Author Topic: Is this confirmation of an infected site?  (Read 6315 times)

0 Members and 1 Guest are viewing this topic.

zhandax

  • Guest
Is this confirmation of an infected site?
« on: January 30, 2013, 08:27:28 AM »
I went to this site to check the menu before I left work, and got a lot of replicating popups.  I finally got pissed and used task manager to close Firefox.  At this point, I got a ransomeware notice so I re-booted.  The ransomware notice persisted after I logged on.  I re-booted and logged on as another user (same domain) and had no problems.  I had been at work for 10 hours, I was hungry, and decided it could wait until tomorrow.  Here is the report: http://urlquery.net/report.php?id=887943

The damnedest thing about this is I got it at work and they use that joke McAfee.  I just want to make sure you guys know about it so I don't get it at home.  I suspect my easiest remedy at work is to re-image.  If anyone has any alternative thoughts, let me know.

As a postscript, I did report this to Google so they can blacklist it.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Is this confirmation of an infected site?
« Reply #1 on: January 30, 2013, 08:57:41 AM »
Quote
I suspect my easiest remedy at work is to re-image.  If anyone has any alternative thoughts, let me know.
we have a very smart man here that can fix this....

follow the guide and attach the requeste logs   http://forum.avast.com/index.php?topic=53253.0

AdwCleaner
Malwarebytes
OTL
aswMBR


when done he will be notified...



Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Is this confirmation of an infected site?
« Reply #2 on: January 30, 2013, 03:19:12 PM »
You could run either RogueKiller or MBAM from the alternate account.  If they fail I should be able to kill it manually with OTL

zhandax

  • Guest
Re: Is this confirmation of an infected site?
« Reply #3 on: January 31, 2013, 09:46:37 AM »
Today wasn't my day for extra-curricular projects.  Apparently lightning hit the building around 7am and set off the fire alarm and they evacuated all 300+ people to the parking lot across the street in a driving thunderstorm.  Things had gone downhill between then and the time I got there.  I will try this again tomorrow.

zhandax

  • Guest
Re: Is this confirmation of an infected site?
« Reply #4 on: February 01, 2013, 10:58:30 AM »
Things were still not quite back to routine today, and I had to change plans.  I downloaded a live ISO, blew that onto a USB key, and let it percolate a couple of hours.  Looks like I rang the bell.  Here is what it found:

EXP/CVE-2013-0422
JS/iFrame.ADI.1
JS/LoadSpam.G
JS/Expack.BW
JS/iFrame.ADI.1
Java/Dldr.Lamar.IX
TR/Rogue.kdz.5639.2

Just as it appeared to be, it was the Java exploit.  That returned control to my login and I rebooted into safe mode to run MBAM.  I had forgotten to change 're-name anything that can't be fixed' to 'delete', so it found the two which were renamed as well as two registry keys and identified all as Trojan.ransom.df, which pretty well describes the infestation.  After that, I ran OTL. Thanks for the tip; this looks pretty thorough.  I got an "exceeds the maximum allowed length" when I pasted it here, though.  Since I don't see any way to attach a text file, do you have a preferred filehost I could link?




Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Is this confirmation of an infected site?
« Reply #5 on: February 01, 2013, 02:21:27 PM »
To attach a file click Attachments and other options
Browse to the OTL log and select it
Then Post

zhandax

  • Guest
Re: Is this confirmation of an infected site?
« Reply #6 on: February 01, 2013, 06:50:42 PM »
Here is the (anonymized) log.  You will notice the first thing I did after MBAM is replace Java 7.10 with 7.11.  I then added the MVP HOST file.


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Is this confirmation of an infected site?
« Reply #7 on: February 01, 2013, 07:18:14 PM »
There is only one remnant left of the ransomeware.  You will need to enter the proper username to delete this file

What are your current problems 

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


Code: [Select]
:OTL
[2013/01/29 18:54:27 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\ThisUser\Application Data\skype.ini

:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

zhandax

  • Guest
Re: Is this confirmation of an infected site?
« Reply #8 on: February 02, 2013, 11:08:33 PM »
I wore that system out yesterday trying to catch up and was surprised there were no residual effects observed.  I will take care of the skype.ini Monday, rescan, and save the log before I copy over the MVPS HOSTS file.

zhandax

  • Guest
Re: Is this confirmation of an infected site?
« Reply #9 on: February 05, 2013, 07:39:38 PM »
Here is the latest log.  Thank you!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Is this confirmation of an infected site?
« Reply #10 on: February 05, 2013, 08:15:26 PM »
I would also recommend that you update to IE8

Any apparent problems ?

zhandax

  • Guest
Re: Is this confirmation of an infected site?
« Reply #11 on: February 06, 2013, 08:46:59 AM »
I keep expecting to walk in to a smoking pile of chips, but so far not a hiccup.  Upgrade to IE8 from a security standpoint?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Is this confirmation of an infected site?
« Reply #12 on: February 06, 2013, 08:54:41 AM »
Upgrade to IE8 from a security standpoint?

Yes.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Is this confirmation of an infected site?
« Reply #13 on: February 06, 2013, 02:54:40 PM »
Even if you do not use IE then updating it will also update some windows files to enhance security

zhandax

  • Guest
Re: Is this confirmation of an infected site?
« Reply #14 on: February 07, 2013, 10:22:56 AM »
Done and, once again, thank you.