lolly
Topic Starter
This is a long post….
This is on behalf of my mum (this one isn't my fault
) - I hope it's not a problem to have two active posts at the same time (completely unrelated though). I'm hoping this computer (running Windows XP) is saveable. It happened back in April and I posted on Microsoft Answers, but I didn't know about WTT back then…so I thought I'd try here to try to fix it. The computer has been offline ever since (turned on maybe three times with data cable removed), so it hasn't been updated since April.
Microsoft rated the trojans as severe risk, so I didn't want to connect to the internet using that computer in case it was one of the ones that transfered information from the computer to another computer (this was used as the main computer before the virus appeared).
Because it was so long ago, I've posted below what I posted to Microsoft Answers. Maybe I can buy a new USB and download the programs I might need on a computer that isn't (to my knowledge
) compromised and then whack it in the infected computer and run detection/removal programs from there (so I don't connect while it's still possibly unsafe).
—–
[April 15, 2012]
About 2 hours ago, my mum had been looking up some stuff on Google Images, but MSE kept popping up with a warning. She clicked Quarantine or Remove. She shut all the sites except for her email. Then she walked away from the computer for a little while and when she returned, after about 15 minutes, more warnings had appeared and 'Allowed' themselves automatically.
The computer restarted.
The first file to be quarantined was Exploit:Java/CVE-2012-0507.D!dr at 12:49.
The files that allowed themselves (according to MSE history) were:
VirTool:Win32/Obfuscator.XD (denied at 12:56, but allowed itself at 1:02 and 1:06)
Trojan:Win32/Sirefef.AC (removed at 12:51, 12:52, 12:54, 12:55, but allowed at 1:26 and 1:32)
Trojan:Win32/Sirefef.AH (removed at 12:52, 12:55, 12:56, but allowed at 1:32)
I got her to pull out the internet as soon as I realised. I pulled out another one I thought was the wireless adapter but realised I'd pulled the wrong cord about an hour later and it was still active (would my computer, on the same network, be okay?).
It took a long time to restart and when I managed to open MSE, it restarted the computer again.
When I finally I restarted the computer, quarantined AC and AH at 1:34, removed them when they popped up again at 2:12 and quarantined them again at 2:48 (usually, Quarantine would be the only option given).
First it wouldn't let me reactivate MSE. Then I went into Safe Mode and ran some scans, nothing came up on MSE (and the other programs weren't showing up), but it still wouldn't let me reactivate MSE anyway. I did that two or three times and then the next time it skipped Safe Mode and went straight to the normal Windows, with MSE activated again.
The scans come through as clean (I don't trust it though
). I've run MSE (nothing shows up with MSE until a restart, then it's always one random System32 file) and Spybot (nothing beyond the usual browser ads), downloaded Malwarebytes (nothing shows up) and Microsoft Windows Malicious Software Removal Tool (nothing) from another computer. I ran HijackThis, but then realised that I have no idea what the output means anyway.
Password was changed for an email account that was open when the computer became infected. Removable drive was taken out when I shut the computer down (not a restart of its own accord). Nothing critical was open at that point, but when I go into Add/Remove programs and sort by date last accessed, it shows that eTax was 'last accessed' at some point today (it could be a coincidence? Please don't freak me out on this if you don't have to…the tax files were last modified last year, when sorted by last modified date). [This could have been from the scans, maybe?]
I've done a Disk Cleanup too.
This wouldn't have been a problem if they hadn't allowed themselves, right? Is there anything I can do now or has that ship sailed?
I would've tried to upload the files to VirusTotal, but they have disappeared? The files that were allowed were:
C:\Windows\Temp\dyemrh\setup.exe
C:\Windows\Temp\rodauh\setup.exe
C:\Windows\system32\XilinxPC4Driver.dll
C:\Windows\system32\XilinxPC4Driver.dll (service: FINEPIX_PCC)
C:\Windows\Temp\oukvxf\setup.exe
containerfile: C:\Windows\system32\XilinxPC4Driver.dll
file: C:\Windows\system32\XilinxPC4Driver.dll->EWS->1.cod
service: FINEPIX_PCC
Others (now removed or quarantined) were:
XilinxPC4Driver.dll
toshidpt.dll (service STV680)
nvmd.dll (service: netdevio)
The scanners say it's clear, but when I restart the computer, it tells me there's another infected file (just restarted it then and it tells me it's Sirefef.AC with the status 'Suspended' and the Recommended Action being to Quarantine. That's now in system32\IASJet.dll. I applied the recommended action and it now has the status 'Succeeded'.
Then the MSE icon in the bottom corner is still red, so when I click on it, it comes up as 1 potential threat on your computer (as always, after I quarantine the AC file, it's the AH file). This one has the status of 'Active', so I Quarantine it (the only option). It is in the sale file ->EWS->1.cod (service cpucoolserver). Whenever I Quarantine the AH file, it comes up saying the actions were applied successfully, but the status is 'Not found'.
I run a MSE scan after it and it tells me that 35942 items and no threats were detected. Then I run a MalwareBytes scan (database out by 10 days [straight from website download] though…but I don't want to connect to update it!) and it doesn't detect anything (and I assume it wouldn't, if the virus is only a couple of days old from what I can find).
Edit:
Superantispyware won't open. Hitman Pro needs internet (and I don't particularly want to connect if the computer is compromised?)
Edit 2:
Okay, RogueKiller shows some changes…I think.
Registry entry
[HJ] NewStartPanel
Infection: ZeroAccess
(LOCKED) windir\NtUpdateKBxxxx present! (<— this one is bad news, right?)
A bunch of hosts files, most sites with 0s in them
–
Okay, I just ran TDSSKiller and it found 1 threat. I clicked Cure and it disappeared, but MSE found two new threats, both 'Suspended'.
Trojan:Win32/Alureon.FP
Trojan:Win32/Sirefef.AB
Both of these are located within file C:\TDSSKiller_Quarantine\15.04.2102_16.48.34\rtkt0000\zafs0000\ as tsk0009.dta and tsk0002.dta respectively.
It says that it processed 308 files, found 1 threat, neutralised 12 threats and quarantined 12 objects.
I have quarantined them both. Both say status 'Succeeded'.
—-
Back to today:
So…is there anything I can do? Is this a particularly bad infection (ie, rootkit or backdoor)? I think the Microsoft Answers people had mentioned the word rootkit, but when they did, my mind may have shut down.
Most important thing - would there be a problem in transfering images, video, music and some documents from that computer to a USB drive? (before a clean install). I assume a clean install would be the best approach?
This is on behalf of my mum (this one isn't my fault
Microsoft rated the trojans as severe risk, so I didn't want to connect to the internet using that computer in case it was one of the ones that transfered information from the computer to another computer (this was used as the main computer before the virus appeared).
Because it was so long ago, I've posted below what I posted to Microsoft Answers. Maybe I can buy a new USB and download the programs I might need on a computer that isn't (to my knowledge
—–
[April 15, 2012]
About 2 hours ago, my mum had been looking up some stuff on Google Images, but MSE kept popping up with a warning. She clicked Quarantine or Remove. She shut all the sites except for her email. Then she walked away from the computer for a little while and when she returned, after about 15 minutes, more warnings had appeared and 'Allowed' themselves automatically.
The computer restarted.
The first file to be quarantined was Exploit:Java/CVE-2012-0507.D!dr at 12:49.
The files that allowed themselves (according to MSE history) were:
VirTool:Win32/Obfuscator.XD (denied at 12:56, but allowed itself at 1:02 and 1:06)
Trojan:Win32/Sirefef.AC (removed at 12:51, 12:52, 12:54, 12:55, but allowed at 1:26 and 1:32)
Trojan:Win32/Sirefef.AH (removed at 12:52, 12:55, 12:56, but allowed at 1:32)
I got her to pull out the internet as soon as I realised. I pulled out another one I thought was the wireless adapter but realised I'd pulled the wrong cord about an hour later and it was still active (would my computer, on the same network, be okay?).
It took a long time to restart and when I managed to open MSE, it restarted the computer again.
When I finally I restarted the computer, quarantined AC and AH at 1:34, removed them when they popped up again at 2:12 and quarantined them again at 2:48 (usually, Quarantine would be the only option given).
First it wouldn't let me reactivate MSE. Then I went into Safe Mode and ran some scans, nothing came up on MSE (and the other programs weren't showing up), but it still wouldn't let me reactivate MSE anyway. I did that two or three times and then the next time it skipped Safe Mode and went straight to the normal Windows, with MSE activated again.
The scans come through as clean (I don't trust it though
Password was changed for an email account that was open when the computer became infected. Removable drive was taken out when I shut the computer down (not a restart of its own accord). Nothing critical was open at that point, but when I go into Add/Remove programs and sort by date last accessed, it shows that eTax was 'last accessed' at some point today (it could be a coincidence? Please don't freak me out on this if you don't have to…the tax files were last modified last year, when sorted by last modified date). [This could have been from the scans, maybe?]
I've done a Disk Cleanup too.
This wouldn't have been a problem if they hadn't allowed themselves, right? Is there anything I can do now or has that ship sailed?
I would've tried to upload the files to VirusTotal, but they have disappeared? The files that were allowed were:
C:\Windows\Temp\dyemrh\setup.exe
C:\Windows\Temp\rodauh\setup.exe
C:\Windows\system32\XilinxPC4Driver.dll
C:\Windows\system32\XilinxPC4Driver.dll (service: FINEPIX_PCC)
C:\Windows\Temp\oukvxf\setup.exe
containerfile: C:\Windows\system32\XilinxPC4Driver.dll
file: C:\Windows\system32\XilinxPC4Driver.dll->EWS->1.cod
service: FINEPIX_PCC
Others (now removed or quarantined) were:
XilinxPC4Driver.dll
toshidpt.dll (service STV680)
nvmd.dll (service: netdevio)
The scanners say it's clear, but when I restart the computer, it tells me there's another infected file (just restarted it then and it tells me it's Sirefef.AC with the status 'Suspended' and the Recommended Action being to Quarantine. That's now in system32\IASJet.dll. I applied the recommended action and it now has the status 'Succeeded'.
Then the MSE icon in the bottom corner is still red, so when I click on it, it comes up as 1 potential threat on your computer (as always, after I quarantine the AC file, it's the AH file). This one has the status of 'Active', so I Quarantine it (the only option). It is in the sale file ->EWS->1.cod (service cpucoolserver). Whenever I Quarantine the AH file, it comes up saying the actions were applied successfully, but the status is 'Not found'.
I run a MSE scan after it and it tells me that 35942 items and no threats were detected. Then I run a MalwareBytes scan (database out by 10 days [straight from website download] though…but I don't want to connect to update it!) and it doesn't detect anything (and I assume it wouldn't, if the virus is only a couple of days old from what I can find).
Edit:
Superantispyware won't open. Hitman Pro needs internet (and I don't particularly want to connect if the computer is compromised?)
Edit 2:
Okay, RogueKiller shows some changes…I think.
Registry entry
[HJ] NewStartPanel
Infection: ZeroAccess
(LOCKED) windir\NtUpdateKBxxxx present! (<— this one is bad news, right?)
A bunch of hosts files, most sites with 0s in them
–
Okay, I just ran TDSSKiller and it found 1 threat. I clicked Cure and it disappeared, but MSE found two new threats, both 'Suspended'.
Trojan:Win32/Alureon.FP
Trojan:Win32/Sirefef.AB
Both of these are located within file C:\TDSSKiller_Quarantine\15.04.2102_16.48.34\rtkt0000\zafs0000\ as tsk0009.dta and tsk0002.dta respectively.
It says that it processed 308 files, found 1 threat, neutralised 12 threats and quarantined 12 objects.
I have quarantined them both. Both say status 'Succeeded'.
—-
Back to today:
So…is there anything I can do? Is this a particularly bad infection (ie, rootkit or backdoor)? I think the Microsoft Answers people had mentioned the word rootkit, but when they did, my mind may have shut down.
Most important thing - would there be a problem in transfering images, video, music and some documents from that computer to a USB drive? (before a clean install). I assume a clean install would be the best approach?