also @ TechSpot: OCZ Vertex 450 SSD Review

Iexplore.exe processes pop up, apparent rootkit infection

Discussion in 'Virus and Malware Removal' started by DoktrMik, Jul 24, 2010.

  1. DoktrMik Newcomer, in training Posts: 68

    Logs as requested.

    Attached Files:

  2. DoktrMik Newcomer, in training Posts: 68

    iexplore processes came back even in the brief time it took to upload those logs. I did re-download all three from links on this forum, as you suggested.
  3. Broni Malware Annihilator Posts: 39,373   +175

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Vista users:: Right click on SystemLook.exe, click Run As Administrator
    • Copy the content of the following box into the main textfield:
      Code:
      :filefind
      hardlock.sys
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    =======================================================================

    1. Please open Notepad
    • Click Start , then Run
    • Type notepad .exe in the Run Box.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    File::
    c:\windows\system32\REND.tmp
    
    
    Driver::
    ALSysIO
    
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=-
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP"=-
    "3724:TCP"=-
    
    RegLock::
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    
    
    
    

    3. Save the above as CFScript.txt

    4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [IMG]


    5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
  4. DoktrMik Newcomer, in training Posts: 68

    I know I've said it already, but I really appreciate your help.


    SystemLook v1.0 by jpshortstuff (11.01.10)
    Log created at 22:46 on 25/07/2010 by [name removed] (Administrator - Elevation successful)

    ========== filefind ==========

    Searching for "hardlock.sys"
    C:\WINDOWS\system32\drivers\hardlock.sys --a--- 693760 bytes [19:32 20/07/2008] [14:01 22/11/2006] D95554949082FD29A04D351B58396718
    C:\WINDOWS\system32\Setup\aladdin\hasphl\hardlock.sys --a--- 693760 bytes [19:32 20/07/2008] [14:01 22/11/2006] D95554949082FD29A04D351B58396718

    -=End Of File=-

    Attached Files:

  5. Broni Malware Annihilator Posts: 39,373   +175

    You're very welcome :)

    Now...
    I want you to reconnect your computer to the internet and keep it that way.
    I suspect, that we can't eradicate the culprit, because it seems to be alive only when you're connected.
    I don't think, we can make things any worse.
    While connected, re-run GMER and Combofix, post fresh logs.
    If Combofix will want to update itself, make sure to allow it.
  6. DoktrMik Newcomer, in training Posts: 68

    I ran ComboFix while connected at least once before. While I do it again, here's the GMER log:

    Attached Files:

     
  7. Broni Malware Annihilator Posts: 39,373   +175

    OK. I'll wait for Combo.
  8. DoktrMik Newcomer, in training Posts: 68

    FYI I'm going to be crazy busy in the next couple of days and I don't know when I'll get to it. I still have my laptop!

    Really appreciate your time and we'll hopefully be able to get this resolved when I have some time.

    BTW. I noticed this line appeared in my new GMER log (when I was connected) that wasn't in the old one:


    ? C:\WINDOWS\System32\svchost.exe[1824] image checksum mismatch; time/date stamp mismatch; unknown module: OLEAUT32.dll



    Does this mean anything?
  9. DoktrMik Newcomer, in training Posts: 68

    Also, I noticed the message about OTL. I think you asked me to download it around 6pm yesterday... does the fact that I got logs successfully mean it's OK? Or should I be worried? :(
  10. Broni Malware Annihilator Posts: 39,373   +175

    That's fine...

    That OTL issue started probably couple of hours later, but I wanted to be safe, so I put 6PM there.

    If OTL ran fine, you're OK. Infected file was installing Security Tool malware.

    Is iexplore.exe issue still present?
  11. DoktrMik Newcomer, in training Posts: 68

    Yes, it's present. I'm not using the machine until I have time to deal with this problem.
  12. Broni Malware Annihilator Posts: 39,373   +175

    Post back, please, when you're more free and we'll go from there.
  13. Broni Malware Annihilator Posts: 39,373   +175

    Thread has been reopened.
  14. DoktrMik Newcomer, in training Posts: 68

    So should I run Combofix again, as you last requested, or do you have some other idea?

    I've literally done nothing to the machine since we last discussed this, except for print a couple of documents. It's been turned off for all but a few minutes in the last couple weeks ;(
  15. Broni Malware Annihilator Posts: 39,373   +175

    Yes, download fresh copy of Combofix and run it.
  16. DoktrMik Newcomer, in training Posts: 68

    Alright, let's get this done!

    I connected to the internet, closed all my programs other than task manager, disabled my antivirus (NOD32), then started to run ComboFix from the desktop. Almost immediately, between six and eight iexplore.exe processes appeared, then immediately disappeared (presumably because ComboFix disconnected me?). Task manager closed pretty quickly too, so I have no idea if the processes were there afterwards.

    ComboFix then ran through to step 52, and rebooted the machine. After rebooting, i could hear a commercial playing while ComboFix was creating its logs. CF finished, created the log file.

    I rebooted and after being connected for 30-40 seconds, a pair of iexplore.exe processes popped up. So we're right back where we were, but I have a fresh log and hopefully running ComboFix while connected did something differently.

    Attached Files:

  17. Broni Malware Annihilator Posts: 39,373   +175

    Clear your Java Cache

    • Go Start>Control Panel (Classic View)>Java
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - leave BOTH checked
      • Applications and Applets
      • Trace and Log Files
    • Click OK on Delete Temporary Files Window.
      • Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
    • Click OK to leave the Temporary Files Window
    • Click OK to leave the Java Control Panel.

    ======================================================================

    Go Start>Run (Start search in Vista), type in:
    cmd
    Click OK (in Vista, while holding CTRL, and SHIFT, press Enter).

    In Command Prompt window, type in following commands, and hit Enter after each one:
    ipconfig /flushdns
    ipconfig /registerdns
    ipconfig /release
    ipconfig /renew
    net stop "dns client"
    net start "dns client"


    Your router may be infected.
    We need to hard reset it.
    Turn the computer off.

    On your router, you'll find a pinhole marked "Reset".
    Keep pushing the hole, using a pencil, or a paperclip until all lights briefly come off and on.
    Restart computer and check for redirections
  18. DoktrMik Newcomer, in training Posts: 68

    I don't have Java installed. Due to these issues I uninstalled Java completely. Should I clean up some directory instead?

    How sure are you about the router? I have a complex router setup that took me some time to configure correctly, and I don't want to have to repeat that. Basically I have a FIOS router but in order to get wireless N capability I have connected a D-Link wireless router directly to the FIOS router, which has wireless turned off. Should be straightforward but I had no end of trouble getting it to work.

    Another data point is that I have multiple machines in the house: another Windows XP machine (which I'm typing on now) and a Macbook.

    Do I need to be connected in order to run the ipconfig commands?
  19. Broni Malware Annihilator Posts: 39,373   +175

    Good question, but I don't think, you have to be connected. It resets your computer, nothing else.

    Regarding router, I can see it as one our last chances to solve this issue.
    Your computer should be 99.9% clean at this point and I've seen number of cases (especially lately), where resetting router solved the problem.
    Just make sure, you write all necessary info down before proceeding.
  20. DoktrMik Newcomer, in training Posts: 68

    Fair enough. I'll consider resetting the router. Interestingly, I ran the ipconfig and net commands while connected, then rebooted. After connecting it took almost 10 minutes for any iexplore.exe processes to be created - much longer than usual. I wonder if I somehow resolved the issue but the router re-infected me.

    One interesting thing I just thought of is that the other machines connect wirelessly, whereas the desktop in question is the only thing connecting directly via ethernet cable. Gonna try a couple more things before I reboot the router...