Problems caused by whitesmoke and offerbox malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by NewLink, Feb 25, 2011.

  1. NewLink

    NewLink Private E-2

    sys specs
    ---------
    HP Pavilion t365.be (custom model)
    Pentium 4 3GHz
    1 Gb DDR
    C:/ 80 Gb HDD
    D:/ 4.36 Gb HDD
    Samsung DVD-ROM
    HP DVD-writer +r +rw
    Nvidia Geforce fx5200
    Windows XP home editon SP3
    ---------

    Recently, when looking for pics for my mp3's I suddenly came across a site that started installing an app called whitesmoke on my pc.
    Microsoft Security Essentials detected 2 trojans and removed them.
    I also have Symantec Endpoint Protection and since yesterday avira antivir on my pc. Some peeps told me to remove two of them to avoid conflicts.
    I haven't done so (yet).

    After the install of whitesmoke and offerbox malware, symantec started to report backdoor tidserv request2 problems.
    I uninstalled the whitesmoke and offerbox malware programs, but the problems persisted.
    Here is a sample of the log:

    [SID: 23615] HTTPS Tidserv Request 2 detected.
    Traffic has been blocked from this application: C:\WINDOWS\system32\svchost.exe

    [SID: 23621] HTTP Tidserv Request detected.
    Traffic has been blocked from this application: C:\Program Files\Internet Explorer\iexplore.exe

    [SID: 23615] HTTPS Tidserv Request 2 detected.
    Traffic has been blocked from this application: C:\Program Files\Internet Explorer\iexplore.exe

    I tried tdss killers from symantec and malwarebytes (iirc) but both found nothing.
    I ran a symantec scan and an avira scan, and both also found nothing.
    Also a S&D scan didn't find anything.

    After installing avira, it reported that something tried to access D:/ autorun.inf and blocked it.

    Then someone advised me to run malwarebytes antimalware in safe mode, followed by combofix with all active security programs disabled.
    Included in this post are the mbam, combofix and hijack this logs (run in that order).

    Apparently combofix yanked out a driver that it shouldnt have (see log)...

    Is there anything I should still worry about and what about that driver?
    I am absolutely no PC-expert, that's why I ask the help of you top notch guys.

    Thx in advance.

    PS. I've only been showed to this website as of a few moments ago, so I read that I should remove all but one AV indeed. All the above has already happened as it was though...
    I guess two of these have to go now: symantec endpoint, ms security essentials, avira.
    Which is best?
     

    Attached Files:

    Last edited: Feb 25, 2011
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please also attach a log from running SUPERantispyware and MGTools.exe ---> C:\MGlogs.zip. I shall link to our procedures below for reference so you can see how to run these.

    READ & RUN ME FIRST. Malware Removal Guide

    Don't worry, we'll restore the driver.
     
  3. NewLink

    NewLink Private E-2

    After reading your post I've decided to run the readme for malware removal to the letter (including the things I already did before), so I executed all steps till this point of posting the logs.

    Additional info: I remember that I was running Google Chrome when the malware attacked and after the trojan removal by MSSE the browser would no longer load pages. Also FF encountered similar problems so I had IE8 reinstalled and also FF. Chrome is not reinstalled.

    Avira and MSSE were removed following the readme.
    The combofix log is in Dutch. I've added English descriptions for your convenience. No log info was altered.

    (additional post follows with remaining logs)
     

    Attached Files:

  4. NewLink

    NewLink Private E-2

    Here is the remaining MGtools log and a new HJT log.
    After your analysis I hope all is fine and that I can get that driver back.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Looks like the scans took care of things.

    Use windows explorer to navigate to: C:\Qoobox\Quarantine\c:\windows\system32\drivers\HP_DT313A-B14 T365.BE_YW_Pavi_QNLD350_E34NLwwBLT1_4_IYale_SASUSTeK Computer INC._V1.xx_B3.28_T040827_WXH1_L413_M1024_J80_7Intel_8Pentium 4_93_1104C8023_N104A0500_P_Z14F12F00_K_A808624D5_U808624D2_G10DE0322_O_DNVXBAR .MRK.vir

    Rename it back to disinclude the .vir extension and move it back to it's original location of: c:\windows\system32\drivers

    C:\MGtools (run from C only).exe <--- Rename back to MGTools.exe

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Did you get your driver restored okay?
     
  6. NewLink

    NewLink Private E-2

    Hi again

    Following your instructions the 6 entries were successfully removed with HJT (analyse.exe) and the regkeys were also successfully added with a message in the lines of: "data was successfully added to the registry".

    I was unable to copy, cut or rename the driver in the qoobox folder. Attempts to do anything with it just yield no response. Altering properties from the qoobox folder, like 'read only', also doesn't work.

    I've also noticed that my second combofix log again showed these for removal:

    AV: Symantec Endpoint Protection *Disabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
    FW: Symantec Endpoint Protection *Disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}

    Is this normal?

    Awaiting your next reply. Thx for your efforts.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DeQuarantine::
    C:\QOOBOX\Quarantine\C\WINDOWS\SYSTEM32\DRIVERS\HP_DT3~1.VIR
    QUIT::
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\DeQuarantine.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Did that restore it?
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    This is a standard part of ComboFix's header information, to show installed anti-virus and firewall programs if present. They are not indicated for removal.

    dr.m
     
    Last edited: Feb 27, 2011
  9. NewLink

    NewLink Private E-2

    The combofix procedure did not unlock that file but I did indeed get a cf update.
    The file is still totally unresponsive to everything.
    Funny thing is, I can now see what is inside the backenv folder that was totally inaccessible before.

    @dr.m thx 4 the .nfo

    Edit: did you rename it to "HP_DT3~1" and will it work under a different name?
    There is indeed such a copied file with that name in my sys32/drivers now but with that name and no .MRK extension.
    The original file is still locked in qoobox.

    Additional thing I noticed: where the original file still is the folder now says that it is empty while I can still see it inside.
     

    Attached Files:

    Last edited: Feb 27, 2011
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just to be clear,you can see the above?
     
  11. NewLink

    NewLink Private E-2

    Yes I can but normally when you click a file it should show the full name.
    This stays shortened as an unclicked file with ... at the end.

    The only options available with rightclick are: open, scan for viruses with s&d and copy to- , but it doesn't respond to anything.
    The popup window when pointing at it doesnt show the full name either, but it does say .vir file.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  13. NewLink

    NewLink Private E-2

    Here is the updated log.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please do the following:

    1. Click on the Start button, then click on Run...
    2. In the empty "Open:" box provided, type cmd and press Enter
    • This will launch a Command Prompt window (looks like DOS).
    3. Copy the entire bold text below to the clipboard by highlighting all of it and pressing Ctrl+C (or after highlighting, right-click and select Copy).
    4. In the Command Prompt window, paste the copied text by right-clicking and selecting Paste.
    5. Press Enter.
    6. When successful, you should get the below message within the Command Prompt:
    * "1 file(s) copied"
    7. NOTE: If you didn't get this message, stop and tell me first. Executing any following instructions are dependent upon this file being successfully copied.
    8. Exit the Command Prompt window.

    Now take a look directly in the root drive C:\ Do you now have the long names .MRK file (with a .vir extension?)
     
  15. NewLink

    NewLink Private E-2

    "The syntax of the command is incorrect."
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    My apologies. We will get the file restored very soon with a batch file. I am going to edit out the below instructions I had included to try and restore the file using combofix because it will not work. I'll post back soon be patient.
     
    Last edited: Mar 4, 2011
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Create and Run Batch File
    • Open Notepad and copy/paste the entire contents of the codebox below, into Notepad:

    Save this as copy.bat Choose to Save type as - All Files and where to save - Desktop - then close the Notepad file.
    Double-click on copy.bat to run it.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  18. NewLink

    NewLink Private E-2

    A DOS window appeared briefly while running the bat from the desktop.
    The driver is not present in C/windows/system32/drivers.
    Here is the updated log.

    The driver did copy with a different name as I described in post #9. Wouldn't it just be possible to rename it to its original name?
    Its size is identical to the driver stuck in qoobox (3.61kb).
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and save docp to your desktop and then double click to run it.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  20. NewLink

    NewLink Private E-2

    All that was left was this pesky driver, but now it's no use anymore.
    A plastic hook broke from my cpu-fan releasing an iron clamp that fell down and fried the motherboard. Needless to say that the pc is dead.

    Anyway thx alot for your help Kestrel. I'm on a laptop now but might ask in a different section on how to save the hdd's data.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ouch. Sorry to hear about your troubles. :(
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds