Deskktop Security Still

Discussion in 'Malware Help (A Specialist Will Reply)' started by dkgoodwin, Mar 3, 2010.

  1. dkgoodwin

    dkgoodwin Private First Class

    While browsing images in google, I got the*'Enable*Security" popup. Didn't click on it but

    it*downloaded anyway. ZoneAlarm is my AV. Didn't not use it to scan because it didn't see the

    problem until minutes after I had recognized it.

    Tried to run TrendMicro*online scan, wouldn't run. Turned off System restore. Ran CCleaner

    Downloaded Malwarebytes and SuperAntiSpyware.

    Ran Malware quick scan and then deep scan. Files found and deleted. On restart bug screens

    launched again.

    Ran superantispyware. Found infections, deleted. Restarted computer.
    Ran*online Kaspersky scan, infections found. Deleted, restart computer. No bug screens.

    Redownloaded and on reinstall of ZA, bug screens re-appear. Stopped ZA install and deleted

    installer. Downloaded and installed*BitDefender. Ran rkill, which reported stopping about 6 items

    (see uploaded report).

    Ran malwarebytes again. Infection found. Deleted. (Deleted recycle bin items also) Bug screens

    continue to appear.

    Ran Combofix; during run, bug screens disappeared. On restart, bug screens appear again.

    Malwarebytes stopped functioning. Uninstalled, ran mbam cleaner, reinstalled mbam, ran deep

    scan, no infections found, bug screens continue.

    Ran Vundofix, no infections found.* (Deleted recycle bin items also) Bug screens continue to

    appear, Restart, run rkill, doesn't work. Now reporting stopping the rkill file.

    Ran Vundobegon.exe, reports no infections. Still infected.

    Ran combofix*again (report attached). Bug screens continue. (Combofix reports are showing the

    files named on bug screens.)

    Ran, deep malwarebytes scan in safemode, nothing found. Bug screens continue to appear.

    Ran rootkit repeal. Ran MGtools. Reports attached. See second post for remaining reports.
     

    Attached Files:

  2. dkgoodwin

    dkgoodwin Private First Class

    Desktop Security Still (part 2)

    Continuing with report attachments for previous thread. Screen shots available as well.

    Please help. Can't work until I get this resolved. Thank you for making your talents available here.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Bad thing to do. Contrary to what antivirus companies and some websites tell you, you should keep your restore points until your malware has been removed. You now may have remove the only chance of fixing your system if a problem occurs during the removal process and you may also have removed the ability to give yourself a quick fix by just restoring to the day before th problem began. Having even infected restore points is better than none at all. You will notice that our cleaning process does not have you disable system restore until your system has been verified to be clean.

    You need to attach the proper logs from SUPERAntiSpyware and Malwarebytes and since you ran them more than once, you will need to attach a few. Please attach the below specific log files:
    Code:
    "C:\Documents and Settings\Debra\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    Feb 28 2010         685  "SUPERAntiSpyware Scan Log - 02-28-2010 - 10-34-19.log"
    Feb 27 2010        1371  "SUPERAntiSpyware Scan Log - 02-27-2010 - 13-26-20.log"
    Feb 27 2010         962  "SUPERAntiSpyware Scan Log - 02-27-2010 - 23-51-24.log"
    
    "C:\Documents and Settings\Debra\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\"
    Mar  1 2010         898  "mbam-log-2010-03-01 (15-16-02).txt"
     
    C:\Documents and Settings\Debra\Desktop\mbam-log-2010-02-28 (20-00-15).txt
    I strongly advise you to cleanup your Desktop immediately. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    You did not put your PC into normal startup mode with MSconfig as requested in step 4 of the READ & RUN ME. You need to do this now.

    Before we can continue, I need an answer to the following. Are the below startup processes all valid and related to something you do with Citrix. They all look more like malware than anything else
     
  4. dkgoodwin

    dkgoodwin Private First Class

    Thank you for your reply. I will certainly apply your advice regarding my desktop items.
    Regarding the files you noted: Citrix is part of my work software. However, I checked with another person who does the same work I do and she does not have any of these files in her system. So I believe we can assume these are all part of the virus package. Uninstalling Citrix is fine as I can redownload the software from the company once the computer is free of infection.

    I am attaching the requested files. I have an external drive that was attached to the computer at the time of infection. Please advise what I might do to check it for infection.

    Superantispy logs attached to this message. Remaining logs next message.

    Thank you again.
     

    Attached Files:

  5. dkgoodwin

    dkgoodwin Private First Class

    Malware logs attached.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We will not uninstall it on purpose, but we will fix the things I was concerned about. If Citrix gets broken, then you can reinstall later when we are all finished with cleanup.

    Just run scans on it with your antivirus and with SUPERAntispyware and Malwarebytes.

    Please do the below while I prepare the rest of your fix which I have already started working on.

    Now download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the lsp5d.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move lsp5d.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have run what is in message # 6 before continuing with the below instructions.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [ApplicationWatson12.0.6413.1000] c:\program files\common files\microsoft shared\dw\watsondw2012.0.6413.1000.exe
    O4 - HKLM\..\Run: [SystemSystem] c:\program files\common files\microsoft shared\msinfo\oinfoveroffice.exe
    O4 - HKLM\..\Run: [SSLSDKBCONCENTR] c:\program files\citrix\ica client\resource\zh-tw\icalogonvdzlcn10.100.55836.exe
    O4 - HKLM\..\Run: [STATUIUICONCENTR] C:\program files\citrix\ica client\resource\zh-tw\icalogonvdzlcn10.100.55836.exe
    O4 - HKLM\..\Run: [dwtrig20DW2012.0.6413.1000] C:\program files\common files\microsoft shared\dw\watsondw2012.0.6413.1000.exe
    O4 - HKLM\..\Run: [visnasAnimation] c:\program files\common files\ahead\nas\nerovisnas.exe
    O4 - HKLM\..\Run: [ErrorDWIntl20] c:\program files\common files\microsoft shared\dw\1058\applicationdwintl2012.0.4518.1014.exe
    O4 - HKLM\..\Run: [QuickTimeResourcesQuickTime] c:\program files\quicktime\propertypanels\panelhelperbase.resources\zh_tw.lproj\quicktimequicktimeresources.exe
    O4 - HKLM\..\Run: [QuickTimeQuickTimeResources] C:\program files\quicktime\propertypanels\panelhelperbase.resources\zh_tw.lproj\quicktimequicktimeresources.exe
    O4 - HKLM\..\Run: [visnasNero] C:\program files\common files\ahead\nas\nerovisnas.exe
    O4 - HKLM\..\Run: [ReportingDWIntl20] C:\program files\common files\microsoft shared\dw\1058\applicationdwintl2012.0.4518.1014.exe
    O4 - HKLM\..\Run: [SystemInformation5.1.2600.0.0108171148] C:\program files\common files\microsoft shared\msinfo\oinfoveroffice.exe
    O4 - HKLM\..\RunServices: [Officemsinfo32] C:\program files\common files\microsoft shared\msinfo\oinfoveroffice.exe
    O4 - HKLM\..\RunServices: [CitrixNRTCPN] C:\program files\citrix\ica client\resource\zh-tw\icalogonvdzlcn10.100.55836.exe
    O4 - HKLM\..\RunServices: [StudioAnimation] C:\program files\common files\ahead\nas\nerovisnas.exe
    O4 - HKLM\..\RunServices: [QuickTimeQuickTimeResources] C:\program files\quicktime\propertypanels\panelhelperbase.resources\zh_tw.lproj\quicktimequicktimeresources.exe
    O4 - HKLM\..\RunServices: [SubscriberNetwork12.0.6413.1000] C:\program files\common files\microsoft shared\dw\watsondw2012.0.6413.1000.exe
    O4 - HKCU\..\Run: [1fsc01usdu83] C:\Documents and Settings\Debra\Local Settings\Temp\m.2F.tmp.exe

    After clicking Fix, exit HJT.



    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. dkgoodwin

    dkgoodwin Private First Class

    I have followed your in structions and attach the logs to this posting. A couple of notes for you, regarding mgtools/analyse.exe - all but two files listed were there the first
    O4 - HKLM\..\Run: [SystemInformation5.1.2600.0.0108171148] C:\program files\common files\microsoft shared\msinfo\oinfoveroffice.exe
    did not exist at all.
    O4 - HKCU\..\Run: [1fsc01usdu83] C:\Documents and Settings\Debra\Local Settings\Temp\m.2F.tmp.exe - existed with a slightly different file name which was m.239.tmp.exe.
    I selected this last file in place of the m.2F.tmp.exe - assuming this was a camiflouged version of the file you wanted.

    I proceeded with all instructions and with one exception the sequence went just as you anticipated.

    At combofix/CFscript - I got an error that windows had been shut down to prevent disk distruction. I left the screen for 30 minutes to allow for combofix to run in the case this was a false warning. However after that time I went ahead and restarted the computer and again applied the combofix/CFscript exe. This then proceeded as expected.

    I am more than happy to report no more bug screens, no more crackling and burning sound effects and no screen flickering.

    Per your further instructions I will run the scans on my external drive once you have given me the go ahead. And I will turn on my restore points as well.

    Just one other question, please. My acquaintances are speculating that this was a targeted hit. Does this infection give any signs that it might have been a specifically directed hit? If so, are there sniffers that can be employed to trace the source?

    Let me add my thanks to your many thank you's already received. I was hearing wipe hard drive sort of advice, which would have been far more costly in more lost work days and fees than I could have sustained.

    I wish you terrific rewards for the good work you do here, dkgoodwin
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps it is related to an infection that targets Citrix users. Not sure since it is the first I have seen like this.

    Not really and you would not have the time to learn the tools needed to do this and likely would not have the time either. Also in many cases, the people behind the infection are in countries where they are unreachable.

    Your logs are clean but just a security note, we don't recommend putting anything into the Trusted Zone like you are doing unless is absolutely necessary and it rarely is. I have never ever needed anything in the TZ. You have the below:
    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds