This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

A few viruses.... [Solved]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This is a long post….

This is on behalf of my mum (this one isn't my fault ;) ) - I hope it's not a problem to have two active posts at the same time (completely unrelated though). I'm hoping this computer (running Windows XP) is saveable. It happened back in April and I posted on Microsoft Answers, but I didn't know about WTT back then…so I thought I'd try here to try to fix it. The computer has been offline ever since (turned on maybe three times with data cable removed), so it hasn't been updated since April.

Microsoft rated the trojans as severe risk, so I didn't want to connect to the internet using that computer in case it was one of the ones that transfered information from the computer to another computer (this was used as the main computer before the virus appeared).

Because it was so long ago, I've posted below what I posted to Microsoft Answers. Maybe I can buy a new USB and download the programs I might need on a computer that isn't (to my knowledge :unsure: ) compromised and then whack it in the infected computer and run detection/removal programs from there (so I don't connect while it's still possibly unsafe).

—–

[April 15, 2012]

About 2 hours ago, my mum had been looking up some stuff on Google Images, but MSE kept popping up with a warning. She clicked Quarantine or Remove. She shut all the sites except for her email. Then she walked away from the computer for a little while and when she returned, after about 15 minutes, more warnings had appeared and 'Allowed' themselves automatically.

The computer restarted.

The first file to be quarantined was Exploit:Java/CVE-2012-0507.D!dr at 12:49.

The files that allowed themselves (according to MSE history) were:

VirTool:Win32/Obfuscator.XD (denied at 12:56, but allowed itself at 1:02 and 1:06)

Trojan:Win32/Sirefef.AC (removed at 12:51, 12:52, 12:54, 12:55, but allowed at 1:26 and 1:32)

Trojan:Win32/Sirefef.AH (removed at 12:52, 12:55, 12:56, but allowed at 1:32)

I got her to pull out the internet as soon as I realised. I pulled out another one I thought was the wireless adapter but realised I'd pulled the wrong cord about an hour later and it was still active (would my computer, on the same network, be okay?).

It took a long time to restart and when I managed to open MSE, it restarted the computer again.

When I finally I restarted the computer, quarantined AC and AH at 1:34, removed them when they popped up again at 2:12 and quarantined them again at 2:48 (usually, Quarantine would be the only option given).

First it wouldn't let me reactivate MSE. Then I went into Safe Mode and ran some scans, nothing came up on MSE (and the other programs weren't showing up), but it still wouldn't let me reactivate MSE anyway. I did that two or three times and then the next time it skipped Safe Mode and went straight to the normal Windows, with MSE activated again.

The scans come through as clean (I don't trust it though ;) ). I've run MSE (nothing shows up with MSE until a restart, then it's always one random System32 file) and Spybot (nothing beyond the usual browser ads), downloaded Malwarebytes (nothing shows up) and Microsoft Windows Malicious Software Removal Tool (nothing) from another computer. I ran HijackThis, but then realised that I have no idea what the output means anyway.

Password was changed for an email account that was open when the computer became infected. Removable drive was taken out when I shut the computer down (not a restart of its own accord). Nothing critical was open at that point, but when I go into Add/Remove programs and sort by date last accessed, it shows that eTax was 'last accessed' at some point today (it could be a coincidence? Please don't freak me out on this if you don't have to…the tax files were last modified last year, when sorted by last modified date). [This could have been from the scans, maybe?]

I've done a Disk Cleanup too.

This wouldn't have been a problem if they hadn't allowed themselves, right? Is there anything I can do now or has that ship sailed?

I would've tried to upload the files to VirusTotal, but they have disappeared? The files that were allowed were:

C:\Windows\Temp\dyemrh\setup.exe
C:\Windows\Temp\rodauh\setup.exe
C:\Windows\system32\XilinxPC4Driver.dll
C:\Windows\system32\XilinxPC4Driver.dll (service: FINEPIX_PCC)
C:\Windows\Temp\oukvxf\setup.exe
containerfile: C:\Windows\system32\XilinxPC4Driver.dll
file: C:\Windows\system32\XilinxPC4Driver.dll->EWS->1.cod
service: FINEPIX_PCC

Others (now removed or quarantined) were:
XilinxPC4Driver.dll
toshidpt.dll (service STV680)
nvmd.dll (service: netdevio)

The scanners say it's clear, but when I restart the computer, it tells me there's another infected file (just restarted it then and it tells me it's Sirefef.AC with the status 'Suspended' and the Recommended Action being to Quarantine. That's now in system32\IASJet.dll. I applied the recommended action and it now has the status 'Succeeded'.

Then the MSE icon in the bottom corner is still red, so when I click on it, it comes up as 1 potential threat on your computer (as always, after I quarantine the AC file, it's the AH file). This one has the status of 'Active', so I Quarantine it (the only option). It is in the sale file ->EWS->1.cod (service cpucoolserver). Whenever I Quarantine the AH file, it comes up saying the actions were applied successfully, but the status is 'Not found'.

I run a MSE scan after it and it tells me that 35942 items and no threats were detected. Then I run a MalwareBytes scan (database out by 10 days [straight from website download] though…but I don't want to connect to update it!) and it doesn't detect anything (and I assume it wouldn't, if the virus is only a couple of days old from what I can find).


Edit:

Superantispyware won't open. Hitman Pro needs internet (and I don't particularly want to connect if the computer is compromised?)

Edit 2:

Okay, RogueKiller shows some changes…I think.

Registry entry

[HJ] NewStartPanel

Infection: ZeroAccess

(LOCKED) windir\NtUpdateKBxxxx present! (<— this one is bad news, right?)

A bunch of hosts files, most sites with 0s in them

–

Okay, I just ran TDSSKiller and it found 1 threat. I clicked Cure and it disappeared, but MSE found two new threats, both 'Suspended'.

Trojan:Win32/Alureon.FP
Trojan:Win32/Sirefef.AB

Both of these are located within file C:\TDSSKiller_Quarantine\15.04.2102_16.48.34\rtkt0000\zafs0000\ as tsk0009.dta and tsk0002.dta respectively.

It says that it processed 308 files, found 1 threat, neutralised 12 threats and quarantined 12 objects.

I have quarantined them both. Both say status 'Succeeded'.


—-

Back to today:

So…is there anything I can do? Is this a particularly bad infection (ie, rootkit or backdoor)? I think the Microsoft Answers people had mentioned the word rootkit, but when they did, my mind may have shut down.

Most important thing - would there be a problem in transfering images, video, music and some documents from that computer to a USB drive? (before a clean install). I assume a clean install would be the best approach?
Hi ,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.


It is generally not a good idea to be working on more than one computer at a time as it is easy to get confused as to which instructions you are following for which machine. However, if you want to give it a try… I'm game.

One of the infections you've noted is Sirefef. That's a rootkit. A particularly nasty one - though all rootkits are nasty. Many experts believe that there is no way of being 100 percent certain that a rootkit has been cleaned completely off of a system once it's been infected. A reformat and reinstall of the complete system is really your only way to be sure you've gotten it all. If you don't do sensitive things on your system… like online banking… we can try to clean it. The choice is yours.

If you choose to reformat… you are usually safe to recover your personal data. Pics, music, video's (a little caveat here. I'm talking legitimate music and videos. Not pirated ones downloaded from some torrent site. These are infected the vast majority of the time), word docs, excel files. Before transffering files to your USB drive… do the following on it:

Download and Run FlashDisinfector

You may have a flash drive infection. These worms travel through your portable drives. If they have been connected to other machines, they may now be infected.

  • Please download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
    Note: Some security programs will flag Flash_Disinfector as being some sort of malware, you can safely ignore these warnings
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.


Anti-Malware programs flag Flash Disinfector as being infected because of in which the way it runs.

Let me know what you want to do. Do you want to reformat or try to clean?
Thanks very much for the reply :). We're happy to reformat. I think we might have to wait until the weekend to get time to do that though. I'll get her to download the file and start moving stuff across between now and then. Just thinking though, I know that the USB HD that was in the computer at the time has been used in other computers since. Is there a way for me to tell if the other computers have been infected? (Oh I hope not!). When the computer had been taken offline, some files were transfered to another HD in preparation for a reformat, will running the FlashDisinfector get rid of any nasties there or does that need to be done at the start? That one hasn't been into another computer. I know you probably can't answer this, but a guess would be great - Mum keeps asking me to ask how much information could be sucked from a computer in around 30 minutes? Is that the point of the rootkit? Would pulling the phone line have been a good move?
Flash disinfector prevents your USB drive from transferring a virus. If you install an infected file on the USB drive and then transfer it to another computer and then run it… the 2nd computer will be infected. If you don't transfer any executable files (.exe, .com. .scr. pif…) then there is little likelihood that you will transfer a virus. As for the other computers… are the behaving "strangely"? Do you have up-to-date Anti-virus programs installed and running on them? The risk of passing a nasty with a USB drive is significantly reduced on a Windows 7 system. As you have suspected, it is impossible to tell what could have happened in 30 minutes. Information is stolen in two different ways. One way is by accessing your computer through a backdoor at which time the nefarious perpetrator would have access to everything on your computer. Obviously a significant amount of information could be obtained in 30 minutes. But… typically this type of infection requires that it report back to a host and then your system would have to be accessed. There are thousands of infected computers out there. The likelihood that in that 30 minutes your system was accessed is probably pretty small. In the second scenario, the infection intercepts packets of information and sends them "home". The information it is trying to glean is things like passwords. In order for it to obtain this information, you would need to send the information before it could steal it. In other words, you would have to access a site (such as a bank) that requires a username and password. The information could then be intercepted and sent to the bad guys. If in the 30 minutes in question you were not accessing any "sensitive" sites, there probably wasn't much information that was at risk of being intercepted. However, you should never take that risk. All passwords should be changed immediately and if your computer is used for things like online banking then your accounts should be monitored carefully.
Sorry about the delay getting back to you. I don't think the other computers have been acting strangely. One is a work computer (XP) on a network and the other is a personal laptop (Win7). We had run ESET on the laptop and it didn't pick anything up - it has always had MBAM and MSE running and I don't recall any instances of restarting or having MSE not working. ESET had a bit of a problem running once but then it worked the next time. We'll be transferring stuff off the big computer today, ready for the clean install! :D
Hmm. Okay. This may be unrelated. Hopefully. The laptop has just had a bit of an issue, but it's the first issue it has had. I'm not aware of any updates being installed on the computer today (other than the general MBAM and MSE updates), but it took a while starting up tonight (had the black Windows screen and the Windows logo with the 'starting Windows'). It was taking a few minutes, so she restarted it. When she turned it back on, it came up with one of the black screens with 'Windows failed to start. A recent hardware or software change might be the cause'. We let the startup repair do its thing and then it shut down (it had said that it might shut down and start up a couple of times, but it just shut down and turned off). Not sure if it shut down because it overheated (it's an Inspiron 15 that has a history of problems with overheating). We turned it back on and it's doing a Pre-boot System Assessment Build 4124. So far CD-Rom Optical, Video Card, LCD Connect, LCD Bright and Graphics have passed, but it's now on Memory WCMch Test and it's at 5% complete and taking forever. Edit: It just finished. It found no problems, but asked if we wanted to run remaining memory tests, we said No and exited. When it started up again, it gave us the 'Windows failed to start again' so we chose Start Windows Normally and Windows loaded. Are there any tests I should do on this computer to check that nothing has happened? Could this all be because she restarted it while it was loading…. :unsure:
It is likely that it's just because she restarted. If it doesn't manifest itself again… then I'd not worry about it. If it does it again… then I suggest you seek help from the Tech Team in the hardware forum. They will be much more useful for you than I will for this type of problem.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI