Author Topic: Win32.Downloader-PKU, Win32:Malware-Gen  (Read 7782 times)

0 Members and 1 Guest are viewing this topic.

Village Idiot

  • Guest
Win32.Downloader-PKU, Win32:Malware-Gen
« on: August 05, 2012, 07:25:23 PM »
My daughter clicked on a post and should not have.
OTL log attached

MBAM log
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.08.05.06

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421


8/5/2012 1:18:03 PM
mbam-log-2012-08-05 (13-18-03).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 196807
Time elapsed: 3 minute(s), 25 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 3
C:\Windows\Installer\{9dabbef6-4905-955b-f467-a3da8cbbe60e}\U\00000008.@ (Trojan.Dropper.BCMiner) -> Quarantined and deleted successfully.
C:\Windows\Installer\{9dabbef6-4905-955b-f467-a3da8cbbe60e}\U\trzA602.tmp (Rootkit.Zaccess) -> Quarantined and deleted successfully.
C:\Windows\Installer\{9dabbef6-4905-955b-f467-a3da8cbbe60e}\U\trzA71D.tmp (Rootkit.0Access) -> Quarantined and deleted successfully.

(end)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37506
  • Not a avast user
Re: Win32.Downloader-PKU, Win32:Malware-Gen
« Reply #1 on: August 05, 2012, 07:26:59 PM »
yes....seems  she got this months most popular   :-\

do you also have the aswMBR log

Village Idiot

  • Guest
Re: Win32.Downloader-PKU, Win32:Malware-Gen
« Reply #2 on: August 05, 2012, 07:34:13 PM »
Will download and generate for you.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Win32.Downloader-PKU, Win32:Malware-Gen
« Reply #3 on: August 05, 2012, 07:43:13 PM »
Monitoring  8)
...waiting for aswMBR log  ;)

Village Idiot

  • Guest
Re: Win32.Downloader-PKU, Win32:Malware-Gen
« Reply #4 on: August 05, 2012, 07:48:33 PM »
Here is the aswMBR logfile

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Win32.Downloader-PKU, Win32:Malware-Gen
« Reply #5 on: August 05, 2012, 07:53:01 PM »
Hello,
I will be working on your Malware issues  ;)

Step1
> Temporarily disable your AntiVirus - AntiMalware program.
If you are unsure how to do this please read this Instruction.

How to disable avast:


  • Right-click on the avast! icon in the lower right corner of the screen and choose Open Avast! User Interface.
  • In the window that opens on the top right corner, click Settings.
  • In a new window that opens, choose the option Troubleshooting, Uncheck Enable avast! self-defense, and click OK.

  • Right-click on the avast! icon in the lower right corner of the screen and select avast! shield controls .
  • In the menu that appears, choose Disable Permanently. When you are prompted to turn off security, click Yes.
Note: Do not forget to turn on this option after the cleaning.


Step2

Re-run OTL.exe.

  • Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.

Code: [Select]
:files
C:\Windows\Installer\{9dabbef6-4905-955b-f467-a3da8cbbe60e}
C:\Windows\System32\config\systemprofile\AppData\Local\{9dabbef6-4905-955b-f467-a3da8cbbe60e}
ipconfig /flushdns /c

:commands
[CREATERESTOREPOINT]
[emptytemp]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered; it will reboot the system when it is done and open notepad with logreport. Attach here that logreport.
********************************
Step3

> Download ComboFix from here and save it to your Desktop.
If you are unsure how ComboFix works please read this guide carefully.
note: ComboFix must be downloaded to your Desktop.

> Temporarily disable your AntiVirus program.


> Run ComboFix. Click on I Agree!
ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.

ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.

If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
Note:Do not mouse-click Combofix's window while it is running.


> When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt )
  Attach log reports ( ComboFix.txt) back to topic.

Village Idiot

  • Guest
Re: Win32.Downloader-PKU, Win32:Malware-Gen
« Reply #6 on: August 05, 2012, 08:07:10 PM »
Thanks for the quick reply.

Step 1-  complete
Step 2-  I can see it is creating a restore point and then my computer restarts like it crashed since the windows menu comes up and asks how I want to run windows since it did not close properly. No log file generated, I believe due to the way windows shut down?

Should I continue or run this in safe mode and try again for the log file?

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Win32.Downloader-PKU, Win32:Malware-Gen
« Reply #7 on: August 05, 2012, 08:18:39 PM »
No, its Ok, run Combofix.
If you had some problems with running Combofix, run it then from safe mode.

This ZeroAcess rootkit is installed on your computer is sometimes interferes with running our tools.

Village Idiot

  • Guest
Re: Win32.Downloader-PKU, Win32:Malware-Gen
« Reply #8 on: August 05, 2012, 08:44:25 PM »
Got the log file after running in Safe Mode.

Ran combofix and it ran fine in safe mode and found a few issues in services.exe and then it said it had fixed them rebooting.

Computer rebooted and it said it was generating log file and then the laptop crashed again.

Running combofix again in safe mode

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Win32.Downloader-PKU, Win32:Malware-Gen
« Reply #9 on: August 05, 2012, 08:49:30 PM »
Running combofix again in safe mode

Ok.

Village Idiot

  • Guest
Re: Win32.Downloader-PKU, Win32:Malware-Gen
« Reply #10 on: August 05, 2012, 08:54:33 PM »
Finally got it!

attached Combofix.txt

Will wait for next instructions.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Win32.Downloader-PKU, Win32:Malware-Gen
« Reply #11 on: August 05, 2012, 09:22:36 PM »
>. Delete current Combofix. Download fresh one from here:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe


>> Open notepad and copy/paste the text present inside the code box below:


Code: [Select]
Driver::
nfxbp
pgwso

KillAll::

File::
c:\windows\System32\drivers\kjdfd.sys
c:\windows\System32\drivers\cwdyqg.sys

RegLock::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)


Save this as CFScript.txt



Close all browser windows and refering to the picture above.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:\ComboFix.txt )

Note: Run Combofix/CFScript from normal mode!!!

Village Idiot

  • Guest
Re: Win32.Downloader-PKU, Win32:Malware-Gen
« Reply #12 on: August 05, 2012, 09:33:24 PM »
Thanks magna86 - I tried to run in normal mode and it starts to run the script and it crashes out of normal mode and reboots.

Should I try in safe mode?

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Win32.Downloader-PKU, Win32:Malware-Gen
« Reply #13 on: August 05, 2012, 10:36:26 PM »
Ok, try it. Run CFScript in safe mode.

Village Idiot

  • Guest
Re: Win32.Downloader-PKU, Win32:Malware-Gen
« Reply #14 on: August 06, 2012, 03:41:00 PM »
Still trying to get this to work. I have tried in Safe mode and Normal mode and when it complete it is trying to create a log file but the pc crashes and reboots just as it trying to create the log. While I am still trying any other suggestions?