Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

false windows essentials and possible other infections


  • This topic is locked This topic is locked
2 replies to this topic

#1 script-kitty

script-kitty

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:06:13 PM

Posted 16 September 2010 - 08:10 PM

OK so first my cursor keeps getting re focused so i do a scan with my malwarebytes and it finds and removes 1 infection... i go on and google chrome starts crashing repeatedly within like a 20 minute period it had crashed 4 times. then as i am about to close it and do another scan everything starts closing and shutting down! in the process of everything closing i get a little box impersonating a windows essentials infection found... now i know i didn't install windows essentials so i tried to close it. of all the things that where closing this one thing i actually wanted gone wouldn't close! that is until the entire system rebooted itself.... i let it boot and start normally but just as it got to the user sign in i got a blue screen... so i then moved to reboot in safe mode. the fake error message popped up again so i figured from it popping up in safe mode and the blue screen earlier it was something starting with the system. so first i run another Malwarebytes scan which finds 56 infections which it then removes and i check out my Avast anti-virus to turn on a boot scan hoping i could catch it before it starts again. i find that not only are all my shields off but i cant turn them back on! also it wont let me set the boot scan.... i attempt to open windows task manager and of-course whatever is screwing with my system doesn't allow it. it closes as soon as it opens... i figured id reboot in safe mode and try a system restore... but it tells me that system restore has been turned off by group policy... this is MY computer and Ive never turned the the thing off so i assume its the infection screwing with another "threat" to its malicious behavior. so i run another scan with malwarebytes, not much else i could do at this point.. and it already finds even more infections! i reboot to get rid of those new infections, try normal start- blue screen- reboot to safe mode.... ran another scan because i figure the less infections there are when i figure out how to get rid of this the better... except now malwarebytes is erroring and wont scan... i connect to bleeping computer, reinstall malwarebytes, fixes malwarebytes, and check for a similar infection listed... found what describes the windows essentials fake but nothing to explain the blue screen at startup.... so i attempt to remove the windows essentials fake before moving on to the blue screen. i run rkill and it pops up with the same message i get at safe mode startup notifying me that this is safe mode and asking if i want to system restore. i click that i want to continue in safe mode and out of my own stupid curiosity i run rkill again thinking if the processes are dead then it wont do anything but th message pops up again and this time i click that i want to restore but it tells me i cant restore because it was turned off and yada yada... so swomething was aparently still running that wasnt supposed to be so after another nice boot and scan im posting this....

sorry to sound like im posting my life story but yeah im just bad with summerizing and keeping the important information.... so yeah... help please =(

update: i keep doing malwarebytes scans and it keeps finding new infections, the longer i wait before i do another can the more infections it seems so i think there's probably something on my computer downloading all this that malwarebytes isnt catching... seeing as how im doing nothing but hanging out in safe mode on bleepingcomputer and scanning


here are the malwarebytes logs:

1
xxxxxxxxxxxxxxxx



Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702

9/16/2010 8:33:30 PM
mbam-log-2010-09-16 (20-33-30).txt

Scan type: Full scan (C:\|)
Objects scanned: 242917
Time elapsed: 24 minute(s), 38 second(s)

Memory Processes Infected: 5
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 14
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 21

Memory Processes Infected:
C:\WINDOWS\login.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\wininst.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\csrss.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\spoolsv.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\win32.exe (Trojan.Downloader) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkcrc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkcrc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkfre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkfre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkayc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkayc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkeuf (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkeuf (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hnugroxrspc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hnugroxrspc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkze (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkbuqc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> Delete on reboot.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\login.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\wininst.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\csrss.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\spoolsv.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\win32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\avp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\iexplarer.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\1516408094.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\2738809982.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\3695997482.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\gdi32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\iexplorer.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\mdm.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\services.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\system.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\avp32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\hexdump.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\lsass.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\services.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\winamp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.



xxxxxxxxxxx
2
xxxxxxxxxxx




Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702

9/16/2010 10:13:46 PM
mbam-log-2010-09-16 (22-13-46).txt

Scan type: Full scan (C:\|)
Objects scanned: 243320
Time elapsed: 24 minute(s), 24 second(s)

Memory Processes Infected: 8
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 20
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 9

Memory Processes Infected:
C:\WINDOWS\drweb.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\hexdump.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\mdm.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\svchost.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\sysedit.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\user.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\win16.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\winamp.exe (Trojan.Downloader) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkasc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkasc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkbtc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkbtc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkcz (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkcz (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkese (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkese (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mketc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mketc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkee (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkee (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkfpc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkfpc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkfpe (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mkfpe (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hnugroxrrg (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hnugroxrrg (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\drweb.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\hexdump.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\mdm.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\svchost.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\sysedit.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\user.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\win16.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\winamp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\smss.exe (Trojan.Agent) -> Delete on reboot.




xxxxxxxxxxxxxxx
3
xxxxxxxxxxxxxxx




Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702

9/16/2010 11:35:39 PM
mbam-log-2010-09-16 (23-35-39).txt

Scan type: Full scan (C:\|)
Objects scanned: 243742
Time elapsed: 21 minute(s), 33 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 5
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
C:\Documents and Settings\Administrator\Local Settings\Temp\cmd.exe (Trojan.Downloader) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hnugroxrnz (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hnugroxrnz (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hnugroxrrg (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hnugroxrrg (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Administrator\Local Settings\Temp\cmd.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\3199554904.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\3508148654.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\smss.exe (Trojan.Downloader) -> Delete on reboot.

Edited by script-kitty, 16 September 2010 - 11:54 PM.
Moved from XP to AII. ~BZ


BC AdBot (Login to Remove)

 


#2 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 37,011 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:06:13 PM

Posted 16 September 2010 - 10:49 PM

Hello script-kitty,

Given what you stated in Chat,

[23:41] <script-kitty> i do however know im also infected with a TDSS type thing which i can take care of after all this


you have a bad rootkit aboard. Please follow the instructions in ==>This Guide<==. If you cannot complete a step, skip it and continue.

Once the proper logs are created, then make a NEW TOPIC and post it ==>HERE<== Please include the link to this topic in your new topic, a description of your computer issues.

If you can produce at least some of the logs, then please create the new topic and explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the topic and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs.

Orange Blossom :thumbsup:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript

#3 Pandy

Pandy

    Bleepin'


  • Members
  • 9,559 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:06:13 PM

Posted 20 September 2010 - 01:42 PM

Hello script-kitty,

Now that you have posted a log here: http://www.bleepingcomputer.com/forums/topic347854.html you should NOT make further changes to your computer (install/uninstall programs, use special fix tools, delete files, edit the registry, etc) unless advised by a MRT Team member, nor should you ask for help elsewhere. Doing so can result in system changes which may not show in the log you already posted. Further, any modifications you make on your own may cause confusion for the helper assisting you and could complicate the malware removal process which would extend the time it takes to clean your computer.

From this point on the MRT Team should be the only members that you take advice from, until they have verified your log as clean.

Please be patient. It may take a while to get a response because the MRT Team members are EXTREMELY busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have made your post and are waiting, please DO NOT make another reply until it has been responded to by a member of the MRT Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another MRT Team member is already assisting you and not open the thread to respond.

Please be patient. It may take several days to get a response but your log will be reviewed and answered as soon as possible. I advise checking your topic once a day for responses as the e-mail notification system is unreliable.

To avoid confusion, I am closing this topic. Good luck with your log.

Do not anticipate trouble, or worry about what may never happen. Keep in the sunlight.

Hide not your talents. They for use were made. What's a sundial in the shade?

~ Benjamin Franklin

I am a Bleeping Computer fan! Are you?

Facebook

Follow us on Twitter





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users