Author Topic: IE infection and could not solve by myself  (Read 3980 times)

0 Members and 1 Guest are viewing this topic.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
IE infection and could not solve by myself
« on: July 26, 2012, 01:58:21 PM »
Well, sooner or later we all come here to ask for help.
In a business computer of a friend of mine, he has AVG (paid) and got an infection that I could not solve.
I've run MBAM (detect at first, clean, but then it comes back). Some scannings with MBAM return clean.
I've run ESET online. The same, first clean, then clean scannings.
I could not manage to run Norton on demand scanning.
Comodo Cleaning Essentials does not pick it up.

The symptom is an add popup at the end of each webpage.
I've attaching some logs.

Side note, C:\WINDOWS\system32\drivers\gbpkm.sys is a banking plugin. It's clean.
The best things in life are free.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: IE infection and could not solve by myself
« Reply #1 on: July 26, 2012, 01:59:19 PM »
Logs
The best things in life are free.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: IE infection and could not solve by myself
« Reply #2 on: July 26, 2012, 02:11:34 PM »
Tech, you're in the German section here..!!
Guess, you wanted to post this in V&W... ;)

Nevertheless, you're always welcome here..!! :)
Asyn

Edit: Well, it doesn't really matter, just leave it here and I'll ask Essexboy to take a look at it. ;)
« Last Edit: July 26, 2012, 02:19:46 PM by Asyn »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: IE infection and could not solve by myself
« Reply #3 on: July 26, 2012, 03:44:10 PM »
Hi Tech I feel that there may be a TDL 3 type infection there based on the aswMBR results

I am happy about the banker plugin and will not touch it honest ;D

Quote
18:11:23.443    ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys >>UNKNOWN [0x89d554f1]<<
18:10:43.536    Service ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys **LOCKED** 32

Download the latest version of TDSSKiller from here and save it to your Desktop.
 
 
  • Doubleclick on TDSSKiller.exe to run the application


  • Then click on Change parameters.
     

     
  • Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.
     
  • Click the Start Scan button.
     
     
  • If a suspicious object is detected, the default action will be Skip, click on Continue.
     

     
  • If malicious objects are found, they will show in the Scan results and offer three (3) options.
  • Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.

  • Get the report by selecting Reports

 
  • Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
Please copy and paste its contents on your next reply.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: IE infection and could not solve by myself
« Reply #4 on: July 26, 2012, 04:52:13 PM »
Seems you've win at the first  8)
What would be of us without Essexboy?  ;)

No more ads. Now only 10 suspicious files detected by Kaspersky.
I'm running a full scan with aswMBR.exe also.

THANKS.

And sorry for the off board post.
The best things in life are free.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: IE infection and could not solve by myself
« Reply #5 on: July 26, 2012, 05:06:57 PM »
Could you attach the log please Tech  ;D

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: IE infection and could not solve by myself
« Reply #6 on: July 27, 2012, 12:02:57 PM »
And sorry for the off board post.

NP Tech..!! :) As said, you're always welcome here, but next time you've to post in German. ;D

PS: It seems Essexboy is still waiting for one of your logs... ;)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0