Still Infected?

Discussion in 'Malware Help (A Specialist Will Reply)' started by ChrisA, Jan 26, 2010.

  1. ChrisA

    ChrisA Private E-2

    After over a month of problems, I am not certain whether or not my machine is clean.

    Problems began in mid-December when I became infected with something redirecting Google searches. I was running XP Home SP3 with all updates, AVG9 with daily updates and Zone Alarm. AVG 9 performed daily scans (in the middle of the night) but, apart from tracking cookies, had found nothing.

    The Google redirects only happened when I was browsing with IE8; Google behaved normally with FireFox.

    A scan with Malwarebytes Anti-Malware found, quarantined and deleted a number of items (which surprised me) but the problem continued. Further scans with SAS and SpyBot Search & Destroy only found tracking cookies.

    A few days later, without any intervention from me, the redirect problem disappeared. But it came back 24 hours later. A scan with MBAM once again found some items, quarantined and deleted them but the redirect problem continued. Other scans found only tracking cookies.

    Over the next few days the Google redirect issue disappeared and reappeared several times - more or less randomly as far as I could tell.

    Around Christmas, it disappeared again and, to date has not returned. However, IE 8 runs much more slowly than I would expect and programs take much too long to open. Repeating the various scans finds nothing (other than tracking cookies).

    One final clue - though this may be a total red herring - every time I reboot, there is intense disk activity for 45-50 minutes. During this period of activity, only about 4% of CPU is used (I have an AMD Phenon II 955 and 4GB of memory) but everything is unbelievably slow - eg 30 seconds to open IE then another 20 seconds to load Google's page and programs take about four times as long as normal to load.

    However, just by accident, I discovered that if I physically unplug my internet connection during a re-boot and then leave it unplugged while Windows opens and all the start-up programs load before plugging it back in, then the PC does not go through the period of disk activity at all and everything seems much quicker.

    I have followed all the advice on what to do before using the tools you suggest and the various log files are now attached. I would just make the following observations which might be relevant: ComboFix did two restarts that were not mentioned in the Guidance - it restarted after installing Recovery Console (which I expected), then shortly after beginning its scan it found something and said it needed a restart. Foolishly I did not write down the details of what it found because I assumed it would go in the log but I am not sure if it did! I think it might have mentioned the word "Rootkit" (sorry not to be more helpful). Later, it deleted a whole lot of .dll files and some folders and then did another restart.

    I was also unable to run Rootrepeal - a copy of its crash report is available but there doesn't seem to be space to upload it.

    I apologise for the length of this but I have tried to be comprhensive in the hope that it will help.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Combo found a MBR infection and healed it. I am not seeing anything in your logs.

    However, I would like you to go to start / run / and type:
    services.msc

    Scroll down to IGRXTPCH. Right click and tell me what the properties are, as in signed and date.
     
  3. ChrisA

    ChrisA Private E-2

    Hi TimW

    Many thanks for assisting me.

    In the properties section of IGRXTPCH I found the following:

    On the "General" Tab:
    Service Name: IGRXTPCH
    Display Name: IGRXTPCH
    Description: (This box was blank)
    Path to Executable: C:\DOCUME~1\Chris\LOCALS~1\Temp\IGRXTPCH.exe
    Startup type: Disabled
    Service Status: Stopped

    On the "Log On" Tab:
    Local System account Radio Button - selected
    Allow service to interact with desktop - box checked
    Rest blank except: Hardware Profile 1 Service enabled

    On "Recovery" Tab:
    All three "failure" boxes: Take No Action
    Reset fail count after: 0 days
    Rest greyed out

    On "Dependencies" Tab:
    All greyed out

    Maybe I am missing something very obvious (or completely misunderstood your request) but I couldn't find any references to properties being signed or dated.

    Regards

    Chris
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did fine. I just can not find anything on that service, so I don't know if it is good or bad. Let's leave it for a while and see if you have any issues. The other thing to do is to go to the C:\DOCUME~1\Chris\LOCALS~1\Temp\IGRXTPCH.exe file and rename it by just adding a .old to the end. If there are no issues that occur with your system, then after a while we can delete it.
     
  5. ChrisA

    ChrisA Private E-2

    Hi again

    Maybe it is just me, but I cannot find that file anywhere on my C:\ drive. I have looked myself and had Windows Explorer search for it - but nothing!

    Regards

    Chris
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  7. ChrisA

    ChrisA Private E-2

    Hi TimW

    Followed your "final steps" and everything here seems fine.

    Many thanks for your help - it is very much appreciated.

    Regards

    Chris.:wave
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds