Help! Worst I've seen

Discussion in 'Malware Help (A Specialist Will Reply)' started by walker428, Mar 11, 2009.

  1. walker428

    walker428 Private E-2

    Ok working on my fiance's sisters computer, this time its the other sister. She had some serious issues going on with multiple variants of vundo a couple rootkits, browser hijacker and some droppers. Its really quit messy. I couldnt hardly boot up the machine, but I have it cleaned up as much as i can now. It took forever to be able even load up the microsoft update page. let alone get the computer to update spybot s and d. So with that I have already done considerable work and I can post some of the earlier logs if needed. But here are the most current logs.
    -Currently I keep getting an adaware watch warning that it is blocking "crt5.tmp (3680) from loading" it is triggering as a win32 downloaderinjector.

    -None of the spyware programs seem to adequately clear the memory of these problems I been having with each reboot the keep reloading. But at least I could finally update adaware, windows xp, spybot s and d, mabm, and superantispyware. previously they would be blocked or hijacked if in a browser.

    -most current logs follow
     

    Attached Files:

  2. walker428

    walker428 Private E-2

    -other current logs
     

    Attached Files:

    Last edited: Mar 11, 2009
  3. walker428

    walker428 Private E-2

    This was one of the original logs to see what was all on there before I could update windows, java, or any of the malware removal programs because it was blocked but should give you some idea of what was on here originally if that helps. THIS IS NOT THE MOST CURRENT LOG, see below


    Let me know if you need anything else

    and

    Thanks for your help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know why she was running this PC with no protection? No wonder it was so badly infected. And it may not be fixable since many of the Window Operating System files could be infected and it may be difficult to find clean replacement copies. At a minimum, the below files are infected:
    • C:\WINNT\explorer.exe
    • c:\WINNT\system32\ctfmon.exe
    • c:\winnt\system32\lsass.exe
    • c:\winnt\system32\svchost.exe
    • c:\winnt\system32\spoolsv.exe
    • C:\WINNT\system32\winlogon.exe
    • C:\WINNT\system32\dllcache\winlogon.exe
    Do you have Windows XP Home Edition SP3 on CD?

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Kazaa Media Desktop 2.1.1 <-- should have been uninstalled in step 1 of the READ ME
    Kazaa Media Desktop 2.5 <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O1 - Hosts: 195.245.119.131 browser-security.microsoft.com
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O4 - HKCU\..\Run: [system tool] C:\WINNT\sysguard.exe
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O23 - Service: Logical Disk Manager NDIS (dmserver) - Unknown owner - C:\Program Files\System\smss.exe (file missing)

    After clicking Fix, exit HJT.



    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )



    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Mar 13, 2009
  5. walker428

    walker428 Private E-2

    First off thank you for your help I will try to answer the questions the best that I can

    “Do you know why she was running this PC with no protection?”

    I don’t know why they didn’t have an up to date virus protection on the computer. It did have an old out of date version of Norton from 03’ that I have removed in preparation of installing CA on it for them. That is if I don’t need to do a full format and reinstall.

    “Do you have Windows XP Home Edition SP3 on CD”

    I currently only have a Home edition sp2 slipstream I created. but I have upgraded my xp home with sp3 and so I will need to make a new slipstream sp3 disc anyhow if I ever plan on restoring it, without wiping all my info, so. Yes that is doable.

    “Uninstall the below old versions of software….. Kazaa”

    I have tried to manually uninstall those files I think the uninstall file is corrupt I will search for a means to manually uninstall them. I cannot find this anywhere on the c:\ and I have deleted a few registry items still left over from it, but if you know of any other way to remove it or if it still shows on the coming scans please let me know.

    “Run C:\MGtools\analyse.exe by double clicking on it”
    “fix…. Exit hjt”

    done, no problems

    “open note pad and copy…. Kill all <cmd>” “run combofix using this script”

    done no problem

    “run cc cleaner”

    done, no problem

    “install new copy of MG tools, and run”

    Done, Rootkit activity detected, 2 reboots later I got error at very end, don’t know if it was related but I suspect it was. Error said application failed to initialize properly 0xc0000007b. After I closed that window and the log finished.

    My Ethernet was connected to the network, and while I was typing this out on the other computer to post spyware protect 2009 popped up. So I know I am not clean. Adaware live scan also noticed some kind of attack called banker fox.a to port 62657 of the machine. I have turned windows firewall on but usually these things have some kind of ways to bypass or turn these off.

    Let me know what the logs uncover, and if you have any more ideas. I am thinking I may need to backup their text, pictures, pdf files and the like and then just do a complete HD reformat and reinstall at this point. Unless you think there is anyway we may salvage it. If I do go this route what should I avoid saving, that may risk reinfestation if I move it over. Could anything follow the pictures, mp3s and pdf files over?

    Thanks for you help.
    Logs posted.
     

    Attached Files:

  6. walker428

    walker428 Private E-2

    Ok i found the attack detected was actually that spyware protect malware program. it was doing it even when not connected to the router. I have installed ca firewall and virus, and it did detect virtu.17408 infecting 4 key files that it couldnt clean till a reboot.

    -it was infecting winnt\system32\rundll32.exe (x2 one was in capital letters and on in lower case letters)

    -an it was infecting system32\svchoste.exe (x2 one in capital letters and one in lower case letters)

    I think it cleaned these and corrupted the files and made them unstable. upon reboot windows boots but when selecting a user it logs on and then quickly logs that user off to the user select screen again. even in safe mode. so looks like i will be slipstreaming that sp3 disc after all. to see if i can get back in to the desktop gui :cry

    please still let me know what the logs show, as if i get xp backusable i need to determine if backing up the pics, docs. and reformatting the hard disk will be the best method or if it is cleanable.

    thanks for all the help
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This will not help clean the system. You could potentially make it bootable again but it will still be very infected.

    The system requires a total clean reinstall after deleting partitions and then recreating them. There are many people getting infected by new forms of Virut, Virtub, Win32.Vitro....etc and basically what is happening is that ALL executable files on all hard disks, on network drives connected to the infected PC, and all removeable devices containing executable files will get the infection. Even the antivirus and antispyware programs will get infected. The safest and most reliable course of action is to reinstall. Even if we were to remove all infected items showing in the logs, this is only a small subset of the files on the PC. And it only one file remains on the PC with the infection, it will soon spread back to all executable files.

    The logs showed it was still infected. Note that you must be extremely careful on what is backed up as these new infections can get into many different file extensions ( DLL, EXE, SCR, HTM, HTML, MP3, AVI, WMV, PDF.....etc) Whatever you backup should be scanned from a clean properly protected PC before restoring. Also becareful what scanner is used as some are very poor at detecting and even worse at protecting from this infection. In fact due to the nature of these new infections, there are probably no tools that will properly protect you from the infection. Right now I would suggest doing scans of the backups with Avast! Home Edition and also Dr.Web CureIT
     
  8. walker428

    walker428 Private E-2

    Ok, thank you for your honesty. I will do what I can to back up the necessary items and scan them with a virus checker. I will discuss what has to be backed up and delete everything not essential. I am sure she would want to save financial information, and the like.

    I was aware that the vundo variants did try to spread on the network from shared drives. Do you think my computer would have been at risk if it was connected to a network via router at the same time as that computer too? I know i made sure I had a different work group name from the infected computer, and think i had my software firewall up most of the time, it was connected.

    I had a feeling that it was going to come to this, just by running the first scan and seeing what all had been infected. My original thought was reformat start from scratch but I was hoping to keep all of her information for her. I did end up making the sp3 slipstream disc an unattended version so at least it will come in use, once i delete all those partitions.:cool so at least i know i didnt waste all my time.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Vundo is insignificant compared to Virut, Virtub....etc. Vundo is easy to clean and rarely causes permanent damage. I doubt it spread to you other computer. No the other infections are a different story but odds are low that they spread if you were not sharing files and folders on the same work group.

    It never hurts to have a slipstreamed disk for all versions around.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds