Malware issue, logs attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by pisquared, Mar 31, 2009.

  1. pisquared

    pisquared Private E-2

    I beseech other members of the tech community for assistance in solving a possible Malware issue. Three log files are attached, and I am describing what I do know below. Before going any farther, though, I want to thank anyone who takes the time to read it.

    Description of issues:

    1. Web updates of popular malware removal programs do not work. This includes SpyBot, SuperAntiSpyware, AVG Anti-Virus (free edition), and Avast. Either the updates will crash the program or simply will not progress.

    2. Windows Update is not accessible. The browser either freezes or closes. Sites with information on them (for example I tried searching for the malicious software removal tool) are inaccessible as well.

    3. Other web sites are inaccessible. This includes, for example, bleepingcomputer.com. This is also related to why I don't have a ComboFix log to post - I could not find instructions that were not linked to bleepingcomputer, and the link would not open. Of course, their site could have been down briefly in the time I went there, which I can't rule out before posting this.

    4. I will be automatically redirected to commercial sites when I try to visit online scanning web sites. An example is being redirected from Trend Micro's House Call site to a different one that also purports to scan your computer. The site most likely contains spy/malware as well.

    5. Some programs (for example, World of Warcraft) will not run. WoW was actually what tipped me off to a possible infection since it crashed non-stop today and intermittently yesterday, whereas it was fine before.

    6. I noticed these things happening in the past two the three days. Five people had access to my computer in that time frame and I automatically delete history/cookies regularly. Thus, I have no idea which sites may have been visited, though I do know that at least two people were browsing for "pictures" in my absence. Not surprisingly, I suspect this is related to my current issues.

    I will do my best to answer any questions you may have if that will help you. Again, many thanks to you in advance for reading this post and taking the time to ponder it. To clarify, I have run Avast, SpyBot, SuperAntiSpyware, Malwarebytes' Anti-Malware, Symantec's Conficker removal tool, Trend Micro's Cleanup Engine, and AVG Anti-Virus (free edition). (EDIT) To the best of my knowledge, none of them have found anything other than some adware cookies or some system security settings that needed to be adjusted.

    Thanks again for your time.

    Tim
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Combo is right here:
    C:\Documents and Settings\Tim\Desktop\cf.exe

    I am not seeing any malware. Please run:
    ATF Cleaner by Atribune.

    Now attach the combo log and tell me what issues you still have.
     
  3. pisquared

    pisquared Private E-2

    I am not able to run ComboFix at all. It briefly shows a command prompt and quits, so I cannot provide a log. Earlier I refrenced not being able to access bleepingcomputer.com, and I had time to do a follow-up today. I went to ctunnel.com (proxy site), which did allow me to visit bleepingcomputer.

    I still run in to behavior such as programs quitting unexpectedly and antivirus/spyware programs not running or not updating. The latest attempt was SmitFruadFix, Kaspersky, and Stinger SmitFraudFix would not run correctly (I've run it many times on other infected computers so I know what it is supposed to do), and Kaspersky would not update. Stinger did not find anything either.

    If this isn't some new bit of malware, then I don't know what it could possibly be. Any suggestions are welcome, and I'm more than willing to post any logs that might help at all.

    Thanks for taking the time to respond!
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would first suggest that you disable TeaTImer ( as requested in the Read and Run First instructions )...then disable your av and as protection.

    Now see if you can run Combo. Also try in safe mode.
     
  5. pisquared

    pisquared Private E-2

    I tried both disabling and uninstalling; ComboFix wouldn't run in either case. The same is true for safe mode. I'm really hoping I don't have to wipe this hard drive and start fresh. :(
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's give this a shot:
    Dr.Web Cure IT.

    If it runs, attach the log.
     
  7. pisquared

    pisquared Private E-2

    I'm not sure exactly what you meant by the log. I was able to get this .csv file out of it, though. It mostly found SmitFraudFix and MGTools, though it found one other process killer in windows/system32. Since I can't upload a .csv file, I pasted the text below.

    I don't know how to interpret these results, though. After running, I still run into the same problems I have before. Searches for virus scanning products redirecting, programs not running or updating, etc.

    smf.exe\SmitfraudFix\Process.exe;C:\Documents and Settings\Tim\Desktop\smf.exe;Tool.Prockill;;
    smf.exe\SmitfraudFix\restart.exe;C:\Documents and Settings\Tim\Desktop\smf.exe;Tool.ShutDown.14;;
    smf.exe;C:\Documents and Settings\Tim\Desktop;Archive contains infected objects;Deleted.;
    Process.exe;C:\Documents and Settings\Tim\Desktop\SmitfraudFix;Tool.Prockill;Deleted.;
    restart.exe;C:\Documents and Settings\Tim\Desktop\SmitfraudFix;Tool.ShutDown.14;Deleted.;
    Process.exe;C:\MGtools;Tool.Prockill;Deleted.;
    Process.exe;C:\WINDOWS\system32;Tool.Prockill;Deleted.;
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds