Malware/Suspected Alureon

Discussion in 'Malware Help (A Specialist Will Reply)' started by pawville, Mar 27, 2013.

  1. pawville

    pawville Private E-2

    Hello,
    I am troubleshooting PC issues for a friend. She is using an IBM Lenovo 3000 C100Laptop with Windows XP Pro installed. It has an Intel Celeron Processor with 1.5 GHz and 1 GB RAM. She has AVG Internet Security 2013 installed with the following processes running at start up in the task bar:

    AVG, Kodak Printer, Broadcom 802.11 Multiband Network Adaptor, Thinkvantage Access Connections, Google Desktop, Intel Graphics Media Accelerator for Mobile, Synaptics Pointing Device, LAN, Wireless Connection and Malware Bytes Anti Malware.

    These are the details as I know them. She let her Antivirus subscription lapse in October of last year. She continued to surf the web with old virus definitions. Finally renewing her virus protection to what I listed earlier in January of this year.

    The odd behavior: It was around this time (A couple of months ago) that the computer would turn on and off on its own. Up to this point the battery would hold a charge but as of recently the battery will not hold a charge. This past Sunday she had no internet connectivity. When trying to get online she received an error message about something expiring. She called tech support at AVG. Based on what she told tech support they accessed her laptop remotely and told her she had the Alureon Virus. That is when she called me. On Tuesday, I started her PC in safe mode with networking and ran the scans outlined in the following thread:

    http://forums.majorgeeks.com/showthread.php?t=35407

    followed by:

    http://forums.majorgeeks.com/showthread.php?t=139313

    I have attached all scans from my work. When I was done, I started up the PC normally to see if anything had changed. My friend informed me that it was starting up much slower than it had ever done before. I was able to get online in normal mode by unchecking the work offline option in the file menu of Internet Explorer. Tonight I disabled the Malware Bytes Anti-malware at startup which I believe has resolved the speed issue we experienced on Tuesday.

    When I return the laptop, I will let her know that she can increase startup speed even more by disabling some of the processes she currently has enabled or installing more RAM if this is expandable but she is a what I would say is a low risk user for the PC as she only uses it primarily for word processing, surfing the web where she may view videos on youtube and do some research for writing. So she and I recognize this is an older laptop and speed is not going to be the best and that is OK. I think I have it back to what she would expect.

    The scans did not reveal much but I would like to be sure I am not missing anything and for the scan that did reveal something, what corrective action I need to take. Can you review them and advise if there is anything revealed in the log files that I need to be concerned about before returning the laptop to my friend? Thank you for your help and time.
    Sincerely,
    Fred
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you attach the MGLogs.zip from running MGTools.exe please?
     
  3. pawville

    pawville Private E-2

    Thank you for the prompt reply. I realized I forgot to attach the requested filed after logging off for the night. I have attached the mglogs.zip file. Thank you again for your help and time.
    Sincerely,
    Fred
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm, I am not seeing signs of Alureon...

    If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Re run Hitman and have it delete Potential Unwanted Programs


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O1 - Hosts: 91.212.65.122 antiwareprotect.com
    • O1 - Hosts: 91.212.65.122 www.antiwareprotect.com
    • O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    • O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    • O4 - HKCU\..\RunOnce: [supportdir] cmd /c "rmdir /q /s "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{1A07F627-0F8F-43EE-B667-38908DF85911}""

    After clicking Fix exit HJT.

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 3 detections:

    • [RUN][SUSP PATH] HKCU\[...]\RunOnce : supportdir (cmd /c "rmdir /q /s "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{1A07F627-0F8F-43EE-B667-38908DF85911}"") -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-3396239505-60073489-911017477-500[...]\RunOnce : supportdir (cmd /c "rmdir /q /s "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{1A07F627-0F8F-43EE-B667-38908DF85911}"") -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    Run Ccleaner, not the registry scanner just the cleaner itself.
    Re run RogueKiller - just a scan and attach log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. pawville

    pawville Private E-2

    Hello,
    I have completed steps up to running RogueKiller. I have attached the updated log file. Note that I am performing all tasks in safe mode (not sure whether it is necessary or not). My scans did not find all suggested threats in your post as indicated (I have changed the font color of those that I did not find in red. I will complete the remaining steps in your post after this reply. Should I rerun these steps in a normal system start up? What else, if anything, should I do. Thank you again for your help and time.
    Sincerely,
    Fred
     

    Attached Files:

    Last edited by a moderator: Mar 30, 2013
  6. pawville

    pawville Private E-2

    Ccleaner ran and RogueKiller ran again (in normal start up mode to see if different scan results would appear....not so much). Log file attached.
     

    Attached Files:

  7. pawville

    pawville Private E-2

    Updated MGlogs.zip file attached (ran in normal start up mode).
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Seeing nothing in those logs that needs taking care of. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. pawville

    pawville Private E-2

    Thank you for your help with this. I will perform the close out tasks listed in your last post. One concern I have is with the malware software. To leave it enabled on the PC literally cripples the PC to where it takes an extremely long time to start up and just generally use the PC. Ok to leave on, disabled, but use as a scanning tool on a regularly scheduled basis (enable as needed)?

    I also performed a PC analyzer scan using AVG Internet Security 2013 (which I uninstalled and reinstalled due to their tech support telling my friend it did not install correctly the first time). It found 297 registry errors and over 5K junk files and 9 broken shortcuts. I am hesitant to fix these which it offers one time for free or you can pay for a service through AVG.

    Any thoughts?

    Again, thank you for your help and time.
    Sincerely,
    Fred
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The first question should be asked in the software forum. As foo the reg errors avg finds, leave them alone. That's my opinion. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds