Network infection - need advice on where to start

Discussion in 'Malware Help (A Specialist Will Reply)' started by Off White, Apr 27, 2014.

  1. Off White

    Off White Private E-2

    I've got a malware issue that has spread across my home network and presently affects four computers, and there is a fifth I haven't examined. It's one of those "update your video" type things, with several bogus messages, pop-ups, and browser redirects.

    I've done the read-and-run-me-first process on one machine, and nothing much turned up. On another machine, AdwCleaner found some items. Tdskiller didn't find anything, but OTL found some suspicious items and something rootkit it didn't like. Gmer gave me a blue screen of death. Ultimately, it sunk in that I really don't know how to start with something that has spread through my network, so I'd deeply appreciate some advice on how to start. I need a coherent approach rather than just flailing around.

    thanks
    Off White
    Tenino, WA
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :)

    As time consuming as it may be, you should really run through the malware removal procedures on each of the 5 machines. Let's just start with computer number 1 for now.

    I'll link to the procedures below:

    READ & RUN ME FIRST - Malware Removal Guide
     
  3. Off White

    Off White Private E-2

    Here are the reports from machine 1. I assume we don't need to worry about isolating computers from each other until we start fixing things?

    thanks

    Off
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Machine #1 is clean. I am not seeing anything to do at all with it. Follow final steps now and move onto machine number 2. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  5. Off White

    Off White Private E-2

    Machine 1 doesn't act clean: using firefox results in extra windows opening to some Onclick.ads site, with the content blocked, and these keep opening periodically. Chrome brought up some spurious "get paid for reviews" screens that were identical on machine 3.

    Here are the logs on machine 2. MGTools didn't want to run, the computer claimed to not know what to do with a .bat file. Opening it from the folder on the C drive didn't work either, I had to use the command prompt and dust off my DOS skills to navigate to the folder and run it that way.

    I'll upload the logs on machine 3 momentarily, they're also finished.

    I figured I'd do this stuff with my Sunday, but what are you doing working today? I'm impressed. :)
     

    Attached Files:

  6. Off White

    Off White Private E-2

    Machine 3 logs attached
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I do this every day of the week. :)

    OK, before I move onto machine 2 & 3 I would like to pick you up on what you said about the browsers still acting funky. (Firefox and Chrome)

    Let's do this:

    Reset Mozilla Firefox to Defaults
    Reset Google Chrome to Defaults

    Did that help at all??
     
  8. Off White

    Off White Private E-2

    Resetting browsers brought no relief. All browsers on all five computers are compromised, either new tabs or windows open, often involving appimat.com. The fifth computer has been off since last wednesday afternoon, and when i turned it on today, with all other computers on the network shut down, it had the same problems. Can this be something in one of my three routers? On the network hard drive?

    Here are logs for machine 4
     

    Attached Files:

  9. Off White

    Off White Private E-2

    Not bumping, just needed more upload slots. Superantispyware log and aswMBR log from machine three, the only scans that seem to have turned anything up. SAS says trojan Tracur, but I think the five scans in read me run first came up clean.

    Apologies if uploading logs you haven't requested is a huge faux pas, I want to be both helpful and a good citizen.

    thanks
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please stop attaching more logs until we have dealt with each machine. It's alot to do in one thread as well.

    For machine number 1 I want you to do this:

    We are going to be uninstalling your old version of FireFox and installing the new version. (Except we will use Revo Uninstaller to do the job) So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bookmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files (x86)\Mozilla Firefox
    • C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    -------------------

    Now Uninstall Google Chrome with Revo Uninstaller too please. Then reinstall.
    Let me know afterwards how machine #1 is doing.
     
  11. Off White

    Off White Private E-2

    No, both browsers are still compromised.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, what I'm going to do is fix all that I can SEE needs fixing on each machine and then at the end we can weigh up what issues remain. I assume each time we run fixes on a machine all the OTHER machines are disconnected from the network?

    Machine #2...

    Re run Hitman Pro and have it remove all that it finds.



    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.






    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Tell me what problems remain with this machine.
     
  13. Off White

    Off White Private E-2

    Yes, I've only been connecting one computer at a time to the network, seemed prudent.

    Machine 2 still has the browser behavior, either new tabs or new windows that open. Today's redirect seems to be Parker Grand Casino, had that on Machine 1 when it was connected, and now here on Machine 2.

    JRT wouldn't run from the desktop, Windows claimed to not know what to do with get.bat. I chose notepad to open it, saved it to desktop as get.bat, and ran it from the command prompt. Any ideas about this?

    My phone also connects to the network, though I haven't had any browser misbehavior on it. Does the different OS (android) make it not an issue?

    thanks
    Off
     

    Attached Files:

    • JRT.txt
      File size:
      3.5 KB
      Views:
      1
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So your browsers are actually redirecting you to different websites or are you saying you are seeing pop ups about these things?

    Did you mean Getlogs.bat? You might have some operating system/software problems.

    I know nothing about Android, sorry. :(
     
  15. Off White

    Off White Private E-2

    Sorry for the improper use of the term, it's not really redirecting, just opening new tabs within the browser (typically in chrome) or a new window (typically in firefox). These ARE sites I haven't clicked, and the same range of links show up on different computers. Without adblock extensions working, it will lock up and I have to go to the Task Manager to shut down the browser.

    When I clicked "jrt.exe" it opened an extraction progress bar, and apparently it runs a batch file named "get.bat" as part of the process. Windows brought up the "which program to run this" screen. I had this happen before (somewhere in the MGtools process), but I can't recall if it also happened on machine 2 or a different one. In that instance the batch file was in the MGTools folder and was easier to run from the command prompt, with JRT it was somewhere in the .exe process and I had a separate step to create a batch file I could run. It was definitely from JRT, not something else, and JRT ran fine when I opened the batch file via command prompt.

    No worries on the android thing, I don't think the phone is involved.

    NEW QUESTION/DIAGNOSTIC OPPORTUNITY:
    I have a sixth computer, one of the laptops I supply to my employees, and I replaced the hard drive and I'm in the process of re-installing windows 7 and assorted software. The OS is installed and working, but I haven't connected it to my network yet. Should I avoid my network at all costs with this clean machine, or is it a useful experiment to connect it to the network with all my other computers turned off and see if it gets infected? As it is freshly set up, I could just wipe and reinstall Windows again, without adding another thing to this thread.

    I'm sorry to present such a pesky project. :(
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Aw no need to be sorry. We are here to help and if I can't sort it out I'll get Chaslang on the case. He's an extremely busy man though so we'll have to be patient. :)

    Machine #3...


    Did you purposely set this restriction yourself? I assume so.

    Also in your very first post you said:

    Do you have the log please?
     
  17. Off White

    Off White Private E-2

    I couldn't say if I set that restriction, it doesn't ring a bell, but my wife is the one who uses IE.

    I've attached a recent OTL log (along with the Extras log OTL created), but in reviewing things I think it was aswMBR that flagged something in red, and SuperAntiSpyware declared something a trojan. Scanning the SAS declared suspect c2mp/updatechecker.exe file with SAS confirms the flag, but scanning it with MBAM says its fine. I attached Machine 3 logs for aswMBR and SAS a few posts back, so I won't do that again.

    Here on Machine 3, curiously, I wasn't getting the usual new tabs popping up in firefox or chrome, but opening IE stirred the beast, and I had to kill the process with Task Manager to get it to close, so whatever this thing is, its still loose on this computer.
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good morning. :)

    For machine #3.


    We need to run an OTL Fix

    • Right-click OTL.exe to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :otl
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.



    Please download GMER and save it to your desktop:

    • Unzip (extract) it to your desktop.
    • Disconnect from Internet and close all running programs.
    • There is a small chance this application may crash your computer so save any work you have open.
    • Double-click gmer.exe to run it.
    • Let the gmer.sys driver to load if asked.
    • If it gives you a warning at program start about rootkit activity and asks if you want to run a scan... click NO.
    • Click the Rootkit tab.
    • Make sure all the boxes on the right of the screen are checked, EXCEPT for "Show All".
    • Then click the Scan button. Wait for the scan to finish.
    • Once done, click the Copy button.
    • This will copy the results to the clipboard. Open Notepad and press CTRL + V to paste the log, and save it to your desktop. Attach this log to your next reply.

    NOTE: If you're having problems with running gmer.exe, try it in Safe Mode. This tool works in Safe Mode whereas many other rootkit revealers do not.
     
  19. Off White

    Off White Private E-2

    Here's this morning's logs from machine 3.
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am sorry. I think I may have just found what might be causing the problem.

    Is this installed on every machine?
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also re run Hitman for machine #4 and have it remove what it finds.
     
  22. Off White

    Off White Private E-2

    Not sure if its on every machine, but I know its on 1, and likely on 2.

    Nothing to be sorry about, it would be great to have an angle on this thing.

    I'll re-run hitmanpro on machine 4, let me know if you want a log.
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK and uninstall that what I said on each machine that it is indeed installed on. Use Revo Uninstaller! :)
     
  24. Off White

    Off White Private E-2

    I've only found exactly what you named on Machine 1, though most others had similar codec installations with an "updatechecker" that I've uninstalled. All had a version number of 4.0.8

    Ran Hitmanpro on Machine 4 and deleted some ask toolbar traces.

    Unfortunately, Machine 4 still exhibits the popup tabs/window issues, with occasional lockup as does Machine 5. Machine 1 seems okay, but I need to go do some work on it, so we'll see how it does.
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So far only machine 4 and 5 are affected? (correct?) Surf around a while and let me know if the other computers are okay.
     
  26. Off White

    Off White Private E-2

    Machine 1, the only one I've had time to mess with, is definitely still infected. Machine 3 might be clean, at least I haven't had a reaction in the few minutes I've browsed around. Four and Five definitely have problems too. Haven't fired up Two recently.

    I'm going to run out of time to mess with this shortly, I have to leave town on Saturday morning and I had too much to do even before this malware issue cropped up. I can do one more round of stuff, then I'll have to put things on hold until Thursday.

    thanks
    Off
     
  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall Mozilla Firefox and Google Chrome (Using Revo Uninstaller) on each of the machines that are affected.

    Then do this for each machine affected:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    (Label the logs appropriately for each computer)

    Surf around on each of these machines just using Internet Explorer. Do you have any issues then?
     
    Last edited: May 2, 2014
  28. Off White

    Off White Private E-2

    I've run out of time, so I'll pick this back up and run these procedures on Thursday.

    thanks
    Off
     
  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK no problem. :) And when you return please start checking for any unwanted extensions or add ons to each of the browsers on each of the affected machines.
     
  30. Off White

    Off White Private E-2

    I'm back, but out sick today, but hopefully I'll get to mess with at least one of the affected machines, however I had an idea I wanted to toss out there.

    Is there a chance Dropbox could play a role in all this? A few months back I noticed it had been hacked, with an unknown user logged in. I booted the user and wised up to the two step verification business, but they had access for a number of hours. Dropbox is installed on all my machines, as well as the employee laptops, two of which seem to have some issues, though not necessarily identical to what I have going on.

    thanks
    Off
     
  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It might have something to do with it. Unsure. One thing I need to ask, are pop up blockers installed on each of the browsers on each of the machines?
     
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do any of the pop ups you've had look like this? :confused
     

    Attached Files:

  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now, I'd also like for you to consider resetting your router. This might just clear it.
     
  34. Off White

    Off White Private E-2

    I'd have to catalog the extensions on each machine to know for sure. Most have Ad-Block or Ad-Block Plus on both Firefox and Chrome. I know one machine has a fairly feeble limited version on Explorer. I'll start with the revo-uninstall of chrome and firefox on machine 2, and post the MGlog and a list of extensions/add-ons found. That's the Windows tablet and and I can work from bed. :zzz

    That screen you posted isn't exactly like ones I've seen, but its somewhat similar, usually about updating a video player or codec.

    You'll have to walk me through resetting my router(s) if its more complicated than just unplugging, waiting, and plugging back in. I have a dsl modem/wireless router and an additional wi-fi router next to it, another wi-fi router 200' away in the office, as well as a network hard drive, and my network skills are minuscule.
     
  35. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Pop into the software forum. Ask about how to reset your routers. Then as soon as you have successfully done that post back here and let me know if the problem has gone away. ;)
     
  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. Are you still with us? :)
     
  37. Off White

    Off White Private E-2

    I am, though on a train in North Dakota at the moment. I have had machine 2 with me on the trip, and haven't had any symptoms since I left, I'll have a report on other computers early next week, and I still need to reset routers, but its possible we've done something to correct what was going on.

    Thanks! Off
     
  38. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would imagine it's your router that needs resetting yes. Well good luck on your trip and let me know more as soon as possible. Thanks.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds