Hijacker virus. Windows XP.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Arcanum, Aug 26, 2010.

  1. Arcanum

    Arcanum Private E-2

    So says the title, I followed the initial stage of the Malware removal to the point of the XP Cleaning Procedure.

    So far...

    MGTools - Nothing wrong.
    Combofix - Snagged something in the root. Auto-restarted the computer.
    SuperAntiSpyware - Active. No virus detected.
    RootRepeal - Well, not sure, but it finished.

    The problem is with the last one, the MalwareBytes. It has error 440. Any tips on how to fix that?

    This virus wasn't present yesterday, and today, it's being a literal nail in my system. So far, I can't use Firefox Google, then Yahoo, then normal Google, Bing followed next, so did MSN. This applies to both Firefox and Internet Explorer. I've noted it goes through bits like Redirect Clickshield and 154Clicks, and sends me to all sorts of useless crack. The worst possible being when it redirects me to some "antivirus in progress" page, where I terminate the system from Task Manager instead.

    I only use Windows Firewall and AVG Free 8.5.

    P.S.: Where do I get the SuperAntiSpyware Log? Well, I got a substitute direct from the log.

    Apologies if I did something wrong. I'm new to these forums.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you have a problem automatically installing the update due to no internet connection or other reason, you can manually download and install the update from here: Malwarebytes' Anti-Malware Database

    Also run this:

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Attach the two logs.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Fcopy::
    C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\explorer.exe | C:\WINDOWS\explorer.exe
    C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\winlogon.exe | c:\windows\system32\winlogon.exe
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Double click MGTools.exe again, this time when the option to agree to the Trend Micro Hijackthis license crops up, click "accept" you will have to click accept twice, it's a bug.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from TDSSKiller and the MBAM log.
     
  4. Arcanum

    Arcanum Private E-2

    Got the MalwareBytes to work properly now. Installed and ran TDSSKiller.

    So far...

    MalwareBytes - Clean.
    TDSSKiller - Clean.

    Log for TDSS Killer:

    Will update with new ComboFix log after acquired.
     

    Attached Files:

    Last edited by a moderator: Aug 26, 2010
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do not post logs inline like you are doing. It causes general forum clutter and makes a post hard to read. :)

    Simply attach the C:\Mglogs.zip after running combofix and the GetLogs.bat.
     
  6. Arcanum

    Arcanum Private E-2

    This is the one for the second Combofix run.

    The bugger is still in my system. I test by running Google to Wikipedia.

    EDIT:

    Apologies, but I was kind of lost looking for some of the logs. Well, I did find the TDSSKiller Log though.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    as stated.
     
  8. Arcanum

    Arcanum Private E-2

    Erm. Minor issue. It won't let me upload the MgLogs.zip, says I already uploaded it. Unless you mean use MGTools again then get a new log.

    As for the GetLogs.bat, where do I find that?

    Apologies if I am causing trouble, I'm not exactly good with directions.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, don't apologise, it was my fault, just do this then:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this
     
  10. Arcanum

    Arcanum Private E-2

    New MgLogs.zip acquired. Uploading now.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Bear with me, I have not forgotton you, I am having to seek advice and assistance from Chaslang regarding your issues.
     
  12. Arcanum

    Arcanum Private E-2

    No worries. I'm used to my string of bad luck. Exceptionally bad luck. If I get something good, something bad immediately follows. I even have a recollection of all those events. Though this is the only time I've had a computer virus try to make my life miserable.

    P.S.: If I'm not wrong, this might be sheer coincidence, but I trying to install the MalwareBytes yesterday which I downloaded from the author's site caused a neighborhood blackout. Either coincidence, or just my bad luck again.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't feel blue. :) Chaslang will guide us through this. Just sit tight.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run combofix by double clicking it's file and then attach the C:\combofix.txt.

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread
     
  15. Arcanum

    Arcanum Private E-2

    Tests were done. Logs are up.

    I re-tested the Google to Wikipedia, it worked.
    But being the paranoid guy I am, I tried it with some other sites.
    Sites that I have been to occasionally work.
    But sites I have not been to do not.

    This only applies to Google. Bing, MSN, Yahoo, and pretty much every other search engine I tried were still botched in the head.
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you try to update from Service Pack 2 to Service Pack 3, and had some troubles with it??
    I do not know what you mean by this statement.
     
  17. Arcanum

    Arcanum Private E-2

    Err... What is Service Pack?
    If you meant updating anything. No, not really.

    By the way, my automatic updates picked up something called: "Windows Malicious Software Removal Tool - August 2010 (KB890830)"
    I don't trust it. I know there are malware that use the Automatic Updates to hack their way in. Can I confirm if this is safe?

    By the statement. It means that while Google is able to connect me to pages I have been before. But using other search engines like Bing and Yahoo still redirect me to useless ads.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    See this ;)

    You have Service Pack 2, yet we are seeing signs of files from service pack 3, which lead us to ask you about it. We are trying to find out why, perhaps you started to install SP3 but it crapped out part way through or something?
    And why not? :confused

     
  19. Arcanum

    Arcanum Private E-2

    With regards to the Service Pack issue. I'm not sure. So far whatever extra-techy bits we've handled, I've noted no error issues to date.

    So, I'll take it the Malware Removal Tool is 100% safe?

    As for the not trusting part. Considering how paranoid I am, better safe than sorry to confirm first. I've seen enough bad things happen to go paranoid as I am currently.
     
  20. Arcanum

    Arcanum Private E-2

    Sorry if this is what you call "bumping". But I felt it would be best to put it up.
    The Service Pack is Service Pack 2. I just confirmed because my updater just picked up Service Pack 3, after installing the Malware Removal Tool.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Does this mean you installed SP3 or did you just get a notification from Windows Update, that it is available?
     
  22. Arcanum

    Arcanum Private E-2

    I have not installed SP3 yet, and yes, I just got a notice that there is an SP3 to upgrade to.

    Google, Bing, and Yahoo seem to be working currently, but I'm still paranoid whether they are "okay" to use again. I will re-confirm whether they are safe for use the next time I turn on the computer.
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      winlogon.exe
      explorer.exe
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    Now go to VirusTotal and upload the following files for analysis, report back to me the results.

    • C:\WINDOWS\system32\winlogon.exe
    • C:\WINDOWS\explorer.exe
    Run this:

    Using ESET's Online Scanner

    Attach the ESETScan.txt to your next reply.

    Now download and save this XPsp3bu.exe to your C:\ root folder. You must do this properly. Now run the XPsp2bu.exe program by double clicking on it. You may or may not notice a quick flash of a black window. This is normal. The program runs quickly and just extracts some files we need.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Also attach logs from running SystemLook, post the VirusTotal results, and attach the ESET log,
     
  24. Arcanum

    Arcanum Private E-2

    I've installed SP3. Retested the Google to various sites, all except one time was successful. One time the Firefox crashed when I hit enter after typing in something, the other 8+ or so tries show no abnormalities.

    I'm guessing the virus has gone dormant for now.

    Here are the files requested.

    VirusTotal results:
    The ESET Scanner was effective. Detected around 15 trojans.

    P.S.: What's the XPsp3bu.exe for? Just curious.
     

    Attached Files:

  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It enables us to replace infected files with valid ones that are appropriate for the SP that you are using, which is SP3

    Run Combofix again by double clicking it's icon and attach the resulting C:\combofix.txt
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before running Combo, do this, I made an error:

    Download and save this XPsp2bu.exe to your C:\ root folder. You must do this properly. Now run the XPsp2bu.exe program by double clicking on it. You may or may not notice a quick flash of a black window. This is normal. The program runs quickly and just extracts some files we need.
     
  27. Arcanum

    Arcanum Private E-2

    I read the ComboFix log before sending, it looks clean. Well, I'm not tech-savvy so my opinion probably doesn't count. But I didn't find anything along the lines of "infected".

    Ran another test to see if the search engines are working. Successful.

    Overall, it runs like it used to before the whole incident.
     

    Attached Files:

  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm, give me some time to think (and sleep LOL) We have to discuss something regarding the infection.
     
  29. Arcanum

    Arcanum Private E-2

    Sure, go ahead.

    I take it this is not over yet, and we should still assume the infection is still around.

    Odd fact. Remember that thing I said about bad luck? Whatever results from it usually gets rectified by the end of the period if it's a holiday. Fact, this incident started the day I got a 5 day holiday all the way until Tuesday. Second fact, the thing seems back to normal now, and it IS Tuesday here. Coincidence?
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay, Chaslang sugests that you reboot your computer a few times. Your logs are looking good, but we do wish to see another combofix log from you, so after rebooting a couple, three times, please re-run ComboFix by double clicking it, and attach the resulting log for our reviewal.
     
  31. Arcanum

    Arcanum Private E-2

    Okay, three times I've rebooted, let's hope it is for better, properly terminated.

    P.S.: What do these Trojans do?

    Win32/Batimal.DX
    Win32/Batimal.DZ
    Win32/Genetik
     

    Attached Files:

  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Looking good, but I am waiting on Chaslang's final say so, see what he thinks.

    It likes to infect valid windows files, making sure that finding a replacement for them is hard.
     
  33. Arcanum

    Arcanum Private E-2

    Okay, so what precautions should I take from now on to ensure the bugger don't come back? Other than running AV scans every once in a while.

    I'm definitely keeping the ESET Scanner around, it's the most effective at hunting Trojans so far. AVG deals with my tracking cookie issues. Anything else I should note?
     
  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sit tight for now, I have to go to work soon, I want Chaslang's thoughts before I give you final steps.
     
  35. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So tell me how things are running because I believe we can wrap up soon ;)
     
  36. Arcanum

    Arcanum Private E-2

    Probably a bit late to start saying, but I'll do so anyway.

    More or less, the system is running normally. I have not noted any abnormalities so far. Antivirus programs are run pretty much all the time now.

    Other than that, on an unrelated note. The follow-up event to the computer virus is that my LAN connection has decided to conveniently break down in time for my mid-semester break. Fortunately, I have a broadband connection on the side. The only downside is that only one computer can use the internet at a time.
     
  37. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well any remaining issues can be resolved in another forum here at Majorgeeks. For now, in the malware forum, we are done! :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds