read & run me first procedure

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by triplenelson, Oct 29, 2006.

  1. triplenelson

    triplenelson Private E-2

    hi, in the last days i've been attacked by this "Trojan horse dialer.28.a" as avg detected. it was constantly sending information by internet. i sent it to quarantine several times but it kept reappearing; so i decided to follow this procedure "READ & RUN ME FIRST before..." and i am sure i haven't misssed any steps. when i ran spybot, it was unable to delete from the register some altnet file and it appears as a potential damage. then i had to run counterspy twice because i realized that i had not updated the first time, but anyway i'll be attaching both logs if it's ok.
    i think it stopped transfering information by itself when i connect to internet which can be a good sign. however, i noticed that my printer has been uninstalled and the last time i restarted my pc, an error appeared (winlogon.exe) because it couldn't find a file called sfc_os.dll; i believe they might have been deleted when fixing files in these previous steps.
    i don't understand how the attachments work, should i add them to other posts or what? i have 7 to send, but only 3 are are allowed, what am i supposed to do?
    i would appreciate it if someone could help me out with all this problems.
     
  2. triplenelson

    triplenelson Private E-2

    i'm attaching the files anyway, in case someone would like to help me
     

    Attached Files:

  3. triplenelson

    triplenelson Private E-2

    here there are some more...
     

    Attached Files:

  4. triplenelson

    triplenelson Private E-2

    and the last one...
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Well you did forget to attach your HijackThis log, but I don't think it will show us anything.

    Try the below:

    Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    I doubt this is related to anything done while running the READ ME, but malware can cause any number of problems.

    The sdc_os.dll file was detected as being infected by PandaActiveScan however it said that it disinfected the file. It did not say that it deleted the file. Check in your G:\Windows\System32 folder to see if the file is there.

    Did you recently (on October 28th) update or change files in your Windows OS. Is see the below new versions of ftp.exe and tftp.exe in your system32 folder.
    Code:
    G:\WINDOWS\system32\
    ftp.exe       28 Oct 2006       43520  "ftp.exe"
    tftp.exe      28 Oct 2006       17920  "tftp.exe"
    
     
    Last edited: Nov 1, 2006
  6. triplenelson

    triplenelson Private E-2

    hi! thanks for writing back.
    you're right, i forgot to attach the hjt log, i see i've made a mistake :eek: i'm sorry for that, i'm attaching it now.
    i copied the bold text & followed the instructions, that's done, but what's that for exactly?
    about the printer, shoud i install it again? i suppose it's the only solution...
    i checked in G:\Windows\System32, but there was no sfc_os.dll whereas ftp.exe & tftp.exe both appeared in the folder, modified on 28 Oct 2006, but I don't remember having updated or sth. what can i do about that?
    finally, i forgot to tell you that my pc is running rather slower than before, especially when windows starts, it takes it ages to finish opening all the programs.
    well i think that's all. i'm waiting for your reply.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you did not give exactly what Spybot found, I took a guess at what it may have seen. This is a typical item it may fid for Altnet in the registry. What I gave you is a registry patch that attempts to delete the registry key if it exists.


    Yes you should try that.

    You can get a copy here: free dll files - download sfc_os.dll


    Paste the below file list into the program given in this procedure: Using GetDetails
    Then attach the log that is created back here as an attachment.


    I'm not sure it is malware. Let's try another scan.

    Please run the below procedure and attach the requested log:

    Using Sophos Anti-Rootkit


    I will be away for 9 days! Hopefully one of the other helpers here can continue to help you! Or you will have to wait until I get back!
     
  8. triplenelson

    triplenelson Private E-2

    well, what a coincidence! i'll be away too, but only for the weekend, on monday i'm back again.

    returning to our business, i have a few items to comment:

    1. I've scanned the computer again with spybot and counterSpy, just to check if everything was normal and while spybot concluded there were no problems, counterSpy keeps finding that dialer that's driving me mad (i've attached the log if you want to take a look); i don't know where it comes from - when avg detected "Trojan Horse Dialer.28.a", they were the same kind of files reappearing.

    2. i tried to reinstall the printer (remember i said that it was working normally but suddenly while i was doing the scans for my first post i realized it had disappeared) but the computer doesn't recognize it as new hardware, any ideas?

    3. i've attached both logs you requested.

    4. with regard to the speed, just wanted to let you know that it also started after all these scans, so i guess sth must have been deleted...

    5. if you need more information, please just ask.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a problem! It is just in system restore which will be cleaned by our final steps that I will give below following some additional steps to help speed things up and to fix one more malware item.

    Since I will not be around and this not really a malware problem, you would be better of working this in the Hardware Forum.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to LSA Shel
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteExport Version into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [QuickTime Task] "G:\Archivos de programa\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "G:\Archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [MSMSGS] "G:\Archivos de programa\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Microsoft Office.lnk = H:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - G:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - G:\WINDOWS\web\related.htm

    After clicking Fix, exit HJT.

    Now reboot in normal mode.

    Delete the below files if found:
    G:\WINDOWS\lsass.exe
    G:\WINDOWS\system32\ftp.exe
    G:\WINDOWS\system32\tftp.exe


    Attach a new HJT log so we can double check that everything was removed.

    Final steps given below (since I will be gone) assuming you are not having anymore problems!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    7. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
    Last edited: Nov 4, 2006
  10. triplenelson

    triplenelson Private E-2

    the hjt logs attached at the bottom correspond to the steps mentioned above: before fixing and after deleting the last files, respectively. i am waiting for a response before moving on to the final items also mentioned in the message above. i would like to know whether everything is ok or there's sth missing.
    finally, i wanted to know if it is necessary for me to keep counterSpy installed in my pc, i can notice how much it is slowing things down, so i was considering removing it (it will expire in a few days anyway) and instead using only spybot, avg and some firewall.
     

    Attached Files:

    Last edited: Nov 7, 2006
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You log is clean now so you need to complete the other steps!

    Yes you can uninstall CounterSpy since it is of no use after the trial period. However you do need to have a full realtime spyware blocking tool installed which will in have an impact on performance. This is a necessary price to pay for your security. It is the same thing that happens when an antivirus program or firewall is installed. They each have an impact. If you do not want to buy a realtime blocker, you can try the Teatimer function of Spybot but it has been troublesome for many people. Another alternative (but it is not as up to date or comprehensive as new programs) is to use SpyWare Guard which is mentioned in the "How to protect" link I gave you.
     
  12. triplenelson

    triplenelson Private E-2

    well, i'm back.
    first of all, thanks for all you help, i really appreciate it.
    secondly, i wanted to know if spyware guard is actually useful since the last updates are about 3 years old. i was thinking about using only spybot activating the immunizer but not teatimer, do you think it'll be enough? how about spyware blaster?
    in addition to this, i activated windows updates and everything was working normally, but today when i connected to internet it started downloading things and my disc (where windows is installed) is full, and it wasn't a couple of days ago. i ran spybot and avg and they found no problem, so i disabled the updates, however, it continues downloading every time i connect. i looked in zoneAlarm and there appears "Generic Host Process for Win32 Services Listening to port(s): TCP: 1025,3002,3003 UDP: 1026 (Trusted Zone Only)" flashing, and next to it "Generic Host Process for Win32 Services". i'm rather worried about this, and i wanted to know if there's anything i can do about it.
    now, after writing all this, i looked at my disk to tell you the numbers but now it's not as full as the previous time, i now have 650MB left while there were less than a hundred the time before, all i did was disabling the updates - this machine is crazy!! it's still downloading...
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not the same kind of program as other antispyware programs and does not require updates as often however as I said in my previous message, it is also not as comprehensive a checker/blocker since so much has changed in the malware world.

    Inadeqate!!! YOU MUST HAVE a realtime blocker. You must buy one or you must use one of the free ones. Even when you do add a realtime blocker, you should still use BOTH SpywareBlaster and Spybot with its SDHelper and Immunizer.

    You could give one of the below free tools a try for realtime blocking and see how you like them:

    Arovax Shield

    Spyware Terminator


    This is svchost.exe which is part of your Windows OS. If you block it from having access to the internet there will be a whole load of things that will not work. ZoneAlarm will block any non-required ports by default. Like TCP Port 1025 which is commonly used for Microsoft Remote Procedure Call (RPC) service.



    If you are running in the area of only having 1000 Mb or less diskspace free then you need to cleanup and get more diskspace. Windows requires lots of free space for temporary files and caching. Many programs require temp space too. Not having enough will just slow everything you do down.
     
    Last edited: Nov 25, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds