Malware removal help needed

Discussion in 'Malware Help (A Specialist Will Reply)' started by Tsultrim, Jul 22, 2013.

  1. Tsultrim

    Tsultrim Private E-2

    Have been invaded by a particularly nasty malware attack. I ran your tools to get logs and am attaching the ones I can find. I'm running my PC in safe mode at the moment until this damn thing is exorcised. Some of the tools I ran came up empty, but Hitman and MGTools produced logs.

    Can you help?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We relly require logs from Normal Boot mode to properly help you. So unless if is impossible for you to run in normal boot mode, please do this from now on. However I will attempt to get started with what you have posted thus far. If you cannot run in normal boot mode, please tell us this. Also we need all of the logs whether they show anything or not. Please take note of where the instructions say the files are located or where you save them so that you can attach them when finished.

    You also need to tell us exactly what problems you are having. You did not descibe your problems at all; however base on what you attached thus far, I can tell that you have several problems including one of the newest forms of Zero Access infection along with multiple other infections.

    Also note that you have multiple antivirus programs installed ( Avast and Microsoft Securty Client ). As stated in the READ & RUN ME FIRST, you should never do this. Uninstall both of these now. We will reinstall one and only one later ( not now ).

    Okay so let's try to get started with your cleanup. Continue in normal boot mode if possible otherwise use safe mode.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: SearchHook Class - {D8278076-BC68-4484-9233-6E7F1628B56C} - "C:\Program Files\AskPartnerNetwork\Toolbar\searchhook.dll" (file missing)
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Ask Toolbar BHO - {4F524A2D-5637-006A-76A7-7A786E7484D7} - (no file)
    O3 - Toolbar: (no name) - {4F524A2D-5637-006A-76A7-7A786E7484D7} - (no file)
    O4 - HKLM\..\Run: [ApnTBMon] "C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
    O4 - HKUS\S-1-5-21-1614895754-1035525444-725345543-1003\..\Run: [wwvn] "C:\Documents and Settings\Joanne\Application Data\Microsoft\Konjyj\konjyj.exe" (User 'Joanne')
    O4 - HKUS\S-1-5-21-1614895754-1035525444-725345543-500\..\Run: [zarw] "C:\Documents and Settings\Administrator\Application Data\Microsoft\Uxcdgaa\uxcdgaa.exe" (User 'Administrator')
    O4 - S-1-5-21-1614895754-1035525444-725345543-1003 Startup: konjyj.lnk = ? (User 'Joanne')
    O4 - S-1-5-21-1614895754-1035525444-725345543-1003 User Startup: konjyj.lnk = ? (User 'Joanne')
    O4 - S-1-5-21-1614895754-1035525444-725345543-1008 Startup: aquafk.lnk = ? (User 'Ro')
    O4 - S-1-5-21-1614895754-1035525444-725345543-1008 User Startup: aquafk.lnk = ? (User 'Ro')
    O4 - S-1-5-21-1614895754-1035525444-725345543-500 Startup: uxcdgaa.lnk = ? (User 'Administrator')
    O4 - S-1-5-21-1614895754-1035525444-725345543-500 User Startup: uxcdgaa.lnk = ? (User 'Administrator')

    After clicking Fix, exit HJT.

    Along with uninstalling Avast and Microsoft Security Client, also uninstall the below software:
    Ask Toolbar
    J2SE Runtime Environment 5.0 Update 11
    Java(TM) 6 Update 17
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6 Update 1
    Uniblue DriverScanner 2009
    Uniblue SpeedUpMyPC 3
    Uniblue System Tweaker
    Viewpoint Media Player

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    :Services
    APNMCP
    Viewpoint Service
    weujmvu
     
    :Files
    C:\Documents and Settings\Joanne\Application Data\Microsoft\Konjyj
    C:\Documents and Settings\Administrator\Application Data\Microsoft\Uxcdgaa                   
    C:\Documents and Settings\Alan\Local Settings\Application 
    C:\Documents and Settings\All Users\Application Data\
    C:\Documents and Settings\All Users\Application Data\APN
    C:\Documents and Settings\All Users\Application Data\AskPartnerNetwork
    C:\Documents and Settings\All Users\Application Data\coNtinuuetosave
    C:\Documents and Settings\Alan\Desktop\
    C:\Documents and Settings\Alan\Desktop\HijackThis.exe
    C:\Documents and Settings\Alan\Desktop\hijackthis.log
    C:\Program Files\AskPartnerNetwork
    C:\Program Files\ContinueToSave
    
    :Reg
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "ApnTBMon"=-
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{8DE1B9F2-9747-42D6-AA90-D56346E8400A}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4F524A2D-5637-006A-76A7-7A786E7484D7}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{4F524A2D-5637-006A-76A7-7A786E7484D7}"=-
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    • Now exit any programs that you may have started.
    • Please disconnect any USB or external drives from the computer before you run this scan!
    • Rerun RogueKiller ( if running Vista,Win7, or Win8 user right-click and select Run as Administrator to run ) for WinXP and Win 2K just double click to run
    • Wait until Prescan has finished
    • Then Click on "Scan" button
    • Wait until the Status box shows "Scan Finished"
    • click on "delete"
    • Wait until the Status box shows "Deleting Finished"
    • Click on "Report" and attach the content of the Notepad into your next reply.
    • The log should be found in a new RKreport[x].txt on your Desktop
    • Exit/Close RogueKiller and reboot your PC.


    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jul 22, 2013
  3. Tsultrim

    Tsultrim Private E-2

    I can't remove Microsoft Security Client as this thing has blocked all access. I can't even scan the files. So before I can remove that one, I will need instructions as to how to gain access to it again. This was my primary AV tool.

    So far, I have identified that there is a Qakbot variant installed and it also downloaded a number of other little nasties. It blocked access to all anti-virus sites so I could not download updates or install any other AV software, so I have been forced into working in Safe Mode with Networking in order to prevent any further invasion. I am sure this baby has done alot of damage, and am concerned it may have also migrated over to my MS Home Server, but I can't tackle that until I get my PC stabilized.

    Once I stabilize this PC, I am considering backing up the data and doing a clean install of Windows 7 (or Windows 8) to improve security.

    Please advise on the MS Security Client.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just continue on with the rest of my instructions and we will come back to this later because this program's file system has been corrupted by the ZeroAccess infection
     
  5. Tsultrim

    Tsultrim Private E-2

    Hi there,
    I ran all the tests in normal mode and the system seems to be much more responsive. I can now access AV sites as well. Here are the results of teh tests.

    When I ran HJT, some of the lines you listed did not appear:
    O4 - HKUS\S-1-5-21-1614895754-1035525444-725345543-1003\..\Run: [wwvn] "C:\Documents and Settings\Joanne\Application Data\Microsoft\Konjyj\konjyj.exe" (User 'Joanne')
    O4 - HKUS\S-1-5-21-1614895754-1035525444-725345543-500\..\Run: [zarw] "C:\Documents and Settings\Administrator\Application Data\Microsoft\Uxcdgaa\uxcdgaa.exe" (User 'Administrator')
    O4 - S-1-5-21-1614895754-1035525444-725345543-1003 Startup: konjyj.lnk = ? (User 'Joanne')
    O4 - S-1-5-21-1614895754-1035525444-725345543-1003 User Startup: konjyj.lnk = ? (User 'Joanne')
    O4 - S-1-5-21-1614895754-1035525444-725345543-1008 Startup: aquafk.lnk = ? (User 'Ro')
    O4 - S-1-5-21-1614895754-1035525444-725345543-1008 User Startup: aquafk.lnk = ? (User 'Ro')
    O4 - S-1-5-21-1614895754-1035525444-725345543-500 Startup: uxcdgaa.lnk = ? (User 'Administrator')
    O4 - S-1-5-21-1614895754-1035525444-725345543-500 User Startup: uxcdgaa.lnk = ? (User 'Administrator')


    Also when I ran OTM my system became unresponsive. I tried this 3 times and all 3 times the same result. So I do not have a log file for that test. I am attaching the remaining ones asked for as they all ran as expected.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we need to get OTM to run. Please reboot into safe boot mode and run the fix with OTM. Afterwards, reboot into normal boot mode and then continue with the below.

    • Run a new scan with Hitman Pro and save a new log.
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

      Then attach the below logs:
      • the C:\_OTM\MovedFiles log
      • the new Hitman Pro log
      • C:\MGlogs.zip
     
  7. Tsultrim

    Tsultrim Private E-2

    I got OTM to run. However, in Safe Mode with Networking the system hung again when it got to the step of deleting temporary internet files under NetworkService. I had to reboot under safe mode (without networking) for it to run to completion. I copied the code to a .txt file and used that.

    One unexpected outcome is that my desktop was cleared of items and moved to the OTM files directory as well. I am also getting the Windows Installer popping up from time to time since the OTM cleaning. I just cancelled out of it to avoit any unwanted installs.

    I ran hitman using the instructions... only getting a scan - no fixes. So whatever it detected is still there.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's see if we can fix this first before doing anything else.


    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    RestDesk.bat

    Now reboot your PC to see the affects.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    • C:\MGtools\cpylist.txt
    Did this restore your Desktop files and also Application Data files (probably the cause of Windows installer running )?
     
  9. Tsultrim

    Tsultrim Private E-2

    Hi chaslang,
    I ran the .bat file and it seems to have stropped the windows installer pop-ups, but did not restore all my desktop files. I am assuming that this is because they went missing on the first attempt in Safe Mode. This created a folder named 07222013_223927, but since the OTM program hung in the last stages it did not create a .log file. There are only 2 desktop folders that are important to restore and I can do that later if we don't remove that OTM folder.

    The MGLogs.zip file you requested is attached, but the cpylist.txt file was empty and would not upload.

    Thanks for all the help so far...MUCH appreciated.
     

    Attached Files:

  10. Tsultrim

    Tsultrim Private E-2

    One more thing.. may not be related, but the dkservice.exe program is encountering an error (has been for a couple of weeks so I don't know if related).
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I modified RestDesk.bat. Please try the whole process all over again starting with downloading the file again.


    No the DiskKeeper issue ( the dkservice.exe service ) is not related, You may need to reinstall later.
     
  12. Tsultrim

    Tsultrim Private E-2

    The process seems to have stalled when restoring then All Users Application Data. It's been sitting for hours doing nothing. All my desktop files have been restored. My thought was to reboot and collect the logs to send in, but I thought I would confirm first.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There were quite a lot of files to restore in Application Data. Don't reboot yet.

    Just attach a copy of the cpylist.txt file as it is right now.
     
  14. Tsultrim

    Tsultrim Private E-2

    Here it is. :)
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I see the problem. I have made new batch file name RestDesk2.bat which will write to a new log file named C:\MGtools\cpylist2.txt Follow the below instructions.

    You should be able to terminate the existing batch file by click the command prompt window and type CTRL-C a couple of times. If that does not work then just close the command prompt window by click the X


    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    RestDesk2.bat

    Now reboot your PC to see the affects.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\MGlogs.zip
    • C:\MGtools\cpylist2.txt
    Did this restore your Application Data files ?
     
  16. Tsultrim

    Tsultrim Private E-2

    OK. That seemed to move some of the files, but not all of them. The process terminated on its own (and it did not take long) and I recall having to close the window the first time I ran it.
     

    Attached Files:

  17. Tsultrim

    Tsultrim Private E-2

    Hi chaslang,
    I had a look at the files that were transfered and tried the applications I use, so I believe I am okay to continue. I also had a look at what was in the OTM moved files directory and it appears that what wasn't moved I don't need moved back anyway.

    Cheers!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not too sure about that, there were a lot of different folders in there for many applications ( like Adobe, Epson Printer, DivX, Intuit......many more ).

    Do you know how to copies folders/files using Windows Explorer from one location to another?
     
  19. Tsultrim

    Tsultrim Private E-2

    Yes, I have no problem with that. Not as familiar with xcopy (haven't used that in about 20 years or so), but windows explorer... copy/paste and drag/drop... no problem.
     
  20. Tsultrim

    Tsultrim Private E-2

    I understand that I would be copying files and folders from the All Users\Application Data directory. Are there any that I should not copy over?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes what I want you to copy ( not move ;) ) is the below folder and all contents

    C:\_OTM\MovedFiles\07222013_223927\C_Documents and Settings\All Users\Application Data

    Back into the below folder ( overwrite any existing files ):

    C:\Documents and Settings\All Users\Application Data


    Also since OTM was used at two different times, copy the below folder and all contents:

    C:\_OTM\MovedFiles\07222013_230648\C_Documents and Settings\All Users\Application Data

    Back into the below folder ( overwrite any existing files ):

    C:\Documents and Settings\All Users\Application Data
     
  22. Tsultrim

    Tsultrim Private E-2

    Okay, I've copied all files that would copy. Some of the moved files would not - under the microsoft folder, and mostly under crypto. The keys had access denied errors. I believe these regenerate as needed anyway, so I am not concerned. There were 1 or 2 more files in the microsoft folder that had a similar error, but they already existed in the target folder, so I believe these are also regenerated files. Everything else was fine.

    What is the next step?
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay sounds good. If everything is back to normal and you have everything you need copied out of the C:\_OTM folders then you can work thru the below. The below will remove most of what we have done ( including the C:\_OTM folder ) when you run MGclean.bat. So make sure you are really good before running these steps.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  24. Tsultrim

    Tsultrim Private E-2

    Hi Chaslang,
    Thank you ever so much for all the help in getting rid of this nasty malware. I ran a scan using Malwarebyte and installed Comodo Internet Security (AV and Firewall) All scans look good!

    You guys at Major Geeks are awesome!

    One last thing... I ould like to make my router more secure and couldn't find any pointers on the forum. Can you point me in the right direction?

    Many Thanks!:-D
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and thanks.
    Yeah I never really added too much about this into the How to Protect... thread other than a little bit mentioned in the Firewal section. There are quite a few tips out there that are helpful. See the below:

    http://www.pcmag.com/article2/0,2817,2409751,00.asp

    https://www.grc.com/nat/nat.htm

    http://www.ciscopress.com/articles/article.asp?p=461084

    https://krebsonsecurity.com/2011/12/new-tools-bypass-wireless-router-security/

    http://news.cnet.com/8301-1009_3-57579981-83/top-wi-fi-routers-easy-to-hack-says-study/

    http://compnetworking.about.com/od/wirelesssecurity/tp/wifisecurity.htm
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds