I really need some help please from suspected Malware/Repeated intrusion attempts

Discussion in 'Malware Help (A Specialist Will Reply)' started by Carla15, Dec 21, 2013.

  1. Carla15

    Carla15 Private E-2

    Hi there, I wonder if someone could please help with a problem I am having with Windows 7.

    I posted my initial problem in another forum; here is the background;

    SYSTEM

    - Windows 7 64bit Home Premium edition (Up to date).
    - Norton 360 (Up to date).
    - 8GB memory
    - Intel Core i7 processor.

    Everything was stable and running well until only recently.

    I have recently experienced repeated intrusion attempts, most of which seemed to have been successfully prevented by Norton, and I have also been receiving multiple zipped-up trojans each day via email (but these are always detected and quarantined with Norton). I called Norton tech support, and they assured me that Norton should be protecting me fine, that they could see no problems, and that the Norton software would let me know if there were. However, ever since these attacks begun, I have experienced the following problems with Windows 7.

    - After start-up, sometimes only the task bar icons are active, and sometimes only the desktop icons are active. However, every now and then they both work at the same time, or are both frozen. This problem also reoccurs regularly while trying to use the PC; icons freezing, taskbar freezing, links freezing.

    - Desktop icons have moved location and have become randomised. They can no longer be dropped, dragged or moved, and are permanently fixed. I tried changing this in the options, but the problem remains.

    - Sometimes after opening a folder and/or a browser (Firefox or IE), for example, the folder window/browser freezes, and you cannot select anything within. Sometimes it unfreezes, but I have no idea why. Sometimes when you minimise/re-maximise the window it works again. Pressing Ctrl, Alt and Delete, and then closing some unused processes seems to temporarily unfreeze anything that is frozen.

    - Drop down menus on web pages; you can click the arrow to expand the list, but you need to use the cursor keys/enter to scroll/select, the mouse won't work.

    - Dragging and dropping files no longer works; either folder-to-folder, or straight into a related program. You can only open a file via navigating.

    - The middle mouse wheel is permanently disabled from scrolling down web pages.

    - Discovered that by ending all of the 'Processes by all users' that are not needed seems to temporarily fix the problem/lessons it, but then it reoccurs, and I have to repeat the process.

    - No apparent performance issues when working/unfrozen.

    - In Safe mode the problems still occur.

    - Currently I can use my computer, and it seems secure, but I repeatedly experience the problems above which is frustrating.

    Norton scans and Malwarebytes scans find nothing. However, looking at the Norton security history has been strange, and a couple of entries seem to have changed from an initial 'High' level of security risk to 'Info' and 'no action required'. The entries in question appeared to be network attempt related, so i blocked communication with this IP. I had also recently downloaded the evaluation copy of Malwarebytes anti-malware software, and I noticed the problems actually spiked after I had installed it. After the scan I uninstalled it, and then the Windows problems seemed to become less severe/less frequent, but unfortunately still an issue. The desktop icons moved to the new position automatically after uninstalling the program. Changing the desktop theme also doesn't affect the icon locations, but the background changes fine.

    I was thinking of applying the last System Restore point, however, when I went to do this it said that no restore points had been created, and if i wanted to create one. I don't remember creating a system restore point, maybe once, however, I am certain I have run various scans in the past that had auto backed up with the system restore, and I was expecting to find these.

    I was wondering if there is a way that I can look for/fix just the damaged Windows components, if that is what it is causing the problem?

    Re-installing Windows from scratch is not a realistic option, I have many programs/plug-ins installed that would take an eternity to re-install and re-configure (around 3 weeks).

    I have just performed a clean start-up, but the exact problem remained, so I assume the problem is within the core windows services, as opposed to a background program?

    I was advised to re-install just the Windows 7 OS, but beforehand, I downloaded and ran all the scans as advised here http://forums.majorgeeks.com/showthread.php?t=35407

    Unfortunately I cannot appear to attach the requested scan logs, as the icons are greyed out. Perhaps a related problem. Although I am sure that the scans found something. Is it ok to post the scan log results as copy?

    Any help would be much appreciated, and I have had constant intrusion attempts for 5 days now :(

    Kind regards
    Carla
    x
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :)

    Have you tried using different browser(s) to attach the logs?
     
  3. Carla15

    Carla15 Private E-2

    Hi Kestrel13!

    Thank you for your reply.

    I really need some help, especially as my second computer is now experiencing the same problems; frequent intruder attempts, security settings changing by themselves, Firewall rules creating themselves, a User folder called 'Default User' where accessibility is blocked for 'Everyone', IE security settings changing from the highest setting to 'Custom' by itself, one folder called 'DVD Maker', not an installation, just data, but located in my Program Files and needs permission from 'Trusted Installer' for access - i tried to uninstall with Revo Pro, even tried a forced uninstall in Safe mode/clean boot but still it remains, 'Documents and Settings' became inaccessible for Administrators (I managed to change this), 8 folders found in 'Users'; Me, All Users, Default, Default User, Public, TEMP, TEMP.PC_NAME, UpdatusUser, recycle bin is blocked and I keep having to manually close processes/services in Windows Task Manager under 'All Users' as i am unsure where exactly the malware is located...multiple problems etc. :(

    The System specs for the 2nd PC are the same as the main PC, albeit with a little less powerful hardware, and a slightly older version of Norton.

    Thanx for your advice, I have installed the most recent version of Firefox, and will attach the scan results of both PC's.

    Kind regards
    Carla
    x
     

    Attached Files:

  4. Carla15

    Carla15 Private E-2

    Hi Kestrel13!

    Thank you for your reply. I am not sure if my initial reply/upload was saved, as I cannot see it. Could you please let me know if I need to upload the scan logs for PC1 again?

    I really need some help, especially as my second computer is now experiencing the same problems; frequent intruder attempts, security settings changing by themselves, Firewall rules creating themselves, a User folder called 'Default User' where accessibility is blocked for 'Everyone', IE security settings changing from the highest setting to 'Custom' by itself, one folder called 'DVD Maker', not an installation, just data, but located in my Program Files and needs permission from 'Trusted Installer' for access - i tried to uninstall with Revo Pro, even tried a forced uninstall in Safe mode/clean boot but still it remains, 'Documents and Settings' became inaccessible for Administrators (I managed to change this), 8 folders found in 'Users'; Me, All Users, Default, Default User, Public, TEMP, TEMP.PC_NAME, UpdatusUser, recycle bin is blocked and I keep having to manually close processes/services in Windows Task Manager under 'All Users' as i am unsure where exactly the malware is located...multiple problems etc. :(

    The System specs for the 2nd PC are the same as the main PC, albeit with a little less powerful hardware, and a slightly older version of Norton.

    Kind regards
    Carla
    x
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman Pro and have it delete Potential Unwanted Programs.



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Users\Aerial\AppData\Roaming\die.bat
    C:\Users\Aerial\AppData\Roaming\inst.exe 
    C:\AI_RecycleBin
    
    :reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  7. Carla15

    Carla15 Private E-2

    Hi Kestrel13!

    Thank you for your reply, and my apologies, I didn't realise the forum thread rules :)

    Ok I shall run through the steps shortly.

    Cheers again friend,

    Kind regards
    Carla
    x
     
  8. Carla15

    Carla15 Private E-2

    Hi Kestrel13!

    Just to confirm that I have now completed the steps as advised.

    Please see the additionally requested scan logs attached.

    Here is the latest:

    - My system still freezes, desktop icons, browsers etc.
    - Am still receiving intrusion attempts, seemingly detected by Norton 360 which lists them as Intrusion Prevention Engine started etc. and zipped up trojans via email. These emails sometimes seem to be coming from my own domain email address.
    - I still have a suspiciously large number of Users, some of which are inaccessible.
    - The DVD Maker folder in Program Files is still un-deletable, however, the permissions for 'TrustedInstaller' seems to have changed from All access to 'List Folder contents' only. Although I still can't change the permissions. I have also noticed in Task Manager that sometimes a process by 'TrustedInstaller' starts under All users called Windows Module Installer.
    - I have uninstalled several programs that had suddenly stopped working.
    - New processes that I haven't seen before occasionally activate themselves. I am manually closing everything I don't recognise that isn't essential to the system.
    - One of the most common things I am seeing in Norton 360 history is:

    Rule rejected UDP(17)
    traffic with (192.168.0.1)
    Port(2048)

    Kind regards
    Carla
    x
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Further elaborate please. I don't know what you mean.
    Such as which? Let me know.

    Everything else you mentioned, including the spam, can be discussed in the software forum. What email program are you using?
     
  10. Carla15

    Carla15 Private E-2

    Hi Kestrel13!

    Both my computers have identical OS's installed, Windows 7 64bit.

    When I look at my second PC at the following location, C:\Users there are only 3 folders within; 'My Username', 'Administrators' and 'Public'.

    However, at the same location on my main PC (the one with the more severe problems) there are now 8 folders, and there never used to be. As the OS is the same on both PC's, I was expecting to find the same number of folders at this location.

    I can confirm that on both PC's only one User account has ever been created by me.

    The 8 folders within C:\Users are:

    My Username, (I can access this folder as administrator).
    All Users (I can access this folder as administrator).
    Default (I can access this folder as administrator).
    Default User (I CANNOT access this folder as administrator, blocked for a user group or name called 'Everyone' denying access to all Users. - I have never created this user name or group).
    Public (I can access this folder as administrator).
    TEMP (I can access this folder as administrator).
    TEMP.PC_NAME (I can access this folder as administrator).
    UpdatusUser ( I have no idea what this folder is for. Initially I didn't have access, but managed to change the permissions. It contains an 'AppData' folder and lots of shortcuts to places such as 'My Documents', 'Favourites' and 'Searches'. It also contains NTUSER.DAT, ntuser.dat.LOG1, and lots of .regtrans-ms files with names such as NTUSER.DAT{2b0a965a-f078-11e2-91a4-4061867a63ca}.TMContainer00000000000000000001.regtrans-ms

    Also, whenever my computer freezes, I can click Ctrl, Alt and Delete to bring up the Task Manager, and then my PC seems to un-freeze. However, if I try to access Task Manager via right clicking on the Task Bar, Task Manager often crashes. I have had several random crashes over the last few days also (freezing to the point where the only solution is powering down).

    Well I tend to manually close down any unnecessary processes to try to increase free memory, and am quite familiar with the processes and services I should see. The only software I have installed since these attacks began are the malware related scanning programs, which I can see in Task Manager.

    If I go to Task Manager --> Show processes from all users --> There have been some unfamiliar processes appearing e.g. One I can see is called 'Windows Module Installer' and the User name next to it is 'Trusted Installer', which is also the user name/user group that has sole permissions over that DVD Maker folder I can't delete. It seems strange as I have never even created this User account. Another process that kept popping up automatically for the last few days was Microsoft Volume Shadow service. This process only began appearing after the problems and I don't know what it is for. This particular process hasn't appeared for a day or so now though. One other process that kept appearing yesterday was Virtual Disc Service, again I am unfamiliar with it and therefore suspicious, of course it is possible that I am just being a little paranoid with everything that is going on.

    Email program; I am using Windows Live Mail, configured to receive emails via my own domain .co.uk email address.

    Kind regards and Merry Xmas,
    Carla
    x
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Carla.

    Everything that you mentioned there is indeed subject for the software forum. None of what you mentioned sounds suspicious but do go ahead and post in the other section if necessary.

    Merry Christmas. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     
  12. Carla15

    Carla15 Private E-2

    Things have improved :) Thank you for all your help Kestrel13!

    Wishing you a very Merry Christmas and a Happy New Year =)

    Carla
    x
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Merry Christmas Carla! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds