This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Trying to get rid of "Nutcracker Family" virus

13 min read

This thread's last reply is from December 19, 2008, 6:11 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Hi steel316th,

So, I decided to download the free antivirus "Avast Home Edition 4.8.1229.80923" and this program keeps getting a "Nutcracker Family" virus alert (everytime) and it's not able to delete/move/rename it ("access denied")
It looks to me like Norton 360 has detected and quarantined something, and Avast has scanned the Norton quarantine area and found the same malware. Removal attempts have failed because Norton has somehow protected it's quarantine area.

The malware is not active or dangerous because it has been safely quarantined by Norton, however, it might be good to check the Norton history or activity logs to find out when it was originally detected so we know whether this is a new infection or something old.

I keep getting a "Tracking Cookie" virus everytime I run the antivirus program.
Cookies are not malware and this particular detection does not indicate an infection. Cookies will usually be created on your machine whenever you browse the web and can be very useful, however advertising cookies such as you listed in your post do not help you and can be a privacy risk - this is why your protection software removes them.

There is some straightforward information on cookies from Microsoft here:
http://www.microsoft.com/info/cookies.mspx
This article covers cookies in detail and explains some of the privacy concerns associated with them:
http://www.howstuffworks.com/cookie.htm/printable

Generally speaking they aren't anything to be overly concerned about, especially if you are regularly scanning with your anti-malware products. However if you are concerned about cookies and wish to have more control over the cookies placed on your machine, let me know in your next response and I'll give you some further suggestions.


Something else to be aware of is that it's not advisable to have two antivirus programs installed at once as they can conflict and cause system problems. If you want a "2nd opinion", then using an online scanner is the preferred method.

We can do some checks to see if there is any further malware on your machine:

Download Malwarebytes' Anti-Malware to your Desktop (right-click the link, select Save Target As..., select your Desktop and press Save)
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to both of these options:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Quick Scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure everything is checked, and click Remove Selected.
  • When finished, a log will open in Notepad. Please save it to your Desktop, and post the contents in your reply.
  • The log can also be found here if you need it:
    • Start->All Programs->Malwarebytes' Anti-Malware->Logs


Download RSIT by random/random to your Desktop (right-click the link, select Save Target As..., select your Desktop and press Save)

  • Double click RSIT.exe to start the program, and click Continue at the disclaimer screen.
  • When the scan is complete, two text files will open - log.txt <- this one will be maximized and info.txt <-this one will be minimized
  • Make sure Format->Word Wrap is unchecked
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of log.txt and info.txt in your reply


Once complete, please post the Malwarebytes Antimalware report and both RSIT logs, you won't need to produce a new HijackThis log as RSIT produces one for you.
Do you still need help with your machine?

If the instructions are unclear or something isn't working, please let me know before proceeding.
Hi Steel316th,

I'll give you some detailed instructions concerning cookies once we have finished cleaning :) for now, please try running Malwarebytes Antimalware using the following instructions - they use a different procedure and different links:

Download Malwarebytes' Anti-Malware to your Desktop (right-click the link, select Save Target As..., select your Desktop and press Save)
  • Double-click setup.exe and follow the prompts to install the program.
  • At the end, UN-check both of these options:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware, then click Finish.
  • Once the installer has finished, then download rules.exe to your Desktop (right-click the link, select Save Target As..., select your Desktop and press Save)
  • Double-click rules.exe to install the latest definitions.
  • When the definitions have been installed, then double-click the Malwarebytes shortcut on your Desktop to start the program.
  • Once the program has loaded, select Perform Quick Scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure everything is checked, and click Remove Selected.
  • When finished, a log will open in Notepad. Please save it to your Desktop, and post the contents in your reply.
  • The log can also be found here if you need it:
    • Start->All Programs->Malwarebytes' Anti-Malware->Logs


Please also download and run RSIT as previously:

Download RSIT by random/random to your Desktop (right-click the link, select Save Target As..., select your Desktop and press Save)

  • Double click RSIT.exe to start the program, and click Continue at the disclaimer screen.
  • When the scan is complete, two text files will open - log.txt <- this one will be maximized and info.txt <-this one will be minimized
  • Make sure Format->Word Wrap is unchecked
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of log.txt and info.txt in your reply


------------------------------------------------------------------------

Once complete, please post the Malwarebytes Antimalware report and both RSIT logs, you won't need to produce a new HijackThis log as RSIT produces one for you.
Hi steel316th,

Please open Start->Control Panel->Add/Remove Programs, and remove the following:
Java(TM) 6 Update 10
Java(TM) 6 Update 5
Java(TM) 6 Update 7
LimeWire 4.18.8
The Java installations are out of date and now a security risk, you can get the latest update (version 6 update 11) from here

LimeWire needs to be removed as site policy is to require users to remove all P2P programs as part of cleaning.

------------------------------------------------------------------------

Download Gmer to your Desktop from here:
http://www.gmer.net/gmer.zip
  • Unzip the program onto your Desktop (right-click, select Extract All... and follow the prompts)
  • Disconnect from the internet and close all running programs
  • Double click gmer.exe, let the gmer.sys driver load if asked
  • If it gives you a warning at program start about rootkit activity and asks if you want to run scan...say OK
  • If there is no warning, then check that the Rootkit tab is selected and click the Scan button - don't change any settings before you do so
  • Please do not use your computer during the scan
  • Once the scan is complete, click the Copy button
  • Open Notepad (Click Start->Run, type notepad and Enter) and hit Ctrl+V to paste the log and then save the log to your desktop


------------------------------------------------------------------------

Press Start->Run, copy/paste the following command (it's one long command) into the box and press OK:
cmd /c ipconfig /all >> "%userprofile%\desktop\dns.txt"
A new file called dns.txt should appear on your Desktop, please post the contents with your next response.

------------------------------------------------------------------------

Once complete, please post the Gmer report, the dns.txt output and a new HijackThis log, also let me know how your computer is running now.
Hi,

I don't know any reason why disconnecting and reconnecting your internet connection should cause problems like you describe, because this has the same effect as turning your machine off and on. I can understand why you are suspicious, but there is nothing I have found on your machine and no procedures we have performed which should have had any such effect. Please do however monitor the symptoms and if they persist, I'll give you some advice on getting assistance with them.

It was good to have the internet disconnected for the gmer scan, however we actually need it connected for the DNS information check, so please repeat these instructions with the internet connected:

First, delete the dns.txt file from your Desktop.
Press Start->Run, copy/paste the following command (it's one long command) into the box and press OK:
cmd /c ipconfig /all >> "%userprofile%\desktop\dns.txt"
A new file called dns.txt should appear on your Desktop.

Please post the contents of dns.txt and a new HijackThis log for me to see. Please do not attach them, instead copy/paste them into your response.
Hi steel316th,

The reports look pretty good, how are the connection issues at present - are the problems persisting? Are there any other issues?
Hi Steel316th,

All the reports look fine and I haven't seen any indication of infection, so if you are experiencing no symptoms then yes, at this stage I think your machine is very likely to be clean. :)

Some important final steps:

Please now delete rsit.exe, gmer.exe and any remaining logs from your Desktop, also delete this folder:
C:\rsit


Create a new, clean System Restore point which you can use in case of future system problems:
Press Start->All Programs->Accessories->System Tools->System Restore
Select Create a restore point, then Next, type a name like All Clean then press the Create button and once it's done press Close

Now remove old, infected System Restore points:
Next click Start->Run and type cleanmgr in the box and press OK
Ensure the boxes for Recycle Bin, Temporary Files and Temporary Internet Files are checked, you can choose to check other boxes if you wish but they are not required.
Select the More Options tab, under System Restore press Clean up... and say Yes to the prompt
Press OK and Yes to confirm

------------------------------------------------------------------------

I have some recommendations on keeping your computer clean, but first some suggestions regarding cookies:

I strongly recommend you read the links I provided earlier if you have not done so already. They explain the privacy concerns better than I can, but the key point is that some cookies are important and useful, others we are better off without. Some easy ways to keep them under control:
  • If you use Internet Explorer, adjust cookie management settings via Start->Control Panel->Internet Options. Choose the Privacy tab, and under Settings click Advanced.
    • Make sure the box marked Override automatic cookie handling is checked
    • Under First-party cookies select Accept
    • Under Third-party cookie select Block
    Press OK twice to apply the changes
  • If you use the Firefox browser, open Tools->Options and select the Privacy tab. Make sure Accept cookies from sites is checked, but un-check Accept third party cookies.
  • For better protection under Firefox, you can select Keep until - I close Firefox. This will remove all cookies at the end of your browsing session and mean other cookie cleaning measures are not necessary. However, in order to avoid being 'logged out' of sites you wish to stay logged into, you will need to add the domain names of the relevant sites using the Exceptions button - cookies from sites listed here marked 'Allow' will not be removed.
  • A custom hosts file will block a large number of 'bad' cookies from ever reaching your machine, there are instructions for installing one further down this post.
  • Regular scanning with antispyware software can remove bad cookies from your machine, there free programs which target these such as Spybot S&D and Ad-Aware


------------------------------------------------------------------------

You have a good antivirus program installed, however I recommend you install antispyware software with real-time capabilities - this means it protects you from system changes and spyware while you are working, not just removing malware after it has been installed. There are a range of paid-for and free packages available, a free one I can recommend is Windows Defender, available here:
http://www.microsoft.com/athome/security/spyware/software/default.mspx

I recommend you install a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.
Also: subscribe to the mailing list to get update notifications.

Please take care when downloading programs. One of the easiest ways to be infected is to download freeware/shareware programs which come laden with malware - this includes allowing websites to install browser plug-ins or ActiveX controls. Before downloading, it is crucial to check whether the source is reputable.
One way to check is to use McAfee SiteAdvisor. Copy the domain name into the space provided and SiteAdvisor will give you a report on the website which can help you decide if it is safe. They also have a toolbar for IE and Firefox which adds this functionality to your browser.

Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

Find out more about how to prevent infection in the future
http://forum.malwareremoval.com/viewtopic.php?p=33687

Please post back to let me know that you have read this, and if there are any further issues.
Hi,

I have Adobe Reader 9 (that's the latest, right?) Also I noticed I apparently have Adobe Flash Player 10 ActiveX, according to my 'Add/Remove Program', but I actually don't remember allowing it to download it to my hard drive.
Acrobat Reader 9 is the latest version, as is Flash Player 10. If you surf with IE, then Flash Player isn't normally downloaded to your hard drive, it is installed as an ActiveX control which appears as a pop-up which asks you whether to install it.
I get a little concerned when Adobe (and also Java) keeps updating itself (or it ask me if I want to update it) often. Nothing to be concerned about, right? Adobe (and Java) products are pretty safe, right? Basically, I just want to be able to read PDF files.
It's actually very important that both these programs as well as Java are up to date. The reason for the frequent updates is that security holes are found which need to be patched. If you use an old version then malware can be installed on your machine very easily, so always update whenever you are prompted.

Even better is to use Secunia PSI to scan your machine for vulnerable software and update all vulnerable applications.

Also, so was that "Nutcracker Family" virus that Avast found, really a 'Tracking Cookie' that my Norton 360 kept finding?
It's not clear because I haven't found any indications of malware on your machine. If you want to know for sure, you'll have to review the activity log or history of Norton to find out. If you find something in the logs, let me know and I'll try to give you some more information on it. In any case, I recommend you clean the quarantine area to make sure nothing is still there.

They told me it could affect the MBR of my hard drive, but since then I haven't had anymore "AntiEXE" detections. Do you think my MBR should be fine?
I can't tell, but I expect most antivirus programs should detect this so it's probably OK. Please do one further scan to make sure:

Download Dr.Web CureIt to your Desktop (right-click the link, select Save Target As..., select your Desktop and press Save)
  • Double-click launch.exe to start the program.
  • Press Start and then OK to start the Express scan
  • The Express scan takes just a few moments to finish, if something is found, click Yes to cure it
  • Once the short scan has finished, Click Options->Change settings
  • Choose the Scan tab and UN-CHECK Heuristic analysis
  • Choose the Actions tab and make these changes:
    • Next to Objects - Infected objects select Report
    • Next to Objects - Incurable objects select Report
    • Next to Infected packages -> Archives select Report
    • Next to Infected packages -> Containers select Report
  • At the bottom, UN-CHECK Prompt on action, then press OK to close the settings box.
  • Note: These settings changes are IMPORTANT, please ensure you have made them before scanning
  • Then select Complete scan and press the green arrow to start the scan
  • When the scan is complete, click File-> Save report list, save the report to your desktop and close Dr Web CureIt


Once complete, please post the CureIt report and a new HijackThis log.
Are you still with me?
Hi,

It looks like Dr.Web Scanner found no viruses, however it thought the "Malwarebytes' Anti-Malware program (mbam.exe)" was a 'backdoor Trojan'. The odd thing is that I ran the scanner twice and it detected the mbam.exe on the 2nd scanning. Other than that, I guess my PC seems clean, right?
I think so, and if all Dr Web found was 'mbam.exe' then there is no need to post the report.

Again, Silver, thanks for your outstanding technical help & advice! :cheers: I wish you and your family a safe and happy holidays!
You are most welcome, and I wish the same to you.

If you have any further questions or issues please let me know :)
This topic is now closed
We are pleased to have been of assistance in getting you clean.

If you have been helped and wish to donate with the costs of this volunteer site, you can do so using this link
Donations For Malware Removal