Anyone want a challenge? I need help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Trisha1964, Aug 10, 2010.

  1. Trisha1964

    Trisha1964 Private E-2

    Hi
    I downloaded clickpotato 3 days ago and have been fighting viruses since. I have attached the logs as requested and also added some adapted notes below.
    Have run countless bug checkers and had many crashes trying to clean things.
    I ran Malwarebytes twice (have enclosed 2 logs) the 2nd time it appeared clear but other checkers are still picking up bugs.
    Many thanks- hope someone can help :)


    QUARINTINED

    TR/Crypt.XPACK.Gen2 Trojan
    7.10.10.103
    C:\Users\Trisha O\AppData\Local\Xpieap.dll

    TR/Crypt.XPACK.Gen2 Trojan
    7.10.10.103
    C:\Users\Trisha O\AppData\Local\Xpieap.dll

    Contains recognition pattern of the HTML/Infected.WebPage.Gen HTML script virus
    C:\Users\Trisha O\AppData\Local\Microsoft\Windows\Temporary
    TR/Crypt.XPACK.Gen2 Trojan
    c:\Users\Trisha O\AppData\Local\Temp\~TMD83F.tmp
    TR/Crypt.XPACK.Gen2 Trojan
    C:\Users\Trisha O\AppData\Local\Xpieap.dll
    TR/Krap.H.1 Trojan
    C:\Windows\System32\drivers\nafdjs.sys
    TR/Crypt.ZPACK.Gen Trojan
    C:\Windows\System32\drivers\lcnxexu.sys
    TR/Crypt.XPACK.Gen2 Trojan
    C:\Users\Trisha O\AppData\Local\Xpieap.dll
    TR/Agent.HM.887 Trojan
    C:\Users\Trisha O\AppData\Roaming\Mafe\ytsu.exe



    CAUSE???

    Begin scan in 'C:\Users\Trisha O\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EWKMYJVJ\ClickPotatoInstaller[1].exe'
    C:\Users\Trisha O\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EWKMYJVJ\ClickPotatoInstaller[1].exe
    [DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware

    Begin scan in 'C:\Users\Trisha O\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EWKMYJVJ\77840@Middle[1].htm'
    C:\Users\Trisha O\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EWKMYJVJ\77840@Middle[1].htm
    [DETECTION] Contains recognition pattern of the HTML/Infected.WebPage.Gen HTML script virus


    REGULAR OFFENDERS

    C:\Windows\System32\drivers\nafdjs.sys
    [DETECTION] Is the TR/Krap.H.1 Trojan
    [WARNING] The file could not be copied to quarantine!
    [WARNING] The file could not be deleted!
    [WARNING] The file could not be selected for deletion after the restart. Possible cause: A device attached to the system is not functioning.

    C:\Windows\System32\drivers\lcnxexu.sys
    [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
    [WARNING] The file could not be copied to quarantine!
    [WARNING] The file could not be deleted!
    [WARNING] The file could not be selected for deletion after the restart. Possible cause: A device attached to the system is not functioning.
     
  2. Trisha1964

    Trisha1964 Private E-2

    more logs:)

    thanks again in advance!
     

    Attached Files:

  3. Trisha1964

    Trisha1964 Private E-2

    other logs (didn't post properly)
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I don't mind taking on a challenge, I have a fix prepared already, but I need to draw something to your attention. ;) Would you rather me or JonTom @ PCPitstop assist you?
     
  5. Trisha1964

    Trisha1964 Private E-2

    Hi Kestrel
    I'd be grateful for your help-
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    Teatimer is running and it is going to interfere with my fix:

    How to disable Spybot's TeaTimer


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    • O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    • O2 - BHO: (no name) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - (no file)
    • O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
    • O2 - BHO: (no name) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - (no file)
    • O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
    • O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} -
    • O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} -
    • O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
    After clicking Fix exit HJT.

    Now we need to use ComboFix (Make SURE you let it run to completion without any mouse clicking or keyboard touching.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Windows\System32\drivers\nafdjs.sys
    C:\Windows\System32\drivers\lcnxexu.sys
    C:\Users\Trisha O\AppData\Local\Dfatojoqozi.bin
    C:\Users\Trisha O\AppData\Local\Wkono.dat
    C:\Users\Trisha O\AppData\Roaming\bawuho.dat
    C:\Windows\temp\1b6cdb~1.tmp
    C:\Windows\temp\3c5766~1.tmp  
    C:\Windows\temp\4a7ff3~1.tmp 
    C:\Windows\temp\5baa6f~1.tmp  
    C:\Windows\temp\86fb34~1.tmp  
    C:\Windows\temp\8a4ea6~1.tmp 
    C:\Windows\temp\ae120f~1.tmp  
    C:\Windows\temp\b68e90~1.tmp  
    C:\Windows\temp\fc5030~1.tmp  
    C:\Windows\temp\fcc1d8~1.tmp 
    C:\Windows\temp\tmp000~1   
    C:\Windows\temp\wer-83~1.xml 
    C:\Users\Trisha O\AppData\Local\Xpieap.dll
    
    Folder::
    C:\Users\Trisha O\AppData\Roaming\Qoowba
    C:\Windows\system32\%APPDATA%
    C:\Users\Trisha O\AppData\Roaming\Mafe
    C:\Users\Trisha O\AppData\Local\Temp\STOPzilla!
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\NoExplorer]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now rescan with Malware Bytes, fix anything it may find and attach the log regardless of it's findings.

    Run CCleaner!

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this. Don't forget the new MBAM log.

    Let me know how things are running for you!
     
  7. Trisha1964

    Trisha1964 Private E-2

    Hi Kestrel
    I can't get normal startup. Assume it's down to the trojan.
    I have just ticked all the boxes in selective startup instead. is this ok?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, just carry on for now, just try and remember to have a go again at being in normal start up before you run the getlogs.bat.

    Oh.. and out of courtesy, tell JonTom that you are receiving help elsewhere so that you are not wasting any of his time and resources. :)
     
  9. Trisha1964

    Trisha1964 Private E-2

    Thanks
    so far doing it's thing well-
    Have messaged John too.

    I just saw the words "deleting" and "lcnxexu.sys" appear in a sentence together on the screen- can't tell you how good that felt :)
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good. Then please attach the logs whever you are ready.

    :-D Yes, combofix will wipe those suckers out I expect.
     
  11. Trisha1964

    Trisha1964 Private E-2

    Hi
    about to post logs- but i have a question (which will avoid this sort of thing happening again).
    I kind of see myself as more than an ameteur with older computers and stuff however am rather a novice with vista. Currently on each pc/laptop I work with I put:

    vista firewall
    and
    2 out of the following
    spywareblaster/spybots or superantispyware
    plus
    Avira or AVG free

    I also run cleaner daily and regsitrycleanup etc too

    Is this sufficient?
    Would appreciate your expert advice.
     
  12. Trisha1964

    Trisha1964 Private E-2

    logs :)
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    When I give you final steps, there will be a link to "How to protect yourself from malware" which you should take a look at. :)

    So, tell me now, as I review the logs, how things are running for you now.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well the logs reflect that all is good.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Use windws explorer to locate and delete the below bold file:

    • C:\Windows\system32\LogConfigTemp.xml

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Only the cleaner... not the registry section of ccleaner. Sometimes more harm than good can be caused by reg cleaners. I have Ccleaner myself, but I do not ever bother with the registry section.
     
  16. Trisha1964

    Trisha1964 Private E-2

    "Make sure that you tell me if you receive a success message about adding the above"

    It was a success! :)
    Thanks very much
    am off to enable something or other via defogger- (was told to wait till given the all clear)
    and am going to read the Majorgeeks firewall pages...
    :wave
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds