maps-outline
maps-outline
maps-outline
Username:    Password:    Remember me       [Forgot Password?]
MalwareTeks :: Forums :: Malware Support :: Resolved Malware Threads
 
<< Previous thread | Next thread >>
[RESOLVED] Extremely infected
Moderators: ShadowPuterDude, D3m3nt3d, jholland1964, TurcoLoco, JeanInMontana, RatHat, MrCharlie, evilfantasy, Laurent
This thread is now closed
Author Post
hassaan
Sun Oct 18 2009, 03:28AM
Registered Member #417
Joined: Thu Apr 02 2009, 09:12AM

Posts: 44
Hi,
I was gone to holidays and this pc was used by my friends.HE had installed all types of RATS,keyloggers and crypter etc etc.
The bitdefender,hijack this and iseeyouxp logs are attached.
iseeyouxp.txt
hijacthis.txt

[ Edited Sat Nov 14 2009, 08:05AM ]
Back to top
ShadowPuterDude
Sun Oct 18 2009, 02:24PM
...the Shadow knows


Registered Member #1
Joined: Thu Apr 27 2006, 04:52PM

Location: Northern NY
Posts: 669
Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
    See HERE for help
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, ComboFix will produce a log.

Note:
1. Do not mouseclick combofix's window while it's running. That may cause it to stall!
2. Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.

-----------------------------------------------------------


Post fresh logs for:
  • ComboFix
  • ISeeYouXP
  • HijackThis


Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!

"Only those who fail greatly can ever achieve greatly" - Robert F. Kennedy
Microsoft Most Valuable Professional - Consumer Security (2007-2008)
Member - Alliance of Security Analysis Professionals - Since 2006
Linux Registered User # 363218
Back to top
Website
hassaan
Mon Oct 19 2009, 05:02AM
Registered Member #417
Joined: Thu Apr 02 2009, 09:12AM

Posts: 44
Hi,
the logs are attached.
iseeyouxp.txt
mbam-log-2009-10-19_14-32-28.txt
hijackthis.txt
Back to top
hassaan
Mon Oct 19 2009, 05:04AM
Registered Member #417
Joined: Thu Apr 02 2009, 09:12AM

Posts: 44
Sorry the combofix log is attached here.
combo.txt
Back to top
hassaan
Mon Oct 19 2009, 06:09AM
Registered Member #417
Joined: Thu Apr 02 2009, 09:12AM

Posts: 44
Either he using my pc remotely or my pc is sending him the data and passwords.Please ur help will be appreciated
Back to top
ShadowPuterDude
Mon Oct 19 2009, 08:32AM
...the Shadow knows


Registered Member #1
Joined: Thu Apr 27 2006, 04:52PM

Location: Northern NY
Posts: 669
The installed version of Java on this computer is out-dated. Install Java Runtime Environment (JRE) 6u16 available from Sun Microsystems.

-----------------------------------------------------------

Using Add or Remove Programs in the Control Panel; uninstall the following:
wrote ...
Java(TM) 6 Update 14

-----------------------------------------------------------

Now we need to use ComboFix to remove some stuff.
  • Make sure that the copy of combofix.exe that you downloaded earlier is on your Desktop but Do not run it!
  • If it is not on your Desktop, the below will not work.
  • Open Notepad and copy/paste the text in the below code box into it

(make sure you scroll all the way down in the code box to get all lines selected ):
KILLALL::

Driver::
PBDOWNFORCE_SERVICE

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"winconfig"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2D9C4564-461A-4E66-9908-D42E0E630803}]
[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{BE2FEDB0-52E2-24E6-DC63-5585FF9D6C74}]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PBDOWNFORCE_SERVICE]

RegNull::
[HKEY_USERS\S-1-5-21-1060284298-1417001333-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{EB24C1A7-AF14-18B0-95F6-FB6066D5FFC0}*]

File::
c:\windows\system32\bdod.bin
c:\windows\winconfig
c:\docume~1\Hassaan\LOCALS~1\Temp\PHQ20.tmp
c:\windows\system32\Msi16\server.exe

Folder::
c:\windows\system32\Msi16

  • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
  • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
  • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
  • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

  • Follow the prompts.
  • When it finishes, a log will be produced named c:\combofix.txt
  • I will ask for this log below

Note: DO NOT mouseclick combofix's window while it is running. That may cause it to stall.

The ComboFix folder should not be renamed since ComboFix and even we would have suspicions about it. Also when you uninstall CF, the folder would not be removed since it does not look for that folder name.

-----------------------------------------------------------

Post fresh logs for:
  • ComboFix
  • ISeeYouXP
  • HijackThis


Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!

"Only those who fail greatly can ever achieve greatly" - Robert F. Kennedy
Microsoft Most Valuable Professional - Consumer Security (2007-2008)
Member - Alliance of Security Analysis Professionals - Since 2006
Linux Registered User # 363218
Back to top
Website
hassaan
Mon Oct 19 2009, 11:06AM
Registered Member #417
Joined: Thu Apr 02 2009, 09:12AM

Posts: 44
Hi,
the logs are attached.
hijackthis.txt
iseeyouxp.txt
combo.txt
Back to top
ShadowPuterDude
Mon Oct 19 2009, 05:12PM
...the Shadow knows


Registered Member #1
Joined: Thu Apr 27 2006, 04:52PM

Location: Northern NY
Posts: 669
You did not update Java as instructed. Using outdated versions of Java leave your computer vulnerable to attack.

-----------------------------------------------------------

Now we need to use ComboFix to remove some stuff.
  • Make sure that the copy of combofix.exe that you downloaded earlier is on your Desktop but Do not run it!
  • If it is not on your Desktop, the below will not work.
  • Open Notepad and copy/paste the text in the below code box into it

(make sure you scroll all the way down in the code box to get all lines selected ):
KILLALL::

File::
c:\program files\RuntimeSetup.exe
c:\program files\runtimesetup.ini
C:\WINDOWS\system32\2065.txt
C:\WINDOWS\system32\tmps.execu
C:\WINDOWS\system32\un2065.txt

  • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
  • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
  • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
  • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

  • Follow the prompts.
  • When it finishes, a log will be produced named c:\combofix.txt
  • I will ask for this log below

Note: DO NOT mouseclick combofix's window while it is running. That may cause it to stall.

The ComboFix folder should not be renamed since ComboFix and even we would have suspicions about it. Also when you uninstall CF, the folder would not be removed since it does not look for that folder name.

-----------------------------------------------------------

Post fresh logs for:
  • ComboFix
  • ISeeYouXP


Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!

"Only those who fail greatly can ever achieve greatly" - Robert F. Kennedy
Microsoft Most Valuable Professional - Consumer Security (2007-2008)
Member - Alliance of Security Analysis Professionals - Since 2006
Linux Registered User # 363218
Back to top
Website
hassaan
Tue Oct 20 2009, 03:56AM
Registered Member #417
Joined: Thu Apr 02 2009, 09:12AM

Posts: 44
Hi,
The logs are attached
combo.txt
iseeyouxp.txt
Back to top
ShadowPuterDude
Tue Oct 20 2009, 08:16AM
...the Shadow knows


Registered Member #1
Joined: Thu Apr 27 2006, 04:52PM

Location: Northern NY
Posts: 669
Your logs look fine.

Unless you are having problems from Malware it is time to do the final steps.

If I had you use ComboFix, Uninstall ComboFix:
  • Click START then RUN and enter the below into the run box and then click OK. (Use only the command of the same name as your copy of combofix.)
  • AvoidTDSS /u or combofix /u (Which command depends on whether or not I had you rename ComboFix)
    Note: The space before /u, must be there.
    This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
  • Delete the C:\AvoidTDSS or C:\ComboFix folder from combofix.

Delete everything in C:\!KillBox

Delete the following from your Desktop: (If they exist)
Avenger.exe
Avenger.zip
Combofix.exe
AvoidTDSS.exe
ISeeYouXP.exe
ISeeYouXP.txt
DisableAutoRuns.reg
FixMe.reg
FixReg.reg
Any Registry patch I had you use

Delete the following files: (If they exist)
C:\Avenger.txt
C:\ComboFix.txt

Delete the following folders: (If they exist)
C:\Avenger
C:\SDFix
C:\Qoobox

You can delete and unistall any programs I had you download, that you do not wish to keep on the system.

Run Windows Update and update your Windows Operating System.

Run the Secunia Online Software Inspector, this will inspect your system for software that is out-of-date and in need of updating. Update anything program/application detected as being out-dated.

Empty the Recycle Bin

Run ATF Cleaner

In the ISeeYouXP folder double-click HideIT.bat.

Turn off System restore to flush all your restore points then turn system restore back on.

To manually turn off System Restore, follow these steps:
1. Click Start, right-click My Computer, and then click Properties.
2. Click the System Restore tab.
3. Click to select the Turn off System Restore check box (or the Turn off System Restore on all drives check box), and then click OK.
4 Click Yes when you receive the prompt to the turn off System Restore.

To turn on System Restore, follow these steps:
1. Click Start, right-click My Computer, and then click Properties.
2. Click the System Restore tab.
3. Click to clear the Turn off System Restore check box (or the Turn off System Restore on all drives check box), and then click OK.

Delete C:\ISeeYouXP

That should take care of everything.

Safe Surfing!

"Only those who fail greatly can ever achieve greatly" - Robert F. Kennedy
Microsoft Most Valuable Professional - Consumer Security (2007-2008)
Member - Alliance of Security Analysis Professionals - Since 2006
Linux Registered User # 363218
Back to top
Website
 

Jump:     Back to top

Syndicate this thread: rss 0.92 Syndicate this thread: rss 2.0 Syndicate this thread: RDF
Powered by e107 Forum System


< About Us | Terms of Service | Acceptable Use Policy | Copyright Notice | Privacy Policy | Software Piracy | Infected? | Want to Help? | Link to Us | Contact Us >


Copyright 2006-2010 MalwareTeks

All products mentioned herein are the trademarks of their respective owners.
In addition, images, logos, pictures or other material may be trademarks or registered trademarks of their respective owners.

This site is powered by e107, which is released under the terms of the GNU GPL License.
Internet X theme by Flash


ICRA.org
Banner