1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved I need help with very strange Chinese SPAM/Malware

Discussion in 'Malware and Virus Removal Archive' started by bellisimo, 2014/05/25.

  1. 2014/05/29
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    There's a message that says another antivirus software was detected. This may affect the performance and quality of the scan. It shows AVG. I have it disabled.
     
  2. 2014/05/29
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Disregard that warning.
     

  3. to hide this advert.

  4. 2014/05/29
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    Hi Broni,

    After 45 minutes, ESET is still on Step 1 of 4. The only indication that it might be working at all is that the Ethernet and Internet lights on the router are flickering a little bit.
     
  5. 2014/05/29
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Eset may take time.
    Leave it overnight.
     
  6. 2014/05/29
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    Okay.

    I've started to tun it on Firefox though I don't hear any activity from the tower. I would have thought I'd hear more than the fans spinning around.
     
    Last edited: 2014/05/30
  7. 2014/05/30
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    Hi Broni,

    Its 4 pm and ESET doesn't seem to have done anything after more than 18 hours. It's still on Step 1. I did a Ctrl. Alt. Delete and it seems to still be running.

    If you think it would make a difference I uninstalled my AVG.
     
    Last edited: 2014/05/30
  8. 2014/05/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Try to run Eset with different browser.
     
  9. 2014/05/30
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    Okay, I've started to run it with Firefox though I don't hear any activity from the tower.
     
  10. 2014/05/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please run F-Secure Online Scanner

    • Disable your Antivirus program.
    • Click on Run now button.
      NOTE. If you're using non-IE browser you'll be asked to download small file (F-SecureOnlineScanner.exe). After downloading double click on the file to run the scan.
    • Click on Start button.
    • Click on "Accept" button.
    • When scan is done, in Step 3: Clean the files, leave all settings as they're.
    • Click Next button.
    • Click Full report... button.
    • Copy report's content and paste it into your next reply.
     
  11. 2014/05/30
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    Broni,

    The F-Secure scan finished quickly and it said there were no problems.

    There's a message saying: Your device is not protected. We recommend that you use a security application to protect your device.

    Then, there is a button on which it says Get SAFE. I think it would probably take me to an antivirus download. What next?


    I think you've cleaned it out. The system has been running beautifully and I haven't seen the wireless light on the router for two days. Before, it was on constantly.
     
    Last edited: 2014/05/30
  12. 2014/05/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    [​IMG] Update Firefox to the latest 29.0.1 version.

    [​IMG] Update Adobe Flash Player: http://get.adobe.com/flashplayer/
    Make sure you UN-check Yes, install McAfee Security Scan Plus

    NOTE 1: Beginning with Adobe Flash Version 11.3, the universal installer includes the 32-bit and 64-bit versions of the Flash Player.
    NOTE 2: While installing make sure you UN-check any extra garbage which wants to install alongside.

    =================================

    Your computer is clean [​IMG]

    1. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
    This is a very crucial step so make sure you don't skip it.
    Download [​IMG]DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

    Double-click Delfix.exe to start the tool.
    Make sure the following items are checked:
    • Activate UAC (optional; some users prefer to keep it off)
    • Remove disinfection tools
    • Create registry backup
    • Purge System Restore
    • Reset system settings
    Now click "Run" and wait patiently.
    Once finished a logfile will be created. You don't have to attach it to your next reply.

    2. Make sure Windows Updates are current.

    3. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    4. Check if your browser plugins are up to date.
    Firefox - https://www.mozilla.org/en-US/plugincheck/
    other browsers: https://browsercheck.qualys.com/ (click on "Launch a quick scan now" link)

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC), AdwCleaner and Junkware Removal Tool (JRT) weekly (you need to redownload these tools since they were removed by DelFix).

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    11. Read:
    How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
    Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/
    About those Toolbars and Add-ons - Potentially Unwanted Programs (PUPs) which change your browser settings: http://www.bleepingcomputer.com/for...curity-questions-best-practices/#entry3187642

    12. Please, let me know, how your computer is doing.
     
  13. 2014/05/31
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    Broni,

    I just opened my computer to send you a thank you message, and as soon as my machine booted up, I was shocked to find the attached on my screen.

    I guess we didn't get it all yet.

    I did everything else you suggested and the only thing that was different was that the Adobe Flash Player is updated to version 13.

    Have you ever seen one worse than this? I don't know what to do.

    I changed my passwords last night, too. Will I have to change them again?

    It's not a very sharp image, I'm afraid. It's the one I described earlier with the trash can about the size of a business card. I can send another if you need it.

    Please let me know what you think.

    Thanks,

    bellisimo
     

    Attached Files:

  14. 2014/05/31
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please re-run MBAM, AdwCleaner and JRT.
    Post all logs.
     
  15. 2014/05/31
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    Hi Broni,

    Here is the MBAM report:

    Malwarebytes Anti-Malware (Trial) 1.75.0.1300
    www.malwarebytes.org

    Database version: v2014.05.31.10

    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 10.0.9200.16899
    a :: BBELL-PC [administrator]

    Protection: Enabled

    5/31/2014 9:29:25 PM
    mbam-log-2014-05-31 (21-29-25).txt

    Scan type: Full scan (C:\|)
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 449883
    Time elapsed: 15 minute(s), 58 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
     
  16. 2014/05/31
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    Here is the JRT scan:

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 6.1.4 (04.06.2014:1)
    OS: Windows 7 Home Premium x64
    Ran by a on Sat 05/31/2014 at 21:48:43.35
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    ~~~ Services



    ~~~ Registry Values



    ~~~ Registry Keys



    ~~~ Files



    ~~~ Folders



    ~~~ Event Viewer Logs were cleared





    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on Sat 05/31/2014 at 21:55:09.14
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     
  17. 2014/05/31
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    Here's the AdwrCleaner scan:

    # AdwCleaner v3.211 - Report created 31/05/2014 at 22:00:09
    # Updated 26/05/2014 by Xplode
    # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
    # Username : a - BBELL-PC
    # Running from : C:\Users\a\Desktop\AdwCleaner.exe
    # Option : Clean

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****


    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****

    Key Deleted : HKCU\Software\AppDataLow\Software

    ***** [ Browsers ] *****

    -\\ Internet Explorer v10.0.9200.16866


    -\\ Mozilla Firefox v29.0.1 (en-US)

    [ File : C:\Users\a\appData\Roaming\Mozilla\Firefox\Profiles\naxv236a.default\prefs.js ]


    -\\ Google Chrome v

    *************************

    AdwCleaner[R0].txt - [845 octets] - [31/05/2014 19:50:53]
    AdwCleaner[R1].txt - [902 octets] - [31/05/2014 21:58:58]
    AdwCleaner[S0].txt - [814 octets] - [31/05/2014 22:00:09]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [873 octets] ##########
     
  18. 2014/05/31
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    OK...I want to make sure...
    The issue happens only if you're actually using IE.
    It doesn't happen when some other browser is being used or no browser is being used at all.
    Is that correct?
     
  19. 2014/05/31
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    Yes, I believe that's true because IE is the only browser I have been using, and my email account is Outlook on IE as well.
     
  20. 2014/05/31
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I can see you also have Firefox installed.
    I want you to use Firefox for couple of computer sessions and see if the issue happens there too.
     
  21. 2014/05/31
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    Sure, I'll try that. For how many days should we try it for? I only ask because if the malware is active in my system, could it now be destroying files during the period when I'm using Firefox.

    I looked up some email files I had saved 2 or 3 years ago and pages of them that I used to be able to open have changed into a type of file that I can no longer access. I don't know if it has anything to do with this malware though.

    I do have all my hard drives backed up with Acronis True image on my external drive though I haven't a clue how to restore my C: Drive with them.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.