Solved Is this a virus?! Never seen this before... so weird and creepy.

Discussion in 'Virus, Spyware and Malware Removal' started by superfly75, Jul 4, 2012.


Thread Status:
Not open for further replies.
  1. superfly75 Bronze Member

    I've Donated!
    Bronze
    Message Count:
    29
    Likes Received:
    0
    My System
    Loading...
    So here we go, I have problems with my laptop again. It was running very well until this week-end, when I updated Avast, Flash and Java (the typical updates).

    Avas put me in trouble again because after updating to a new software version, the desktop would not populate (no icons, no Start menu, nothing...). This happened before (I suspect a conflict with Zone Alarm at startup) and the workaround is to start in Safe Mode, uninstall Avast, reinstall Avast.

    However since then I have extremely weird behavior, with windows getting washed of their content! See the images. Even the logon windows, task manager and other basic Windows functions are getting washed... basically ending in me loosing total control of the computer until I go for hard reboot. It doesn't happen straight after reboot, maybe after 5-6 hours of uptime... I am not sure wether its a virus or something else... Any ideas?

    I suspected Skype for a while but was able to ruled that out when the problem appeared again while Skype was not running. I also suspected Avast and anyway I was ****** with the recurring problem of empty desktop after ugrading Avast to latest version, so I uninstalled Avast and upgraded to Zone Alarm free AV+Firewall.

    At the time I am writing this, I still have control of my machine. MBAM did not return any positive threat.

    Any ideas or suggestions?

    Thanks,

    Alex

    IMG_5965.jpg



    IMG_5967.jpg

    IMG_5969.jpg

    IMG_5971.jpg
  2. Kedar Geek

    PCHF Staff
    Message Count:
    9,244
    Likes Received:
    786
    My System
    Loading...
  3. superfly75 Bronze Member

    I've Donated!
    Bronze
    Message Count:
    29
    Likes Received:
    0
    My System
    Loading...
    Hi Kedar, thanks for your response.
    Here are the two first files.

    Attached Files:

  4. Google Advertisement

  5. superfly75 Bronze Member

    I've Donated!
    Bronze
    Message Count:
    29
    Likes Received:
    0
    My System
    Loading...

    Attached Files:

  6. Pancake Security Team

    PCHF Staff
    Message Count:
    13,497
    Likes Received:
    594
    My System
    Loading...
    Download Combofix from any of the links below, and save it to your desktop.
    Link 1
    Link 2
    Link 3
    When saving ComboFix rename it to PCHelpForum.exe to prevent it from being blocked by malware.

    Refer to this image:
    To prevent your anti-virus application interfering with ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.
    • Close any open windows and double click PCHelpForum.exe to run it.
      You will see the following image:
    [IMG]

    Click I Agree to start the program.
    ComboFix will then extract the necessary files and you will see this:

    [IMG]

    As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7
    It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    If you did not have it installed, you will see the prompt below. Choose YES.

    [IMG]

    Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [IMG]

    Click on Yes, to continue scanning for malware.
    When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).
    Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.
    Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.
  7. superfly75 Bronze Member

    I've Donated!
    Bronze
    Message Count:
    29
    Likes Received:
    0
    My System
    Loading...
    Thanks! Here is the report

    Attached Files:

  8. Pancake Security Team

    PCHF Staff
    Message Count:
    13,497
    Likes Received:
    594
    My System
    Loading...
    Ok.All done.I see no more malware.Log looks good! All that was detected is now either in quarantine or system restore, both of which we'll be cleaning out in just a minute. Congratulations, well done.

    You can now uninstall ComboFix

    • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
    • In the field, type in ComboFix /uninstall
    [IMG]

    (Note: Make sure there's a space between the word ComboFix and the forward-slash.)

    • Then, press Enter, or click OK.
    • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.

    Over the course of the fix you've used a variety of special tools to help with the cleaning process - none of these are of any use to you now that you're clean, and it's best not to have them hanging around on your computer. OTC is a small program that removes all the leftover tools and logs from cleanup of malware.

    Please download OTC to your desktop.

    Double-click OTC to run it. (Vista users, please right click on OTC and select "Run as an Administrator")
    Click on the CleanUp! button and follow the prompts.
    You will be asked to reboot the machine to finish the Cleanup process, choose Yes.
    After the reboot all the tools we used should be gone.
    Note: Some more recently created tools may not yet be removed by OTC. Feel free to manually delete any tools it leaves behind.

    Here are some tips to reduce the potential for malware infection in the future; I strongly suggest that you read them and take them to heart so that you don't have to endure the process of cleaning your computer again.
    Afterwork
    Malware Prevention
    How Did I Get Infected
    More Tips on Prevention

    =============================
  9. superfly75 Bronze Member

    I've Donated!
    Bronze
    Message Count:
    29
    Likes Received:
    0
    My System
    Loading...
    OK cleaning done! Thanks a lot!
    Do we know what was this nasty virus? How come Avast, MBAM and ZA did not protect me?
    I think the virus leveraged the time gap when I updated Avast to sneakingly infect my computer? Anyway something was wrong as Avast did not upgrade properly... maybe some dormant virus....
    :-(
  10. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,781
    Likes Received:
    883
    My System
    Loading...
    Hello.
    Before we can let you go, I spotted another issue in your Combofix log. 1 of your system files has failed verfication check, so it's either corrupt, or malware is messing with it, and it needs replacing.

    Please re-download Combofix.

    1. Close any open browsers.
    2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    3. Open notepad and copy/paste the text in the quotebox below into it:
      Code:
      File::
      C:\WINDOWS\System32\drivers\rpkkmcif.sys
       
      FCopy::
      c:\windows\$NtServicePackUninstall$\tcpip.sys | c:\windows\system32\drivers\tcpip.sys
       
      Registry::
      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
      "5985:TCP"=-
       
      Reboot::
      
    4. Save this as CFScript.txt, in the same location as ComboFix.exe

      [IMG]
    5. Referring to the picture above, drag CFScript into ComboFix.exe
    6. When finished, it shall produce a log for you at C:\ComboFix.txt
    7. Please post the contents of the log in your next reply.
    s
    Pancake likes this.
  11. superfly75 Bronze Member

    I've Donated!
    Bronze
    Message Count:
    29
    Likes Received:
    0
    My System
    Loading...
    Hi Thanks for the doublecheck! I ran the combofix with script and here is the report.

    Note that I had some trouble after reboot because the ZA and MBAM re-started too and Combo fix was stuck. I was asked whether to allow mbr.3XE and I figured out it was probably combofix-related... (I dunno if there is a way to deactivate ZA to start after reboot, because I just quit the program manually)...

    So if it clean now? :)

    IMG_5976.jpg

    IMG_5978.jpg

    Attached Files:

  12. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,781
    Likes Received:
    883
    My System
    Loading...
    Yeah, MBR.3xe is part of Combofix, it's for scanning/repairing the MBR.

    Everything looks fine now.
  13. superfly75 Bronze Member

    I've Donated!
    Bronze
    Message Count:
    29
    Likes Received:
    0
    My System
    Loading...
    Thanks! Do I have to clean combo fix like before?
  14. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,781
    Likes Received:
    883
    My System
    Loading...
    Yes please.
  15. superfly75 Bronze Member

    I've Donated!
    Bronze
    Message Count:
    29
    Likes Received:
    0
    My System
    Loading...
    OK. Cleaned and rebooted.
    However now I have a pop-up of Windows Update asking me to update kb2509353.
    Is it safe? Is it due to the fix we just did?
    I'm always scared that a virus could use the Windows Update protocol to infect my machine...
    This KB is pretty old : "MS11-030: Vulnerability in DNS Resolution could allow remote code execution: April 12, 2011"
    http://support.microsoft.com/kb/2509553
    http://www.microsoft.com/en-us/download/details.aspx?id=16350
    Better safe than sorry, I will wait for green light...
  16. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,781
    Likes Received:
    883
    My System
    Loading...
    I'd download it anyway, updates are always good.

    In terms of malware exploiting Windows Updates protocol, there's only ever been 1 piece of malware that exploited the update protocol and that was made by the US Gov made to attack Iran so your safe.

Is this a virus?! Never seen this before... so weird and creepy.

Thread Status:
Not open for further replies.