Solved Difficult, very deep virus infection on legitimate Win 7

Status
Not open for further replies.
As for Panda....probably some registry leftovers.
Let's try to remove couple of entries, I can see.

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    Code:
    :OTL
    
    :Services
    
    :Reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{8F66842A-B63E-4B86-85F5-F9D37A3BDC10}" =-
    "{E9637CBC-A784-4E9E-973C-47D05868B7FD}" =-
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • You will get a log that shows the results of the fix. Please post it.

===================================================================

Is the word "Censored" here for real, or is it some bad word, which was replaced by this forum tool:
C:\Users\CENSORED\AppData\Roaming\Panda Security
In any case, remove "Panda Security" folder manually, from the above location (if still exists).

=====================================================================

1. Update your Java version here: http://www.java.com/en/download/installed.jsp

Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

2. Now, we need to remove old Java version and its remnants...

Download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.

====================================================================

Update Adobe Reader

You can download it from https://www.techspot.com/downloads/2083-adobe-reader-dc.html
After installing the latest Adobe Reader, uninstall all previous versions.
Note. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

Alternatively, you can uninstall Adobe Reader (33.5 MB), download and install Foxit PDF Reader(3.5MB) from HERE.
It's a much smaller file to download and uses a lot less resources than Adobe Reader.
Note: When installing FoxitReader, make sure to UN-check any pre-checked toolbar, or any other garbage.

=======================================================================

Post new Security check log, when done.
 
Sorry for the delay, my PC has been a bit iffy lately.

See this: ;)
https://www.techspot.com/vb/topic164636.html

Note that this is not the post infected PC, this is the PC which we use to access TechSpot. So, let's get back to business:


Ran OTL, pasted code into 'custom scans/fixes'.
OTL did its job, PC rebooted.

OTL log:
(
All processes killed
========== OTL ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\\{8F66842A-B63E-4B86-85F5-F9D37A3BDC10} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8F66842A-B63E-4B86-85F5-F9D37A3BDC10}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\\{E9637CBC-A784-4E9E-973C-47D05868B7FD} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E9637CBC-A784-4E9E-973C-47D05868B7FD}\ not found.
========== FILES ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: CENSORED
->Temp folder emptied: 5691874 bytes
->Temporary Internet Files folder emptied: 9399616 bytes
->Java cache emptied: 2027 bytes
->Opera cache emptied: 53729324 bytes
->Flash cache emptied: 1412 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 192912 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 3241745880 bytes

Total Files Cleaned = 3*157,00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: CENSORED
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 05062011_074208

Files\Folders moved on Reboot...
C:\Users\CENSORED\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\Windows\temp\kls8A9C.tmp not found!

Registry entries deleted on Reboot...

)

============

The word CENSORED is an alibi, yes. My brother was very keen on that he did not want his name to appear on sites he doesn't visit regularly.
Just treat it like it's his name. ;)

Removed Panda security folder.
(Success.)

============

Successfully updated Java to the latest version.
Ran JavaRa, removed older versions successfully.

Successfully updated Adobe Reader to the latest version.


Alright, Doc. Broni; what's our next move?
 
Since I don't know what's the replacement for the word "Censored" remove these two items manually:
- C:\Users\CENSORED\AppData\Local\Opera\Opera\temporary_downloads\Steam Cracked Build 06.10.09.rar
- C:\Windows\$XNTUninstall643$\xgoir.dll

===================================================================

Your computer is clean

1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following:

Code:
:OTL
:Commands
[purity]
[emptytemp]
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]
[Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Post resulting log.

2. Now, we'll remove all tools, we used during our cleaning process

Clean up with OTL:

  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.

If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

3. Make sure, Windows Updates are current.

4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

7. Run Temporary File Cleaner (TFC) weekly.

8. Download and install Secunia Personal Software Inspector (PSI): https://www.techspot.com/downloads/4898-secunia-personal-software-inspector-psi.html. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

10. Run defrag at your convenience.

11. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

12. Please, let me know, how your computer is doing.
 
I'll just keep this post clean and simple, then ;)

The first file was removed without a hitch. But the .dll-file did not respond - explorer.exe crashed (locked up for 5 min at first) when 'del' was pressed!

So I simply removed xgoir.dll using CMD, done and done!

================

Ran OTL, don't know if it was successful though.
OTL log:
(
All processes killed
========== OTL ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: CENSORED
->Temp folder emptied: 3932160 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->Opera cache emptied: 539287 bytes
->Flash cache emptied: 611 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 479240 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 2359350 bytes

Total Files Cleaned = 7,00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: CENSORED
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0,00 mb

Error creating restore point.

OTL by OldTimer - Version 3.2.22.3 log created on 05072011_094803

Files\Folders moved on Reboot...
C:\Users\CENSORED\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\Windows\temp\kls8DA9.tmp not found!

Registry entries deleted on Reboot...

)

Steps 3-11 completed.

How the PC is doing:
The BSOD's have completely disappeared.

Generic Windows programs like the connection diagnostics, Windows security centre, Windows defender, does not work. (Does not start/respond)

Although some programs/functions like the "Activity Handler" (Ctrl+Alt+Delete) does work.

Programs relying on generic Windows programs does not work either. Like the connection manager we use for the USB-modem (which relies on the windows dial-up function/program to work).

In a nutshell, so to speak.

Oh, and the Fn-button stopped working ever since the first BSOD.

Also,
Windows Update does not work either. It simply produces an error when trying to update; "There has been an internal error in Windows update!"

Kaspersky's autorun does not work either - we have to manually start it at every bootup. I think it may be related to the "Generic Windows program no-go".
 
Well, at this point....

In this forum, we make sure, your computer is free of malware and your computer is clean :)
Because the access to malware forum is very limited, your best option is to create new topic about your current issue, at Windows section.
You'll get more attention.

I'd probably suggest Windows repair installation. It looks like some system files are messed up.
 
Sure! I'll go into the Windows-section.

We thank you with our greatest of gratitude!

There is no telling what would've happened should we not have come here looking for help. All in all, we do contribute to a better world, a world without poverty, war and malware.And for that, we both thank you a lot for taking your time.

:grinthumb :D
 
You're very welcome
smiley_says_hello.gif
 
Status
Not open for further replies.
Back