Trojan & Rootkit from fake UPS message

Discussion in 'Malware Help (A Specialist Will Reply)' started by ce34, Jul 30, 2008.

  1. ce34

    ce34 Private E-2

    Made the mistake that should never happen . Received a message from UPS (i was just waiting a shipping) and without fully reading the message did double click on the attached file (which was a .ZIP!!!).
    Result is a severe infection with Trojan Dropper.Gen Rootkit.Gen...
    I did follow alll the steps of read & run Malware removal (Hours!!) .Then ran SuperAntispyware, Spybot S&D , Malwarebytes, Combofix and MGTools.
    Unfortunateley , only Combo did not run exactly as described since it did not produce Log .
    I Did try 3 times combo fix as described (it seems to perform as described very quickly and then reboot , and 2 times i got "Windows recovered from severe" and the last one i got the blue screen . But Never any combofix log .

    Tip : the only thing i see is that i still run basic XP SP1
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I do not see the Combo-Fix.exe file on your Desktop as requested. Where did you put it and run it from?


    Did you setup the below default search assistant settings yourself?
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66017
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66017
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66017

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O20 - AppInit_DLLs: cru629.dat

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jul 30, 2008
  3. ce34

    ce34 Private E-2

    Thank you for this quick reply . Before do start the other scans & analysis , i want to answer you your 2 first items
    1. I have downloaded combo fix on the desktop and rename it in combo-fix.exe (just loook at it and still is on the desk)
    2. No i did not set up any default search assistant myself

    Will let you know later what i get with aitrher scans
     
  4. ce34

    ce34 Private E-2

    Just wanted to show you the HJT Log before to fix all the outputs
     

    Attached Files:

  5. ce34

    ce34 Private E-2

    Just forget my previous post . I realized you had already the MGTools analyse output and then I did fix the 020 line only , without any specific msg back .
    Now i'm going to continue with aevnger & will let yu know
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The user account you attached the logs for was: USERNAME=Claude And combo-fix.exe was not on this Desktop. This means either it is not there or you did not download the current version. And older out of date version would not show since we look for new files and ComboFix should be new.

    Since you did not add those search entries, you can also have HijackThis fix those lines.
     
  7. ce34

    ce34 Private E-2

    1. Ran Avenger OK with the script (added the log)
    2. fixme.reg merged ok with the registry
    3 CCleaner ran
    4. MGTools . Zip added
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to tell me how things are working so I will assume everything it fine.


    Since you did not add those search entry settings you should have HijackThis fix the below lines:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66017
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66017
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66017


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. ce34

    ce34 Private E-2

    Hi, no i did not forget you , but yesterday i just could tell how it worked since i just finish the extra tests before to go to bed (at 23:57 my time ) and i sent you a mail at that time to tell you that all extras that you had asked me to do have been working ok (i.e. Avenger, fixme.reg, ccleaner and GetLogs from MGTools..)

    Since then i only reconnected 2 hours ago , and everything seemed perfect so far .

    Then i've been back to follow your last advices and i did:
    HJT fix the 3 lines
    Uninstalled combofix per your procedure & it worked fine !
    Deleted Comfix folder
    Deleted Avenger & fixme files
    Unisntal HJT
    Deleted MGTools folder & exe as well as MGLogs.ZIP
    Toggled System restore with reboot in the middle

    Now i expect to be in good shape .
    Thank you again for your prompt replies and your time .
    Let me know if i should consider doing more
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds