Stupid Obfustat and Generic Virus.

Discussion in 'Malware Help (A Specialist Will Reply)' started by aliengod, Nov 23, 2007.

  1. aliengod

    aliengod Private E-2

    Hi! This site has been so awesome. I just followed the malware guide upto step 7 and am not seeing any signs of irritation from my pc. It started off as an annoying taskbar popup that kept telling me to install the liveone scanner or w/e and interfered with full screen applications by appearing. It isnt there now after an avg virus scan, but I can still tell there is a tiny bit of lag when i start my pc. (maybe 5-6 seconds, but I've been using this pc quite heavily and know if something is wrong.)

    After the last scan with panda, it fixed 2 viruses of the 2 viruses found, but it seems like there is no end to the virus #s. I'm sure if i run a scan with something else, I will encounter yet another. I had the obfustat (annoying popup) first, and then while running the one before panda scan, I saw there was a Generic.32 virus as well. I usually use Zonealarm pro and avast pro, but now i got rid of avast pro and use avg antivirus and antispyware. I still have the other applications (CCleaner, etc) just in case.

    I use this pc for my university work so the quicker I solve any problem from getting worse, the better.

    Thank you for such a great site by the way!
     
  2. aliengod

    aliengod Private E-2

    These are the scans bdscan.txt and activescan.txt, along with my runkeys.txt and the newfiles.txt.
     

    Attached Files:

  3. aliengod

    aliengod Private E-2

    The runkeys.txt couldnt be attached so here it is.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the logs from CounterSpy and HijackThis from step 7.

    Also you need to do the below.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.1_02

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
     
  5. aliengod

    aliengod Private E-2

    these are the two log files u requested
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the CounterSpy trial program now since we are finished with it.

    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.1_02
    LiveUpdate 3.1 (Symantec Corporation)
    LiveUpdate Notice (Symantec Corporation)


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O1 - Hosts: 66.98.148.65 auto.search.msn.com
    O1 - Hosts: 66.98.148.65 auto.search.msn.es
    O2 - BHO: {c09b28ef-415d-f838-7424-470a5f0e2ed0} - {0de2e0f5-a074-4247-838f-d514fe82b90c} - (no file)
    O2 - BHO: (no name) - {4A54500A-65FE-4F4A-B860-20EAE2F577F9} - (no file)
    O2 - BHO: (no name) - {53514640-5E9E-4B8E-A81B-AD95FCB0E52E} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {CF8E87B7-9F8C-4D2A-A2D8-2ADFE32072A1} - (no file)
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O20 - AppInit_DLLs:
    O20 - Winlogon Notify: awtroon - awtroon.dll (file missing)
    O20 - Winlogon Notify: hvktaqhu - hvktaqhu.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!
     
  7. aliengod

    aliengod Private E-2

    I haven't done these last steps you messaged me about, but my computer is fine so far. I have no more problems but will bookmark your reply if I should need it.

    It's just that we have a lot of work due this upcoming week and then exams start. Thankyou for all your help.

    Roger
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to do them immediately. You computer is still infected whether you see signs of it or not. The longer you wait the better the likelyhood that you will become reinfected from one of those files and the next infection could be worse as they mutate and spread overtime.
     
  9. aliengod

    aliengod Private E-2

    I ran everything but did encounter an error running the fix from hijackthis. It had an error with these two lines. It might be because I had installed sunjava when you first suggested it.

    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
     

    Attached Files:

  10. aliengod

    aliengod Private E-2

    here is the remaining log.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your logs you did not follow the steps properly. Your HJT log still shows everything that I asked you to fix. Did you get the log where it was requested?? That is at the end of the procedure. Or did you get it when you ran HijackThis to do the fix which would be the wrong time. Based on the time in your HJT log it appears that you did get the log when you were not suppose to. You need a log from after doing the fix. Also you must not run ShowNew while GetRunKey is still open showing the runkeys.txt log. You must finish GetRunKey and close the notepad window with runkeys.txt in it before running ShowNew.

    Attach a new HijackThis log so I can determine your true status.
     
  12. aliengod

    aliengod Private E-2

    yup you're right. I attached the log from before the scan. Here is the log afterwards.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds