Trojan, Worm or just plain Hacked??

Discussion in 'Malware Help (A Specialist Will Reply)' started by StiinaQT, Nov 29, 2010.

  1. StiinaQT

    StiinaQT Private First Class

    Here I am again, after another of my son's sleep overs and my machine has something again. I don't know what it is as nothing seems to identify it. I found a hidden user that had been added (now gone) and my networking (wireless) adapter and associated files all have this user now attached to them that I can't get rid of and it keeps shutting my adapter down so I can't access the internet through my network at home. I am using my other son's computer now to try to get a clue what is going on.

    I have run Spybot and got my usual cookies/trackers (4) that keep coming back (log to come).
    I have run Super AntiSpyware (log to come) and it found more cookies/trackers.
    I have run MBam and it found a trojan which may not have been, but I deleted it anyway in case it was hiding in a known software. (Log to come)

    I got to ComboFix and have Never had this issue, it not only got deleted from my desk top when I went to load the installation file, but the copy on my flash drive got deleted--twice!-- as well. I'm going to try to rename it to see if that will trick my computer, but I'm not really too hopeful.

    I forgot to copy my log files to my flash drive, but thought I would go ahead and post this in case you have an idea as to what is going on with my computer and post the logs here shortly when I go try the ComboFix again. Right now I'm re-running my Avast scan just because I had nothing else to try at this point until I post my logs and get some direction from you.

    You guys are the best! Thanks in advance for your help. I'd be completely down if you didn't help me every time this happens.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Hard to give you any reasonable answer without looking at your logs.
     
  3. StiinaQT

    StiinaQT Private First Class

    Tim, sorry about that but my computer is so bad that I ended up turning it off and not retrieving the logs. It's either a Trojan or a worm and I can't seem to get anything to work. It either deletes the file (as in entire program like ComboFix and RootRepeal) or shuts it down and corrupts the files so it can't run. I am at wits end with it. I ran CCleaner and I have never had that many bad registry files in less than one day. I did get the Worm Blaster (? I think that is the program) to run once, but it took 5 hours to complete and then what ever I have returned with a vengeance and now it won't run again. I'm ready to hand my CPU over to my local professional Geek and see what he can do with it. I hate to bother him, but I think this is one of those times I back off and let a pro take over--plus my oldest son's CPU has a bad power supply--and he usually gives a bit of a discount when he fixes two.
    Sorry for not getting the logs, I have just run out of time and patience with this one. I have spent just about 2 full days and nights on it and working full time, I don't have any time left. So much for my leisurely vacation day... I'll see if my son has time tomorrow to work with it and post the logs for me with no computer to surf with what else does he have to do? lol
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem. Just let me know what you finally decide to do with that system.

    If you want to try this, it may help:

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then doube click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running.


    Now download and Run exeHelper

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log.

    Then try running these instructions: Using MGtools


    Attach the below logs when finished with all of the above:

    • C:\avplog.txt - from AVPfind
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools

    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  5. StiinaQT

    StiinaQT Private First Class

    Just got back, Tim and I will try that. After I posted that last note, the computer I'm working on has Online Armor that popped up with "Apartment" as an unrecognized script. The second time it popped up, I did some research that sent me to Cisco/Linksys and 3 patches to fix a vulnerability in our wireless router...exactly the problems I was seeing. Apartment is apparently some type of trojan or worm. I will try what you asked and see if I can get anything from it. In the mean time, DS#1 has been directed to update the drivers for the wireless and perhaps we can get somewhere. I'm at least encouraged. Thanks!!
     
  6. StiinaQT

    StiinaQT Private First Class

    I was able to run the AVPFind, but the execHelper link didn't work for me. I found out that my Avast was the culprit that deleted my ComboFix, when I was going and getting my logs. I went ahead and ran the ComboFix which took several hours, but it did run and my computer seems functional, but I turned it off until I hear back from you on how to proceed.
     

    Attached Files:

  7. StiinaQT

    StiinaQT Private First Class

    Here is the ComboFix Log too
     

    Attached Files:

  8. StiinaQT

    StiinaQT Private First Class

    Please look below...duh...I posted at the bottom with my logs. Thanks again.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download MGtools and save it to your root folder. That would typically be the C:\ drive. Run the exe and attach the resultant C:\MGLogs.zip.
     
  10. StiinaQT

    StiinaQT Private First Class

    As luck would have it, I had initiated that scan this morning before going to work. Here is the MGTools log.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not attach the C:\MGLogs.zip. You only attached one log from the many that are in the zipped folder.
     
  12. StiinaQT

    StiinaQT Private First Class

    Sorry, I missed that one! Here it is.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have some leftover junk to remove, but other than that, I am not seeing any malware remaining in your logs.

    Let's do this:
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:'
    C:\$AVG

    Tell me what malware issues you are having, if any.
     
  14. StiinaQT

    StiinaQT Private First Class

    I did what you had me do. The registry update was successful. I have restored the user account control and rebooted my computer. My only problem is I still cannot get my wireless adapter to work. Something is still defeating it. Any ideas?
     
  15. StiinaQT

    StiinaQT Private First Class

    I spent some quality time with Linksys & on line chat. I now have driver v2 for my computer adapter and all is connected, albeit very slow, but probably until my updated anti's get their sea legs, lol. Thanks again.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  17. StiinaQT

    StiinaQT Private First Class

    I am still having trouble with my network adapter because of that hidden user I'd picked up when my wireless got hacked. It kept turning it off. Just an FYI, I went into my C: drive sharing and permissions and disabled the account then went and changed everything below the C: drive (yes, using inherited permissions) to my account which is the admin. I still have some locked files, but that did enough to allow my adapter to work once I rebooted.

    Do you have any suggestions for getting rid of this? It refers to an "RDH Setup Log" file that is locked and wouldn't allow me to change the ownership. I still have something lurking on my machine, I think, but right now it's beaten into submission. I'm worried it will take over again and it's extremely annoying to have the sound on as the cpu makes the connection/disconnection sound over and over and over again then not be able to connect to the internet.

    And yes, I am now as we speak using my very own computer, finally!!! Yeah!!!
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This sounds like an issue best discussed in the software forum. Am I to assume that you can not delete that user account?
     
  19. StiinaQT

    StiinaQT Private First Class

    I am not able to get to it with my skill level. I can only see it with the sharing and permissions. I will post the question there. Thanks!

     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Good luck and safe surfing. :)
     
  21. StiinaQT

    StiinaQT Private First Class

    Just a follow up. Although my machine was declared critter free, I continued to have problems until yesterday I could not do anything with it, whether I was in safe mode or what. I spoke with my local Geek about helping me with it and when I told him what the error was, he said that my only choice was to to a factory restore. Crap! I did the F11 as my machine calls for and tried diagnostics, and anything else that might figure out what was going on. One of the detail reports showed: "No Os installed." Bottom line is either I had a boot sector problem or what ever was causing this problem, did so much damage that the OS became unstable.

    I have restored it to factory level and tried to reinstall my adapter, but again, something is still trying to turn it off. I think I have retransferred whatever this is to my compter via the flash drive. I am going to reinstall all the software and updates to go back through the critter removal process and see if we can remove it from the flash drive too. Hopefully this time we will get it.

    If you have any ideas on alternatives, please let me know.
    Thanks for your help, it's been incredible. And may I add how much I hate Vista? :cry

    Laura
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are restoring the system back to factory settings, any malware will be removed. You then only need to be certain that any media you use to re-transfer files or data is also malware free. Once you are back up and running, you must make sure all your protection software is updated and you should then scan any media. We suggest that you keep both SAS and MBAM for back up scanning.

    Insert your flash drive before you begin. Hold down the Shift key when inserting the flash drive until Windows detects it to bypass the autorun feature. This will keep the autorun.inf from executing automatically.

    Please have all your removable storage devices ready for disinfection.

    Download Flash Disinfector by sUBs and save it to your desktop.

    * Double-click Flash_Disinfector.exe to run it.
    * Your desktop and icons may disappear. This is normal.
    * It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
    * Follow any prompts that may appear.
    * The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
    * Wait until it has finished scanning and then exit the program.
    * There will be no GUI interface or log file produced.
    * Reboot your computer when done.

    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.
     
  23. StiinaQT

    StiinaQT Private First Class

    Okay Tim, here is the scoop. I tried to run the Flash Disinfector, but apparently it aroused whatever critter is on this machine. Online Armor kept asking about process that were wanting to run, but I don't know what should be started and what shouldn't. I ran Hijack Free 4.5 and here are the suspicious files: (Sorry, no way to log I don't think--tell me how if there is a way to capture everything for you to evaluate.)
    Service:

    * Secondary Login => C:\windows\system32\
    - Microsoft, version 5.1.2600.5512 (xpsp.080413-2111), copyrighted
    (this looks like a hidden user account is why I'm listing it)
    *rasacd.sys = > C:\windows\system32\DRIVERS\

    When I looked this up, I went ahead and downloaded TFC to remove it. I will come back and let you know what happened next.
    Laura


     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is a normal system file. ;)
     
  25. StiinaQT

    StiinaQT Private First Class

    I didn't remove it or anything, those running processes told me something was afoot. The TFC was really only a crap cleaner, but it did kill the process I needed to be dormant long enough to run your Flash killer. I ran that second and now I'm starting through the Malware removal process. I will post any logs. BTW, I'm leaving the flash drive in and doing the scans on it as I go. You Flash killer may have already done that, but I'll be sure this way.

    Thanks again!
    Laura
     
  26. StiinaQT

    StiinaQT Private First Class

    Really, really bad....I started the Root Repeal and made sure it was going then back to the kitchen to fix my son and his buddies breakfast. I just got back to see if I could get the final log and my computer screen only shows "Missing Operating System" with the cursor blinking just after the m.

    I'll give you the logs I have. I just don't know what to do. Please help! Thank you in advance.

    Laura
    PS These are the only two log I had saved on my flash drive.:cry
     

    Attached Files:

  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your Windows CD? If so, try to boot into the bios and change the boot order so that the CD-Rom drive is the first device. Put in your windows cd and reboot. Then you will need to try doing a repair install. That is the second screen where you press R ---- to repair windows.
     
  28. StiinaQT

    StiinaQT Private First Class

    This CPU didn't have a disk, just a special factory partition with the software on it. Can we work with that? I normally would have purchased the disk, so let me go make sure that I don't have it. I don't remember having one for this computer, though. Will get back to you. Thanks again.
     
  29. StiinaQT

    StiinaQT Private First Class

    Tim,
    I hope this is good news. I do have 3 disks labeled Recovery Disk and each is sequentially numbered. Will these work?
    Laura
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can try booting to the factory restore partition. But it will wipe everything and put you back to when you first got the system. You can use another CD as long as it is the same version as what you have installed.
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, they should, but they will put you back to when you created those discs. You should first try to boot into the bios to see if the hard drive is recognized at all.
     
  32. StiinaQT

    StiinaQT Private First Class

    Not a problem as it was already at factory installation level. I tried all of the fixes, check for errors, etc and one of the helpers here plus my local geek both told me I had to reload the OS and that I would lose everything. Guess the best part is I hadn't reloaded very much other than my network adapter and my antivirus and antispywares.

    I didn't try to boot to the bios. I'm not sure how to do that, but I will do some research to see what I need to do. I've only done that a few times and they were all when I was talking to a support person on the phone.

    Thanks!
     
  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    When you first boot up, you should get a prompt to hit ( maybe ) F2 or F12 or similar to take you into the bios ( or setup ). There you go to the boot order tab and move the CD-Rom into first boot order. Then you can put in the first recovery disc and reboot. You should then get a prompt to boot from CD.
     
  34. StiinaQT

    StiinaQT Private First Class

    That is what I was going to try, but thank you for confirming it. Will let you know what happens.

    Laura
     
  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Fingers crossed!! :)
     
  36. StiinaQT

    StiinaQT Private First Class

    I'm going to go try now...I just am dreading this....
     
  37. StiinaQT

    StiinaQT Private First Class

    Here's what happened:
    I went into the startup options and my machine was already set to boot from the disk drive, then hard disk .

    I put the recovery disk in and opted for repairing the Windows installation
    I didn't see it end and there was a statement that it may take several times through the repair to get it all fixed up. That second time, I waited to see what happened and this is the resulting message:

    Unable to repair windows automatically. (then the typical disclaimer to contact your network admin or computer manufacturer)

    Problem event / Name
    01 / unknown
    02 / 6.0.6001.18000.0.0.0.0
    03 / 0
    04 / 65537
    05 / unknown
    06 / NoOsInstalled
    07 / 0
    08 / 1
    09 / Fix Partition Table
    10 / 1168
    OS Ver: 6.0.6001.2.1.0.256.1
    Local ID: 1033

    I have initiated the reinstallation from the recovery disks. Let me know if this means it's a hardware issue.

    Thanks again,
    Laura
     
  38. StiinaQT

    StiinaQT Private First Class

    I went back and tried again, had to use the disk to get the recovery started, but since the computer doesn't like disk 1, I tried to use the recovery from the HDD, but got the error:

    Error 0x4001001300001002

    So, I clicked next and it tried to boot before I could catch it and I got tis:

    Bootmgr is missing
    Press <CTRL> <ALT> <DELETE> to restart

    Put the recovery disk 1 back in and again try from the HDD and the same error as before:

    Error 0x4001001300001002

    I don't have to be a genius to see the writing on the wall. Bad HDD? What is your opinion or experience?

    Thanks again
    Laura
     
  39. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Considering the events, that would be my guess. However, I suggest you pursue this in the software forum where others may be able to advise you on how to diagnose the issue. ;)
     
  40. StiinaQT

    StiinaQT Private First Class

  41. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Vista and Win7 Recovery disc


    For fixing the boot issues:
    To run the Bootrec.exe tool, you must start Windows RE. To do this, follow these steps:

    1. Put the Windows Vista or Windows 7 installation disc in the disc drive, and then start the computer.
    2. Press a key when you are prompted.
    3. Select a language, a time, a currency, a keyboard or an input method, and then click Next.
    4. Click Repair your computer.
    5. Click the operating system that you want to repair, and then click Next.
    6. In the System Recovery Options dialog box, click Command Prompt.
    7. Type Bootrec.exe, and then press ENTER.

    If necc. you can do this:

    Bootrec.exe /fixmbr
     
  42. StiinaQT

    StiinaQT Private First Class

    All that is fine until I get to the "click the operating system you want to repair." My screen shows absolutely nothing, no O/S, nothing and then asks to install the HDD drivers.

    I'm going to see if I downloaded the wrong version of Vista since my reinstallation disks won't work. Nice, huh? I'm in a real pickle. When I look at the windows partition it shows 0 bytes used. Whatever got into my system has apparently effectively deleted these files. I'm also reading that the reinstallation protocol originally provided by MS didn't work on any system.

    I appreciate your following up. I had to help get the house ready for Christmas tonight so I'm working on this instead of sleeping. Gonna pay for this too. :zzz

    Thanks,
    Laura
     
  43. StiinaQT

    StiinaQT Private First Class

    I was able to get to the DOS prompt. I did the repairs and it reported success. I actually ended up doing two types of Bootrec.exe, the /Fixmbr and /FixBoot. Both reported success, but still I seem to be missing the drivers. I can't find a driver disk and it can't find them even though it looks like they are all there.

    While in DOS, I checked the directories and my C: drive is completely empty. My D: drive is now what my E: drive used to be and somehow my D: drive (the recovery partition) is now labeled as the E: drive. Does this have anything to do with my problem?

    When I try to do the Windows repair, I get the following error messages:
    Problem signature:
    Problem Event Name: StartupRepairV2
    Sig01: External Media
    Sig 02: 6.0.6000.16386.0.0.0.0
    Sig 03: 0
    Sig 04: 65537
    Sig 05: unknown
    Sig 06: MissingBootManager
    Sig 07: 0
    Sig 08: 2
    Sig 09: WrpRepair
    Sig 10: 21
    OS Version: 6.0.6000.2.0.0.256.1
    Locale ID: 1033

    Do I need to take this to the Software Suport forum? Do you have a Vista reinstallation instruction?

    Thanks again for all your help.
    Laura
     
  44. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you need to take this to the software forums for further assistance. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds