Need Help! Trapped with Malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kruzman, Jun 23, 2007.

  1. kruzman

    kruzman Private E-2

    Hello,

    I own a website time4tips.com which is currently been hit by a malware or a virus I suspect.... whenever one tries to access its homepage, the following script mystabcounter.info/exp/z-png-ov.php is automatically started and then an applet BaaaaBaa is also activated on the user's browser. I don't have even a single hint what all is happening... also this website as been listed out of google and tagged with a message "This site may harm your computer" on the google results. Same is the case with my other websites.

    I believe that there is something in my system which is causing such problems. Everytime, I upload the files to my server, the virus also gets transferred along with those files. I may be wrong, but I am not able to identify the real cause behind that and also, I have re-examined the source code of all the files and I havn't found any link to the above script from anywhere within those files.

    Any help would be highly appreciated!

    Thanks
     
  2. kruzman

    kruzman Private E-2

    Also, I have already followed the step-by-step procedure as per your malware removal guide and thereby attaching the logs below. Please do take a look and let me know what actions I need to take to get out of this.
     

    Attached Files:

  3. kruzman

    kruzman Private E-2

    more information...
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You forgot to attach the log from CounterSpy.

    Also I have a question. What PC are you giving us logs from? Is it your PC where you work on your pages (the one you upload from) or is it the server?

    You need to first go back to the READ ME and do steps 0 & 2 of the READ ME properly. You are using MSconfig to control startups and you still have file extensions hidden. Attach new logs from GetRunKey and HJT after fixing these issues.

    I also see signs of possibly 3 antivirus programs. AVG seems to be installed. Did you have Norton/Symantec and Quickheal installed at one time and are they uninstalled now?
    Your security may be at risk because it appears that you have this installed: http://www.sophos.com/security/analyses/trojdowdecf.html
    It can do the following
    • Steals information
    • Monitors browser activity
    • Installs a browser helper object
     
  5. kruzman

    kruzman Private E-2

    I carefully read the guide once again and implement everything from the beginning. I switched over to the normal startup mode and also allows the visibility of file extensions. Also, on my system AVG antivirus is installed, rest which you mentioned either have been removed earlier or aren't installed on my pc.

    Also, I use the same system to upload my files to the server and logs have been generated from this system only. Let me know if you need any further information in order to help me in fixing this problem. Here are the following attachments
     

    Attached Files:

  6. kruzman

    kruzman Private E-2

    Here is the HJT log
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That was not the point of my question. I was really concerned about the server. If your PC is not the source of the problem (yet to be determined) then the server could be.

    Let's address the issues on your PC!

    Do you know what this Bryxen Software is that was installed on June 9th?
    Also do you know what the below two lines are for?
    O4 - Startup: Free WebSite Tools.lnk = ?
    O4 - Global Startup: 24Online Client.lnk = C:\Program Files\eLitecore\Cyberoam Client for 24Online\CyberoamClient.exe

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 8

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Update Scheduler] C:\PROGRA~1\QUICKH~1\UPSCHD.EXE /CHECK
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [Startup Scan] C:\PROGRA~1\QUICKH~1\sensor.exe /loadrun
    O4 - HKLM\..\Run: [ScreenPrint32] C:\Program Files\ScreenPrint32 v3\ScreenPrint32.exe -startup
    O4 - HKLM\..\Run: [On-Line Protection] C:\PROGRA~1\QUICKH~1\CATEYE.EXE
    O4 - HKLM\..\Run: [Messenger] C:\PROGRA~1\QUICKH~1\scanmsg.exe
    O4 - HKLM\..\Run: [Email Protection] C:\PROGRA~1\QUICKH~1\EmlProxy.exe
    O21 - SSODL: msindeo.dll - {7ACB5731-5839-13AB-EABC-124791194525} - (no file)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. kruzman

    kruzman Private E-2

    Hello Sir,

    I did exactly what you asked me to do so and everything goes fine. Bryxen Software is known to me and indeed very useful. Global Startup: 24Online Client.lnk was my internet host earlier but now I have switched on to some other. Can you tell me how to completely uninstall it from my system. And about Startup: Free WebSite Tools.lnk, I don't have any idea what it is and what is the use of it. I have also uninstalled CounterSpy and J2SE Runtime Environment Updates. Rest is also being done. Here are the new generated logs:
     

    Attached Files:

  9. kruzman

    kruzman Private E-2

    HJT Log
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You picked up a new malware item. Probably arrived inbetween your first posting and the time you were able to complete my cleaning steps. We will remove it with Avenger.


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - Startup: Free WebSite Tools.lnk = ?
    O4 - Global Startup: 24Online Client.lnk = C:\Program Files\eLitecore\Cyberoam Client for 24Online\CyberoamClient.exe


    After clicking Fix, exit HJT.
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  11. kruzman

    kruzman Private E-2

    I did run HijackThis and tried to fix those programs, but some error occurred something like "Bad line #52...." and after that Avenger was successfully accessed. So here are the new logs...
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds