persistent malware - hijack this log

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by knada, Feb 11, 2007.

  1. knada

    knada Private E-2

    Hi, I am trying to clean up my father-in-law's laptop. I think he picked up some virus/trojan from downloading some kind of 'torrent accelerator' or something (he is unclear on details). Ran the recommended steps to clear everything but now I am still getting bits of spyware found by spybot. These aren't the same things coming back, rather it's always some different 1 or 2 things. I am attaching my latest hijack this log if anyone can help.
    I *really* appreciate any help, have been at this quite a few hours and haven't seen such persistent malware before!

    ALSO, just thought of this: for the moment, anyhow, the unwanted popup ads seem to have stopped, however I am concerned as spybot is still reporting spyware.

    -Andrew
     

    Attached Files:

    Last edited: Feb 11, 2007
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome


    Your log doesnt show much, but then hijackthis is not the best all round application to highlight malware as its limited in what it scans and finds, so please do run the below and attach all the logs requested, even if they say they found nothing.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. knada

    knada Private E-2

    Halo, thank you so much for responding.

    I don't have physical access to the infected machine now and won't for at least a couple days, however I did do the complete process as outlined on the read & run me first page so hopefully we can at least get to the next stage of info.

    I am realizing now that I don't seem to have the logs from GetRunKey or ShowNew, sorry. I couldn't see anywhere to save a log from Counterspy, so I only have the logs from BitDefender and Panda. And for some reason the BitDefender one is html formatted.

    If you wouldn't mind taking a glance and see if anything obvious pops out at you, would appreciate it, otherwise if you want me to just try again when I have access to the machine again can do that.

    Thanks again.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry but we need all six of the logs to help you! That is why they are all in the procedure.
     
  5. knada

    knada Private E-2

    OK - Sorry to waste your time with this to-and-fro.

    As soon as I can get ahold of his laptop again I will do the complete procedure and post all the logs here. I am still a little puzzled why I couldn't see any option to save the log from Counterspy but will try again.

    Thanks again.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If CounterSpy has been used in the past, it may have passed the trial period which means it will not remove anything. Also you must remove the malware at the time of the scan! Some people seem to have problems using it, I don't know why! I have run the trial on a few dozen PCs myself and never had a problem getting it to fix problems. It really is not that complicated. But as I said, if the trial has expired, it will not work. Thus as recommended in the READ ME, AVG Antispyware should be used instead.
     
    Last edited: Feb 15, 2007
  7. knada

    knada Private E-2

    OK! At last, I have the laptop and have gone through the recommended process. So if you wouldn't mind taking a look, I'll attach all my logs. I'm not sure Pandascan was willing to disinfect (it's a little unclear as my screen resolution is very low in safe mode and for some reason I get no scroll bars on their site) but I did get a report.

    Anyhow, I really appreciate any help you can give!

    Thanks
    Andrew
     

    Attached Files:

  8. knada

    knada Private E-2

    ...and the last 3 logs

    Here are the other 3 logs requested. Tx -A.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: ...and the last 3 logs

    You really do no show that much to worry about. Just a few minor things to do!

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Mozilla Firefox (1.5.0.9)

    Then install the current version of FireFox from: Mozilla Firefox


    Okay now uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also delete the below malware folder!!
    C:\Documents and Settings\Bren\Application Data\Torrent101


    How is everything working?
     
  10. knada

    knada Private E-2

    Thanks a million Chas. Everything looks pretty good. I just did a Spybot scan which only found a DoubleClick cookie which I guess I picked up from Mozilla.

    Just for my peace of mind I'm going to do the complete series of scans again; do you want me to post an update here if I find problems or would you rather I leave you alone at this point?

    Also, do you guys take donations and/or do you have a favorite charity?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cookies are not problems! Read step 11 of the link given below in your final steps!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    Not necessary. You have no malware to be concerned with.

    We are working on a way to setup donations that can be sent to charity but we don't have that in place yet. Some of us do have PayPal accounts though.
     
  12. knada

    knada Private E-2

    Great - thanks again Chas. My final question (I promise!):

    I ran one final check and all looks well with the exception of Panda Scan which gives the alarming looking report of 4 'hacking tools/rootkits' -- this is the same result as on the last scan that you OK'd as fine, so I think this is just them being unnecessarily cautious so as to sell more disinfection services. The 4 items listed on the log appear to be 'possibly unnecessary' drivers...

    I'm mainly bringing this up just cause I think it might be instructive to others happening across this thread.

    Thanks 10^6 for all your help. -A.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. The answer lies in the log itself. They are not problems. They are for your Dell AIO 810 printer.

    Also it just says they are potentially unwanted tools. It does not say they are rootkits.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds