Can I post a log?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jf38081, Sep 19, 2005.

  1. jf38081

    jf38081 Private E-2

    Hello,
    First of all, I have done everything in the "Read me first.." about virus, spyware and so on. The only thing unexpected, is that I could not get the VX2 plugin for adaware to install. It downloaded a .zip file with a .dll and .dlx but does not appear in the add ons for adaware.

    Some of the tools came up clean (Spybot, Adaware) others did not (Bitdefender online, microsoft antispyware.) Stinger found something the first time I ran it, but doesn't find anything now. I don't know where all the logfiles are, but there are a couple I can post. (Bitdefender and HJT)

    The have been 2 persistent problems that I can't make go away: AVG keeps alerting to a virus dtnttg.exe (type Trojan backdoor Pakes.C) in the windows/system32 folder. I can heal/delete/quarantine, but it keeps coming back. The other problem is microsoft antispy keeps finding "aproposmedia" with the same result. If I heal/delete/quarantine it keeps coming back.

    Can I post the HJT and Bitdefender logs?
    Thanks,
    Jim
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you installing and running the VX2 plugin per the instructions on the download page?

    Yes post your two logs as attachments. But make sure you have follow the instructions below for installing and running HijackThis:


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. jf38081

    jf38081 Private E-2

    Thanks,
    You are right about the vx2 pluggin, i had not installed it correctly. Having corrected it, I ran it, and it came up clean.

    Here are the log files we spoke about. I had to change both extensions to .txt to get them uploaded. bitdefender.txt was origionally bitdefender.html

    In the HJT file, both 023 items that end with "(file missing)" are also persistent, and always come back no matter how often I deleted them. Hope this helps. Thank,
    Jim
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run CCleaner per the READ ME FIRST. If so, I would have expected the items in your Recycle Bin and temp folder to be cleaned up now. You can also manually empty your Recycle Bin and c:\windows\temp folder. Check with BitDefender again.

    You should not be attempting to have HJT fix O23 service entries. First services cannot be fixed that way. The first have to be stopped and disabled. And then the NT Service must be deleted. Second HJT has a bug that shows items to be missing when they are not. You do have two malware services we need to remove. I'll post a fix in my next message.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to Command Service (or if not found look for cmdService) ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now repeat the above for:
    .NET Framework Service ( or if not found look for .NET Connection Service)

    Next, go back to HJT and select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Command Service

    If that does not work try entering the short name: cmdService

    Now repeat the above for:
    .NET Framework Service ( or if not found look for .NET Connection Service)

    Now exit HJT but and reboot into normal mode. Post a new HJT log and tell me how things are working.
     
  6. jf38081

    jf38081 Private E-2

    Thanks for the help so far.

    I ran CCleaner and Bitdefender again. This time I didn't get to save the logfile. Bitdefender deleted CCleaner! (so I reinstalled it.)

    The 2 items we spoke about no longer appear in HJT, but I couldn't remove them the way you said to. They both appear in services.msc (startup disabled,) but when I try to remove the way you said, HJT kicks back an error that say "Service .Net Framework Service was not found in the registry, make sure you entered the short name of the service., vbExclamation" using the short name "cmdService" - I was able to remove that one. But I don't know the short name for .Net Frameword Service

    The trojan virus has not appeared again since I ran bitdefender again, however, aproposmedia is still coming up in microsoft antispy. I even tried to delete it by removing the registry keys, but it came right back again.

    Here is the latest hjt file. what do you think?
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The short name was given in my directions: .NET Connection Service
    Looks like it may be gone anyway but you can double check.

    Please run MS Antispyware in safe mode. If it does not fix the problem with aproposmedia , post the log from MS Antispyware or tell be exactly what and where it is finding it. I would bet it is a registry key.

    Also look to see if the below exist:
    C:\Program Files\SysAI\AproposPlugin.dll
    C:\Program Files\CxtPls\CxtPls.dll

    If so, delete the SysAI and CxtPls folders.
     
  8. jf38081

    jf38081 Private E-2

    Your right about the .Net Command Service.

    And you were also right about safe mode not removing the apropos.
    According to microsoft antispy - this is the location of the keys that keep reappearing:

    hKEY_Local_machine\software\APRPS
    hKEY_Local_machine\software\APRPS\clientPartnerId...

    (the capitalization errors are my own)

    If I follow that path in regedit, i can find:

    hKEY_Local_machine\software\APRPS\client

    with a Key named PartnerId of type REG_SZ and the data WB.VER2 even after running microsoft antispy.

    how does this keep getting back on there? The computer is running better than ever now. If the microsoft program didn't keep showing this, i would not be concerned at all. What do you think?

    Also, here is my most recent hjt log...
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not post a HijackThis log.

    Try the below!

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixit.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixit.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes
    If necessary, repeat it from safe mode.
     
  10. jf38081

    jf38081 Private E-2

    Thanks again, but it is still at the same place. As soon as I run ms antispy and remove aproposmedia, it is immediately right back. Actually, when I ran fixit.reg in safe mode, aproposmedia did not return until I went back to normal mode.

    Also, on a whim, I ran panda active scan online, and it found quite a bit more garbage that the others have missed - but it didn't get me an option to remove the junk. I will post the log.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's do two things:

    1) Download this trial version of Ewido Security Suite
    • Install ewido security suite
    • Launch ewido, there should be an icon on your desktop double-click it.
    • The program will have a window come up. One of the buttons on the left is to Update. Click the Update button.and then Start the Update. The update will start and a progress bar will show the updates being installed.
    • After it completes the update, click the Scanner button

    Now exit Ewido. Now print the below instructions or save them locally because I want you do have no browsers opened and also have no connection to the internet (unplug your cable) while doing the below.

    Okay, reboot into safe mode with no network support and follow the steps below. (If you have any problems at all trying to get into safe mode to complete these steps, just run them in normal boot mode and make sure you tell me when you come back.)

    Open up Ewido and do the following:

    • Click on Scanner
    • Then click Settings
    • Under What to Scan? Select Scan every file
    • Then click OK
    • Click on Complete System Scan and the scan will start.
    • Let the program scan the machine
    While the scan is in progress you will be prompted to clean files that are infected. Leave the defaults selections (to Remove and backup) and click OK. To save yourself some time, you can select Perform action with all infections and then click OK. With the option to scan every file, a lot of cookies will be removed.

    Once the scan has completed, there will be a button located on the bottom of the screen named Save report

    • Click Save report
    • Save the report to your desktop or anyplace you will be able to find it to upload here.
    2) run a full scan with MS Antispyware after booting in safe mode with no network support.

    Now Reboot into normal mode and reconnect to the internet.

    Come back here and post the Ewido Scan Report. Tell me what MS Antispyware found.
     
    Last edited: Sep 21, 2005
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  13. jf38081

    jf38081 Private E-2

    Hi

    Just wanted to let you know that the ewido tool didn't solve the problem either. I gave up and reformatted.

    Thanks again for all the help.

    Jim
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry to hear that you had to reformat. Did you try the Symantec tool first?
     
  15. jf38081

    jf38081 Private E-2

    I did not. I formatted before I saw it.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Too bad! I wonder if it works. Now that you reformatted, you need to make sure you get your system fully protected ASAP. See the below:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds