Jump to content

Recommended Posts

Hi there.

This is my first post and i was encouraged to seek help in this forum from reading the solution given by kahdah in post http://forums.malwar...howtopic=32278. I am having similar problems with a virus called trojan vilsel. Although malwarebytes program has deleted this many times now (in safe mode too), the redirects still happen (I am using a diff comp to post this). The most annoying is I can not system restore. A week or two ago, i was infected by the xp security 2011 but system restore solved it but not now. I have downloaded everything as suggested in that post....OTL, GMER,and combofix (i have not run combofix yet...waitin for the suggestions first). Attached below are the output files from OTL (two files: OTL.txt and Extra.txt) and GMER (named results.log). I have ran all these in safe mode! I hope that is alright. I just need to do custom fix with OTL...rest I will follow the above post if that is all that is needed. I would really appreciate ur help.

Thanks in Advance.

KAVV

NB: I have also followed the post as suggested by a moderator at http://forums.malwarebytes.org//index.php?showtopic=9573. I have updated the malwarebytes program and scanned in the safe mode....no virus detected. I downloaded avira antivirus program but it was not able to update the virus definations...blocked reason unknown (again this was done in the safe mode). Defogger downloaded, DDS done...logs attached (DDS.txt and attach.txt). GMER as suggested in this post done and log file attached...this time named ark.txt.

ONETHING DO I HAVE TO ADD THESE ATTACHMENTS TO POST ....IE CUT AND PASTE?

OTL.Txt

Extras.Txt

results.log

mbam-log-2011-05-22 (15-33-29).txt

dds.txt

attach.txt

ark.txt

Link to post
Share on other sites

Hello kavv

Welcome to Malwarebytes.

=====================

One or more of the identified infections is a backdoor trojan or rootkit.

This type of infection has the capabilities to allows hacker to remotely control your computer, steal critical system information and download and execute files.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identity Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall

We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do.

If you still want to clean it please do the following

===================

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

========

Download ComboFix from one of these locations:

Link 1

Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Link to post
Share on other sites

HI Thanks for your suggestions. So is the virus that serious and there is no way around it like before with OTL. I am gonna to do as you suggested with TDS killer and all. I have not reformatted my PC ever so I am tempted to do that as well...will do if all fails. I think if i am able to system restore after the steps u suggestd, we can ascertain that the pc is not infected that seriously, In the meantime, i just use email and fb with the infected computer...i hope that is fine.

KAvv

Link to post
Share on other sites

The malware can be removed I just wanted to let you know of the dangers associated with it.

OTL will not remove the main infection.

Continue on with the steps no need for a system restore as it will bring the infection back.

Post those logs and we can continue.

Link to post
Share on other sites

Hi again.

I was able to do the TDSSkiller.exe, again this in safe mode, and it found a rootkit virus and subsequentley rebooted. Attached is the log file. However, the combofix was not able to complete as it kept crashing the computer. I even let it update itself. I did once in safe mode with all the antivirus and comodo firewall disabled...it crashed. Again i did in normal setting, it again crashed.

NB since the TDSSkiller killed the rootkit thing, i am able to access the malewarebytes forum from the infected computer..i am actually doing this post from it. THere has not been any pop ups or redirects yet.

Thanks.

Kavv

TDSSKiller.2.5.1.0_23.05.2011_16.12.41_log.txt

Link to post
Share on other sites

hi Both combofix did not work. IN both normal and safe mode, it crashes just after when it is saying "scanning for infected files". I suspect there is still something lurking araound as I am unable to update the avira antivirus program even after fresh installation. Is there any other way to investigate the culprit? I have run the TDSSkiller again and it found nothing infected.

Kavv

Link to post
Share on other sites

Yes you can re-enable it now.

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTL
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O4 - HKCU..\RunOnce: [scan_after_setup] File not found
    [2011/05/11 23:49:09 | 000,007,558 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\t5h3710btkyvc7ysrur63f5pk32e0x8r082s66

    :Commands
    [emptytemp]
    [resethosts]


  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • It will produce a log for you on reboot, please post that log in your next reply.

================================Malwarebytes' Anti-Malware=================================

Please update\run Malwarebytes' Anti-Malware.

Double Click the Malwarebytes Anti-Malware icon to run the application.

  • Click on the update tab then click on Check for updates.
  • If an update is found, it will download and install the latest version.
  • Once the update has loaded, go to the Scanner tab and select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatley.

================================Online scan=================================

ESET OnlineScan

  1. Click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the esetOnline.png button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

    1. Click on esetSmartInstall.png to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the esetSmartInstallDesktopIcon.png icon on your desktop.

    3. Check esetAcceptTerms.png
    4. Click the esetStart.png button.
    5. Accept any security warnings from your browser.
    6. Under scan settings, check esetScanArchives.png and check Remove found threats
    7. Click Advanced settings and select the following:
      • Scan potentially unwanted applications
      • Scan for potentially unsafe applications
      • Enable Anti-Stealth technology

[*]ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.

[*]When the scan completes, push esetListThreats.png

[*]Push esetExport.png, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.

[*]Push the esetBack.png button.

[*]Push esetFinish.png

Link to post
Share on other sites

Hi again. Attached is the OTL.txt. I still can not successfully install avira anti virus program...is not able to update. I have uninstalled it and tried to install it again but with no luck. I am trying to install it now by disabling mydisable my comodo firewall in normal boot. One error in normal boot start up is

"Error loading C:\WINDOWS\tefiePOL.dll

The specified module could not be found."

I just click ok. About system restore, can i follow your 2009 post? THere is also a computer icon saved in the C: folder called comodofix...about 28 mb in size. Can I delete that since combofix always crashed? Ok i shall wait for your reply.

Thanks.

Kavv

OTL.Txt

Link to post
Share on other sites

Ok the OTL scan seems to be run in safe mode please boot normally and run it again please it is not showing me anything new.

So boot normally open OTL click on run scan then post the newest log.

About system restore, can i follow your 2009 post?

As far as system restore we do not need to use it the only thing I ever have anyone do is manually delete all restore points.

We will do this before we are done.

Leave Combofix for now it will get removed shortly.

Also try to install another antivirus such as AVG or Avast your choice and see if hte same thing happens.

Link to post
Share on other sites

We will not need system restore at all.

Did you try the different antivirus?

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTL
    O4 - HKCU..\Run: [Csulihirewapan] File not found


  • Then click the Run Fix button at the top
  • Let the program run unhindered,when it is done it will say "Fix Complete press ok to open log"
  • Please post that log in your next reply.

Link to post
Share on other sites

I am happy to say that i was able to do a successful installation of a fresh copy of avira antivirus...updated, scanned...removed some not so serious files. So, do i assume my computer is disinfected so that i could check my bank online or paypal etc.? I did not do system restore for the fear of getting those infections back...i just want to maybe delete prev system restore files and start a new one. Is there a way? THis is so that those infections that might be lurking in the system restore folder might be wiped off too.

Thank you again.

kavv

Link to post
Share on other sites

Great.

Sure the following will take care of system restore points as well as remove the leftovers of what we used.

=======Cleanup=======

  • Click START then RUN
  • Now type Combofix /uninstall in the runbox and click OK. Note the space between the X and the Uninstall, it needs to be there.


    ======Next======
    • Double click on OTL to run it.
    • Click on the Cleanup button at the top.
    • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.
    • This will remove itself and other tools we may have used.

===============Update Java===============

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:

  • Download the latest version of Java SE Runtime Environment (JRE) and save it to your desktop.
  • Scroll down to where it says "(JRE) then click on it
  • Click the "Download" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u25-windows-i586.exe to install the newest version.

======================Clear out infected System Restore points======================

Then we need to reset your System Restore points.

The link below shows how to do this.

How to Turn On and Turn Off System Restore in Windows XP

http://support.microsoft.com/kb/310405/en-us

If you are using Vista then see this link: http://www.bleepingcomputer.com/tutorials/...143.html#manual

Delete\uninstall anything else that we have used that is leftover.

After that your all set.

===The following are some articles and a Windows Update link that I like to suggest to people to prevent malware and general PC maintenance===

Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.

Prevention article Some great guidelines to follow to prevent future infections please read the Prevention artice by Miekiemoes.

How did I get infected in the first place? Also this one by Tony Klein.

If your computer is slow Things you can do if your computer is slow.

PC Safety and Security - What Do I Need? Security suggestions and general hints and tips for PC security.

File sharing program dangers Reasons to stay away from File sharing programs for ex: BitTorrent,Limewire,Kazaa,emule,Utorrent etc...

===Free antimalware tools used for on demand scanning and cleaning no real time unless purchased===

Malwarebytes Antimalware

superantispyware

===Free antivirus links===

This is antivirus and antispyware.

Microsoft Security Essentials

This is free antispyware protection and Antivirus protection.

AVG free

This is just antivirus protection.

Antivir

This is antivirus and antispyware protection.

Avast

Link to post
Share on other sites

Hi done the OTL clean up but when i typed ComboFix / uninstall in the normal boot (i actually used combofix in the safe mode before), it started to scan. I stalled it and quickly changed into the safe mode but this time it is not recognizing the command.

Kavv

Link to post
Share on other sites

Hi. Done all that. I hope my laptop is now clean from serious infections. They should really build a counter inbuilt program to tackle future viruses within the operating system analogous to our own immune system....happy days! My laptop is running faster and smoother. I want to reformat but I have lost some of my installation Cds ( or the keys) of some imp softwares i use in my research. SO after the phd is finished, i will definately format it.

So can i use online banking now? I know it is not 100% clean. Regarding windows update, i stopped them because they eat my hardisk space and slows the computer, dont they?

One last thing is regarding pop ups i receive at start up...errorMSG1.jpg attached ...it is regarding a prehistoric mouse i used to use but i tried uninstalling it many times but i keep on getting the msg. When i click stop, then i get the second msg.

Also can i delete these three unknown folders in my C:\...jpgs attached plus what are these in the windows folder with the $ sign...they are taking up some space. Sorry...if u know these only.

Kavv

post-81595-0-02038900-1306367634.jpg

post-81595-0-70001200-1306367653.jpg

post-81595-0-72468900-1306367667.jpg

post-81595-0-20755400-1306367684.jpg

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.