Malware remove - what point to reconnect to internet?

Discussion in 'Malware Help (A Specialist Will Reply)' started by GRJackson, Oct 25, 2007.

  1. GRJackson

    GRJackson Private E-2

    I am in the process of running the malware clean up and am following the instructions to the "T" however it is not clear exactly when to reconnect your internet connection.

    I am at the point of running Spybot and am about to immunize but to do so I assume I must be connected to the net.

    I apologize if this is too simple but considering the problems im experiencing and the scam and trojan.bayrob i'm experiencing, I want to do EXACTLY what I should. :eek:

    Please advise.
     
  2. GRJackson

    GRJackson Private E-2

    I apologize... I guess I've been too stressed and sitting in front of these screens entirely too long.

    I've made my way to the 'reconnect cable' section. (Took rereading a couple of times)

    I'll pay closer attn to the instructions and will post should i have further problems. Thanks.
     
  3. GRJackson

    GRJackson Private E-2

    Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    I've completed the steps located in the Read & Run Me First thread of the Malware Forum. PandaActive is still reporting over 600 spyware applications and is not running clean.

    I was involved in the ebay scam for a Jeep and was told the file that I opened - ThePictures.zip was infected with a form of Trojan.bayrob. (I KNEW better than to do this!)

    Any assistance would be greatly appreciated. Logs attached per instructions.

    Thanks so much!
    Gen
     

    Attached Files:

  4. GRJackson

    GRJackson Private E-2

    Completed "Read & Run Me First" - logs attached - Trojan? Pt 2 of 2

    The remaining attachments are attached hereto.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 2 of 2

    Welcome to Major Geeks!

    First a note. Don't worry about cookies. They are not problems. You can read what I mean by this in step 11 of this link: How to Protect yourself from malware!

    Please run the below.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach a new log from ShowNew. Also please describe what malware problems you are having while I continue to look thru all of your logs.
     
  6. GRJackson

    GRJackson Private E-2

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    I had also completed the steps listed under Sticky -E2Give removal because I've recently had problems with that application as well.

    I am including a copy of the Avenger scan. Please note, when I ran the Hijack app the lines references in the clean up procedure were not found.

    Thanks again!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    You need to complete what I requested in message # 3.
     
  8. GRJackson

    GRJackson Private E-2

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    OK, I ran the ATF file as requested and am attached the newfiles.txt log.

    As I mentioned, I opened a zip file which I shouldn't have that installed some sort of application that redirects ebay, carfax, escrow.com to phishing sites and compromises my ebay account so that it shows I have won an auction (the previously mentioned jeep).

    When I look at ebay from a computer that I didn't open that file, the jeep is not displayed, nor can you navigate to the site (the jeep auction id page).

    Scans are showing 1 rootkit in my system. Ad Aware goes as far as showing 15 infections then 'encounters an error and must close' without ever actually finishing.

    I ran through the read me steps twice because my system would lock up and the files would not be found on reboot.

    Sheesh -my attach files button is not enabled and not allowing me to attach a file (the newfiles.txt)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    Click Refresh a few times or also trying emptying your browser cache and then click refresh. Then try to attach again.
     
  10. GRJackson

    GRJackson Private E-2

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    That worked. Here is the newfiles.txt report.

    Thanks so much again for your time.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    Did you run ATF-Cleaner? I wondering why the below folder in not being cleaned up?

    C:\Documents and Settings\gjackson\Local Settings\Temp\

    Can you manually delete all files in this folder? Windows should only stop you from delete folders from the current date.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    Here are the next steps for you to continue with.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    Viewpoint Media Player <-- should have been uninstall in step 0 of the READ ME

    Also uninstall the CounterSpy trial program since we are finished with it now.

    Did you put the below settings in your hosts file? If so, are they really necessary?[quote]O1 - Hosts: 172.22.48.3 dev.medremit.com
    O1 - Hosts: 172.22.48.3 devmedring.medring.com
    O1 - Hosts: 172.22.47.23 qa.medremit.com
    O1 - Hosts: 172.22.47.23 qa.medring.com
    O1 - Hosts: 172.22.48.6 devintranet
    O1 - Hosts: 172.22.47.26 qaintranet
    O1 - Hosts: 172.22.48.212 demotest.remettra.com
    O1 - Hosts: 172.22.48.5 presentation2.remettra.com
    O1 - Hosts: 172.22.48.3 devmedring.medremit.com
    O1 - Hosts: 172.22.47.23 demo.medring.com
    O1 - Hosts: 172.18.94.3 www.medring.com
    O1 - Hosts: 66.55.41.154 demointranet
    O1 - Hosts: 66.55.41.152 demo.medremit.com (Remettra skinned site of medremit)
    O1 - Hosts: 66.55.41.152 acmedemo.medremit.com (skinned site for Acme Health providers)
    O1 - Hosts: 66.55.41.152 demo.medring.com[/quote]


    What is the below folder? Did you create this? If not, delete it.
    Code:
    "C:\"
    1SPYWA~1      Oct 25 2007              "1 SpywareCleanup"

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {53EAB302-52B2-B05F-7E9B-0ADE836DD569} - C:\WINDOWS\system32\lxgqco.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - Startup: PowerReg Scheduler V3.exe
    O15 - Trusted Zone: *.aflashcounter.com
    O16 - DPF: {07740CF1-1989-1872-4645-1F4C0B42436C} - http://85.255.114.166/1/rdgUS2516.exe
    O16 - DPF: {07EA967B-5796-0B7C-3AB2-00C53BEAD803} - http://85.255.114.166/1/rdgUS2516.exe
    O16 - DPF: {0C80B24A-92BE-4E81-49B5-2E2255017A10} - http://85.255.114.166/1/rdgUS2516.exe
    O16 - DPF: {22825EEB-9B41-6106-38E3-0EE564CB9DFC} - http://85.255.114.166/1/rdgUS2516.exe
    O16 - DPF: {29DB6EEE-ED07-7661-205E-1B7D7C6A5462} - http://85.255.114.166/1/rdgUS2516.exe
    O16 - DPF: {29DD4975-CFA6-2A41-F399-04CF247C8B3A} - http://85.255.114.166/1/rdgUS2516.exe
    O16 - DPF: {2D8B3D59-EB3E-03D9-6992-5D5B4A7D68D6} - http://85.255.114.166/1/rdgUS2516.exe
    O16 - DPF: {31D61BE3-8152-53AE-56F3-1C844E02E968} - http://85.255.114.166/1/rdgUS2516.exe
    O16 - DPF: {3A3B6E62-087B-5606-0B3F-37FA7A59ABBE} - http://85.255.114.166/1/rdgUS2516.exe
    O16 - DPF: {3F3743FA-B88E-1483-F58C-4D2A34126267} - http://85.255.114.166/1/rdgUS2516.exe
    O16 - DPF: {400429E4-BED4-472E-93BF-F85AB8565DFF} - http://www.terp17.com/ax/axo.cab
    O16 - DPF: {4AB34253-976F-1581-3481-73720A497D95} - http://85.255.114.166/1/rdgUS2516.exe
    O16 - DPF: {4AC75F7E-F456-4E48-0DA8-2E892F045A59} - http://85.255.114.166/1/rdgUS2516.exe
    O16 - DPF: {5AAFEADA-FF76-4024-2556-711D3EAC3A17} - http://85.255.114.166/1/rdgUS2516.exe
    O16 - DPF: {5CC0591C-19BE-23F1-E83C-2F8D4FFB6278} - http://85.255.114.166/1/rdgUS2516.exe
    O16 - DPF: {5E3100D2-4305-4B78-C1A6-5D383BED850D} - http://85.255.114.166/1/rdgUS2516.exe
    O16 - DPF: {6567C541-470E-46DA-0110-64BB1746576C} - http://85.255.114.166/1/rdgUS2516.exe
    O16 - DPF: {68AE3A5C-0709-7B71-DC62-3AD71315B6BE} - http://85.255.114.166/1/rdgUS2516.exe
    O16 - DPF: {6F75C08F-5505-7BB1-98D2-20773CAEBC5C} - http://85.255.114.166/1/rdgUS2516.exe

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run ATF-Cleaner again!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  13. GRJackson

    GRJackson Private E-2

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    Yes, I ran the ATF file from the link provided below. I'm unsure why it didn't delete the files.

    I manually deleted all of the files. There are no files in this directory now.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    Good! Continue with message # 10.
     
  15. GRJackson

    GRJackson Private E-2

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    the other system is rebooting from uninstalling Windows Messenger.

    I have a desktop.ini file opening in notepad (2 of them to be exact).
    says:

    [.ShellClassInfo]
    LocalizedResourceName=@SystemRoom%\system32\shell32.dll,-21787
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    What do you mean the other system? We should only be working on one PC in this thread.

    What PC is opening up desktop.ini files and when?
     
  17. GRJackson

    GRJackson Private E-2

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    Sorry for the confusion... I have 2 systems. My other system is rebooting from the requested uninstalls. We are working on only 1 system. I just want to make sure I don't miss any of your instructions.

    The desktop.ini files are opening on the system we've been working on - the one with the malware. It is rebooting now from uninstalling Counterspy as instructed.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    Okay! You don't need to post anything else until you finish everything I gave in message # 10.
     
  19. GRJackson

    GRJackson Private E-2

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    (Unsure how to quote)

    Yes, the 01 Host entries were manually added - they are no longer necessary.

    Yes, I did create the 1 SpywareCleaner folder based on the recommendation of not saving the files to the desktop or my document.
     
  20. GRJackson

    GRJackson Private E-2

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    I'm receiving quite a few error running Avenger. Invalid entries
     
  21. GRJackson

    GRJackson Private E-2

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    Completed the requested steps and attaching the files - 3 of 4 below.
     

    Attached Files:

  22. GRJackson

    GRJackson Private E-2

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    HJT Log 4 of 4
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    Okay than let's remove them.


    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
      [*]It will create a folder named HostsXpert in whatever folder you extract it to.
      [*]Run HostsXpert.exe by double clicking on it.
      [*]click the Make Writeable? button.
      [*]click Restore Microsoft's Hosts File and then click OK.
      [*]Click the X to exit the program
    Delete the below folder.
    C:\Documents and Settings\gjackson\Application Data\Sunbelt Software

    You did not tell me how things are working. Your logs are clean.
     
  24. GRJackson

    GRJackson Private E-2

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    Sorry for the delay. Everything appears to be running smoothly!

    Thanks for your help!
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Completed "Read & Run Me First" - logs attached - Trojan? Pt 1 of 2

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds