need help with malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by dukimen, Jun 12, 2008.

  1. dukimen

    dukimen Private E-2

    My AVG and ZoneLabs icons dissapeared. Computer is slow. Cannot run CCcleaner, Spybot, Uninstaller. HAve to reboot computer every 7 or 8 clicks in FF.
    Went through Read&Run Me First.
    SUPERAntispyware works 1 minut than blue screen (see Trojan.Unknown Origin)
    Spybot does not work (not valid Win32 Program)
    Malwarebytes (log attached)
    MGtools (logs attached)
    Combofix does not work (not valid Win32 Program)

    Strange: don`t have anymore "Show hidden files and folders" in Folder options/View tab! Sure it was there two weeks ago.

    Thanks in advance
    dukimen
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The first thing you need to do is re-run MalwareBytes and have it fix everything it finds!

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from MalwareBytes.
     
  3. dukimen

    dukimen Private E-2

    Thanks for quick reply!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  5. dukimen

    dukimen Private E-2

    It looks ZoneLAbs is not loaded. I had to uninstall AVG.
    HijackThis did not fix O10 (message attached)
    I delete ONLY files in \Temp (NO folders). Just file ~DF6498.tmp left

    I don`t see much improvements at the moment except CPU is not very loaded anymore... still have to reboot PC because FF could not connect to internet after 5 or 6 clicks
     

    Attached Files:

  6. dukimen

    dukimen Private E-2

    Things are going better now.
    In meantime I ran SUPERAntiSpyware ( picture attached).
    I`ve reinstalled AVG and made two scans (pictures attached)
    I downloaded Ispfix and fix O10.
    I ran CCleaner.
    I ran MAlwarebytes and MGtools (logs attached in next post)
    Still can not run Spybot and ComboFix
     

    Attached Files:

  7. dukimen

    dukimen Private E-2

    Regarding previous post I attached logs of MAlwarebytes and MGtools.
    After all I also ran Ad-Aware (log attached).

    Tim, I appreciate all your efforts and help. Thank you very much!
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The log that you posted a screenshot of shows an infection on the E:\ drive...is that a thumb drive?

    I am not seeing anything else..what problems are you still having?
     
  9. dukimen

    dukimen Private E-2

    E:\ is logical disk of a 250GB thumb (USB) drive.
    In meantime I succesfully reinstalled Spybot and ran it.

    I still can not start ComboFix (not valid Win32 program)

    I can not reinstall ZoneAlarm (something with TrueVector service)

    This is what I see at first sight.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Don't worry about Combofix....delete it.

    For the reinstallation of Zonealarm...

    Right click My Computer and select Manage.
    Open the Device Manager under the Computer Management tree.
    Click View in the toolbar and select "Show hidden devices".
    Right click each of the klif. klin and true vector drivers and what ever else is related to Zone Alarm.
    Open the Properties and open the Driver tab.
    Under the Current Status, click the Stop button.
    Open the Startup drop down, select the Disabled.
    OK.
    Reboot.

    Now try to install it.
     
  11. dukimen

    dukimen Private E-2

    I opened device by device but there`s no trace of any ZoneAlarm drivers or anything else related to ZoneAlarm . I also tried to find any other true vector driver but nothing.

    It`s a little bit strange what happened with ZoneAlarm.
    First icon disappeared together with AVG icon.
    When I tried to close it (as you requested to close firewall) I did not find icon so I tried to uninstall it from "Control Panel" but "Add/remove programs" said that it`s already uninstalled (I am sure I did not uninstall it).
    I found it later inside "Programs" but when if I try to start it or choose Unistall it says "... not valid Win32 Program"

    And now when I was writing reply to your post my FF "freezed" again.... not exactly freeze but I tried to preview post and it could not connect to majorgeeks (or any other url I tried). And IE neither.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's see what results you have with this:

    Go to Bitdefender agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
     
  13. dukimen

    dukimen Private E-2

    We`re much further now :-D, almost at the end I hope.
    I used Bitdefender as you instructed (except I couldn`t save as .txt and I renamed it later).
    After that problem with ZoneAlarm stayed the same (= uninstall --> not valid Win32 or new install --> True vector problem).
    I tried to stop TrueVector following procedure "The process is vsmon. Start>Run> type services.msc Find True Vector Internet Monitor, right click, and choose "Disable from the small drop down menu box. Then click the "Stop" button to the left." but I could not stop it (it didn`t offer me disable or stop on right click).
    So I used part of procedure http://forums.zonealarm.com/zonelabs/board/message?board.id=AllowAccess&message.id=103 (deleting files and folders and executing .reg file) and I was able to install ZoneAlarm again.
    I went through Windows XP Cleaning procedure again (I deleted ComboFix because it still did not work and download and install it again, than OK).
    Malwarebytes was clean, so I attached MGtools and ComboFix logs only.
    At the moment I can not say if everything is Ok... I am going through regular stuff this weekend an I let you know.
    Have a nice weekend!
    Dusan
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean...but I will suggest that you note what BitDefender found.

    Let's just do some final housecleaning:

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type "%userprofile%\Desktop\cf" /u in the runbox and click OK.
    * Note: The space between the cf and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  15. dukimen

    dukimen Private E-2

    Yes, I`ve got the message :(

    I followed your procedure but avenger did not find folders to delete. I see them as files. Can I delete them?
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, my bad....

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After doing the above...are there any other issues?
     
  17. dukimen

    dukimen Private E-2

    No problem... I just didn`t know if I could delete files instead of folders.
    At the moment I don`t see any other issues related to my first escalation.
    I will be more attentive to this in future to be sure everything is Ok and more careful of course too.

    I`d like to thank you very much again. You`ve been very helpful.
    Regards
    Dusan
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are quite welcome....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds