Fonts Folder hit by trojan, please help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by missmaster, Apr 11, 2008.

  1. missmaster

    missmaster Private E-2

    Hi there,

    I hope someone can help me here.

    I have had the following problem for the past few months and have tried a lot to get rid of it! To no avail...

    There appears to be a hidden folder within my C:/WINDOWS/Fonts folder:

    C:/WINDOWS/Fonts/'

    within which there are apparently around 10,000 zip files, which I didn't put there. I can't access this weird folder nor can I see these weird zip files.

    My ZoneAlarm AntiVirus picks these files up but it cannot delete/delete on reboot/quarantine/rename/etc. them.

    If I go to the location of my fonts folder and right click on it and go to properties, the folder size is constantly increasing, as is the number of files.

    This problem is really irritating me! I had it before I installed ZoneAlarm which maybe is why the program won't delete these rogue files???

    I have tried following the instructions on some related posts here but I assume because those posts were for a specific problem on someone's specific settings, it didn't work.

    I'm ready to download whatever tools I need to beat this ' file and its malicious contents AND whatever is causing them to appear: a virus registry entry perhaps??

    I'd love a walkthrough on how to do this if anyone is willing to oblige?

    Thanks in advance.

    S.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. missmaster

    missmaster Private E-2

    Ok I carried out the tasks as described in Read and Run Me First.

    Attached are the first three requested log files in order:

    SASLog
    Malwarebytes Anti-Malware Log
    ComboFix Log

    MGLogs to follow.

    Ok when I look at the properties of my Fonts Folder it says there are 358 files with a size of 32.2MB. And it's not increasing in size anymore!

    I still wanted to post these logs in case there is anything left there that will cause this problem to come back.

    Also, I'd like to keep one of the programs from the Read and Run Me First instructions as a backup for my ZoneAlarm Security Suite (which didn't pick this problem up!). Which program would you recommend?

    Thanks in advance.

    S.
     

    Attached Files:

  4. missmaster

    missmaster Private E-2

    Here are the MGLogs.

    Thanks.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {11506172-FBAA-4CE4-BA5B-5ED41E43B636} - (no file)
    O2 - BHO: (no name) - {27B26139-EEB1-44B2-AEC5-8B71340F3ED3} - (no file)
    O2 - BHO: (no name) - {2a22822f-2fde-4437-ab65-6dcc3e6595c0} - (no file)
    O2 - BHO: (no name) - {2B1414C1-69E3-408A-B5D5-5034E12971EC} - (no file)
    O2 - BHO: (no name) - {3E3BAC93-78F9-4756-8241-7F0C58E663FC} - (no file)
    O2 - BHO: (no name) - {5e36c1bf-b3a3-45bf-a455-4435242dc4b7} - (no file)
    O2 - BHO: (no name) - {5F90B2FC-36D1-4471-BB9A-073D29F0C153} - (no file)
    O2 - BHO: (no name) - {6B8891F5-BA96-4395-AA75-9EDCB66C3AA5} - (no file)
    O2 - BHO: (no name) - {790573B5-F33F-4F0A-9947-AD774188FD68} - (no file)
    O2 - BHO: {ee640cea-4ea8-d1b8-e384-adb797306c68} - {86c60379-7bda-483e-8b1d-8ae4aec046ee} - (no file)
    O2 - BHO: (no name) - {8b647940-fbbb-47a5-8601-f836a2091396} - (no file)
    O2 - BHO: (no name) - {A199DDEC-3295-408F-A22A-1B31766CFF07} - (no file)
    O2 - BHO: (no name) - {AD3FCE93-440F-4972-84C3-077118D50563} - (no file)
    O2 - BHO: (no name) - {C3AF2FD9-A951-4F28-A555-448E95AD29FF} - (no file)
    O2 - BHO: (no name) - {D318E9BB-A19A-44C7-BCE3-1782ECD0964F} - (no file)
    O2 - BHO: (no name) - {E5BECA9D-AEF2-4D41-898F-9EA5ED4EC52D} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O16 - DPF: {CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_04) -
    O20 - Winlogon Notify: eackrgqu - eackrgqu.dll (file missing)
    O20 - Winlogon Notify: mljgfcy - C:\WINDOWS\

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.



    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. missmaster

    missmaster Private E-2

    Hi Chaslang,

    Ok I did everything you said.

    Attached are the MGLogs zip archive and the ComboFix log as requested.

    The registry changes were applied successfully.

    The problem with the Fonts Folder has disappeared and I don't seem to be having any other problems, apart from trying to decide whether to keep ZoneAlarm or buy SUPERAntiSpyware Professional for the Real-Time protection!

    Thanks.

    S.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    SUPERAntispyware is not an antivirus program nor is it a firewall.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  8. missmaster

    missmaster Private E-2

    That's great, thank you very much for your help!

    I've installed the recommended programs to keep my computer safe from malware in the future.

    I've also bought Outpost Firewall so hopefully I should be ok from now on!

    Thanks again Chaslang, you're a life saver!

    :)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds