Virus that reappears after deletion - Logs Attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by JMys55, Mar 11, 2012.

  1. JMys55

    JMys55 Private E-2

    Hi, I have a really bad virus/malware that I cannot get rid of. I have tried Norton 360 scan, Norton Power Eraser, Norton Recovery Boot Tool. None of those 3 procedures found the problem.

    Also, I ran Spybot and Malwarebytes which found the problem, but it just came back after removal. I think I have a SmitFraud Trojan (based on Malwarebytes scan). Thus, I tried SmitFraudFix and that didnt work or it was blocked.

    At one point I restarted my computer and found that all my virus removal programs were gone! I have never seen that before. Not sure if they were deleted or blocked, but I had to re-install all the Major Geeks recommended programs again. Here is what came up on each:

    1) SUPERAnitSpyware - nothing found

    2) Malwarebytes - found smitfraud, removed, and came back again

    3) ComboFix - looked like it was trying to fix some reigistry keys, however, they were locked so it wasnt fully complete. Also, it gave me a warning before it ran that Norton 360 was running prior and I couldnt disable it as it wouldnt show up in my Icon Tray; access to the program was still being blocked by the virus. Instead I "Ended Process" in Task Manager for the Symantec process beforehand. Hopefully it didnt interfere with the ComboFix run.

    4) MGTools - Ran and generated logs.

    Attached are my respective log files.

    Computer - month old Toshiba Protege Ultrabook
    System OS - Windows 7
    I am working on a separate, stable computer to use this forum and to download programs. I have been transferring programs/logs between a USB, as mentioned before, it seems like the infection is interfering or removing my Anti-Malware programs.

    PLEASE HELP! :cry

    Thanks in advance, Jon
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
     
  3. JMys55

    JMys55 Private E-2

    Hi, looks like it found Rootkit.Boot.Pihar.b. I "cured" and restarted. However, Norton still doesnt work properly and I reran Malwarebytes. This time it found only 1 threat (instead of 2 before). I cleaned and restarted and it is still there.

    :(
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello there. Can you please attach the two logs that I asked for? Thanks.
     
  5. JMys55

    JMys55 Private E-2

    Hey sorry, I was running late this morning for work so I didnt have time to gather logs. Here they are. Thanks for your help.

    Jon
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Java(TM) 6 Update 25 <--- Uninstall outdated Java.

    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Folder::
    c:\users\Jonathan\AppData\Roaming\DriverCure
    c:\users\Jonathan\AppData\Roaming\ParetoLogic
    c:\programdata\ParetoLogic
    c:\program files (x86)\ParetoLogic
    c:\program files (x86)\Common Files\ParetoLogic
    File::
    c:\programdata\Microsoft\Windows\DRM\5104.tmp
    c:\programdata\Microsoft\Windows\DRM\5103.tmp
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}]
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.



    Re run TDSSKiller again and attach the new log.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  7. JMys55

    JMys55 Private E-2

    Thanks for the reply. I performed the procedures you recommended and attached are the logs. Here is what I saw:

    ComboFix ran normally except I didn't get the error message you mentioned below.
    TDS didnt find anything.

    One thing to note....when I run ComboFix, it gives me a warning that Norton is running, but there is no way I can turn Norton off as 1) the program denies me access since it is being blocked by the virus, 2) the Norton Unistall does not respond (probably blocked as well). I don't see the program running in the Task Manager and the only thing I can do is End Process of an item that appears to be a Symantec process. However, even after I end this process, CombFix still gives me a second warning. Do you know another way I can disable Norton? (same problem in Safe Mode)

    My computer still is the same at this point. One other thing this virus is doing is changing my time settings to military format (i.e. 21:21) even after I change it back.

    Thanks for your help.

    Jon
     
  8. JMys55

    JMys55 Private E-2

    Here are the logs. Not sure why they didnt upload with my last message.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seeing any malware. This can be done though.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.

    What issues are you having now?
     
  10. JMys55

    JMys55 Private E-2

    Hi, I removed the item you requested. Things are still the same as before. As I mentioned, I can't disable Norton and possibly other programs as they are malfunctioning and I dont have user interface visability.

    Do you think I can remove Norton through HJT and then re-run some scans to see if it was interfering with ComboFix, etc? What would you recommend?

    Thanks, Jon
     
  11. JMys55

    JMys55 Private E-2

    Update: I removed Norton using their webtool; however, when I run ComboFix again, it gives me a warning that Norton is running even after I uninstalled it. I am thinking this virus is masking through Norton somehow. Also, I ran MalwareBytes again and it found 2 more viruses, but the computer is still the same.

    >sigh<
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Norton will still be detected by Combofix because there is probably some remnants of it, but I do not want you to worry about it, it is not a malware issue!

    Now, what are you saying Malware Bytes found again? Attach the log showing me please.
     
  13. JMys55

    JMys55 Private E-2

    Hi, I re-ran Malwarebytes and it doesnt show anything now, but the virus comes back after a while. I bet if I run it again in a day or two, Malwarebytes will find 1-2 more different items. Attached is a screenshot of my current quarantine which shows different items found on different days. Also, I attached my log with the latest virus and the latest log that I ran just now.

    These scan programs make it look like my system is clean, but my computer still isnt operating the same. My settings still change to odd items (time) and my browser (Firefox) lost its themes, certain programs won't operate. Also, every few days Malwarebytes will find something new.

    If it isnt malware, what is it? A virus/infected registry key? It seems like it is an infected System32 file that keeps changing. I did a PC backup about 2 weeks ago and would be willing to restore it, but I am pretty sure that this problem is more deeply rooted and dont think it will change anything.

    Thanks, Jon
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    C:\Windows\System32\grpconv.exe <--- I have this file on my computers too. It's a legit file, so why MBAM keeps hitting on it I do not know. Sometimes this file can be a problem, but not in the location that you have it in. It's fine.

    Scan with Malware Bytes again and attach the log. If it's not finding anything then I think you will be ready for final steps.
     
  15. JMys55

    JMys55 Private E-2

    Hi, I swear I posted a reply with log on 3/16/12. I came back online today to see if I missed a message or something since it has been 10 days and noticed my last post was not on here. IDK.

    Anyways, attached is a Malware log as of today and a screenshot of my quarantine showing items that have been found in the past 2 weeks. Malwarebytes still shows nothing but I know the virus is still on here as processing problems are still present and new infections will be found in 1-2 days of computer use. I believe it is a deep RootKit infection or System32 infection that just keeps resurfacing. MalwareBytes will find stuff, then in 1-2 days it will find something new. Attached is a screenshot the item in Quarantine. You can see that new infections come up after I scan every few days. I know there hasnt been anything since 3/17/12; however, I have not used the infected computer since that date.

    What would be the final steps? A full reboot? This is the worst virus I have ever had.

    Thanks, Jon
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let a few more days go by, use the computer, scan to your hearts content with Malware Bytes, attach the logs if you wish, or show me what threats are being found. If no threats are being found however then you can follow final steps.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds