More attacks even after Scans

Discussion in 'Malware Help (A Specialist Will Reply)' started by mcemily, Apr 24, 2012.

  1. mcemily

    mcemily Private E-2

    Four weeks or so ago, a bunch of Fake Scan windows appeared and I closed them on impulse - rather than KILL them or let my Micro Trend kill them. After that, Trend Micro started reporting multiple attacks when it usually reports zero or sometimes a few, like on holidays. The PC went crazy, popping up random websites, playing music, etc. etc. Trend Micro scans found a threat it could not remove. The Rescue disk could not find it. One report called it a TDSS.
    Found Major Geeks after researching TDSS and TDL4 etc and finished running all the scans, yesterday. Today, the computer is still dog-slow and Trend Micro is reporting multiple attacks. Help!
    Would greatly appreciate your assistance!!!
    mcemily
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    It looks like you have one or more infection partitions on your hard disk. The one in read is most likely an infection and the one in purple is questionable
    Code:
              Disk #0, Partition #0       49,319,424      Unknown                     
    TRUE      Disk #0, Partition #1  112,842,616,320  Installable File System     
              [B][COLOR=purple]Disk #0, Partition #2    2,146,798,080    Extended w/Extended Int 13  [/COLOR][/B]
          [COLOR=red][B]    Disk #0, Partition #3    4,984,519,680    Unknown[/B][/COLOR]       

    Do you have your Windows XP boot CD?

    Your Malwarebytes log shows that you took no action. Did you fix what it found?


    Also goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now please also download MBRCheck to your desktop.


    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
    Note I also suggest that you uninstall Ad-Aware 2007. It is very old and ineffective. It outlived its usefulness many years ago ( even before 2007 ).
     
  3. mcemily

    mcemily Private E-2

    NICE!! I got a 'Done!' message from MBRcheck.exe!! YAH!

    To answer your questions:

    Windows XP boot disk? I have Trend Micro Rescue disk, I have not made a system disk and the original XP discs are not handy. But I can probably find some from one or another of our computers, if needed.

    (I've inherited this laptop from my daughter - old but works fine for me.)

    Remove Malware? Yes, I saved the log to be sure not to loose it before cleaning, sorry.

    Ran TDSSKiller -- Whoops, did not save log! It found something like 25 suspicious files which I skipped. It found one TDSS which I set to CURE. It also found the TDSS File System which I believe I set to Skip.

    Should I rerun the TDSSKiller to get a new log???

    I have attached the MBRCheck log.

    How important is it to know how the malady was acquired? I remember Googling for Easter Restaurants before the trouble set in and getting a 'BAD' notice on a link. In addition, my hubby's MAC bit the dust at this time so he started using my PC - but says he didn't do anything, go anywhere but who knows. :-D

    And yes, should have removed AdBLock a long time ago. Will do.

    Thank you, Obi Wan, you were may only hope!

    Em
     

    Attached Files:

  4. mcemily

    mcemily Private E-2

    Whoops. Just found the original TDSSKiller log.
    Was expecting it to be on desktop. Sorry...
    Here it is!
    M
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need a Windows XP boot disk. A TrendMicro Rescue Disk will not suffice. If you cannot find yours, then do what is in the below link and tell me when you have successfully been able to do this:

    Using ARCDC to get the Recovery Console Command Prompt


    We don't need that info. It would be more useful to you to know what to avoid in the future.;)

    Once you make the above disk and know you can get into the command prompt of the Recovery Console, we will continue to make another boot cd with partition tools on it. But one thing at a time. :)
     
  6. mcemily

    mcemily Private E-2

    Done. Recovery Console works! Ready for next step.
    THX Em
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now boot off of the newly created GParted CD.
    http://img534.imageshack.us/img534/5492/gpartedsplash011010.th.png
    You should be here...
    Press ENTER
    http://img819.imageshack.us/img819/7286/gpartedkeymaps.th.png
    By default, do not touch keymap is highlighted. Leave this setting alone and just press ENTER.
    http://img404.imageshack.us/img404/9840/gpartedlanguage.th.png
    Choose your language and press ENTER. English is default [33]
    http://img140.imageshack.us/img140/7958/gpartedgui.th.png
    Once again, at this prompt, press ENTER
    You will now be taken to the main GUI screen below
    http://img32.imageshack.us/img32/1122/gpartedo.th.png
    According to your logs, the partition that you want to delete is 4.64 GiB
    Click the trash can icon to delete and then click Apply.
    You should now be here confirming your actions:
    http://img233.imageshack.us/img233/1533/gpartedsteps.th.png
    Now you should be here:
    http://img696.imageshack.us/img696/8471/gpartedsuccessclose.th.png
    Is boot next to your OS drive? According to your logs, your OS drive is the 105.09 GiB sized partition.
    http://img194.imageshack.us/img194/7753/gpartedboot.th.png
    If boot is not next to your OS drive under Flags, right-mouse click the OS drive while in Gparted and select Manage Flags

    In the menu that pops up, place a checkmark in boot like the picture below:
    http://img196.imageshack.us/img196/3483/gpartedmanageflagsboot.th.png
    Now press the Close button to save these changes.
    Now double-click the http://img715.imageshack.us/img715/641/gpartedexit.png button.
    You should receive a small pop up like this:
    http://img88.imageshack.us/img88/8986/gpartedexitreboot.png
    Choose reboot and then press OK.



    Boot the ARCDC boot CD again to the Recovery Console command prompt and execute the following commands pressing ENTER after each:
    • fixmbr
    • fixboot
    • exit
    The exit command above will reboot your PC. Allow it to boot into normal Windows and then continue with the below.

    Now run a new scan with TDSSKiller

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs (See: How to attach):
    • the new log from TDSSKiller
    • C:\MGlogs.zip
     
  8. mcemily

    mcemily Private E-2

    Problem -- can't boot from the gparted-live CD. I just get a flashing cursor -- waited > 5 mins.
    The CD created with ImbBrn looks good -- it contains the files and directories that I get when I unzip the gparted-live-0.12.1-1.iso to its own directory. I downloaded the latest version of gparted-live, should I have gotten a different one?
    :confused
    THX for your help,
    Em
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To make sure this CD was created properly, do you have another PC you can test it booting it with. You only want to test to see if it will boot.

    Also on your original PC when you try booting from it, make sure your PC is set to boot from CD first ( not the hard disk ). Also make sure that you do not have any removable disk ( like USB flash drives or usb external hard disks plugged in ) before trying to boot your PC up from the CD. Power down you PC and then power it back up and make sure that it is actually booting from the CD.
     
  10. mcemily

    mcemily Private E-2

    Hi! I tried a really old desktop - boot from CD - didn't work. I burned a new CD but it still didn't work.
    I will try it on my daughter's PC when she brings it home.
    Otherwise, I was able to boot from the "Windows Boot Disk" just fine - so I do understand how to boot from CD.

    My question right now is: The computer is working great again - is it still infected??
    Is it okay to use for usual stuff or should I wait until the partitions are removed?

    I like the challenge of trying to defeat this bug!!! But it is an old computer - so I may just get myself a new one for Mom's day.

    What is your prognosis - is there hope? Or may this resistance be futile?

    Thanks again!

    Em
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It sounds to me like you are not making a bootable disk. Did you burn the ISO file to the disk using the instructions given to make a bootable disk or did you extract the files from the ISO and simply burn the files to the CD?

    No you need to remove the infection in your partition table. These kind of infections can steal personal info and can be very dangerous.
     
  12. mcemily

    mcemily Private E-2

    YAH! Third time's a charm!! (I downloaded the files and did not try to multi-task this time. My problem may have been in the 'verify' step - or perhaps not - but it worked this time!!)

    Logs are attached. Unfortunately forgot to stop Trend Micro and it blocked the swreg.exe program. So I re-ran the MGtools again w/o Trend Micro. The '00' log is the first one.

    TDSSkiller said no threats found!!! Do I dare hope?

    A side question: Would malware remove files/directories? I can't find a certain directory that I used to have but I may have removed it - as a precaution.

    Thanks so much for the help!!
    Emily
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay. The bad partition is gone now. I assume everything is working okay?

    Sometimes it does but usually it is only specific locations and most of the time it just hides the folders. Which folder exactly are you referring too?
     
  14. mcemily

    mcemily Private E-2

    Thanks so much for your help!

    The laptop is running fine but I did rerun a full Malware scan and it found 9 bad files which it removed. Trend Micro found about 3 during this same time - odd because I wasn't running a Trend Micro scan.

    I'm thinking of rerunning all of the scans in the READ ME FIRST thread as soon as I get some time just to be sure.

    The missing file was a just personal file under My Documents that contained irs files - I think I may have removed them when I heard there was a concerted effort to steal refunds.

    Thanks SO MUCH!! I let you know if the trouble persists!

    Emily
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    What malware scan did you run and do you have a log to attach. Trend Micro was probably just triggered by the other scan running.
     
  16. mcemily

    mcemily Private E-2

    OH DEAR -- Just started getting a "Congratulations! You've won" audio and a redirection to an 'Obama...' website. Is it back??? Started with the 'redirection' directions and TDSSKiller found a TDSS File System but set a default Skip. So I did not remove it. The other scans seem okay. Logs are attached. (More with next post.)

    Do I have a problem again??
     

    Attached Files:

  17. mcemily

    mcemily Private E-2

    The rest of the story...

    Hope I got them all.

    THANKS!!
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

    After clicking Fix, exit HJT.


    Please delete any versions of TDSSkiller that you have and download the most current version from the below link and follow the process in it to rescan. If you see the below lines this time, then delete them

    06:11:48.0167 0348 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
    06:11:48.0167 0348 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip

    Attach the new log from TDSSKiller. Also tell me if you are still having any problems.
     
  19. mcemily

    mcemily Private E-2

    Here is the TDSSKiller log.
    Trend Micro also popped up with this 'Last Scan' log.

    I did this computer to put Audio books on a couple of Sanza Fuse WMA players last week. Could the TDSS be on the players?? Should I scan while they are attached?

    Thanks so much! I'm so glad you are around!!! :)

    Emily
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Too little, too late. We already removed those. They were in quarantine. ;)

    Potentially yes! You could run full scans with TDSSKiller and Malwarebytes while they are attached.

    Also please make sure that you have rebooted your PC and then run another scan with TDSSkiller and attach the new log. I want to make sure it was really able to fix the TDL infection.
     
  21. mcemily

    mcemily Private E-2

    YAH! I've rebooted and rerun the TDSSKiller scan - log attached. Looks good!
    And I will rescan all of our WMA players.
    THANKS SO MUCH!!
    mcemily
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome but you should not have quarantined the unsigned drivers with TDSSKiller. Those are not problems. By quarantining them, you broke all those applications and I'm not sure whether TDSSKiller has really added the ability to unquarantine yet.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds