Help! skitodayplease & doginhispen: Scans Complete/Logs Posted

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by J8son, Feb 18, 2008.

  1. J8son

    J8son Corporal

    Symptoms:

    1) About two weeks ago I start noticing the IE7 just closes for no reason. I can be sitting there, not touching anything and "boom!" It just pops off out of the blue. In fact, it kicked off twice just trying to type this very thread. I finally just had to type it in a blank email and then copy/paste.

    2) Recently, I start noticing something else strange when I access my bookmarks via the Start Menu > Favorites menu in the Windows XP taskbar. TWO tabs load instead of just one. The active tab on the right is the site that I loaded (IE: Google, Major Geeks, etc...) but the tab on the left is an empty IE window with the "Internet Explorer was unable to display this page" message. But, in the address bar of this tab is when I realized that I had an infection. It started off with the skitodayplease in the address and then changed to doginhispen. It seems to alternative between the two. Note: I only get the dual tabs when accessing my Favorites from the Start Menu. If I load IE using the icon on the Desktop, it does not happen.

    Actions Taken So Far:

    1) First I tried scanning with SmitFraudFix in Safe Mode

    2) I cleared out C:\Windows\Temp and C:\Documents and Settings\USER NAME\Local Settings\Temp, again in Safe Mode.

    3) Followed EVERY last step in the Read & Run Me First and Windows XP Cleaning Procedure threads, to the letter, but to no avail.

    I have attached C:\ComboFix.txt, SASlog.txt & MGlogs.zip and await your expert tutelage.

    Thanks! ;)
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download and run FindAWF by noahdfear.
    • Please download FindAWF by noahdfear.
    • Save to your desktop.
    • Double-click the FindAWF icon.
      • If a Security Alert shows, allow the program to run.
    • As instructed, press any key to continue.
    • Use the following option: Press 1 then Enter to scan for bak folders
    • The scan may take a while, please be patient.
    • When done, a text file, Find AWF report is produced.
    • Please attach the Find AWF report in your next post.
    Uninstall the below old versions of software:
    BearShare <-- should have been uninstalled in step 0 of the READ ME
    Java(TM) SE Runtime Environment 6

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
     
  3. J8son

    J8son Corporal

    First, let me start by saying how grateful I am for the help. The willingness to lend a hand on this forum never ceases to amaze me!

    UPDATE:

    1) Un-installed Bearshare (I had hoped to leave this installed as it is the Pro version and the only updated versions are the free Standard ones. But, I un-installed it anyway.)

    2) Un-installed Java

    3) Shutdown/Reboot

    4) Installed updated Java via the link provided

    5) Ran FindAWF.exe and posted the log

    Thanks again! ;)
     

    Attached Files:

    • awf.txt
      File size:
      3.1 KB
      Views:
      5
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Double-click the FindAWF icon.
    • If a Security Alert shows, allow the program to run.
    • As instructed, press any key to continue.
    • Use the following option: Press 2 then Enter to restore files from bak folders
    • A text file opens called: files.txt
    • Click below the line and paste the following list of files to be restored:
    • Next, close and click Yes to save the changes.
    • Once files.txt is saved, FindAWF does the following:
      • It attempts to terminate the process represented by each filename on the list, if running
      • Deletes the rogue file from the parent folder, if present
      • Copies the original file to the parent folder
    • When done with the above, it automatically runs a new scan and opens a new log.
    • Please attach the new FindAWF log to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\MGlogs.zip
    • also the log from FindAWF
    Make sure you tell me how things are working now!
     
  5. J8son

    J8son Corporal

    UPDATE:

    1) Ran FindAWF.exe using Option 2 and copy/paste/saved the above info to the text file.

    2) Ran C:\MGtools\GetLogs.bat to generate a new log and posted that along with the new awf.txt for review below.

    STATUS: FIXED!!!

    Everything seems to be working great now. We tested the laptop all weekend long with no issues. I no longer get any of the tabs with the skitodayplease/doginhispen urls and IE7 has stopped closing/crashing for no reason.

    So, just want to send out a big thank you to everyone at Major Geeks. You guys rock, as usual.

    And just an FYI, even though things are fixed now, exactly what in the last process corrected the problem? Just curious...

    Thanks again! ;)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All of those listed startup files that were in the bak type folders were the real startup files that should have been loading at startup. However the infection replaced the startups with exactly the same file names but they were infected programs to spread and keep reinfecting you anytime any single one of the startups ran. What we did is restore your real programs. Now we need to finish some cleanup to remove the now unnecessary bak folders and some other issues too.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    File::
    C:\Documents and Settings\Windows XP\Local Settings\Temp\1204436350.exe
    C:\Documents and Settings\Windows XP\Local Settings\Temp\3688882967.exe
    C:\Documents and Settings\Windows XP\Local Settings\Temp\3866298987.exe
    C:\Documents and Settings\Windows XP\Local Settings\Temp\461358366.exe
    C:\Documents and Settings\Windows XP\Local Settings\Temp\949383546.exe
    C:\Documents and Settings\Windows XP\Local Settings\Temp\abc123.pid
    C:\Documents and Settings\Windows XP\Local Settings\Temp\h2r12.tmp
    C:\Documents and Settings\Windows XP\Local Settings\Temp\r2h11.tmp
     
    Folder::
    C:\Program Files\QuickTime\bak
    C:\WINDOWS\system32\bak
    C:\WINDOWS\system32\bak
    C:\WINDOWS\system32\bak
    C:\Program Files\CyberLink\PowerDVD\bak
    C:\Program Files\Synaptics\SynTP\bak
    C:\Program Files\Adobe\Reader 8.0\Reader\bak
    C:\Program Files\CyberLink\PowerDVD\Language\bak
    C:\WINDOWS\system32\spool\drivers\w32x86\3\bak
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. J8son

    J8son Corporal

    UPDATE:

    1) Ran C:\MGtools\analyse.exe selecting items 02, 04 and 04 to fix.

    2) Copy/Pasted code to CFscript.txt and ran ComboFix.exe by dragging and dropping the text file.

    3) Ran Ccleaner.

    4) Ran C:\MG tools\Get Logs.bat.

    5) Posted ComboFix.txt and MGlogs.zip.

    My laptop is still running great with no further issues. So, after reviewing the logs, is the system itself clear?

    Thanks ;)
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. Now you need to get properly protect which you currently are not. This is covered in the last step of the below.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  9. J8son

    J8son Corporal

    Again, I can't thank everyone enough for the wonderful help. This is simply an amazing community.

    On a side note, I have no protection running right now as I was originally getting my laptop set back up after a format when this happened. I intended to use Norton Internet Security Suite 2008. What is the buzz about this in relation to protection? Ya'll have pretty much used every protection app available so I figured you'd have some insight there.

    Thanks again! ;)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We hate any Internet Security Suite since they are all massive resource hogs. And many of them are really not as effective as you would think against much of the current malware that is around. The tools we have in the How to protect yourself thread are more than adequate and do not overload you with a pile of junk that you don't need. They also will not slow your PC down as much as an internet security suite.

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds