Smitfraud, Rootkits and no fun

Discussion in 'Malware Help (A Specialist Will Reply)' started by vkinetic, Jul 5, 2010.

  1. vkinetic

    vkinetic Private First Class

    This system was severely infected. Trend had expired and has been removed. After running Spybot, Malwarebytes, SuperAntiSpy and Combifix malware behaviour seemed to stop (no pop ups etc) BUT:

    The system (Vista Home Premium) won't fully shut down (have to power off at the 'System is shutting down screen') and takes about 15 minutes to finally boot into the desktop. RootRepeal could not create it's report, but I have attached excerpts from the results and they indicate rootkit activity. Also, after the malware removal Vista SP2 was successfully installed (before it was realised that the system still had issues). Logs are attached.

    Your help in avoiding a complete reinstall will be greatly appreciated
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not change text log files into PDFs to attach. The text logs are automatically created by each scan and that is what we need you to attach.

    You copy of SUPERAntiSpyware is way out of date. You need to uninstall it and then download, install, update, and run the current version given in the READ & RUN ME just to be safe.

    Now put this PC into Normal Startup mode with MSconfig as requested in step 4 of READ & RUN ME and then rerun MGtools and attach a new log.

    Did you knowingly install the PDFforge Toolbar which hijacks/changes search settings? While some people like this software, many consider it malware/adware.

    Power down problems may not be due to malware
     
  3. vkinetic

    vkinetic Private First Class

    Thanks chaslang - here are the logs

    Yes, PDFForge Toolbar was purposely installed as an option to PDF Creator. I don't consider it malware - its handy to be able to create pdf documents from the web browser. At any rate, you can easily turn the toolbar off with a couple of clicks.
     

    Attached Files:

    Last edited: Jul 6, 2010
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Other than the items already removed, your logs are clean. And there is nothing in the logs that would explain/account for shutdown problems. It is more likely just something that is being run.

    Also slow startup appears to just be due to all the unnecessary toolbars, browser helper objects, and unnecessary startup processes including PDFforge ( which ComboFix broke since SearchSettings is a fairly well known search hijacker ).

    You may want to try working problems in the Software Forum if you are still looking to avoid a reinstall.


    Since you do not appear to have remaining malware problems, it is time to do our final steps. I'm not having you toggle System Restore since this may still be an option you wish to use.
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     
  5. vkinetic

    vkinetic Private First Class

    Thanks again chaslang. One thing though - don't you think the excerpts from RootRepeal (included in my first uploads) indicate something strange? Eg those entries hidden from Windows and which RR couldn't enumerate such as:

    \\?\C:\ADSM_PData_150\* ?

    I thought they indicated some sort of Rootkit activity. But if you don't agree, thanks again for your help. I think I'm facing a reinstall.

    Regards

    kinetic
     
  6. vkinetic

    vkinetic Private First Class

    Re: Smitfraud, Rootkits and no fun - IGNORE LAST POST

    Please ignore my last post chaslang - the references in the RootRepeal excerpts I was concerned about are ACER applications. Unfortunately disabling their associated services does not improve the boot up times.

    Thanks very much for your help anyway
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Smitfraud, Rootkits and no fun - IGNORE LAST POST

    Yes I know which is why I ignored them. ;)


    There is a lot of other unnecessary stuff that can be removed. Look at the startup list seen in the O4 lines of the HijackThis log in MGlogs.zip file that was attached. Below is a list of things for you to investigate why you need them. Many can just be used when needed and I would not install all the toolbars. I would uninstall every one of them.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds