGLogs.zip please.
     
  21. Lohengrin

    Lohengrin Private E-2

    Folder deleted,

    and here's the zip file.

    I dled the exe from the run and read me but not sure if it actually updated anything.
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Of course it updated, that's why I asked you to do it :-D

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:

    If you get infected again/or you wish to check for possible malware again, do NOT link onto this thread. Too much action here already.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds