Blumblebee Virus after DrWeb-cureit scan

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Razbaul, Aug 21, 2007.

  1. Razbaul

    Razbaul Private E-2

    My comp is responding very slow when Azureus Vuze and Mozilla are simultaneous running. Often it freeze and I have to restart. Antivir detected so called W95/blumblebee 1738 virus. First time, it was localized in C:\WINDOWS\system32\ActiveScan\pskavs.dll. I deleted the file, but it reappeared as you can see.
    I already reinstall Window so I hope you will help me fix the problem without reinstall. Thank you.
     

    Attached Files:

  2. abri

    abri MajorGeek

    Hi Razbaul!!

    Welcome to Major Geeks!


     
  3. Razbaul

    Razbaul Private E-2

    01. I downloaded and installed CCleaner, without any unnecessary baggage. I used CCleaner for cleaning my comp HDD and registry
    02. I checked up startup items witc CCleaner and I did not find any unknown items, so I did not delete any of them.
    03. I defragmented yhe hard drive using AusLogics Disk Defrag and it announced that defragmentation has increased the comp performance by 23%. When I pushed the "Display Report" button, comp freezed together with Zone Alarm and I had to restart.
    04. I searched the list at Uninstall Malware via Add/Remove Programs, and there is no program from the list installed on my comp.
    05. After reboot, comp is running in Normal Startup mode
    06. I selected select Show hidden files and folders in Folder Options.
    07. I am not using Multiple Antivirus Applications or Software Firewalls
    08. I downloaded and extracted (not in Desktop) GetRunKey.Zip and ShowNew.Zip.
    09. When trying to search for update for Spybot - Search & Destroy, comp. freezed together ZoneAlarm. I restarted, disabled firewall and followed the steps you are asking.
    10. I ran CCleaner, Spybot and Counter Spy in safe mode, with internet cable unplugged.
    11. SUN JAVA - last version is installed.
    12. Run BitDefender and Panda. Only BD found something.
    13. I disabled and enabled System Restore
     

    Attached Files:

  4. Razbaul

    Razbaul Private E-2

    Last attachement
     

    Attached Files:

  5. abri

    abri MajorGeek

    Hi Razbaul!

    Please do the following and then attach logs for both BitDefender and HijackThis:


     
  6. Razbaul

    Razbaul Private E-2

    Unforyunately, I lost the BD log. Must I do another scan?
     

    Attached Files:

  7. abri

    abri MajorGeek

    Razbaul!
    No. Don't redo it unless I ask you to. Did you have it fix everything it found?
    abri
     
  8. Razbaul

    Razbaul Private E-2

    Yes, he found C:\WINDOWS\system32dbxDgrevCheck.dll and he deleted.
     
  9. Razbaul

    Razbaul Private E-2

    Yes, he found C:\WINDOWS\system32dbxDgrevCheck.dll and he deleted it.
    Now, comp is running very slow. I have to wait 30 - 60 seconds to open a page in my browser. If I shut down Azureus, browser becomes faster. But same situation when I open Nero to burn a DVD.
    If i try to work simultaneously with Mozilla, Azureus and Nero, comp is freezing.
     
  10. abri

    abri MajorGeek

    Hi Razbaul,
    I'm concerned about the slowness of your internet/browser, but I'm not finding much in your logs that would lead to this. I see in your newfiles log that you have gmer installed. Did you run this and did it find anything? I will post you a set of instructions after I've had a second opinion on them. If we're not able to determine malware, there may be something else going on like an incompatibility problem, corrupt files or a bad sector. Since you mention both Asureus and Nero, it seems possible there's a problem in your media software. Have you put a cap on your Asureus so that the download/upload is limited? Otherwise it will flood your internet connection and slow it down. I will get back to you as soon as possible with some final cleanup instructions and possibly one more scan for a rootkit. I appreciate your patience.

    Thanks!
    abri
     
    Last edited: Aug 22, 2007
  11. Razbaul

    Razbaul Private E-2

    Hi abri
    Here is the gmer log. I did run it again ten minutes ago.
    You can also see a warning he gave before scan and another one ge gave at the end.
     

    Attached Files:

  12. abri

    abri MajorGeek

    Hi Razbaul!

    We will try a rootkit removal tool first..

    1) Please copy the bold text including the word REGEDIT4 below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it, double click it and allow it to merge with the registry.

    2) Next, try running this:

    Rustock.b - msguard, pe386, & lzx32 RootKit Removal

    Please post these logs with the others you'll have.


    3) Please go back and run Counterspy in Safe Mode and have it fix everything it finds!
    NOTE: After you've finished this scan, please get the Counterspy log and store it somewhere on your computer where it is NOT in a Sundbelt folder!!

    Once you finished Counterspy and have the log, please go to add/remove programs and uninstall:

    -Sunbelt CounterSpy

    Then delete the below folders which may be left behind by the uninstall:

    C:\Documents and Settings\Raul\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software




    4) Next, if you do not use Windows Messenger (not to be confused with MSN Messenger!!) I would like you to run Disable/Remove Windows Messenger


    5) Now Run The AVENGER by Swandog46 by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it
    yourself.
    * A log file from Avenger will be produced at C:\avenger.txt


    6) Next Reset Web Settings & Default Security Settings

    For IE 6 users:
    To Reset Web Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK

    To Default Security Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Security Tab and click Default Level for Internet, Local Intranet, Trusted Sites, and Restricted Sites. For IE 7 users, simply click the "Reset all zones to default level" button.

    For IE 7 users:
    Select Internet Options, then the Advanced Tab and then the Reset button under Reset Internet Explorer Settings.


    7) Please download ATF Cleanerr by Atribune. This program does not require an installation.

    The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.


    8) After you complete the above, reboot once more and then attach the following logs.
    Let me know how things are running.
    abri
     
  13. Razbaul

    Razbaul Private E-2

    Hi abri
    I followed your instructions and I have the logs. The only problem I was face with is I could not find any log created by Counterspy. Anyway, he didn't find anything. After I deleted Conterspy, I tried to delete manually C:\Documents and Settings\Raul\Application Data\Sunbelt Software and there it was a log inside. I don't know it is a good log, so I have attached it to this message.
    But now I can not attach any file, because the line "Attach Files" is inactive !!!
     
  14. abri

    abri MajorGeek

    Try again after awhile. There seems to be some attachment problems lately.
    abri
     
  15. Razbaul

    Razbaul Private E-2

    First 3 attachements
     

    Attached Files:

  16. Razbaul

    Razbaul Private E-2

    Now my comp is running like Speedy Gonsales, but only in Azureus is closed. Somebody told me I must have 1024 MB RAM, otherwise Azureus will always generate deceleration of comp.
    Anyway, there are still some little irritating problems, such as delay of opening for certain folder, or the infinite time my mail needs for complete opening.
     

    Attached Files:

  17. abri

    abri MajorGeek

    Razbaul!

    I'm happy to hear your computer is faster now. The software forum can probably give you more advice about your Azureus. In case you have a rootkit, as both gmer and that one file found by Bit suggest, please run the following:
    If that doesn't find anything, I declare you clean and will post our final cleanup instructions!!

    abri
     
    Last edited by a moderator: Aug 24, 2007
  18. Razbaul

    Razbaul Private E-2

    Hi abri
    fsbl found something.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you lock/hide Internet Explorer yourself? Perhaps using Drop N Lock which I see in your log:
    Code:
     
    "C:\Documents and Settings\Raul\Desktop\"
    dnlsetup.exe  Aug 20 2007     1175536  "dnlsetup.exe" 
    And did you know that Drop N Lock is adware?

    Azureus Vuse is a known bandwidth hog which will slow down your PC and expecially your surfing performance.
     
  20. Razbaul

    Razbaul Private E-2

    Believe me or not, I didn't even heard about Drop N Lock. And there is no other person who use my comp! But I got a search and I found a little program which I am using for read .dnl files. (See attachement)
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you saying that you know for sure that dnlsetup.exe from August 20 th is something you know about and that it is not drop and lock? Is it this? http://www.desktopauthor.com/faq_showtext.asp?FAQID=76

    Or is it this: http://justecards.com/

    Do you know of any other reason why you would have a hidden iexplore.exe process running? I suggest that you uninstall Azureus Vuze (yes uninstall not stop from loading) and also uninstall any other P2P or torrent type downloaders and then reboot (do not skip the reboot). And then shutdown all browsers and re-run BlackLight and attach a new log.
     
  22. Razbaul

    Razbaul Private E-2

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you ran Blacklight, was uTorrent running, were any browsers running.

    That's because that link is not directly accessible or is just not valid.
     
  24. Razbaul

    Razbaul Private E-2

    None. Now I repeated she scan. I shutted down Mozilla and uTorrent, and I restarted my comp. I have set the firewall to "Block all" and I ran Blacklight.
    He found again that iexplorer.exe is running hidden.
    After I finished, I have set the security level to Custom and Comodo have instantly noyify thet IEXPLORER.EXE is trying to access the internet.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is the file size and date of C:\Program Files\Internet Explorer\iexplore.exe

    Do you normally use FireFox or IE?

    Let's try another rootkit detection program. Run this procedure Using Sophos Anti-Rootkit and attach the requested log.
     
  26. Razbaul

    Razbaul Private E-2

    I am using FireFox, but when is slowing down, I use IE. This is very rare.
    In that moment, SAR is scanning the registry, but it seems to be rather blocked, because I can not see any progress. I attach a Screen.
    As regards iexplorer.exe, I found two locations where it appears. The main is C:\Program Files\Internet Explorer\iexplore.exe, but there is a file named IEXPLORER.EXE, located in C:\WINDOWS\Prefetch
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try something! Boot into safe mode, and then rename the C:\Program Files\Internet Explorer\iexplore.exe file to iexplore.bak

    Now boot back into normal mode and tell me if you get any error messages or popups about not find iexplore.exe. If you do, get a message. Give me the whole message.


    Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to the following key and take ownership of it (explained further down):

    HKEY_LOCAL_MACHINE

    To take ownership of teh key do the following:
    • Copy & Paste the above registry key into the address bar of Registrar Lite and hit the enter key. This will bring you to the regitry key.
    • Click-on Security in the Menu
    • Select Take Ownership
    • Now exit Registrar Lite
    Now try rerunning the Sophos scan and see if you can get it to complete and attach a log.
     
  28. Razbaul

    Razbaul Private E-2

    Finished, after 4 ours of scanning!
    Here is the log.
    I did not fix anything.
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you rename iexplore.exe to iexplore.bak?

    Look in the C:\Program File\Internet Explorer folder and tell me what file names you currently see that begin with the word iexplore
     
  30. Razbaul

    Razbaul Private E-2

    There is only one file that begins with iexplore is iexplore.bak, the file which name I have changed.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmmm! Then how is Sophos showing the below running?

    Hidden: process C:\Program Files\Internet Explorer\iexplore.exe

    Did you reboot after renaming the file?

    Also did you do what was requested with Registrar Lite?

    Download and install this ExplorerXP Use it to look in the C:\Program Files\Internet Explorer folder. Does it show anything else?
     
    Last edited: Aug 25, 2007
  32. Razbaul

    Razbaul Private E-2

    After renaming I reboot for entering in normal mode, because renaming was made in safe mode, as indicated.
    I did not use Registrar Lite, because I waited for Sophos to finish his job. Should I scan again after using Registrar?
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!

    Have you run ExplorerXP to check that folder?
     
  34. Razbaul

    Razbaul Private E-2

    I ran it and the result is in the attachement.

    OK, Sophos did not find anything, but the scan time was very short: 2 min, 34 sec. First scan had taken 4 hours!
    Anyway, Mozilla is running very slow.
     
    Last edited: Aug 25, 2007
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay!

    Since your Sophos log was from before renaming and from before using Registrar Lite, I still need to see a new one.

    Have you noticed any error messages or problems since renaming iexplore.exe?
     
  36. Razbaul

    Razbaul Private E-2

    No messages or problems durin renaming iexplore.exe.
    Sophos did not find anything, as I said in my previous post (later edit).
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now rename iexplore.bak back to iexplore.exe and see if that hidden process starts up again.

    Are you having any current malware problems?
     
  38. Razbaul

    Razbaul Private E-2

    I have renamed iexplore.bak back to iexplore.exe and rescan with BlackLight. He found again the hidden process iexplorer.exe (see attached log).
     

    Attached Files:

  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download Silent Runner's
    • Save it to the desktop.
    • Run Silent Runner's by doubleclicking the "Silent Runners" icon on your desktop.
    • You will see a text file appear on the desktop - it's not done, let it run (it won't appear to be doing anything!)
    • Once you receive the prompt All Done!, open the text file on the desktop, copy that entire log, and attach it to your next message.
    NOTE: If you receive any warning messages from your antivirus or antispyware programs about a script trying to be run , please choose to allow the script to run.


    Also run this procedure: Using AutonRuns and attach the requested log.
     
    Last edited: Aug 26, 2007
  40. Razbaul

    Razbaul Private E-2

    FixVundo says: Trojan.Vundo has not been found on your computer.
    Regarding Silent Runner's, it must be a mistake somewhere, cause there is nothing to save to the desktop. I clicked the link you gave me, and a page containing a script was opening in my browser, ant that's all.
     

    Attached Files:

  41. abri

    abri MajorGeek


    I see Silent Runner's taking you right into the program rather than running it.

    Were you able to run Using Autonruns in post 39 and get a log?
    abri
     
  42. Razbaul

    Razbaul Private E-2

    I ran Autoruns, and attached the log.
    I don't know what I have to do with Silent Runner's.
     

    Attached Files:

  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's possible that you have lost the file association for VBS scripts. Let's try the below:
    • Download the attached Silent Runners.zip file
    • Extract the Silent Runners.vbs file from it to your Desktop
    • Then try to double click on the Silent Runners.vbs file
    • What happens?
    Also let's run the Autruns procedure again but this time I want to change the Hide Microsoft options!
    • On the top of the window click on the menu "Options" and make sure the item "Hide Microsoft Entries" is Unchecked. If it was checked, uncheck it and then the F5 key to refresh/rerun the scan
    • attach the new log
     

    Attached Files:

    Last edited: Aug 26, 2007
  44. Razbaul

    Razbaul Private E-2

    Done
     

    Attached Files:

  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well those don't show a Backdoor.Bifrose infection which is what I was worried about. This infection is known for hidding an iexplore.exe process like you have.

    Do you see a folder named C:\Program Files\Bifrost


    Download Registry Search (see the link titled RegSearch Download Link )
    • Extract the files from Regsearch.zip into a folder.
    • Doubleclick regsearch.exe to start the program.
    • Enter bifrost in the top area of the form and then click "Ok".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well). Attach this file to your next reply.
    Then repeat the above search but look for this string: mdojtgmr
    Attach a second log.
     
  46. Razbaul

    Razbaul Private E-2

    Regsearch created some problems. At the end of the scan, a notepad empty document appeared and comp started to not answer. After Ctrl+Alt+Del, into the notepad appeared some text, but comp still refused to answer, so I was forced to restart. This happened with both scans (bifrost and mdojtgmr).
    Now I see a single log, so I attach it together with another one, called "History".
     

    Attached Files:

  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try again after shutting down any antivirus and antispyware programs you have running. I don't need a copy of history.txt. That is part of the ZIP file you downloaded. Regsrch does not make any changes to your PC. All it does is search the registry for matches to the strings. If the log looks like the below for bifrost, it just means it was not found. The log you already attached for the mdojtgmr search indicates it was notfound.

    Download ProcessExplorer
    1. Unzip it to its own folder somewhere you can locate it.
    2. Now run procexp.exe by double clicking on it.
    3. Let's configure some options first:
      • Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked.
    4. Now click on explorer.exe.
      • Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    5. Now click on File and then Save As. And save the process list to a file named C:\explorer.txt
    6. Now click on winlogon.exe
    7. Now click on File and then Save As. And save the process list to a file named C:\winlogon.txt
    8. Now come back and attach the C:\explorer.txt and the C:\winlogon.txt log files
    Before doing the below, make sure you are not using Internet Explorer yourself. I just want to monitor the hidden process.

    Now download Filemon for WinNT/2K/XP and extract it to a folder of its own.
    • If you wish to know more about Filemon, additional informaton and help for Filemon can be found here: Filemon
    Setting up FileMon to monitor file access
    • Run Filemon by double clicking on filemon.exe
    • When it comes up, change the *.* in the Include box to be iexplore.exe
    • Then click Apply and OK.
    • The Filemon window now comes up and will monitor for anything accessing iexplore.exe
    • Now just leave this running for about 5 minutes.
    • After 5 minutes go back to the Filemon screen and click File and then uncheck the Capture Events selection to stop the capture process. Then use File, Save As to save the log to a file like filemon.log and post it back here as an attachment.
     
    Last edited: Aug 26, 2007
  48. Razbaul

    Razbaul Private E-2

    Looks like he found bifrost.
    Windows Registry Editor Version 5.00
    ; Registry Search 2.0 by Bobbi Flekman © 2005
    ; Version: 2.0.5.0
    ; Results at 27.08.2007 07:35:57 for strings:
    ; 'bifrost'
    ; Strings excluded from search:
    ; (None)
    ; Search in:
    ; Registry Keys Registry Values Registry Data
    ; HKEY_LOCAL_MACHINE HKEY_USERS

    [HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603]
    "000"="bifrost"

    ; End Of The Log...
     
  49. Razbaul

    Razbaul Private E-2

    Logs for Filemon and Process Explorer.
     

    Attached Files:

  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The Filemon log seems to indicated that your Comodo Firewall is using IE.

    I have used Comodo on PCs and never saw this happen. Please first try just shutting down Comodo (right click on the tray icon and select Exit. Then run Blacklight again. Does the hidden Internet Explore process still show? If so, try uninstalling Comdo and run Blacklight again and tell me the results.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds