Something strange is lurking

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by micro, Jan 29, 2007.

  1. micro

    micro Private E-2

    Hi,
    This is my first post. Something weird is occuring on my Windows XP Pro machine. Everytime I start up my PC, McAfee 8 "Enable on-access scan" is disabled. The McAfee Framework service and Network Associates McShield and Network Associates Task manager services are also disabled. I noticed a folder called C:\WINDOWS\exefld has been created and a file named 138531.exe created.
    I have used SpyBot, McAfee and LavaSoft; but know known problems were found. I understand from similar searches on Google that this may be a Trojan.
    Any help would be appreciated.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. micro

    micro Private E-2

    Hi TimW,
    Email 1 of 3
    Thanks for the reply, followed your instructions. I couldn't boot up in safe mode. I had a blue screen, asking me to check for a virus, remove hd and do a chkdsk etc.
    I ran CounterSpy twice the first time I asked for the trojan to be removed: there is a difference between the two; the second mentions a Worm. I will attach both logs + the Bitdefender One (renamed ext to txt from html; couldn't upload an html file).
    My McAfee services are still being disabled.
    Thanks for your help.
     

    Attached Files:

    Last edited: Jan 30, 2007
  4. micro

    micro Private E-2

    Hi,
    Part 2 of 3
     

    Attached Files:

  5. micro

    micro Private E-2

    Hi,
    Part 3 0f 3
    Thanks Again.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download this RegRun

    Post the log from it as well as new:
    GetRun
    ShowNew
    HJT
     
  7. micro

    micro Private E-2

    Hi TimW,
    Part 1 of 2
    Again thanks for your reply. I have attached the three logs as requested.
    Things that stood out for me on the RegRunRun - anti-Spyware wizard were:


    1). Bootexecute Value=autocheck autochk *\n Default Value=autochk* (there were two of these) both marked as suspicious

    2). Drivers mc21D.tmp Value=C:\DOCUME~1\<MYUSERNAME>\LOCALS~1\TEMP\MC21D.TMP - marked as a warning

    3). There was one item that was listed as Dangerous by RegRun:
    %UserProfile%\Application Data\hidires\hidr.exe. I looked it up at Symatec
    http://www.symantec.com/security_response/writeup.jsp?docid=2006-032316-2221-99&tabid=3 and asked RegRun to fix it.

    I have noticed in my registry I still have the key HKCU-Software-FirstRRRun | Name = FirstRR23232Run Type = REG_DWORD Data = 0x00000001(1); I understand this may be part of my problem; there is also a key FirtR, I wondered if this is OK. The folder C:\WINDOWS\exefld is still present but empty.
     

    Attached Files:

  8. micro

    micro Private E-2

    Hi TimW,
    Part 2 of 2
    I won't be around after today until Monday.
    Thanks for your help.
     

    Attached Files:

  9. micro

    micro Private E-2

    Hi TimW,
    Just found this hidden folder on my network profile \\ihaa.local\users\profile\<myname>\appdata\hidires
    it contains the files
    flec003.exe
    hidr.exe
    m_hook.sys
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download and run Kaspersky Cleaner.

    Attach a log of the results as well as a new:
    ShowNew
    HJT
     
  11. micro

    micro Private E-2

    Hi TimW,
    Here are the reports. Just to note I manually deleted the three files from the folder \\ihaa.local\users\profile\<myname>\appdata\hidires and I returned to a previous Win XP Restore point. So far nothing suspicious appears to be happening. I have also turned off the Restore function; should I turn it back on? Next week I intend to go thru the Read & Run Me First procedure again to double check.
    Thanks again for taking the time and energy to help.





     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If after what we did, you restored to an earlier point, you may well have restored some of the problems. I would suggest that you do all of the procedures again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds