Infected: Pyordono.a, Zpevdo.a, Obfuscator

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Lydster, Jul 3, 2018.

  1. Lydster

    Lydster Private First Class

    Hello. Not sure how we got these, but Windows Defender messages started to come up saying that the subject malware was detected and quarantined. However, when I quickly installed MBAM to see if any remnants might be left, the MBAM real-time monitoring kept popping up saying that website after website was trying to be opened by the computer browser. So, it appears that WD may not have actually eradicated these.

    I ran the RUN ME FIRST steps, and these logs are attached: AdwareCleaner, HitmanPro, Mbam, RogueKiller, as well as MGlogs.

    As far as current behavior, I disconnected the computer from the internet to stop the MBAM notices that websites were attempting to launch; so it's not clear to me exactly what the computer would be doing right now if I re-connected it.

    Many thanks for your help.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please rerun RogueKiller and remove this item:
    ¤¤¤ Tasks : 1 ¤¤¤
    [Suspicious.Path] \Update -- "C:\Users\Alexander_Marbach\AppData\Local\Comms\\upaworsch.exe" (/i) -> Found

    Reboot, reconnect and rerun RogueKiller and attach a new log. Be sure to tell me if further activity is reported by MBAM and if so...attach a log.
     
  3. Lydster

    Lydster Private First Class

    Thanks TimW. Attached is the new RK log. MBAM isn't popping up messages about any webpages trying to load. I then ran an MBAM scan, and no threats were found. So, is it really possible that RK was all that was necessary to get rid of all the malware WD detected? If so, Wow! :)
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yup!! :)
    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Re-enable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  5. Lydster

    Lydster Private First Class

    You're the best. Many thanks!
     
  6. Lydster

    Lydster Private First Class

    Oops - spoke too soon (?) I just received more Windows Defender messages, which I figured were the old notifications that need to be cleared, but there is a new one dated today - Fuerboos.A!cl. I'm wondering if this was found earlier, before your RK removal instructions, but I don't see a time notation in WD history. Any thoughts?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun RogueKiller and attach a new log. :(

    Also what browser are you using?
     
  8. Lydster

    Lydster Private First Class

    Attached is rklog from this morning. When I turned the computer on, WD did show another message dated today about Fuerboos.A!cl still being detected. MBAM doesn't seem to be noticing anything, and I don't think the computer is doing anything weird; then again, I'm not really using it much right now. I use both IE and Chrome on this computer -- probably mostly Chrome. Thanks!
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am now pretty certain that it is a false positive. Does WD give you a full path to the file in question? If so, please upload it to http://www.virustotal.com
     
  10. Lydster

    Lydster Private First Class

    Yes, there is a path shown in the WD message, but when I go there, even with all files/folders unhidden (incl protected system files), I don't see the file that the path is referencing. Here's the message from WD:

    Trojan:Win32/Fuerboos.A!cl
    Alert level: Severe
    Status: Quarantined
    Date: 7/4/2018
    Recommended action: Remove threat now.
    Category: Trojan
    Details: This program is dangerous and executes commands from an attacker.
    Affected Items:
    file: C:\Users\**USER NAME**\AppData\Local\Comms\upaworsch.exe
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is the file....( replace **user name** with YOUR user account name).

    Don't just type in the file in Jotti ...you need to "find" the file and upload the actual file.
     
  12. Lydster

    Lydster Private First Class

    Sorry, should have been more clear. Yes, I know what the user name is, and I am using the actual user name path (what I did was type in a placeholder for the user name before posting here). When I go to the actual path, the upaworsch.exe file is not actually there. (I do have all files and folders set as un-hidden.) I also did a search for the file at the AppData level, and it was not found anywhere.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't use Windows defender so I am not sure how to white list it. But there is absolutely no info on the web about upaworsch.exe. So you will need:
    • "Go to Start > Settings > Updates & Security > Windows Security > Virus & threat protection > Virus & threat protection settings > Add or remove exclusions.
    • Under Add an exclusion, select the files, folders, file types, or process. The exclusion will apply to subfolders within a folder as well."
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds