Invisible Virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by Hikaru, Aug 25, 2010.

  1. Hikaru

    Hikaru Private E-2

    Hi,

    I am have a hard time tracking down this virus my machine seem to have contracted. I normally do not run with any anti-virus program as I am very careful about which site I go to and what I click. Recently my wife was using my machine because her was down and now my machine got this horrible virus.

    The virus was acting like the stand adware spamware for buying their anti-virus stuff by saying my machine is infected. I am not sure if my wife rebooted or not but when she told me I assumed she did not reboot so I went and clean the bad files manually, the one I could see. During the course of clean I notice I was in trouble because as I was modifying and deleted the bad registry keys, some process was replacing them. I contine to track all the bogus random name dll and rename them so I could delete them in the reboot. Once I did this I rebooted into safe mode and went and clean up al the files. Once I rebooted everything seems good. The next day the machine started to behave oddly, crashing alot and crashing at start if I tried to see what was starting up, I had to let the machine start up for a good 2-3 minutes and not do anything so that the machine would not crash. The crash was was a total lock out, graphics were stuck and the light on my keyboard and mouse turned off.

    At this point I tried to update my machine to the latest updates from MS, but my computer would not connect to the update page. I also start noticing that every time I went to use my web browser (I.E. or Mozilla) I have a 1/10 chance of a random web pages (ad pages) would pop up. I then downloaded G Data Anti-virus program. I did a full scan and it found nothing. So I uninstall that and downloaded PCTool Spyware Doctor + Anti-Virus program. I ran that and it found a bunch so I purchase the program and clean all the virus. That still didn't work so I contacted the support there and they gave me instruction to run the program in Safemode with Networking and did a full scan and it found a few more virus and I clean those. I then rebooted but the problem persisted.

    I did some research on the web and found your site. So I followed your read me and download all the program and followed all the steps. After doing all of this it seems like it fixed my machine, web was working like normal and I could connect to the window update. So I did as instructed and save a restore point. I then went and upgrade WinXP and adobe flash and ran my virus scanner and it found a few more adware cookies which i delete. All seem well until a full day later I notice my machine seems to be always spinning my disk. I started to crash again and some of my game exe got delete. At this point I ran my virus scanner again and it just find low risk adware cookies. My anti virus program has be on after I finish the cleaning process. I am at a lost at this point and it is looking more like I need to do a fresh install. I am trying to avoid this as I have lots of program and the time to reinstall and collect my data is huge. I also don't want to do a reformat as it is an indication of a victory to the virus hacker so i hope you guys can help.

    I am now linking my logs from the clean. Oh I have move back to the restore point i made after I did the clean, so I don't have the MS update or the adobe update currently.
     

    Attached Files:

  2. Hikaru

    Hikaru Private E-2

    The last logs
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Hikaru

    Hikaru Private E-2

    Thanks, looking forward to your post. More problem I notice still after the cleaning is that when I run a full virus scan on my anti-virus program, it will soft lock the machine. My mouse is moving and it seems like the program is scanning except it is suck on one file and the system cloak is stuck and you can't launch anything.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You should always use antivirus ;) Even if you ARE careful. I am careful, but I still use AV.

    Spyware Doctor 7.0 <--- If this is just a trial which is useless anyway then please uninstall it.

    What do you know about this file?
    • c:\windows\system32\CleanMFT32.exe
      [*]
    If you did not deliberately set this proxy yourself then please include it in the HJT fix below:


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      c:\windows\system32\CleanMFT32.exe
    • At the upload site, click the browse button.
    • Use Windows Explorer to navigate to the file(s) we need scanned and click "submit file"
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.


    Could you please get this: CleanMFT32.exe into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:


    log retrievable @ C:\collect.zip


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\windows\UDB.zip
    c:\windows\IDB.zip
    c:\windows\Fyeluvog.bin
    c:\windows\Ovugusumocarezat.dat
    
    FileLook::
    c:\windows\system32\CleanMFT32.exe
    
    Folder::
    c:\documents and settings\Administrator\Local Settings\Application Data\mtjuxxumm
    
    DirLook::
    C:\Cleaners
    
    RegLock::
    [HKEY_USERS\S-1-5-21-220523388-1383384898-725345543-500\Software\Microsoft\Internet Explorer\User Preferences]
    [HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Also do not forget the Jotti results, address any questions I may have asked, and also include to collect.zip as an attachment.

    Let me know how things are running!
     
  6. Hikaru

    Hikaru Private E-2

    I bought the Spyware Doctor anti-virus program. Is it a useless anti-virus program? Or is it only useless if it is the trial/demo version. I am still in my 30-day money back so knowing now would help a lot.

    I have no idea that this file is.

    I don't know if I have zip, I have winrar, if I don't have zip, is this acceptable?
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If it's paid for then keep it if you are happy with it.

    Just follow all of the instructions in my last post and attach the requested logs. :)
     
  8. Hikaru

    Hikaru Private E-2

    Hi Kestrel13,

    I did as you requested and here is the results.

    First step was completed without any errors.

    Second Step found nothing, here is the link.
    http://virusscan.jotti.org/en/scanresult/ef821eb65decc31fbe1abab5f7e6de6d48526202

    I am not attaching all the other files requested, but will also let you know I had problem running the combofix.

    The first time I ran this, as step away from my machine to take a quick shower. I came back and my machine was rebooted, I log in and the combo fix started up again. I step out again thinking it was like last time where it would restart the machine and continue, I came back and the machine rebooted again. I log in again and everything started up but combofix didn't continue. I thought it was done but when I looked for the log file, it was not there. So I did the step again, this time the machine crashed with the stage three completed message in the combo box.

    I had to hard reboot, I held down the power key until the machine turn off. When the machine started I tried to do the process again. Since after each case my script file I made from your instruction was gone so I went back to the website again and this time the machine crashed. In both crash, it was not a blue screen or anything, it was like my other crashes I told you about where my system would crash and the mouse and keyboard lost power (lights turn off).

    I hard booted again and this time let the system start up, after about 3 minutes I went to the web and remade the script and ran. This time it succeeded. One other thing I noticed. After finishing your instruction I re-enable my AV and it found these viruses,
    Trojan-Downloader.Murlo
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME,....

    That is one example, there were like 5-8 of them. I had my AV fixed them.

    Oh and thank you so much for your efforts in helping me out.
     

    Attached Files:

  9. Hikaru

    Hikaru Private E-2

    Hmm could not edit my post, but that should have read,

    I am now attaching all the other files ... not I am not attaching ...

    Sorry if that got confusing.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    catchme is not malware. It is a part of GMER /combofix ;)

    c:\windows\system32\CleanMFT32.exe <--- I now see after viewing the file for myself, and having CF examine it, that it relates to PCTools/spyware doctor.

    Your logs look good now. What malware problems are you still having, if any?
     
  11. Hikaru

    Hikaru Private E-2

    Well, just before I did all the step you mention, my AV would lock up during a scan, and right before I did these step the AV got an update and then could not patch and would not open.

    My machine still locks up if I do stuff during the bootup process, I generally have to let it boot up for the full 3 minutes after logging in to have it not lock up.

    But other than these problems it seems to be fine. My question now is should I apply the WinXP updates?
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes.

    Any remaining issues you have will have to be further discussed in the software forum. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds