Infected with XP Internet Security 2012

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mlydell, Jan 10, 2012.

  1. mlydell

    mlydell Private First Class

    My main computer was infected with XP Internet Security 2012, and when I went through the cleaning steps it looked like there were some other goodies found as well.

    So far it seems to be running better, but I'm a little concerned with what was found by Root Repeal - it said there were several sector mismatches and some MBR infections. I don't know what the next step is, so I'm attaching all the logs.

    I was running AVG Free , and per your instructions I uninstalled that program before running ComboFix. When I ran the uninstaller program it generated a log, but it's too large to post here. Let me know if you need that information.

    When I ran ComboFix, it said there was a rootkit virus - I believe zero.access was the name. It said I may need to run ComboFix a couple times, which I did which is why there are two logs attached to my second post.

    Thanks in advance!! I'll also be cleaning my other computer on the home network, and posting those logs to make sure nothing went across the network into my other computer.
     
  2. mlydell

    mlydell Private First Class

    Additional logs attached.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach all the logs we asked for. You owe us logs from the below tools
    • SUPERAntiSpyware
    • Malwarebytes
    • RootRepeal
    • MGtools
     
  4. mlydell

    mlydell Private First Class

    I had them attached to my first post - I must have forgot to click on the correct button - sorry!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are way out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.


    Now goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also uninstall the below:

    Registry Clean Pro
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    More instructions after completing my previous to messages.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. mlydell

    mlydell Private First Class

    Additional scans run - logs attached.

    The computer seems to be running fine, but it's only been a few minutes. Internet connection is up, and programs seem to be starting normally.

    Per your instructions I uninstalled Registry Clean Pro - is there a utility you recommend that will do a registry clean? I don't know if it's worth messing around with the registry so I try to leave it alone.

    Please advise the next steps!
     

    Attached Files:

    Last edited: Jan 11, 2012
  9. mlydell

    mlydell Private First Class

    Just noticed that my Adobe programs have gone missing Photoshop, Lightroom are both gone. Is this something the virus could have done?

    I'm trying not use the computer much while I wait for your review of the latest logs, but it's my work computer and I have to get some work on it done.

    I'm holding off on reinstalling these programs until I see if there are any further steps that need to be taken.

    Thanks!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We strongly recommend not using registry cleaners unless you are doing it under the guidance of an expert and selectively removing only things that need to be removed to fix some problem.

    According to your logs, Adobe is installed. I see the files folders and registry info. Nothing for Adobe was removed by the cleaning process. Whether you infection some how impacted it, I cannot say. What problem are you having?
     
  11. mlydell

    mlydell Private First Class

    The problem is that Adobe Photoshop and Adobe Lightroom are gone. Missing. No longer there.

    The only thing I ran was an uninstaller for Adobe Acrobat, so I'm wondering if somehow it uninstalled all my Adobe programs, because it didn't run correctly. It only partially uninstalled Acrobat, so now I can't install the newer version I was trying to install.

    Also - I posted new logs from your last message. Was there any other steps I need to take or are the logs clean?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They still show in your Uninstall Programs list. Are you sure it is just no a matter that the folders/files are hidden?

    Please download and save the below tool from Grinler @ bleepingcomputer to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Now see if you can find the Adobe items. If not, you may have to reinstall.


    Your logs were clean. I was just waiting to see what is going on with Adobe before giving any final instructions.
     
  13. mlydell

    mlydell Private First Class

    Sorry I didn't respond sooner - I was out of town.

    I ran unhide, and it didn't bring them back. I had already looked to see if there were any hidden folders when I was trying to see what happened to my programs.

    Yeah - it's weird they are in the install/uninstall list - I don't know why they are still there. All I can think of is the adobe acrobat uninstaller that didn't run right must have been a corrupted file and deleted all adobe folders....

    I also checked and the folders for these programs are in my Application Data folders, so that means at least my settings and configuration files for these programs are saved. I bet I should back those up somewhere.

    So do you recommend I just install the programs again or do I need to backup/delete the files in the Application Data folder? Do I need to make any changes in the registry?

    This is probably a dumb question - would it do any good to go back to a system restore point or would that undo what we just did in the cleaning process?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If they are really missing then you will have to reinstall them. System Restore is not a backup program. It only save certain registry keys and files. It does not save everything. If your problem is related only to registry items being gone ( which does not seem to be your problem ) then a restore may or may not help. You are saying files are missing. Thus I doubt a restore would help. And yes it could restore infections.
     
  15. mlydell

    mlydell Private First Class

    That's what I thought.

    OK - I didn't think I could use System Restore, but wanted to ask.

    I'll reinstall the programs, but you said you were waiting to find out about the missing programs "before giving final instructions." I want to finish everything you had for me to do before I install additional programs.

    Does that mean my computer is clean? What is left for me to do?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  17. mlydell

    mlydell Private First Class

    I uninstalled ComboFix and MGTools.


    I restarted my system, to check everything before toggling System REstore and the computer took a long time to restart, and when it did the screen flashed black a few times before fully starting up and now it seems slow and unresponsive. My cooling fan is also running higher than normal, and it sounds like the hard drive is thrashing.

    I'm wondering if something happened when the Adobe uninstaller crashed.

    I wanted to get your thoughts before I toggled system restore.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not related to the last steps taken. All those steps did were to remove file and settings we used during malware removal. No major changes were made. In fact, the changes were even less than minor. ;)

    This I cannot answer.

    You can hold off on removing restore points just incase you need to try one to fix problems you are having. Just remember that if you do use a restore point and if it is one containing any of the infections, you could restore the infection and it will have to be removed again from square one.
     
  19. mlydell

    mlydell Private First Class

    Since Adobe Acrobat Pro is partially uninstalled and my other Adobe programs are missing, but the Application Data and Local Settings folders for them still exist, is there a program you can recommend that would remove all traces of Adobe Products from my computer and registry so I could do a clean install?

    And I just discovered a wonderful (NOT) surprise...

    I was going to use Revo Uninstaller to see if it would remove traces of Acrobat, Photoshop and Lightroom before I reinstalled. I went to set a restore point before I did all that, and I found that my System Restore had been turned off! I have absolutely no idea how that happened...I know it was working just before I started cleaning my computer as I used it before I installed a couple drivers.

    So I guess I don't need to worry about toggling system restore since it's off! Something turned it off and I have no idea what it is that could have done that. Do some of the virus programs out there have a way to turn it off?
     
    Last edited: Jan 18, 2012

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds