XP Home Security 2012 Trojan

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Brouwer, Jan 16, 2012.

  1. Brouwer

    Brouwer Private E-2

    Windows XP Home 2002 32bit. 1Gb Ram.

    Fake Microsoft XP Home Security Virus opens from (normal) startup; fake microsoft icon appears at bottom right from startup.
    Can't remember the site I got it from - had several open, trying to stream a film.

    Allows access to Firefox and Internet Explorer, but prevents me visiting sites like MajorGeeks.com and certain other sites (takes me to ebay or chat-to-a-girl sites instead) Sites like Hotmail and Microsoft are fine.
    Prevents access to msconfig and prevents me running exe. files. Have been unable to run Combofix, Rootrepeal and mc.exe (Anti-Malware).

    Already had SuperAntiSpyware installed. At first, it found trojans and removed them. Restarted the system, thinking it clean, but it was still infected and new scans by SAS found nothing (have attached trojan logs and more/most recent clean log). Able to run MGtools (have attached log).

    Example of an error message that pops up: (there are several different kinds)

    System Hacked!
    Details
    Attack from 16.130.91.237 port: 54731
    Attacked port 47332
    Threat: Email-Worm.VBS.peach

    Problem started day before yesterday. Have followed the ReadmeandRun instructions up to this point.

    Cheers cheers
    Brouwer
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are having troubles running exe files, go here and scroll down to the exe file fix:
    Fix Exe Association

    Now, Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now download The Avenger by Swandog46 to your Desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif

    1. Extract avenger.exe from the Zip file and save it to your desktop.
    2. Run avenger.exe by double-clicking on it.
    3. Click OK at the warning to continue to use The Avenger
    4. Do not change any of the check box options!
    5. Shut down your protection software now to avoid possible conflicts.
    6. Copy everything in the Quote box below, and paste it into the Input script here: part of The Avenger
    7. Now click the http://img33.imageshack.us/img33/9159/executeavenger.jpg button
    8. Click Yes to the prompt to confirm you want to execute.
    9. Click Yes to the Reboot now? question that will appear when The Avenger finishes running.
    10. Your PC should reboot, if not, reboot it yourself.
    11. A log file from The Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
    12. Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. Brouwer

    Brouwer Private E-2

    Think it's sorted it (thanks a million)
    but there were a couple of niggles probably worth mentioning.
    First, the MGtoolsget.bat, the first time I ran it, ran ok but seemed to crash at the end (after displaying 'hit any key to exit'). I powered off and did it again, it worked this time. Although, neither time did the licence agreement for Trend Micro Hijack This come up.

    When using Avenger, I left ticked the 'Temporary' box for both files AND system. I was unsure about system.

    Before running MGtools, (and after everything before that) I was redirected to a chat-to-girl site when trying to open hotmail. I also, another time, heard audio for a weird, fairly benign sounding website...about foreign language training, or something like that. Couldn't find the source.
    It happened just after I looked around for a download for Ccleaner, so good chance I made a mess of it and stumbled upon something there (should've searched on this site for a link first...what I did in the end).

    Since running MGtools the second time neither problem's recurred.

    I'll go through the Read me First Instructions again just in case, now I'm able to use exe. files. The log files will be available if you think I should repost them.

    Thanks again.
     

    Attached Files:

    Last edited by a moderator: Jan 17, 2012
  4. Brouwer

    Brouwer Private E-2

    I haven't gotten rid of everything. Still had those popups and was still being re-directed to other sites, so ran ReadMe (know you're not supposed to run it twice, but I could only do 2 of them beforehand).

    I've attached the relevant logs. Having trouble connecting to the internet, after using ComboFix. It warned me this might happen and advised me to run again, but I still can't connect. It found Rootkit - anyway, log's (of the second scan I performed) attached. Also advised me to run Check Disk, after it coming up that certain exe. files were corrupt (including IDrive). Ran Chkdsk.

    With Rootrepeal, I ran a scan, but don't think it was a fully functional one: message came up 'Invalid PE image found' and it scanned without me being given the option to Select Drives. (log attached)

    (Tried to attach MGlog but it won't accept because I've attached it before.)

    Apologies if I shouldn't have completed the other scans, thought it prudent in the circumstances.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am having a problem opening your MGLogs.zip, so I have removed it. Please try running the C:\MGtools\GetLogs.bat file again and attach the new MGLogs.zip.
     
  6. Brouwer

    Brouwer Private E-2

    Cheers. I ran it again, but it's the same again, a corrupt file. I've attached it anyway. No idea how to fix it....
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Nope, that one won't open either. Are you getting any specific error messages?

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.
    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
     
  8. Brouwer

    Brouwer Private E-2

    zip warning: missing end signature--probably not a zip file (did you remember to use binary code when you transferred it?)

    zip warning: Zip file structure invalid (C:/MGlogs.zip)

    But I've got a log you should be able to open now, (attached) although i'm not sure if it did a proper scan.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run the exe file and let's see if we can't get a new MGLogs.zip.
     
  10. Brouwer

    Brouwer Private E-2

    Same happened again - corrupt file, so I uninstalled and then reinstalled MGtools and that seems to have done the trick. MGLogs.zip attached
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good job. There are only a few things left to remove.


    1. Run avenger.exe by double-clicking on it.
    2. Click OK at the warning to continue to use The Avenger
    3. Do not change any of the check box options!
    4. Shut down your protection software now to avoid possible conflicts.
    5. Copy everything in the Quote box below, and paste it into the Input script here: part of The Avenger
    6. Now click the http://img33.imageshack.us/img33/9159/executeavenger.jpg button
    7. Click Yes to the prompt to confirm you want to execute.
    8. Click Yes to the Reboot now? question that will appear when The Avenger finishes running.
    9. Your PC should reboot, if not, reboot it yourself.
    10. A log file from The Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
    11. Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Now go to add/remove programs and uninstall:
    Java(TM) 6 Update 24

    Now download and install:
    Java Runtime 7

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  12. Brouwer

    Brouwer Private E-2

    Cool, I've done that and attached the logs.

    But when I ran the C:\MGtools\GetLogs.bat file the licence agreement for TrendMicro HijackThis didn't come up, and neither did the 'accept' button. They've never come up when I've run it....

    It's running fine, as far as I can see...except that I still can't access the internet. It says I'm connected, but it can't find the server. And if I try to repair it, it says it can't connect to the wireless network - that's since I ran ComboFix.

    Cheers
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see if we can do something about your network connectivity
    1. Go to Start ==> Run (or Windows key+R)
      • Type the following in the run box and click OK: notepad c:\windows\inf\nettcpip.inf
        (note that there is space after notepad)
      • The above file will open in the notepad.
      • Under TCP/IP Primary Install section find the following: Characteristics = 0xA0
      • Edit 0xA0 and replace it with 0x80 (replace A with 8)
      • Under File menu click Save and close the notepad.
    2. Go to Start ==> Control Panel. Double-click Network Connections. Right-click Local Area Connection, and select Properties.
      • On the General tab, click Install a popup window opens.
      • Select Protocol from the list and then click Add.
      • A new window opens, click Have Disk....
      • In the browse... box type c:\windows\inf
      • Click OK.
      • Select Internet Protocol (TCP/IP), and then click OK.
      • On the Local Area Connection Properties screen select Internet Protocol (TCP/IP) and click Uninstall, and then click Yes.
      • Wait until it asks to restart, and then restart as requested. Continue with the below after restarting.
    3. Go to Start ==> Run (or Windows key+R)
      • Type the following in the run box and click OK: notepad c:\windows\inf\nettcpip.inf
        (note that there is space after notepad)
      • A file opens in the notepad. Under TCP/IP Primary Install section find the following: Characteristics = 0x80
      • Edit 0x80 and replace it with 0xA0 (replace 8 with A)
      • Under File menu click Save and close the notepad.
    4. Go to Start ==> Control Panel. Double-click Network Connections. Right-click Local Area Connection, and select Properties.
      • On the General tab, click Install
      • A popup window opens. Select Protocol.
      • A new popup window opens. Select Internet Protocol (TCP/IP), and then click OK.
      • Wait until it asks to restart, and then restart as requested. Continue with the below after restarting.
    5. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).



      Then attach the below logs:
      • C:\MGlogs.zip
     
  14. Brouwer

    Brouwer Private E-2

    Cool, I've done all that and attached the logs.

    No internet access as yet. Also, after uninstalling (end of 2.), I wasn't asked to restart. So, I did it on my own. After selecting TCP/IP (4) it did ask me to restart.

    After I realised I still didn't have internet access when I restarted, I followed the steps again, thinking I might've made a mistake the first time since I wasn't asked to restart. The same happened again (no restart requested the first time, but one requested the second time).

    Also, I have LAN (Atheros AR8131 PCI-E Fast Ethernet Controller) and LAN 3 (Cisco Systems VPN Adapter). The former's unplugged and the latter disabled. I assumed you meant the former (LAN) so directed all my actions towards it.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not have it unplugged. Obviously it will not work if unplugged. ;)

    However, I made a mistake in assuming all of your malware had already been removed. You still have an infected partition. Do you have your Windows XP boot CD?

    Also run the below.


    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now please also download MBRCheck to your desktop.


    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
     
  16. Brouwer

    Brouwer Private E-2

    Christ, well, that seems to have done it.

    I'm back on the internet now. Feels weird to be able to use it again on my netbook.

    I don't have a Windows Boot CD (and don't have a CD drive on this netbook).
    The LAN's still disabled, but the Wireless Network Connection's fine (you were just winding me up a bit about the LAN earlier though, eh)

    Have attached all the logs. Thanks to everyone who's helped me through this slog, really appreciate it. I'll be able to move to another country now and get on with writing my thesis, without worrying how I'm going to use my laptop.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's ignore this CD for now. Perhaps we may not need it .


    Let's try to fix it. Make sure your physically plug in the cable to the Atheros AR8132 PCI-E Fast Ethernet Controller.



    Let's see if we can repair your Atheros AR8132 PCI-E Fast Ethernet Controller Adapter problem.
    • Open Device Manager by hold down the WIndows logo key and at the same time press the Pause/Break key. Then in the popup window select Device Manager
    • Then navigate to and expand ( click the + icon to expand ) the Network Adapters area of Device Manager
    • Loccate the Atheros AR8132 PCI-E Fast Ethernet Controller adapter and right click on it and select Uninstall ( but do not delete the drivers/software )
    • Then reboot your PC.
    • Upon reboot, it should re-detect the hardware and reinstall the drivers for the adapter.
    • Let me know how this goes.
    Also after the reboot, download another new version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\MGlogs.zip
     
    Last edited: Jan 24, 2012
  18. Brouwer

    Brouwer Private E-2

    Ah, I'd assumed it said 'unplugged' because the ethernet cable wasn't plugged in because I just use wireless.

    Ok, the log's attached. When I take the ethernet cable out of the laptop now, it goes back to saying "unplugged" and I can't connect (wirelessly) to the internet.

    I'm a bit concerned as to whether I plugged the correct end of the ethernet cable in. I took out the end plugged into the router (where there were lots of other plug-inpoints, each saying 'wired' beside them) and plugged it into my laptop. But maybe I should've taken out the side plugged into...I don't know what it is - a small black box very similar to the router, but with no 'wired' points and with 'power', 'enet' 'send' 'recv' ;sync' and 'ready' LEDs.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't quite understand what you were saying in your last message but it looks like your wired network adapter is fixed now. You can reconnect things the way you used to have them before now so that you can use your wireless interface.

    Are you having any remaining malware problems?
     
  20. Brouwer

    Brouwer Private E-2

    Sorry, aye, that was my fault. I couldn't connect wirelessly once I took the ethernet cable out, but it was just a case of switching off the router at the mains and switching it on again.

    Everything sorted now; connected up and no sign of any malware. Brilliant, cheers
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds