More Unidentified Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by HastyLumbago, Jul 31, 2007.

  1. HastyLumbago

    HastyLumbago Private E-2

    NOTE: THIS IS ANOTHER CLIENT COMPUTER. THIS IS NOT A SECONDARY THREAD FOR THE FIRST ONE

    OK, once again, here I am. This one has some sort of infection which is attempting to send thousands of mails. Only once in a while, and pretty close to unstoppably once it's connected to the internet and decides it wants to start.

    I've run adaware, spybot, and avast, and my boss went ahead and connected it to the network to run Housecall on it.

    logs incoming
     

    Attached Files:

  2. HastyLumbago

    HastyLumbago Private E-2

    final log. I'm told that housecall found 2 low-threat trojans, but was not present for the scan, and have since disconnected the desktop to prevent cross-contamination.
     

    Attached Files:

    Last edited: Jul 31, 2007
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please reset msconfig to normal startup!

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 11"
    J2SE Runtime Environment 5.0 Update 9
    Norton AntiVirus 2003 or avast! Antivirus --- do not run two anti-virus programs. Choose one and uninstall the other.
    Sunbelt CounterSpy
    Zango Browser and Wowpapers Tools


    Please find and delete:
    C:\Documents and Settings\All Users\Application Data\ZangoSA
    C:\
    xmscfg.txt
    xrkey00.txt
    xrkey01.txt
    xrkey02.txt
    xrkey05.txt
    xrkey06.txt
    xrkey07.txt
    xrkey10.txt
    xrkey12.txt
    xrnotif.txt
    xrquery.txt
    xrquery2.txt

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now download and run Blacklight

    Now attach new logs for:
    ShowNew
    GetRun
    Blacklight log
     
  4. HastyLumbago

    HastyLumbago Private E-2

    I'm not seeing those text files anywhere, let alone in plain sight in C:\

    any hints as to where they might be? a full search didn't find them either.


    EDIT: Wait a minute. Those look familiar. Are those text files generated during the run of GetRunKey? Are they gone now that I've closed it down?
     
    Last edited: Aug 2, 2007
  5. HastyLumbago

    HastyLumbago Private E-2

    OK, I'm assuming those are getrunkey files, partially because I rerean it as suggested, and I new see that several of them are referenced during the process.
    Am I to assume therefore that getrunkey and shownew are not to be run at the same time?
    In any case, here are the requested logs... green?
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Direct quote from the READ & RUN ME step 6
    I'll be back later to take a look at your logs.
     
  7. HastyLumbago

    HastyLumbago Private E-2

    Kay, thank you. But there's nothing there to suggest the names of those files, although it does basically say not to run the two simultaneously. I have to admit that I kinda jumped into the thing without reading the documentation too closely.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you do the registry patch that I provided in post #3 ?
    Or the program removals?
     
  9. HastyLumbago

    HastyLumbago Private E-2

    Yes, of course. Wouldn't post the logs if I hadn't done the work. Why?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Because it didn't take ....

    Please download and run Chodefix.

    After running, please attach new logs for:
    Chode
    Shownew
    GetRun
    HJT
     
  11. HastyLumbago

    HastyLumbago Private E-2

    OK... here are the three logs which I can find. Where's the one for Chodefix generated?

    Incidentally, the command line output from chodefix was verbatim what was quoted in the How To by chaslang
     

    Attached Files:

    Last edited: Aug 3, 2007
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    1. Download this file - Combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    What is this:
    C:\longcat

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt
    Attach new logs for:
    Avenger
    ComboFix
    HJT
    GetRUn
    ShowNew
     
  13. HastyLumbago

    HastyLumbago Private E-2

    That's an easy to remember folder to toss things into that isn't in Docs and Settings. It's where I put all the misc tools I play with while I'm screwing around with a client's computer. Keeps me from having to hunt all over for things that don't have uninstall entries.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    LOL ....good name!

    Do the rest and post the logs.:)
     
  15. HastyLumbago

    HastyLumbago Private E-2

    ARGH! So no more on that computer. My boss decided that since I had followed removal instructions,(we log the steps we take on each compy) that reposting logs was a courtesy, and that the computer was ready to be released to the client.

    He wouldn't listen when I told him that there were still infections, and said that the visible behavior was gone. crappy standards.

    Anyways, thanks for the help.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually reposting the logs is not a courtesy. It is a necessity to make sure that things were actually cleaned up.

    In the future if your boss does not want you to follow the instructions that we post (and that includes running the Online Scanners which are a necessity too) then you will have to fix these PCs on your own. After all why should we help you do something for free when you are getting paid to do it to begin with especially when you or your boss do not want to follow our instructions.
     
  17. HastyLumbago

    HastyLumbago Private E-2

    No, I agree.

    Thing is, malware isn't in my job description, but I don't have time to look for new work (I'm moving at the end of the month), and I don't want to do a substandard job.

    I've been tossed onto malware detail when I'm a hardware and networking technician. Part of my participation in this forum, however, has to do with the fact that I feel I should be a malware specialist. Actually, I feel just about everyone dealing with personal computers should be a malware specialist. The world of computer usage has gotten more and more [insert word that works kinda like perilous, but has none of the implications of risk to personal life or limb], and the people who work with computers, I think are going to become less and less employable if they don't adapt.

    So I'm trying to learn. It's a shallow curve, right up to where just running programs doesn't fix it, then it's one heck of a steep climb, especially for the self-taught. I understand that you guys aren't getting paid for this, (and incidentally, if there's a pay pal link around here, just point me at it, because you guys are great) and that you don't want to be doing my job for me. But how am I to learn this? I can't post in someone else's thread, presumably because I'm not tried and tested to be helpful with suggestions, so I can't ask questions anywhere but in my own, and since you don't want me to be posting work computers... I mean, I guess I could intentionally infect my home PC, but something makes me think that would be ill-recieved by both you and my fiance.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I understand what you are saying and I also realize your perspective is different from your boss's. However that does not change the fact that your boss and your company are getting paid for fixing the PCs and we are doing all the work. If your boss wants to use this site to do that, it's okay! But at least he should be sure to allow you to follow ALL of our directions and that includes the online scans (which you have not been running) and then also completing all follow ups. Otherwise why are we bothering to do this when it is contrary to our goals of removing all malware.

    By reading the threads and learning how to recognize problems and the procedures used to remove them.

    Yes that's by design because too many people do not know what they are doing and were giving bad advice (some very bad).

    You can ask as many questions as you want in threads that you start and we will answer them as best as time allows. Non-malware questions should be asked in one of the other tech forums. You need to start posting other useful technical posts to help others in the other forums too. This will demonstrate your knowledge, background, posting styles, the amount of time that you are willing to spend here helping, and will get you even more experince which will help to get you ready to post in the Malware Forum in the future. It is not out of the question that you could not do this. You just need to learn some more first (by your own admission). And then we will help you learn the rest. :)

    That's not what I really was saying. While we really appreciate doing the work and having someone else get paid for it, we do request cooperation and that all of our instructions be followed. That is the price for our freely supplied support.

    Get a spare cheapy PC to play with. ;) We all experiment that way ourselves. I have multiple PCs running all versions of every Windows OS except Vista right now. I don't have a spare PC with enough horse power on it to run Vista. I have 4 PCs that could run it, but I'm not willing to convert any of them to Vista.

    Sometimes the most difficult thing is to get the infections that people have. It is often more difficult to get an exact infection than it is to actually remove it. It is actually pretty amazing how people pick up all the garbage and then they say they don't know how they got it. I find that to be very unlikely since I can even try to get infected and not pickup much of what people get. Too much porn, too much P2P and torrent download, too much illegal cracked software or keygen software....etc are the most likely causes and I tend to doubt that you would not know when this stuff is being used or when those kind of sites are being accessed.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds