Murofet Malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by vvgomez, Apr 17, 2018.

  1. vvgomez

    vvgomez Private First Class

    Hello,

    My internet provider detected a Murofet Malware in my network, apparently it runs under windows platform. I did a scan with SpyBot Search & Destroy that detected and quarantined registries related with slimcleaner/slimware utility, which I don't remember I installed, but not sure if that could be the culprit.

    I am attaching the logs requested for your review hoping you could give me a more clear diagnostic of the health of this computer.

    Thank you for your time and help.

    vv
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This virus hasn't really been seen since 2010. But let's run a few other things.

    Please download the latest version of FRST the below link.
    Farbar Recovery Scan Tool and save it to your Desktop.


    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  3. vvgomez

    vvgomez Private First Class

    Thank you for your soon response!
    Here are the logs.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, so far I am not finding any malware. Have ADWCleaner remove what it found.

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)

    You have Zemana installed, so please run it and attach its log.
     

    Attached Files:

  5. vvgomez

    vvgomez Private First Class

    It took me some time to complete the scan with Zemana, but finally I got the log...
    Thanks,
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Nothing there. Hang out for a while and see if you get any notices from you ISP. You did do what I asked you to do in post #4?
     
  7. vvgomez

    vvgomez Private First Class

    Oh, yes. With the long scan I forgot there was another log pending. Please, find it attached.
    I also removed the files detected by ADWCleaner .
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good. Guess all we can do at this time is wait and see.
     
  9. vvgomez

    vvgomez Private First Class

    I'll let you know if I have another warning.
    Again, thank you so much for help and time.
    vv
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome. Let's leave everything as is until we are sure we can clean up.
     
  11. vvgomez

    vvgomez Private First Class

    Hi TimW,

    Unfortunately, my internet provider insists that I am still infected with this Murofet virus. It is very frustrating. Not sure what to do.
    Any suggestion?

    Thank you,

    vv
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  13. vvgomez

    vvgomez Private First Class

    I told them so, but they insisted that their security scanner is never wrong.
    I'll get back to you after the scan
    Thank you!
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'd be interested to know what scanner they are using.
     
  15. vvgomez

    vvgomez Private First Class

    That was a long scan but here is the log.
    I see mostly old files from an old laptop backup and ccleaner updates in the download folder, but a couple of files look suspicious. Hopefully, this scan could detect the famous Murofet virus.
    Thank you for your time.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTL to your desktop.

    Double-click OTL.exe to start the program.
    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code
    Code:
    :processes
    :killallprocesses
    :files
    C:\Users\v\Desktop\COPY HD 500\Dell laptop copy\Users\EDITINGUNIT\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\775a696b-350ebb83
    C:\Users\v\Desktop\COPY HD 500\Dell laptop copy\Users\EDITINGUNIT\Downloads\Office 2010 toolkit by_moncho6994.rar
    C:\Users\v\Downloads\ADOBE\ox\crackadobe.rar   
    C:\Users\v\Downloads\Adobe cc\Adobe CC 2015 + Patch Gametime Gameplays.zip       
    C:\Windows\Installer\1611bd.msi       
    C:\Windows\Installer\MSIA1D9.tmp   
    C:\AdwCleaner\quarantine\v1\20180417.223355\1\Downloaded Installers\{06E0CADE-89B2-4EFD-B0AF-0DDCE4400E70}\setup.msi#7B238CD47778005F
    
    :commands
    [PURITY]
    [EMPTYTEMP]
    [REBOOT]
    
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.
     
  17. vvgomez

    vvgomez Private First Class

    Here is the log!
    Thx
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, let's see if that satisfies them.

    Warning about cracked software Cracked Software.
     
  19. vvgomez

    vvgomez Private First Class

    Do you think anything killed there could have been a murofet malware?
    Thank you for all your help!!!
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There was a trojan associated with one of the files. However, you can't go by malware "names"...as I said earlier, that malware hasn't really been seen for a long time. It is more likely that the cracked software is to blame.
     
  21. vvgomez

    vvgomez Private First Class

    I see. The files deleted are very old, too, so they could be the ones to blame as you said.
    It is very frustrating because the specialists I talked with at Rogers are not really specialists and they just keep repeating over and over the same with no more details. Now, I have to wait for the next scan to see if their super scanner detect this bug or not.

    I really appreciate all your dedication and time fixing my problem.
    I'll keep you posted.
    Thank you so much,

    vv
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  23. vvgomez

    vvgomez Private First Class

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No...sorry. Apparently they have taken down their online scanning.

    http://support.f-secure.com/enu/home/ols3.shtml#

    Run their online scanner.

    • Follow the Instruction Here for installation.
    • Accept the License Agreement.
    • Once the ActiveX installs,Click Full System Scan
    • Once the download completes,the scan will begin automatically.
    • The scan will take some time to finish,so please be patient.
    • When the scan completes, click the Automatic cleaning (recommended) button.
    • Click the Show Report button and Copy&Paste the entire report in your next reply.
     
  25. vvgomez

    vvgomez Private First Class

    Ok, no problem.
    Thx
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You just need to click on their online scanner...it will download ( choose desktop ) and then click it to run.
     
  27. vvgomez

    vvgomez Private First Class

    The scan finished all clean, but it didn't show any option to get the report at the end, so I hope this one is the right one I found under programdata/f-secure. Please, let me know if it is ok. Thanks.
     

    Attached Files:

  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's ok.....back to waiting. :(
     
  29. vvgomez

    vvgomez Private First Class

    Yes, thank you again.:)
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Question .... are you connecting thru a router supplied by Rogers?
     
  31. vvgomez

    vvgomez Private First Class

    Yes, it is a Hitron CODA
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Any update?
     
  33. vvgomez

    vvgomez Private First Class

    Not yet, but last time they call me back after two weeks with the same issue. Honestly, I think they are picking up a false positive.
    Thank you for keeping up with my case.
     
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Thanks....keep me informed. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds