Malicious Infections... :o

Discussion in 'Malware Help (A Specialist Will Reply)' started by eff, Oct 8, 2005.

  1. eff

    eff Private E-2

    Dear fellow computer fiend's,

    It has recently come to my attention that my computer is infected
    with a virus. Or so i think. I have come across the following symptons:

    Sudden execution of AV software
    " " " Game(Battlefield 2)
    And for some reason all my icons in my control pannel
    were multiplied by 3. Eg. 3 "add/remove programs".
    Alot longer to boot up

    Before even becoming aquainted with virus i had used: Norton AV, Norton Firewall, and Webroot.

    I have downloaded all of the programs that you have recommended but no luck. So here i am, And if you wish
    To see my HiJackThis scan just let me know.

    By the way, Don't make acusations about me looking at obscene websites. Never in my life have i visted websites
    with codensed filth and moral decay.

    Conclusion of Scan-

    KsperSkys:

    Nothing found. Just some AV definitions from Spy Bot

    HS Remove:

    8 Items removed. I have no idea what they were but im happy.


    Ad-Adwarese:

    1 New critcal file. Desc: tracking cookie, IE cache entry

    Cookie: Carson@imrworldwide.com/cgi-bin

    (by the way, my name is carson)

    20 objects deleted.

    Mcafee Stinger:

    Nothing found

    CWSshredder:

    Nothing found

    kill2me:

    n/a

    Aboutbuster5:

    Nothing.

    Spyblaster:

    What the heck. Is the program just used for online protection or is it going to
    delete any malicious software?

    SpyBot:

    Accoding to the scan i had...

    Avenue A, Inc. (wth?)
    Double Click
    Fast Click
    HitBox(3 entries)
    TargetNet

    7 problems fixed.

    :)

    In conclusion.. I don't think any of this helped. Was this to breif?

    Thanks alot! Cya.

    p.s.- In the mean time i will be using Linux...

    p.p.s.- I wrote this while i didn't have an Internet connection so please Excuse the poor structure.

    p.p.s.- i just had an Active Desktop Recovery..
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. eff

    eff Private E-2

    I undertstand that... I know how to use HiJackthis i thought it was pretty simplistic but i guess you want my scan results. Okay, here they are:

    Edit by chaslang: Inline log removed
     
    Last edited by a moderator: Oct 8, 2005
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I guess you don't understand it. Please follow the directions. HJT must be installed properly and logs must be attached as the directions tell you.

    You also never ran step 1 of the READ ME FIRST cleaning section.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way, all of the Control Panel applets are files with the .CPL filetype and they are located in your C:\WINDOWS\system32 folder.

    You should look there to see if there are duplicates that can be deleted.
     
  6. eff

    eff Private E-2

    I can't see how any of the changes i made will benefit but here you go....

    Yeah, I know all about the cpl files... And one time when i went to go remove a program there was multiple icon's. It took me a while to realise how to delete them.
     

    Attached Files:

  7. eff

    eff Private E-2


    If you mean step one of this:

    http://forums.majorgeeks.com/showthread.php?t=35407

    I did. I know the genreal procedure.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you did not! You skipped the first step:
    The sticky I gave you for using HijackThis explains why it must be installed properly.

    However, you HijackThis log really does not show any signs of infection. That does not necessarily mean you are perfecty clean. It just means the locations that HJT looks at show nothing. The only item in you log I wonder about is:

    C:\Program Files\SMASHER\Smasher.exe
    C:\Program Files\SMASHER\Smasher.exe
    O4 - Global Startup: SMASHER.lnk = C:\Program Files\SMASHER\Smasher.exe

    Did you look for and delete and additional .cpl files this time?
    Do you still have multiple icons in Add/Remove programs?
    What other issues do you currently have?

    If you are still having issues you could try the two below scans. They sometime find things others miss:

    Panda ActiveScan Save the log and attach later

    Running Ewido Security Suite attach this log too.
     
    Last edited: Oct 8, 2005
  9. eff

    eff Private E-2

    Okay, My taskbar and icons started flickering and i couldn't my computer basically freezed up. I can't do any of the scans you suggested because IE is executed immediatley after i try to run it.

    Smasher is a program i bought off a friend. it's just a pop up blocker.

    Thanks, cya
     
  10. eff

    eff Private E-2

    i have 3 svchost.exe processes though.

    I also have a process called wowexec.exe. And before is there is a space.. like:

    taskmgr.exe
    wowexec.exe
    firefox.exe
    alg.exe
    svchost.exe local service
    svchost.exe Network Service
    svchost.exe System

    and what aobut explorer.exe. I don't even have the window open but it's running...

    Thanks, Cya
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you mean by "IE is executed"? It is suppose to be executed when you run it. Or did you mean to say, something terminates or kills IE after you run it? If so, do you get any error messages.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All are valid! Explorer is always running! It is your system shell and runs at startup. Without it you would have no Desktop or icons or Start button.
     
  13. eff

    eff Private E-2

    Okay, Thanks Chas!

    What i mean by exectues is that it terminates itself.

    I ran the procedure in safe mode another time and cwsshredder removed..

    CWS.msconfig

    After the removal of that i still cannot run the online scans.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run the two I gave you at the end of message # 8 and post their logs.
     
  15. eff

    eff Private E-2

    Okay, i couldn't run the panda scan because of IE terminating but here's the Ewido results! :)

    By the way, The file was too big to attach so i used YSI.

    http://s5.yousendit.com/d.aspx?id=3GD2QHCY6HL872JUAWXDNNBZ91

    Thanks, Cya
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because of all the cookies you need to empty your Norton protection of your Recycle bin. You could have ZIP the file too.
     
  17. eff

    eff Private E-2

    Okay,

    I have concluded i have a Trojan.

    There is no process running that is harmful and there must be a thread running in explorer that is essentially invisible. I can no longer search for items or use IE.

    Thanks, Cya

    Im willing to do anything besides reformat to get this stuff off.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you empty the Norton Protect folder as I indicated?

    Please post a new HJT log attachment. I do not think you have a trojan.

    When IE terminates, do you get an error message? If so, what is the exact message. This sounds more like a corrupted DLL file than malware.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have your run the below tools:

    Microsoft Windows AntiSpyware

    Spy Sweeper

    It may be worth running them to see if they find anything. They do not require a connection to run. Also would be best to run them with browsers closed.
     
  20. eff

    eff Private E-2

    I already have Webroot and i just ran microsoft's. Detected nothing. What's doing is starting a thread in ie explorer so it's invisible. It's a trojan. When i tried making a new user account it terminated instantly aswell. When i remove CWSMsconfig in CWShredder in safe mode it comes back again after a while? My first assumption was the process would run immediatley after the computer booted up but when i checked the processes nothing was peculiar.

    Yes i purged the norton recycling bin files etc etc.

    No there is no error message after ie terminates.

    Thanks Alot, I thought you gave up on me
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And where are you seeing this? What are you using to see the thread? Or are you just guessing?

    One thing you need to do is use only on antivirus application. I see both Symantec and Kaspersky. Decide which one you want and uninstall the other. It sort of looks like Kaspersky may already be partially but not completely uninstalled.

    Are you sure you trust Smasher?

    Download Process Explorer

    Unzip it and now run ProcessExplorer and lets configure some options first:
    Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked. Now click on explorer.exe. Now also under the View menu choose "Select columns" and put a check mark on "Image Path". Now click on File and then Save As. And save the process list. Post it back here as an attachment.

    Now repeat the above but this time have one (and only one) Internet Explorer browser open and select iexplore.exe instead of explorer.exe.

    Post both process lists here as attachments.
     
  22. eff

    eff Private E-2

    That was just a educated guess from what i know about trojans.

    Smasher is fine and i run it on all of my Virus free computers.

    Uninstalled Norton.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are no strange processes showing running under Windows Explorer.

    You forgot to select iexplore.exe before getting the second process list from ProcessExplorer. Please try it again.

    Also do the following.

    Download WinPFind

    Extract it to the root folder of drive C ( C:\ ). This will create a folder called WinPFind in the C:\ folder. Inside c:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.

    When it is done, it will show the results of the scan. Click on the Copy to Clipboard button and then paste the contents of the log in your clipboard. Then save it to a file using notepad and upload the text file here as an attachment.
     
  24. eff

    eff Private E-2

    bahie was iexplorer.exe for some reason When i save it as iexplorer.exe it would save the file file as a ms dos shortcut when i specificaly said TXT.

    I'll try the WinPF tonight.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not be saving it as iexplorer.exe. That is the name of you Internet Explorer executable file. Just save it to a file like IEprocesses.txt or even jsut processlist.txt However, you did not have iexplore.exe selected when you saved the file. That is why there is no info in the bottom window for all the DLLs.

    It was dangerous to name your explore one as you did (explorer.exe.txt). If you did this in the wrong folder and made a mistake with how you saved it, you could potentially overwrite the explorer.exe shell (normally it should not be possible because it is always running).
     
  26. eff

    eff Private E-2

    Hey Chas, I haven't been having any issues latley so thanks for your help!
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds