My system compromised by malware?

Discussion in 'Malware Help (A Specialist Will Reply)' started by BMUS, Jan 8, 2009.

  1. BMUS

    BMUS Private E-2

    My system may be compromised by malware/spyware/virus or whatever. Attached is my Hijackthis log. I would appreciate any help I can get. Thank you.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!


    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.

    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide


    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid addtional delay in getting a response, it is strongly advise that after completing the READ & RUN ME you also read this sticky Don't Bump! It Only Hurts You!!!. Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. BMUS

    BMUS Private E-2

    I have gone through the "Read and Run Me First" to the point where I am now at the Windows XP Cleaning Procedure. I notice that Combofix.exe is listed there for usage. Somewhere else at MajorGeeks I had read that Combofix was no longer used, because there are now problems associated with it. A few weeks ago I had downloaded Combofix to use it to do an uninstall of Combofix, because last winter I had forgotten to do this after my first session with MajorGeeks last winter. So, I downloaded it to my desktop and then scanned it with McAfee before running it. McAfee said that it was infected with RemAdm-ProcLaunch!171. I think I was finally able to get rid of it. So, does MajorGeeks want me to download and use Combofix?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, we would like you to run ComboFix....but you need to disable McAfee in order to run it.

    We also need the other requested logs:
    SAS
    MBAM
    C:\MGLogs.zip
     
  5. BMUS

    BMUS Private E-2

    I already have Spybot S&D and Malwarebytes' Antimalware running on my system. Is that ok, or should I remove them and then reinstall them?
     
  6. BMUS

    BMUS Private E-2

    Combofix did not run without problems. I disabled McAfee virus scan and firewall. I deactivated Spywareware Terminator. I turned off Resident “SD Helper” in Spybot and unlocked the Hosts file and the IE start page. Then, I ran Combofix. Combofix ran well past the 41 stages listed in the instructions; I saw at least 55 stages. While Combofix was running, a window popped up stating “SQL Server Service Manager has encountered a problem and needs to close. We are sorry for the inconvenience. If you were in the middle of something…etc.” I did not hit the Debug, Send Error Report, nor the Don’t Send button. I just let Combofix continue to run. Eventually, that pop-up window went away. Then another window popped up. It wasn’t there for very long. I think I saw the letters “SQL” in the window along with some other information. The window did not persist long enough for me to read any more of what was there. Combofix eventually rebooted my computer. I think I should have used Autoruns to disable the start-up of McAfee and Spyware Terminator and maybe some other applications, because they started to run when Combofix rebooted my computer. I don’t know what other applications might have started upon rebooting. I know that I was not supposed to touch my computer until Combofix had finished, but I had to allow Spyware Terminator to permit a lot of Combofix files to run. It looked like all of the files that Spyware Terminator was asking me about permission to run, were associated with Combofix, but I could not swear to that. McAfee tells me I now have a “pup” called “RemAdm-Proclaunch!171”.
     

    Attached Files:

  7. BMUS

    BMUS Private E-2

    Here are all 4 log files.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing alot of malware on your system. We can do a little cleaning:

    Please disable all anti-virus and anti-spyware programs while we do the following ( be sure to re-enable when we are finished):


    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    C:\Documents and Settings\FRANK\Desktop\ ---> You need to clean this up. You should only have links as this is a great place for malware to hide.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  9. BMUS

    BMUS Private E-2

    When you say I should only have links on my Desktop, does that mean shortcuts and internet links?

    When I double clicked Avenger.zip to unzip it, it simply opened up Avenger; I did not see the option to save Avenger.exe to my desktop and run it from there, so I simply pasted everything from the Quote Box into the "Input Script Here" and hit the Execute button. Did something go wrong, or is that o.k.? It seemed to run, then my system started rebooting, then I typed in my password, but then my system proceeded to reboot again, then I typed in my password again and then it finished the booting process. Avenger.txt did not pop up on my desktop after the reboot completed, however, I did locate it a C:\.

    I have attached my Avenger.txt file and MGlogs.zip file.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes.

    Your logs are clean.....If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  11. BMUS

    BMUS Private E-2

    Thank you for your help.

    Spyware terminator found these Unclassified Threats:
    1-c:\32788r22fwjfw\hidec.exe
    2-c:\ 32788r22fwjfw \pv.cfexe
    Should I be concerned; should I delete them? Should I let Spyware Terminator remove them?
    Are these left-overs from Combofix? Did I misuse Combofix before I came to MajorGeeks this time?


    Mcafee found a pup called RemAdm-ProcLaunch!171, File Name: C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP11\A0013749.exe
    What should I do with this pup?

    Is it o.k. to get rid of any folders or files with the names Avenger, Combofix, Catchme, NirCmd, Qoobox, etc.?

    After I finished following your last set of instructions, I cleaned off my Desktop as you had recommended. My system was still very slow after all this.

    Sorry for the long delay, but I’ve been working on getting my system to run faster by updating my software with patches. I was finally able to get xp sp3 installed, by running subinacl.exe to give me access so that I could install. Since doing some more clean-up and getting up to date on windows software and taking care of Secunia’s recommendations, my system seems to be running faster, however, not as fast as it had some time ago. I’m continuing to look for things I can do to improve my systems performance. Would you recommend that I now go to a software forum?

    BTW, what did you find on my system?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Delete them or let Spyware Terminator do it.

    That will only go away when you toggle system restore as noted in step 7.

    Those should also be removed when you do step 2 in my final instructions.

    Yes, as there could be numerous reasons for a slow machine that does not involve malware.

    And you are most welcome.
     
  13. BMUS

    BMUS Private E-2

    I toggled system restore as noted in step 7 and I also performed step 2 exactly as instructed, however, those files are there. Should I download Combofix again from the MajorGeeks site and perform the uninstall again? If I do, will the file folders C:\32788R22FWJFW\ and C:\Qoobox\ be deleted? The file folder C:\32788R22FWJFW\ contains 114 objects. I already manually deleted hidec.exe and pv.cfexe from that file folder.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just delete:
    C:\32788R22FWJFW
    C:\Qoobox

    Then look for and delete if found:
    ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds