Intrusion Attempt by HOMEOFFICE

Discussion in 'Malware Help (A Specialist Will Reply)' started by mprepunk, Aug 26, 2008.

  1. mprepunk

    mprepunk Private E-2

    Hello, I've recently been having problems with my PC. I have Windows XP with Service Pack 2 and was browsing the web last week. I closed Internet Explorer and after that couldn't open any applications. I restarted the computer but still could not open any applications. My Desktop still contained all of my icons, but was a blue colour.

    Since then I've booted my computer in Safe Mode and ran a defrag and disk cleanup. After that my computer would open applications in Normal Boot Mode, but I had to change a couple of Registry values in order to restore my desktop background and screensaver etc. Next time I logged on, my desktop background was white, and I had to complete the registry changes again.

    Norton AntiVirus has alerted me of so many different threats this past week. I've acted on them all and some have repeated a few times, so I've followed the instructions in this forum to clean up any issues. After running a Norton Quickscan, it has given me two security alerts:

    One states that a program has made 41 modifications to my computer. A Google Search for the filename returned no results so I've assumed it's a piece of malware that generates random characters in its' filename. I've deleted it, but it has made a couple of registry changes.

    The second alert was that an intrusion attempt by HOMEOFFICE was blocked. HOMEOFFICE is the name of my computer, and so I'm unsure what this means. It shows the risk name as HTTP Trojan Zlob Activity with a High Risk Level. It always just blocks this intrusion attempt and has never removed it. It specifies the attacking computer as IP 192.168.1.81, 1068 and the destination address as 63.219.178.162, 80. Neither of these are my IP address.

    I have attached my logs from the cleanup operations. If you can help me remove this threat I would be most grateful.
     

    Attached Files:

  2. mprepunk

    mprepunk Private E-2

    My final cleanup log is attached
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Policies\Explorer\Run: [NHo91Xn110] C:\Documents and Settings\All Users\Application Data\obytwrap\udizwpkr.exe

    After clicking Fix, exit HJT.

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. mprepunk

    mprepunk Private E-2

    Thanks for your response. Things generally seem to be working alright on my computer, just a couple of small problems related to how menus are displayed in windows.

    I've attached the two logs, and just so you know the registry entries were successful.

    I'll need to see if Norton detects another intrusion attempt. It's something not picked up in the full scan, but seems to happen at random times whilst the computer is in use (whether connected to the Internet or not)

    I started running a Kaspersky scan but on 1% it had already detected quite a few things - you'll have to let me know if you want me to continue with the Kaspersky scan!

    Thanks again!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No. Do not run anything else unless we request it. Until we finish 100% with your cleanup and get thru final instructions which including toggling System Restore, there is no sense in running other scans which could result in detections of things that are not issues.

    All that being said. It looks like your logs are clean and we are ready for final steps.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    After you have completed ALL of the above, you can run anything you like (except malware of course ;) ).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds