Continuous Connection Indication

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jerry1964, Oct 5, 2010.

Thread Status:
Not open for further replies.
  1. Jerry1964

    Jerry1964 Private E-2

    Hello,

    The name of the thread may not sound like I should be using this forum but I'm concerned that my computer may have been hijacked although I'm not able to find the "culprit." Both the Network Connection for Internet and Local Area Network icons in the Notification Area show a continuous blue condition with only an occasional blink to "unlit" status. Checking the "status" of the connection using a right click, shows that there is a continuous uplink/downlink underway. I have gone through the procedures listed for Malware removal and was able to run four of the five listed. Root Repeal would not run as I always got an error when attempting to scan.

    I have attached the logs for the removal/testing applications.

    Thanks,
    Jerry.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well I will check through your logs and if there is no malware present you will have to visit the software forum/networking forum.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seeing alot to do here in the malware removal forum except some miscellaneous items to take care of. Any problems that remain will have to be worked out in the software/networking forum.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    • O15 - Trusted Zone: http://*.hp.com (HKLM)
    • O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -

    After clicking Fix exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\WINDOWS\Temp
    • C:\Documents and Settings\Jerry\Local Settings\TEMP
    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  4. Jerry1964

    Jerry1964 Private E-2

    Thank you very much Kestrel13!

    I plan to get to this during the upcoming long weekend.

    Thanks again,
    Jerry1964
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Safe surfing.
     
  6. Jerry1964

    Jerry1964 Private E-2

    Hi Kestrel13!

    Well, I finally got through the procedure of using analyse.exe followed by the registry fix. The registry fix did NOT give me a successful indication. And, I'm still plagued by the continuous connection indication. Now, one thing I did do, was to save the registry fix to notepad prior to doing the analyse.exe. Do you think that would have an effect on my results? Also, I was a bit unclear as to whether I should restore my anti-virus/spyware prior to the registry fix. Would that have mattered?

    This computer is giving me fits as it is extremely slow and obviously has problems with shortcuts, which slows me down. I use Microsoft Security Essentials as my anti-virus and half the time, it won't launch, even when going to the program list at the start button.

    I have tried to un-install MSE and it won't. Is there an anti-virus tool that you recommend?


    Anyway, I plan to keep the cleanup tools for just awhile longer in case it is decided I need to do it all again. I don't mind really. I kind of enjoy the work.

    So, any comments will be appreciated.

    Have a great weekend and thanks again,
    Jerry.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  8. Jerry1964

    Jerry1964 Private E-2

    Hi Kestrel13!

    Thanks for the reply. I downloaded Your Uninstaller and I'm in the progress of downloading and updating the Kaspersky Online Scanner.

    Once I've done the uninstall and scan, I'll then need to replace MSSE with another anti-virus program. Is there one in particular that I should use in order to keep me virus free? I currently have both Super Anti-Spyware Professional and Malwarebytes paid edition running.

    I'll let you know when the scan completes.

    Have a great day,
    Jerry.
     
  9. Jerry1964

    Jerry1964 Private E-2

    Hello Kestrel13!

    Well the Kaspersky online scan revealed the following:

    Trojan-Dropper.Win32.Agent.bsvg (in two places)

    not-a-virus:RemoteAdmin.Win32.PsExec.b (in two places)

    It is strange that neither SuperAntispyware nor Malwarebytes found these.

    Up for suggestions here!

    Thanks,
    Jerry.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What locations did it find the threats in just out of interest?
     
  11. Jerry1964

    Jerry1964 Private E-2

    Hello Kestrel13!

    The locations were:

    C:\System Volume Information\_Restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP64\A0023489.EXE

    AND:

    G:\SEAGATE BACKUP DELL 4600\HISTORY\LEVEL2\C\DOCUMENTS AND SETTINGS\JERRY\DESKTOP\MGTOOLS.EXE

    These things referred to as "not-a-virus" by Kaspersky, were located at:

    G:\SEAGATE BACKUP DELL 4600\HISTORY\LEVEL2\C\DOCUMENTS AND SETTINGS\JERRY\DESKTOP\MGTOOLS.EXE

    AND:

    C:\DOCUMENTS AND SETTINGS\JERRY\UNZIPPED\PSTOOLS[1]PS EXEC.EXE


    So, I downloaded a 30 Day Trial of Kaspersky Internet Utilities (KSI) and ran it after a lengthy update. It located the above, removed one of the Trojan locations and found no file for the other one. After the complete scan, I did a search for the files and they are not there. Now, I would assume that the not-a-virus that was located on the G Drive was also deleted by KSI when it deleted the Trojan. I was going to go after the other not-a-virus but the computer locked up for some reason so I shut it down and went to bed. I had been fooling with this problem most of night before last and yesterday and I was bushed. So, this morning, I started the machine and it came up normally at first and then locked up. Presently it is off and I'm writing this from my laptop.

    So...That is where I stand at this moment. Computer is off and I'm awaiting further instructions.

    Thanks again. I now realize I inadvertently "bumped" my thread by telling you what Kaspersky had found and for that I am sorry. I'll try not to let that happen again. Guess I was a bit on the panicy side.

    Have a good day and hope to hear from you soon.

    Jerry.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just stuff trapped inside of system restore. After following my final steps it will no longer be detected.
    Obviously a false positive, as MGTools.exe is not malware ;)

    psexec.exe is a launch tool from sysinternals used to launch processes on
    remote machines for which you have appropriate permissions.

    I don't think you have malware problems.
    No, you're fine, it wasn't a bump per se.
     
  13. Jerry1964

    Jerry1964 Private E-2

    Thanks for the reply, Kestrel13!

    By final steps, I assume you are referring to the final steps in the first post of yours on the thread.?

    When I get the time, I'll get right to it and report back to you.

    I'm just wondering what the deal is with the Kaspersky Online Scanner finding the Trojan-Dropper and the same was found on the Kaspersky Internet Security 2011 program.?? (originally called Kaspersky Internet Utilities) Weird, I guess tiredness prevailed.

    Anyway, I'll get back to you as soon as possible.

    Jerry.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes just follow final steps and let me know how everything is.
     
  15. Jerry1964

    Jerry1964 Private E-2

    OK, thanks Kestrel13!

    I'm running another scan in safe mode at this time. It will only come up to a locked up state in normal boot.

    By the way, the Your Uninstaller program you wanted me to try would not un-install the MSE. MSE seems to be very entrenched in my computer and will not allow an un-install. The Your Uninstaller ran for hours to no avail. I think I need to go into the program files and uninstall the thing piece by piece. But, probably not really the best way to go about it. But, I do feel that MSE is the cause of alot of my troubles as it continually wants an update that will not install and come to find out, I'm using the latest version so I think it's totally corrupted.

    Any thoughts on what I need to do while in safe mode to possibly get me running again in normal would be very appreciated. It seems a System Restore might just get me back to where I started.

    Additionally, I am still VERY concerned about the continuous connection. Reading about the Trojan that I supposedly had doesn't make me feel comfortable at all about the safety of "things" on my computer.

    Anyway, thanks again. I really appreciate the time you've been spending with me!!

    Have a good evening,
    Jerry.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are very welcome, but I am afraid there isn't much else I can do for you here in the malware forum. You must at this point seek out further advice in the software section. :) Thanks.
     
  17. Jerry1964

    Jerry1964 Private E-2

    Hello Kestrel13!

    This morning I restarted out of Safe Mode and back into normal mode with no problem. I then did the System Restore cleanup and re-booted. It came up nicely and so I went in and established a new Restore Point. I had also gone through the cleanup of the other utilities I had downloaded. As I left for work things seemed to be working in good order. I still have not gone back in and tackled the MSE problems nor have I done any cleanout of the g and f drives. As you have suggested, if I have further problems I will contact the Software Forum folks. By the way, the Kaspersky Internet Security program seems to be a nice thing to have. I'll continue to evaluate it for the next 20 or so days and probably go ahead and buy it.

    I'd like to thank you for all that you have helped me with. Nice job!

    Have a good day,
    Jerry.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem ;) Safe surfing.
     
  19. Jerry1964

    Jerry1964 Private E-2

    Hello,

    Well, my continuous connection started up again so I did some searching with different anti-virus tools. Last night, Spyware Doctor found Trojan-Downloader.Bagle. This will apparently reload and start its nasty business every time the computer is re-booted.

    And, Oh By The Way, this thing will disable your anti-virus applications. Spyware Doctor seems to run OK though.

    Any suggestions would be appreciated.

    Thanks,
    Jerry.
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Start a new thread in the malware forum after running all of the scans. :)
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds