a.bat Virus/trojan? I need help badly!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by KiLL CraZy, Mar 2, 2007.

  1. KiLL CraZy

    KiLL CraZy Private E-2

    ook, here is what happened...

    After reading this article:
    http://www.engadget.com/2007/03/02/brute-force-keygen-cracks-open-vista/

    I got excited finding out that Vista has been cracked with the keygen and everything... so I foudn the Brute Force file and was just browsing in it and just for no reason, I opened slmgr.vbs thinking it was an info file (don't ask why... i f'd up on that and shouldn't have tried to open it)
    and gave me some type of error thing and ever since I clicked that, my pc got messed up.

    (pic below so show wut I opened)

    My anti virus scanner pops up everytime saying it found a a.bat virus on the c: root drive. I reboot my pc, and my virus scanner keeps popping up with that same virus saying iits in the c: drive even after I delete it through my virus scanner. Also... once my scanner detects it, right away somehow my internect connection dies. I cant go online or anything, (im on my other pc right now via wifi) so I will reboot my pc, ill be able to get on firefox for like a second and then after my virus scanner pops up telling me about the a.bat virus/trojan... my internet connections gets cut offed.

    I also realized that b4 my internet gets cut off, on the bottom right it looks like Windos is doing a system update which I clearly have disabled and I do not want to update at all b/c umm... for certain reasons if u get my drift...

    And then when I try to reboot my pc again I see a new option in the shut down menu along with the basic shutdown stuff "Install updates and shutdown" which i believe means the windows updates. But i just choose shutdown/reboot.

    The way I see it... I think trying to open that file somehow maybe put some type of Vista related file on my Windows Xp SP2 pc and maybe thats why its cutting off internet and trying to update windows maybe? im not quite sure

    Right now im following the main guide on trying to remove virus malware stuff and ill poost back with log files.

    I even tried a system restore and that didn't work.

    I really hope I did not f up my pc :(
     

    Attached Files:

  2. KiLL CraZy

    KiLL CraZy Private E-2

    wow, that counterspy program is taking soo long lol... looks like it's gonna be an all nighter
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes the scans do take a long time to run but in the end you will have a clean PC. You may however not have malware. You just may have corrupted your OS by running a VBS script that was meant for Vista not Win XP.

    See this: thttp://news.softpedia.com/news/Windows-Vista-Software-License-Manager-44976.shtml


    Note: we do not condone cracks, kegens....etc and other illegal activities. If you do this, you are on your own.
     
  4. KiLL CraZy

    KiLL CraZy Private E-2

    thanks for the info dude, yeah I kinda figured i somehow added a part of vista in xp...

    so I read it and im still confused on how to undo what I did...


    I tried the "slmgr.vbs -upk" in the run command window to try and uninstall the key but i get a messaged saying windows cant find "slmgr.vbs"...

    any other help would be greatly appreciated.

    oh, do u still want my to continue the system scans and post the logs so u would like to see them whtn they r done?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you want to check for malware issues, you will have to complete all scans and attach all logs. Since you say your antivirus program is detecting a virus, you should complete these steps.

    As far as slmgr.vbs is concerned, it is not considered malware, thus you would have to approach getting help related to it from the Software Forum.
     
  6. KiLL CraZy

    KiLL CraZy Private E-2

    here is CounterSpy, Panda Scan and runkeys logs
     

    Attached Files:

  7. KiLL CraZy

    KiLL CraZy Private E-2

    newfiles text and hijack

    plz help me out
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you install the below?
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

    I will be posting addition steps in a few minutes but to get started do the below.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.
    Also note you did not do all of step 2 in the READ ME. You still have file extensions hidden.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\WINDOWS\system32\clxrss.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O1 - Hosts: 66.197.153.197 idenupdate.motorola.com #webjal auth
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [clxrss.dat] clxrss.exe
    O4 - HKLM\..\RunServices: [clxrss.dat] clxrss.exe

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\windows\system32\clxrss.exe
    C:\TOOLS\Torrents\Bitlord Pro (UseNext) incl acount-maker 100% working. D.rar
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.
    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  10. KiLL CraZy

    KiLL CraZy Private E-2

    thatnks for the response chaslang, b4 I try any of these attempts, should my pc be in safe mode or normal mode?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Unless we specify otherwise (like in the READ ME), normal mode should be assumed. We will indicate when safe mode is required during a procedure.
     
  12. KiLL CraZy

    KiLL CraZy Private E-2

    ok I just finished doing these steps on both my pc's since I infected my other one earlier this morning trying to remember how I infected the first one last night lol

    just to let u konw when I did this part on my first PC

    "Now run Pocket Killbox by double clicking on killbox.exe

    * select File, Cleanup, Delete All Backups
    * Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    * Then after it deletes the files click the Exit (Save Settings) button."

    when I got up to the Delete Temp Files and click delete selected temp.... after I clicked that, I kept getting a runtime error 6. I dont know wut that means but I tried it a few more times and kept getting that error... SO i just bypassed it and went on with ur instructions.

    However when I did that part on my second pc, it went through fine.

    I did not receive this message on either of my PC's

    there are the three files and so far since I rebooted my pc, my virus scanner hasn't come up with the a.bat problem and my internet is working again.

    I think the problem is fixed... let me know wut u think after u see the logs...
    These r the logs from my first pc... i dont think it's necessary to post the logs from my second pc since both pc's had the same problem and now also my second pc is having working internet again with no signs of the virus scanner popping up

    thanks
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not answer my question about:

    "Groove GFS Stub Execution Hook"

    Also based on your log from ShowNew, you did not run ATF Cleaner. Why not?

    Also are you saying two PCs have the EXACT same problems?
     
  14. KiLL CraZy

    KiLL CraZy Private E-2

    woops im sorry, I completely forgot about ur first post and went straight to the bigger one.

    about the groove gfs thing.... I really have no clue on what that is and have no memory if I put that there or not. wait actually come to think of it... that groove thing... whenever I right click some thing I see an option for groove.. ill show u a pic... wow yeah now I remember that I updated something (not a clue what) and it added something called groove to it.
    I think thats the groove thing that keeps poping up and I still have no clue whats it for and never used it lol

    here is a pic i posted so u can see it

    http://img235.imageshack.us/img235/9253/untitledwh4.jpg

    should I follow the process from ur first post and run ATF Cleaner?

    I believe it was the exact same problems between both my pc's b/c they both had pretty much the 2 main symptoms. Everytime I rebooted my pc, my virus scanner would pop up telling me about the a.bat trojan. And my internet wouldn't work on both pc's. But now internet works on both and the a.bat doens't appear anymore after reboots


    ok for some reason it's not letting me add the showlogfile as an attachment... Where i would usually go to click to add attachments it says
    "Attach Files
    Valid file extensions: bmp doc gif jpe jpeg jpg log pdf png psd txt zip"

    and thats. no clickable areas... wtf?
     
    Last edited: Mar 3, 2007
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you want to remove it?

    You must always be very careful and make sure you follow ALL steps and in the order given. In some case, no doing this can result in total failure of the cleaning procedure. Yes run ATF Cleaner now and then attach a new log from ShowNew.

    Did you run the full READ & RUN ME on the second PC? You should and you should attach the logs to a new thread to be sure it is clean.
     
  16. KiLL CraZy

    KiLL CraZy Private E-2

    yeah I would love to remove the groove thing.

    Here is the new ShowmelOg file

    and no, I did not run the full read me on my second pc... I figured since both pc's had the same problem that ill just follow the guide for my first pc on the second one...

    right now I have to go and probably wont be back till 2morrow night but if you want, I would make a new thread post regarding my second pc and post the log files on it also.

    Thanks

    ok seeing that the log file didn't attach and for some reason it's not letting me attach a file... where I would go to add a file all I see is
    "Attach Files
    Valid file extensions: bmp doc gif jpe jpeg jpg log pdf png psd txt zip"
    wtf?


    ok seeing how it's not letting me add a attachmet I uploaded the file via sendspace here
    http://www.sendspace.com/file/tr7of6
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you are attaching newfiles.txt and make sure it is a new log and not the old one.

    You have another worm that needs to be removed too. Probably due to your P2P and Torrent downloading. You have this: http://www.sophos.com/security/analyses/w32sdbotcnf.html

    It may even be related to the Bootscreen stuff you installed (vidstub.sys)
     
  18. KiLL CraZy

    KiLL CraZy Private E-2

    alrighty, im back from my weekend...
    I just did another shownew scan and posted the log file
    ahh how can I get rid of that worm?

    thanks
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It still looks like you are not running ATFCleaner to clean temp files. Your log from ShowNew shows many files in the below folder that are old and should be getting deleted when ATF Cleaner or even CCleaner is run.

    C:\Documents and Settings\Administrator\Local Settings\Temp\

    Are you sure you ran ATF Cleaner?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\drivers\oreans32.sys
    C:\WINDOWS\system32\drivers\vidstub.sys
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.
    1. ShowNew


    Make sure you tell me how things are working now!
     
  21. KiLL CraZy

    KiLL CraZy Private E-2

    ok, I ran another ATFCleaner and this time I dind't get that runtime error 6 when I tried to clean out the stuff under the firefox tab.

    -Alright, so I did the:
    -ATFCleaner
    -I uninstalled CounterSpy and deleted the directors like u said.
    -Ran Killerbox llike u said.

    "If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself."

    -I did not recieve that message and I let Killbox do it's thing on the reboot process.

    and now here is my ShowNew log

    how do things look?
     

    Attached Files:

  22. KiLL CraZy

    KiLL CraZy Private E-2

    alright.... 2 things.... one... wut type of defrag program do you recommend? Because I hear the default defrag program that comes with windows is not so great.

    and second... After that last reboot... my iTunes isn't opening up...

    did one of those files I delete was related to iTunes?


    EDIT:

    ok nvm on the itunes stuff... lol i fixed that problem :)
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Check in the Software Forum also see this:

    http://www.majorgeeks.com/page.php?id=20

    scroll down to where deframenters are mentioned.

    I'm looking at your log now.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay everything looks okay now!

    How are things working? Once your are sure everything looks okay! Move on to the below steps.

    It is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  25. KiLL CraZy

    KiLL CraZy Private E-2

    woot! just did all the steps u said, made a new system restore checkpoint and everything seems to be running like new now.

    Thanks alot man for all the help you gave me, I really do appreciate it it.

    After my other PC is done with it's systematic virus scan im gonna follow the steps agin and start posting the logs just to make sure everything is good from that pc also.

    And just one thing... since im already doing a virus scan on that pc... do u still want my to do the online virus scan with Bitdefender and PandaScan?

    once again, thanks for your help
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Yes! They typically find things that other antivirus scans may miss. That is why they are in the READ ME. ;) If you do come back to attach logs, please start a new thread and be sure to indicate that it is a new PC and not the one in this thread.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds