Possible infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by mquelch, Jun 30, 2010.

  1. mquelch

    mquelch Private E-2

    Hi,

    I have a possible infection on my PC, and I've followed the instructions in the forum. I've attached the MGlogs.zip file.
    Please tell me if I am clean.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    *EDITED by dr.m - revised reply.
     
    Last edited: Jul 1, 2010
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    Step 1:
    Now download Sophos Anti-Rootkit 1.5 and save to a location you will be able to find such as your desktop
    1. Run sar_15_sfx by double clicking on it.
    2. Click Accept to agree to the EULA
    3. Click Install (if you wish to change the default installation location do so here but remember where you install to, the default is C:\SOPHTEMP)
    4. Once it finishes copying files, exit the installer

    Running the scan
    1. Navigate to the location that you installed the software to (Default: C:\SOPHTEMP)
    2. Run the sargui Application by double clicking on it. (Note: if using Vista or Windows 7, use right click and select Run As Administrator).
    3. Ensure that all three of the options are checked
    4. Click Start Scan
    5. Once the scan is complete, close Sophos Anti-Rootkit by closing the scan window and clicking Exit in the main window

    DO NOT CLICK 'CLEAN UP CHECKED ITEMS' OR ATTEMPT TO HAVE SOPHOS ANTI-ROOTKIT FIX ANYTHING UNLESS SPECIFICALLY INSTRUCTED TO IN THE THREAD YOU ARE WORKING ON

    Finding the logs
    1. Click on Start --> Run
    2. Type in %TEMP%\sarscan.log and press enter
    3. The log file will open in the default editor (probably Notepad)
    4. Click File --> Save As and save the file to your desktop or other location for easy retrieval.

    Step 2:
    Please download OTL by OldTimer, saving it to your desktop:
    • Close all open windows on the Task Bar. Double-click the OTL icon to start the program and let it run uninterrupted.
    • When the windows appears, underneath Output at the top - change it to Minimal Output.
    • Under the Standard Registry box, change it to All.
    • Check the boxes beside LOP Check and Purity Check.
    • Now click the Run Scan button at Top left and let the program run - the scan may take 5-10 minutes.
    • Do not TOUCH your keyboard until the scan completes!
      • It will produce two (2) logs on your desktop, one will pop up called OTL.txt and the other - Extras.txt. These logs are saved normally directly under your C:/ directory.
      • Now exit Notepad.
      • Exit OTL by clicking the [X] at top right.

    Please attach the below logs to your next reply:
    • OTListIt.txt
    • Extras.txt
    • sarscan.log
    • The remaining requested logs from the R & R ME FIRST guide:
      • SASlog.txt log from SuperAntiSpyware.
      • Malwarebytes Anti-Malware log

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"
     
    Last edited: Jul 1, 2010
  4. mquelch

    mquelch Private E-2

    Hi dr.m,

    Thanks for your help.
    Here are the logs.
    I had a problem with my browser being hijacked. I got a popup saying that my home page was about to be replaced. The other problem I had was when I pressed the back button on my browser, all of the url's were the same. I couldn't go back to the previous page.
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome, mquelch

    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and continue on.
    Step 2:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 3:
    Now run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following that is inside of the code box:
    Code:
    :OTL
    :Processes
    explorer.exe
    @Alternate Data Stream - 158 bytes -> C:\ProgramData\Temp:D1B5B4F1:Commands
    [emptytemp]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Open OTL again and click the Quick Scan button. Attach the new log it produces in your next reply.

    Step 4:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 5:
    Now install the latest Sun Java Runtime Environment

    Step 6:
    Please go to Start > Run and paste in the following:
    • The resultant log will be retrievable @ C:\collect.zip

    Step 7:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • updated OTL.txt log
    • C:\collect.zip

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
  6. mquelch

    mquelch Private E-2

    dr.moriarty,

    Here are the logs you requested, I couldn't find the Collect.zip file. I did a search and still couldn't locate it.
    I did not have any problems running any of the programs.

    Was I infected? If I was how was it possible when I have all the necessary protection software running?

    Thank you.
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You never attached the MBAM logs I requested.
    C:\Users\Michael Quelch\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2010-06-28 (22-21-11).txt
    C:\Users\Michael Quelch\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2010-06-29 (12-50-06).txt

    *These files indicate that something was found:
    Quarantine\BACKUP3.53943 - Quarantine\QUAR3.53943

    Downloading torrents is an easy way to get infected. I also found evidence of foistware that was installed. Re: "SearchSettings.dll"

    Please upload the following file to VirusTotal:
    • Click the Browse... button.
    • Navigate to the file C:\Windows\”ôÍ
    • Then click the Send File button
    • Either post a link to the results, or copy & paste the results into Notepad and attach the text file.

    How is your machine running now???
     
  8. mquelch

    mquelch Private E-2

    dr.moriarty,

    Here are the files.
    The computer is running good with no problems at the moment.

    Thanks for your help I appreciate it.

    Antivirus Version Last Update Result
    a-squared 5.0.0.30 2010.06.21 -
    AhnLab-V3 2010.06.21.02 2010.06.21 -
    AntiVir 8.2.2.6 2010.06.21 -
    Antiy-AVL 2.0.3.7 2010.06.18 -
    Authentium 5.2.0.5 2010.06.21 -
    Avast 4.8.1351.0 2010.06.21 -
    Avast5 5.0.332.0 2010.06.21 -
    AVG 9.0.0.787 2010.06.21 -
    BitDefender 7.2 2010.06.21 -
    CAT-QuickHeal 10.00 2010.06.18 -
    ClamAV 0.96.0.3-git 2010.06.21 -
    Comodo 5176 2010.06.21 -
    DrWeb 5.0.2.03300 2010.06.21 -
    eSafe 7.0.17.0 2010.06.20 -
    eTrust-Vet 36.1.7654 2010.06.21 -
    F-Prot 4.6.1.107 2010.06.20 -
    F-Secure 9.0.15370.0 2010.06.21 -
    Fortinet 4.1.133.0 2010.06.21 -
    GData 21 2010.06.21 -
    Ikarus T3.1.1.84.0 2010.06.21 -
    Jiangmin 13.0.900 2010.06.15 -
    Kaspersky 7.0.0.125 2010.06.21 -
    McAfee 5.400.0.1158 2010.06.21 -
    McAfee-GW-Edition 2010.1 2010.06.21 -
    Microsoft 1.5902 2010.06.21 -
    NOD32 5216 2010.06.21 -
    Norman 6.05.06 2010.06.21 -
    nProtect 2010-06-21.01 2010.06.21 -
    Panda 10.0.2.7 2010.06.21 -
    PCTools 7.0.3.5 2010.06.21 -
    Prevx 3.0 2010.06.21 -
    Rising 22.53.00.04 2010.06.21 -
    Sophos 4.54.0 2010.06.21 -
    Sunbelt 6483 2010.06.21 -
    Symantec 20101.1.0.89 2010.06.21 -
    TheHacker 6.5.2.0.302 2010.06.20 -
    TrendMicro 9.120.0.1004 2010.06.21 -
    TrendMicro-HouseCall 9.120.0.1004 2010.06.21 -
    VBA32 3.12.12.5 2010.06.21 -
    ViRobot 2010.6.21.3896 2010.06.21 -
    VirusBuster 5.0.27.0 2010.06.21 -
    Additional information
    File size: 20 bytes
    MD5 : f9f4905664c5b42b49e78efa12d1a6b6
    SHA1 : 9b706deb688bc85688246af31af821b014e72d13
    SHA256: 4dd8aaa8bd9f90459d4dc82aeddf5dcd439a7cd27b70a067e2c6ca904c717c83
    TrID : File type identification
    Generic INI configuration (100.0%)
    ssdeep: 3:uqJsn:ugs
    sigcheck: publisher....: n/a
    copyright....: n/a
    product......: n/a
    description..: n/a
    original name: n/a
    internal name: n/a
    file version.: n/a
    comments.....: n/a
    signers......: -
    signing date.: -
    verified.....: Unsigned
    PEiD : -
    RDS : NSRL Reference Data Set
    -
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    You're welcome, mquelch.

    Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds