Jacked with Crap v2

Discussion in 'Malware Help (A Specialist Will Reply)' started by shiftlessatol, Nov 1, 2010.

  1. shiftlessatol

    shiftlessatol Private E-2

    So, i thought this machine had a virus similar to the Kestrel13! had assisted me with last week. but it seems this one is much more aggressive.

    prior to running TDSSKiller, she was constantly getting pop-up ads about work at home offers. this slowly converted to "Raunchy Porn" as she put it.

    i'll attached all the logs i have to get the ball rolling on this one.

    i had done a Virus removal process and was unaware of the Rootkit activity. i'm going to get the PC this week. here are the most recent logs

    I'll have the Combofix log after i get the machine

    thanks!
     

    Attached Files:

  2. shiftlessatol

    shiftlessatol Private E-2

    MGlogs2 may be incomplete here is a third and most common version
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.

    Be patient whilst I work up a fix.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    J2SE Runtime Environment 5.0 Update 2
    <--- Uninstall this outdated Java
    Viewpoint Media Player <--- Uninstall.

    If you did not deliberately set this proxy yourself then please include it in the HJT fix below:


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    C:\Documents and Settings\Owner\Local Settings\Application Data\{46EFBF0A-A6CF-4D7E-BEE8-BB45551DDC8F}
    Folder::
    c:\documents and settings\Owner\Application Data\Bitrix Security
    File::
    C:\Documents and Settings\All Users\Application Data\1qvH1UX.dat
    c:\windows\system32\pmllii.dll
    c:\windows\system32\khiiff.dll
    c:\windows\system32\yabbxw.dll
    c:\windows\system32\mlmkjh.dll
    c:\windows\system32\vturoo.dll
    c:\windows\system32\vtrpoo.dll
    c:\program files\Windows NT\shell.exe
    c:\windows\system32\jkkigd.dll
    c:\windows\system32\nnmmnk.dll
    c:\windows\system32\ddaxwu.dll
    c:\windows\system32\yaaaww.dll
    c:\windows\system32\efccaw.dll
    c:\windows\system32\tutrpq.dll
    c:\windows\system32\rqpnlm.dll
    c:\windows\system32\pmllml.dll
    c:\windows\system32\qonlkj.dll
    c:\windows\system32\opmmnn.dll
    c:\windows\system32\qoppnn.dll
    c:\windows\system32\ssrspo.dll
    c:\windows\system32\qomlih.dll
    c:\windows\system32\urstqp.dll
    c:\windows\system32\vtroop.dll
    c:\windows\system32\effdaw.dll
    c:\windows\system32\tuvtss.dll
    c:\windows\system32\efdaya.dll
    c:\windows\system32\awtroo.dll
    c:\windows\system32\cbxuvv.dll
    c:\windows\system32\ssqnki.dll
    c:\windows\system32\fcyaby.dll
    c:\windows\system32\urpmjj.dll
    c:\windows\system32\fccayx.dll
    c:\windows\system32\fcyvtu.dll
    c:\windows\system32\rqpqpm.dll
    c:\windows\system32\awtqpq.dll
    c:\windows\system32\ljghhg.dll
    c:\windows\system32\khedax.dll
    c:\windows\system32\vtuust.dll
    c:\windows\system32\tuvsrp.dll
    c:\windows\system32\efdbbc.dll
    c:\windows\system32\opmmkj.dll
    c:\windows\system32\iihgdd.dll
    c:\windows\system32\byywxu.dll
    c:\windows\system32\tusrrp.dll
    c:\windows\system32\effdda.dll
    c:\windows\system32\ursrpn.dll
    c:\windows\system32\pmnllm.dll
    c:\windows\system32\fcyyvt.dll
    c:\windows\system32\mlmnno.dll
    c:\windows\system32\awwxus.dll
    c:\windows\system32\efcdee.dll
    c:\windows\system32\khgdda.dll
    c:\windows\system32\ljgdbb.dll
    c:\windows\system32\tuvwvs.dll
    c:\windows\system32\wvtuuv.dll
    c:\windows\system32\yaaaby.dll
    c:\windows\system32\qopmlm.dll
    c:\windows\system32\rqpomk.dll
    c:\windows\system32\tussqn.dll
    c:\windows\system32\sstqrr.dll
    c:\windows\system32\tutqpn.dll
    c:\windows\system32\cbbbyx.dll
    c:\windows\system32\tuspqr.dll
    c:\windows\system32\yabxxw.dll
    c:\windows\system32\rqrrsq.dll
    c:\documents and settings\LocalService\Application Data\8052.bat
    C:\WINDOWS\system32\drivers\pibxcb.sys
    C:\WINDOWS\system32\geeedc.dll
    C:\WINDOWS\system32\pmnlji.dll
    RenV::
    c:\program files\Lexmark 3600-4600 Series\ezprint .exe
    c:\program files\Lexmark 3600-4600 Series\lxdxmon .exe
    c:\program files\QuickTime\qttask .exe
    c:\windows\system32\rundll32 .exe
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "tutqroaudio"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "nnmnmnaudio"=-
    "tuttsssys"=-
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "ljgfddsys"=-
    "yabywuaudio"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fcbaywaudio]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fcbcbcaudio]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hggfdcaudio]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\khiggesys]
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\Lexmark 3600-4600 Series\\lxdxmon .exe"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{BCA4BCBE-EB6E-406B-B990-3BEBF3024B3B}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Tell me how things are running now.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And who's computer is this exactly? A friends or something?
     
  6. shiftlessatol

    shiftlessatol Private E-2

    she's become a friend quickly she's about 60 years old - i've been combating this for a little over a month now. i think i've removed those dlls but i'll run the script anyway, and post the new logs why do you ask?
     
  7. shiftlessatol

    shiftlessatol Private E-2

    Done
     
    Last edited: Nov 2, 2010
  8. shiftlessatol

    shiftlessatol Private E-2

    not sure why it's arranging my posts as they are but i'm going to try this again


    so far, after doing the same method as before it's looking much more stable. no pops

    here are the logs again
     

    Attached Files:

    Last edited: Nov 2, 2010
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This machine is STILL not set up to be in normal mode by using MSCONFIG.

    You should not be deleting anything manually yourself, you should follow my instructions only.

    My last combofix script got rid of most of it. Just a little remains to be done now.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    File::
    c:\documents and settings\Administrator\Start Menu\Programs\Startup\delrb.bat 
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    • Download bootkit_remover.rar
    • Click the underlined DOWNLOAD text to download the file and save it to your Desktop.
    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip
    • After extracing remover.exe to your Desktop, double click the remover.exe file to run the program.
    • Attach or post inline here, the output from remover.exe
    NOTE: The Command Prompt window text can be copied to the clip board by right clicking on the top bar of the window and using the Edit commands to Mark, Copy, and Paste.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Tell me what problems remain if any. I will be back late on Thursday night.
     
  10. shiftlessatol

    shiftlessatol Private E-2

    "Normal Startup" selected

    i didn't delete it manually, the scanners i ran after i made that log did, but i ran your script anyway?

    Logs attached i followed the instructions on the bootkit remover
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are not attaching the correct output from running BootKit Remover. Here is an example of what I should be seeing instead of the debug logs you keep attaching.

    Read the instructions carefully and either attach a log of the output or screenshot it for me.

    What malware issues, if any, is this computer still having? How are things running now, describe it.
     
    Last edited: Nov 6, 2010
  12. shiftlessatol

    shiftlessatol Private E-2

    i'll try to get you those screen shots soon

    i've had a crazy crazy week. the machine is doing great - bootkit helped considerably

    fyi it indicated that the boot code was normal after i ran the fix on it

    no problems, no malware, no pop ups, no complaints, the machine is running very quick with no gliches. i'm considering it clean and completed, but i'll still try to get you a copy of the echos

    thanks again!
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem! I'll be here waiting when you are ready. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds