BleepingComputer.com: Unknown Malware Infection-changed permissions, corrupted program files

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Unknown Malware Infection-changed permissions, corrupted program files Posting DDS log as requested by boopme

#16 User is offline   myrti 

  • bleepin' _temp_
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 27,518
  • Joined: 25-January 08
  • Gender:Female
  • Location:At home

Posted 14 April 2011 - 07:44 AM

Hi,
thanks for letting me know.


The rouer reset should not knock you offline, but I know that unexpected things can happen and totally understand that you want to wait until you have the peace of mind to handle this.

regards myrti
If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM!

Posted Image
Please don't send help request via PM, unless I am already helping you. Use the forums!

I know not with what weapons World War III will be fought, but World War IV will be fought with sticks and stones. ~ Albert Einstein
Heroism on command, senseless violence, and all the loathsome nonsense that goes by the name of patriotism -- how passionately I hate them! ~ Albert Einstein

#17 User is offline   StephL67 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 25
  • Joined: 27-March 11
  • Gender:Female
  • Location:Georgia

Posted 25 April 2011 - 06:58 PM

I'm finally back! The router reset did knock me offline and I could not get it to work again once I reset it, all I could get was a fast flashing on and off of the lights on it. I finally was able to get my son to fix it, but before the reset I could no longer even sign onto bleepingcomputer.com nor could I properly view any webpage that used any java, activex or any enhanced content. The problems also spread to the base computer. While the router was down I had to connect the base computer directly to the modem and its problems magically went away. I immediately made sure all securities were properly set and updated all software. on my laptop I had to do a new install of Windows 7 and deleted the the 2 partitions. Basically starting over from scratch. This time once I connected I made sure to get the windows updates needed first then I got Microsoft security essentials, since I was able to get it directly from Microsoft's website, I figured the risk was lower, I didn't want to risk surfing the web or doing any searches. Once we got the router back up and running I set all the security settings to the most secure possible I also learned something new , which I feel should be the DEFAULT setting on routers and at the very LEAST clearly explained to consumers, and that is to turn OFF SSID broadcasting. For those that don't know (like I didn't) that makes it so you have to KNOW your SSID to connect to your network, sure you have to set up and connect manually the first time but my gosh its SOOO much more secure!!!! Anyway I think I have the problems fixed, it appears the router was what was infected all along and it was never my laptop or at least not directly. Who knew?! I also ended up having to do a factory reset on my other desktop (going to update that thread next) I just couldn't take a chance on connecting it to the router and re-infecting the whole network again. Wow this is some really scarey, major stuff and I am shocked there is so little info out there about it!

Any thing you would like me to run for you to check? As I said everything seems to be working great now, all systems are faster, cleaner (since I pretty much wiped everything out) All software updates easily including security software. Our IT guy at work is the one who suggested Microsoft Security Essentials, he said it was really good, I would love to know what you and the others here at BC opinion is on it?

many many thanks! I would NEVER have been able to figure it out without your help and knowledge, I had no idea a router could even get infected! BLESS YOU, BLESS YOU, BLESS YOU!!!

#18 User is offline   StephL67 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 25
  • Joined: 27-March 11
  • Gender:Female
  • Location:Georgia

Posted 25 April 2011 - 07:02 PM

I would like to make a donation but I cannot set up a PayPal account as I do not have my own bank account, is there a way to mail a donation? A money order? I would really like to donate because as I said there is no way I could have fixed it and I would have been paying 120.00 plus to have my laptop cleaned at Best Buy just to bring it home and have it get reinfected from the router!

#19 User is offline   myrti 

  • bleepin' _temp_
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 27,518
  • Joined: 25-January 08
  • Gender:Female
  • Location:At home

Posted 28 April 2011 - 03:05 PM

Hi,

sorry for the delay. Easter week-end over extended a little.

I'm happy to hear that you got things sorted, even though it sounds as if you had a rough time sorting things. The router is infected through a PC attached to it, meaning that one of the PCs that were connected to it must have been infected at one point. Though not necessarily still at the point when we started investigating your problems.

I'll PM you about the donation as I don't think paypal accepts money orders and I live in Europe, which would make mailing quite expensive.

regards myrti
If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM!

Posted Image
Please don't send help request via PM, unless I am already helping you. Use the forums!

I know not with what weapons World War III will be fought, but World War IV will be fought with sticks and stones. ~ Albert Einstein
Heroism on command, senseless violence, and all the loathsome nonsense that goes by the name of patriotism -- how passionately I hate them! ~ Albert Einstein

Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users