Laptop infected too - Consequence of the horrible "Copyright Violation Alert"

Discussion in 'Malware Help (A Specialist Will Reply)' started by DUENAS-737, May 7, 2010.

  1. DUENAS-737

    DUENAS-737 Private E-2

    In my previous post a few minutes ago I explained how my pc got infected, but also my laptop caught some nasties while I was transfering files to my pc. My laptop runs Vista Home 32 bits. I followed the instructions from this thread and followed "Vista cleaning procedure" but RootRepeal stalls. First it gave me this message of "PE image not found" or something, I'm sorry I don't remember, it happened only the first time I ran it. Then it ran good but stalled after a few seconds, I don't remember what it says but the main screen states some processes locked to API! I have terminated it three times already because it stalls. The last time I was decided to leave it running the entire night but a small browser came on on top of the rootrepeal browser. The new small browser was transparent so I could read the processes in rootrepeal. I did not touch it for a long while. Then I moved it around and I could see through the browser like through a window. When I closed the browser from the "x" in the right corner, root repeal closed down. Here are the logs, I hope somebody can tell me if I am still infected with rootkits or if I have to skip the rootrepeal step and follow the last one: MGtools.exe
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the log from SUPERAntiSpyware and MGlogs.zip from running MGtools. Just skip Rootrepeal as stated in the begining of the READ & RUN ME.
     
  3. DUENAS-737

    DUENAS-737 Private E-2

    Here is the log from MGtools. I am sorry, in both my pc and laptop I do not find the SAS log. I am going to look for it in my pc in the folder you mention in that thread. Here is the MGtools log.zip. I have received today replies to my email acount from many undeliverable mail notices, e-mails that I have not send. Obviuosly this nasty or someone else is sending it or sending itself getting e-mail addresses from my e-mail account.
     

    Attached Files:

  4. DUENAS-737

    DUENAS-737 Private E-2

    I couldn't sleep early today Sunday and came to my laptop to update and run SAS and Combofix again @ about 2:00am. Well, In Windows vista there's the "Currently Connected" Icon in the system tray. I just happened to roll the mose over it by mere chance and it said I was connected to two networks, one is my regular "Home" network but there was another one that was named "Unidentified Network" that I was connected to. When I went to "Connect or Disconnect" and saw all available networks, sure enough the so called Unidentified Network wasn't there. I right clicked the Icon in the system tray, the menu showed up, at the top of it there's the option to disconect and a submenu. I scrolled over it but it only gave me the option to disconnect from my "Home" network, the Unidentified Network was not in the menu. I ran SAS and CF and the Unidetified Network was still there. I restarted my machine and the Unidentified Network was gone. My wife woke up and started the pc. Went to her e-mail and there was two e-mails supoussedly from me. She opened them up, they're empty but have a web address in them. I googled those addresses and no result were found. Those e-mails were sent one @ 2:00 am early Saturday the day before, and the last one @ 8:30ish Saturday afternoon. However, my laptop seems to be working fine. I do not know if that unidentified network has anything to do with the e-mails all my contacts are receiving from me or if my computers are being used by somebody or something else. I also ran Rootrepeal but as usual it stalled, only this time I did get a log.txt file.

    Also I have an "Access denied" message when I try to run these hidden shortcuts that I hadn't seen before:
    C:\Documents and Settings
    C:\System Volume Information
    C:\Program Data\Application Data
    C:\Program Data\Desktop
    C:\Program Data\Documents
    C:\Program Data\Start Menu
    C:\Program Data\Templates

    it says for example

    C:\System Volume Information is not accesible.
    Access is denied

    These hiden shortcuts appear throughtout, I mean in the 'Users" folder, in owner's folder, etc. and others. I tried deleting one or two and it deleted them but I cannot open them, Is this normal?

    Here are the logs.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is always in the same place. Just the user account name may change. On this PC, you have the below logs.
    Code:
    "C:\Users\Irma\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    May  3 2010   583  "SUPERAntiSpyware Scan Log - 05-03-2010 - 21-59-56.log"
    May  4 2010   465  "SUPERAntiSpyware Scan Log - 05-04-2010 - 22-00-59.log"
    
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normal for Vista and Windows 7. And System Volume Info is never accessible unless special commands are used to allow it to be accessed.


    Your logs are clean. You need to get properly protected which is included in the below.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     
  7. DUENAS-737

    DUENAS-737 Private E-2

    Thanks again for your help. I guess I must asume that the double connection to the Internet I discovered has nothing to do with this infection, right? I will try to keep myself protected following your advices then. Here are the logs from SAS the first, second and third and last time I ran it, although I am clean now, for whatever it's worth I am uploading them and hope that you get a chance to take a look at them and give me a quick feedback.
    Thanks again
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Correct.

    All clean now. ;) The 1st one on 5/3 removed what it found.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds