Malware causing multiple firefox and iexplore processes

Discussion in 'Malware Help (A Specialist Will Reply)' started by Rich_abe, Jul 8, 2009.

  1. Rich_abe

    Rich_abe Private E-2

    Hi Guys,

    This is my first post on this forum and I would really appreciate any advice anyone has to offer.

    My problem is that when I open IE or Firefox, I end up with multiple iexplore.exe or firefox.exe processes running. Usually there will be one or 2 extra processes running in addition to the one that I am actually using. These processes really use up a lot of my CPU resources and slow everything down. I am able to kill the processes and everything will work fine (it seems). But, when I close the browser, the processes start up again and start hogging resources.

    I think I may have got the malware from the svpod.com website where I was trying to watch some streaming sport events. I stupidly downloaded their svpod player and then the problems started with the extra browser processes running and slowing everything down.

    I have done scans with AVAST! and spybot and superantispyware and malbytes malware and although 1 or 2 problems were picked up and repaired, it didn't fix my problem.

    I have read a couple of the other related threads but most of them said that the problem was with processes which could not be killed, whereas mine can so I figure it is a different issue.

    Another problem that has occured as a result is that my itunes shortcut on the desktop started trying to run some kind of installer which was very strange. I stopped the installer and deleted the shortcut.

    I also noticed some strange new folders in my folder where my documents, music etc are stored. They appear to be shortcuts to things like "NetHood", "Local Settings", "Application Data" etc but I cannot access them. I have attached a screenshot.

    I have followed the Malware Removal Guide on this forum and followed all the steps. I have attached the required logs.

    Many thanks in advance,

    Richard
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    Please attach the last two requested logs.
    • RRlog.txt (from RootRepeal)
    • ComboFix.txt (normally C:\ComboFix.txt)

    Be patient after posting your logs and wait for one of the helpers to get to you. It can take a while to read thru all of the logs and to create individual fixes for you.
    • Also DO NOT BUMP your thread to try and get a faster answer. This will actually significantly delay getting an answer. See this: Don't Bump! It Only Hurts You!!!
    • Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.

    Thanks
    dr.m
     
  3. Rich_abe

    Rich_abe Private E-2

    Hi,

    I tried rerunning the cleaning procedure because I screwed up the last time.

    However RootRepeal and Combofix will not run properly.

    Combofix says: "Some files could not be created. Please close all applications, reboot windows and restart this application." I tried following the instructions but the same thing happened.

    RootRepeal starts scanning but then comes up with the message: "Unrecognized partition 6 (0x6)1".

    I have attached new versions of the other 3 logs as a reran them all again today.

    Thanks,

    Rich_Abe
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Rich_abe


    The below fixes are specific to your problem and should only be used for issue(s) on this machine. Also, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    Did you remember to shutdown all protection programs including Windows Defender before trying to run ComboFix and RootRepeal?
    You have avast! Antivirus and COMODO Internet Security installed. Are you using Comodo's firewall only? If not - you should not have two anti-virus programs installed and you need to uninstall one of them now.

    Do you know what these are?
    C:\Program Files\dykqz.txt
    C:\Users\Rich\AppData\Local\Temp\85a5ce9f90df410d70994bddbee5b2aa-i686.cache-2

    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed
    Step 2:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 3:
    Now download The Avenger by Swandog469, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Step 4:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 5:
    Question: What directory did you download ComboFix to? I don't see it where it should be - on your desktop. Please move it there... and try again to run both ComboFix and RootRepeal --- remembering to disable ALL protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere. If it still doesn't run - try running ComboFix in Safe Mode.

    Step 6:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\avenger.txt
    • C:\combofix.txt
    • RRLog.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  5. Rich_abe

    Rich_abe Private E-2

    Hi,

    Thanks for your reply:

    I am only using the Comodo firewall.

    I have no idea what those files are or where they came from.

    I ran steps 1 - 4 without any hassles really. I did have to run avenger in safe-mode though.

    I managed to run Combofix in safe-mode too. However it kept insisting that I had Comodo Defense+ active, which was definitely not the case. I checked the settings twice and basically did everything short of uninstalling the program. The same goes for Windows Defender and avast! They were definitely disabled to the best of my knowledge.

    RootRepeal still won't run properly. It had an error on startup and another when trying to run the scan. I have attached a log file containing both errors.

    I ran the programs as specified, with all firewalls and anti-virus programs disabled.

    Strangely though, the multiple processes problem subsided a couple of days ago. I have no idea why this happened though. Perhaps you could shed some light on this. I worry that my system still has some kind of infection. The system seems to be running ok at the moment although there are still some strange files and folders that have appeared on my system as I mentioned in a previous post.

    Would the comodo defense+ logs be of any use? There is a record of what went down when the problem started. I was trying to install / run FFVJPlayer.exe from Nagasoft (off the svpod.com site as I seem to remember).

    Anyway, here are the logs.

    Many thanks in advance,

    Rich
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Rich_abe

    Comment:
    None of your logs show any malware present. Keep in mind that "Files and Folders" are now set by our tools to be no longer hidden...could that explain you're now seeing things that were hidden before? If you think you see a problem in the logs - please Copy & Paste that exact information into your next reply.

    Step 1:
    Now download The Avenger by Swandog469, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Step 2:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 3:
    Please follow the instructions given in the following link:
    Using Radix To Detect Rootkits

    Step 4:
    Now go to this link MGTools and download the new version of MGtools....overwrite your previous MGtools.exe file with this one.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\avenger.txt

    Make sure you tell me if you had any problems running this procedure, any current problems you are having, and give a description of how things are working now!

    dr.m
     
  7. Rich_abe

    Rich_abe Private E-2

    Hi,

    I ran Avenger and it worked just fine. Log is attached.

    Radix would not run because it said that my version of windows is not supported and that to make the program compatible with my OS, several parts of the program need to be adapted. And then basically asked me to donate money in order to help "financiate" the expenses of the required adaptations.

    I tried running the program in compatibility mode (XP sp2) and it got through most of the scan but then ran into some kinda problems. I have attached the log for that scan in case it is of any use.

    MGLogs is also attached.

    Things do seem to be running fine on my machine at the moment. I haven't really had any trouble lately.

    Thanks again for your support,

    Rich
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hi, Rich_abe

    Okay - Let's use another rootkit tool.

    * Several of the files in the MGLogs.zip from your last attachment show an outdated version was used.

    # Now go to this link MGTools and download the new version of MGtools....overwrite your previous MGtools.exe file with this one.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • updated C:\MGlogs.zip
    • avirarkd.log

    dr.m
     
  9. Rich_abe

    Rich_abe Private E-2

    Hi Dr M,

    I followed all of your instructions. Requested logs are attached.

    Thanks,

    Rich
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello again, Rich_abe

    Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:

    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  11. Rich_abe

    Rich_abe Private E-2

    Hi Dr M,

    Everything seems to be running just fine again.

    Thank you very much for your time and effort. It is greatly appreciated. :)

    Over and out,

    Rich
     
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :cool

    You're very welcome, Rich.

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds