Rogue anti-malware infection that disables executables and periodically opens sites

Discussion in 'Malware Help (A Specialist Will Reply)' started by mrpoate, Jan 3, 2011.

  1. mrpoate

    mrpoate Private E-2

    Hi,
    This morning I was infected with drive-by malware after visiting a rogue website and I was really hoping for some assistance in dealing with it.

    Let me just give a quick description of the symptoms. The infection has installed rogue anti-spyware pop-ups and alerts which spring out from both the task bar and in the centre of the desktop (above the icons and windows).

    When I attempt to open an executable file (.exe, .bat etc) it generates an error along the lines of "Application cannot be opened. *** is infected. Do you want to activate your anti-virus software now?". *** seems to be the first executable I attempt to open, and thereafter it simply closes the file immediately after opening.
    Annoyingly, this means I cannot open any anti-malware programs (along with anything else - i.e. notepad, word, etc). I am also unable to open task manager and add/remove programs from control panel. It also periodically opens up pornographic websites.

    I have read the malware removal guide on this site and downloaded all the recommended tools and programs (super anti-spyware, malwarebytes, MGTools, comboFix, CCleaner, RootRepeal, etc). Majorgeeks has actually very ably assisted me in the past, so I'm familiar with the general malware removal process. However, in this case I am not able to begin with even the preliminary cleaning steps let alone the malware scans because this infection prevents me executing any programs.

    I am running windows XP and have norton 360 installed.

    Just some quick final observations which may or may not be helpful:

    -Norton actually detected an intrusion attempt after visiting the site, and claimed it successfully blocked it. However, an infection obviously got through and looking at the history logs I noticed a malicious executable had been loaded into the temp folder at: C:\Documents and Settings\user\Local Settings\Temp\hxiushave\bwiyquslaib.exe. Also, one level up - in the Temp folder - a malicious executable called 00360693.exe had been planted. When I located these files on disk, they both had the same suspect icon of a ?modem? with a red arrow pointing up on it.

    -An executable d:\installer.exe made 14 modifications to the system.

    -Norton flagged a Trojan.ADH (and blocked it a presume).

    -I tried changing the name of the malwarebytes executable and the extension type, but it was still blocked.

    This is a bit of a bummer particularly given it is the second drive-by infection I've gotten in a relatively small period of time (last 6 months or so). Anyway, any assistance would be greatly appreciated.

    Thanks in advance,
    Nelson (mrpoate)
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Rogue anti-malware infection that disables executables and periodically opens sit

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.


    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post )


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.


    Then try running these instructions: Using MGtools


    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • a log from online SAS scan if you could make one
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  3. mrpoate

    mrpoate Private E-2

    Re: Rogue anti-malware infection that disables executables and periodically opens sit

    Hey Kestrel,

    Thanks very much for your help. Sorry my reply wasn't as immediate as it could have been, your reply reached me in the middle of the night when I was sleeping (aussie over here).

    I attempted to download and run the Rkill tool, but the malware seemed to block them from running. I would try to run them and nothing would happen (Rkill does display some visible window or cue that it is running right?). I noticed though that the window in windows explorer that displayed the contents of the downloads folder (where I downloaded the Rkill files to) lost focus, and regained focus when I hit enter. My theory is maybe an error prompt was provoked by the malware, but I couldn't see the prompt because it was hidden behind the fake anti-virus pop-up in the middle of the screen.

    I also then tried downloading and running AVPFind.bat, with similar results (didn't run). Same deal with exeHelper and the online super anti-spyware scan.

    However, I tried logging into the infected computer on a different account, and many of the problems (at least the obvious ones) disappeared. The fake anti-virus pop-ups seemed gone, as well as (I think but am not sure) the periodic opening of unwanted websites. Unfortunately an error message still emerged when I attempted to open malwarebytes, but on the flip side all other executables seemed to work.

    Again, thanks very much for your time. I think you were the guy that helped me out last time so cheers :) I meant to give an official thanks last time but for some reason couldn't work out how to do it or something.

    Anyway I hope you've got some clue about what to do next,

    Nelson (mrpoate)
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Rogue anti-malware infection that disables executables and periodically opens sit

    What about MGTools? Were you able to run that at least? If so attach the C:\MGlogs.zip.
     
  5. mrpoate

    mrpoate Private E-2

    Re: Rogue anti-malware infection that disables executables and periodically opens sit

    Hi again Kestrel,

    So I attempted to run MGTools today and yes unfortunately it also was almost immediately shut down by the malware. I notice with it and the other recommended anti-malware programs however that they seem able to execute very briefly, so the malware takes maybe a bit less than half a second to close them.
    Consequently some of the tools were able to generate logs, but sadly the logs are empty other than the global header announcing the program (as they didn't have time to be populated properly I would think). Even though the infection closes even the text files when I open them, I was still able to tell this in the half second or so they were open for.

    In short seems like a pretty clever piece of malware albeit nasty. You don't think there's anything I could do with the other user account that seems much less affected by the malware do you (and is able to run most executables)? Like running some of the anti-malware programs off the other user account?

    Anyway, thanks again, this is a real pain in the arse

    Nelson
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Rogue anti-malware infection that disables executables and periodically opens sit

    Make sure hidden files and folders are set to show.

    Rename Combofix.exe to 13hg7.com
    Rename MGTools.exe to J66dd.com

    Reboot into safe mode and try and run both, starting with Combofix.

    Let me know how you get on.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds