Please help disinfect me. - Logs attached!

Discussion in 'Malware Help (A Specialist Will Reply)' started by chrishammons, Nov 29, 2007.

  1. chrishammons

    chrishammons Private E-2

    Thanks for looking at my logs. I caught something nasty when surfing and downloaded something off a questionable site and ran it. It did nothing but infite seemingly endless popups and rouge malware removal software. I normally run Trend Micro PC-cillion Internet Security 2007 but for some reason had it disabled at the time!

    After following the READ & RUN ME FIRST my PC is tolerable but not clean. First a system tray iconstill warns me about malware and takes me to Virus Protect site whe clicked on. Mre serious many games and appilactions fail to load anymore. Age of Empires (yes the kids and I still play it) either gives a "Could not initialize graphics system. Make sure that your video card and driver arer compatible with DirectDraw" or "SetupENU.dll is not a valid Windows image" or"Unable to find the language specific dll". Company of Heroes gives an "application failed to initialize properly (0xC0000142)" as well as WordPad and Calculator! Notepad gives "applcation or DLL C:\WINDOWS\AppPatch\AcGenral.DLL is not a valid Windows image". Internet Explorer seems t be working *mostly*. Finally, Trend Micro warns of suppicios changes when it should not.

    Time to wipe my hard drive and reistall Windows? Let me know and thanks again.

    BTW: I followed READ & RUN ME FIRST but missed saving the AVG report.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    No! You just have a few infections like Vundo and Zlob.

    However ComboFix does not seem to have run properly. Please try running it again after booting in safe mode and see if a full log is produced. Let me know if ou get any error messages.

    Then boot back into normal mode and continue with the below.

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.



    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.




    Now also run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also make sure that you have attach both rapport.txt logs from SmitFraudFix.

    Make sure you tell me how things are working now!
     
  3. chrishammons

    chrishammons Private E-2

    Wow! Thanks for the quick response! I won't get to try your proceures till another night ... must sleep now :zzz
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just attach all of the new logs when you finish and don't forget to say how things are working afterwards.
     
  5. chrishammons

    chrishammons Private E-2

    ComboFix did not seem to complete in Safe Mode either. AutoScan stuck on "Completed Stage_8". I waited more than 30 minutes. atched is a zip of the log and .dat files.

    Also attached is log file from step 1 below.
     

    Attached Files:

  6. chrishammons

    chrishammons Private E-2

    Everthing is really S L O W to load. Sometimes they won't load without trying again. No error message is received usually. At least once I logged out of windows. Also my wallpper is gone and the clock date format is different.

    But at least things are loading at all now and no more warnings about malware in the systray! Is there more I can try?
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This should improve when we finish removing the rest of your malware. There is a lot remaining.

    The wallpaper change is due to the fixes that had to be made by SmitFraudFix. And the clock/date format is due to ComboFix not running properly. Normally it fixes this when it finishes.

    Now let's continue removing your malware but stopping a malware service.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to DomainService
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {01CD0B31-9154-45F2-9414-F5D64B74EAF6} - C:\WINDOWS\system32\fccawxw.dll
    O2 - BHO: {d109d8e4-c817-6139-de44-0af6d3db7260} - {0627bd3d-6fa0-44ed-9316-718c4e8d901d} - C:\WINDOWS\system32\csxonoar.dll
    O2 - BHO: (no name) - {969DD329-F8FB-4874-820C-71D4896DF9A6} - C:\WINDOWS\system32\awvvs.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [2c7f4b5a] rundll32.exe "C:\WINDOWS\system32\ebtknitq.dll",b
    O20 - Winlogon Notify: fccawxw - C:\WINDOWS\SYSTEM32\fccawxw.dll

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.


    Make sure you tell me how things are working now!
     
  8. chrishammons

    chrishammons Private E-2

    Thanks for the help thus far. Now that I have had a chance to use things for awhile I am sure we have some more cleaning to do. My browser seems to "take off" without me when browsing for one thing. Also many applications / games are very slow to load still if they ever load.

    Logs are attached.

    BTW: Happy Holidays!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you wait so long to complete instructions? Even a week is like infinity in the malware world. Waiting like this can result in complete reinfection and it could be a worse infection then when you started. Normally after just a weeks time, we requested that the READ & RUN ME procedure be started all over again because status may have changed completely. You MGlogs.zip file shows that it is from Dec 5th. You need to attach a current logs. Before doing this download and use the current version of MGtools from here: MGtools.exe
     
  10. chrishammons

    chrishammons Private E-2

    Sorry it took so long. Things have been crazy around here. Barely touched my PC the last two weeks. Anyway, new log is attached. I'll try to be more responsive!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you in the middle of doing Windows Updates while you ran the new MGtools? I see the below:


    C:\WINDOWS\SoftwareDistribution\Download\Install\WindowsXP-KB905474-ENU-x86.exe
    d:\af3c62fa3638484b5891a9d0081cf28c\update\update.exe
     
  12. chrishammons

    chrishammons Private E-2

    Yes, I was. Multitasking you know :)
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but for future reference, it is a very bad idea to install updates while you are infected and you still are.

    You need to disable Guest user account. This is a security risk.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    O2 - BHO: (no name) - {01CD0B31-9154-45F2-9414-F5D64B74EAF6} - C:\WINDOWS\system32\fccawxw.dll (file missing)
    O2 - BHO: {baa07e49-0172-213b-e264-d6f0fff966d5} - {5d669fff-0f6d-462e-b312-271094e70aab} - C:\WINDOWS\system32\fmbirosj.dll
    O2 - BHO: (no name) - {969DD329-F8FB-4874-820C-71D4896DF9A6} - C:\WINDOWS\system32\awvvs.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

    After clicking Fix, exit HJT.



    Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  14. chrishammons

    chrishammons Private E-2

    Guest account was off but there was an "ASP.NET" account which I deleted.

    Logs are attached.

    Things seem to be running "okay" but is too early to tell. I think there is still some spyware adware that flashes now and again.

    Again thanks for all the help ... and spend some quality time with the family next week :)
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not according to your log!

    You should not have deleted this. It is part of your Microsoft .NET Framework Software. You should only do what we ask you to do.

    You will have to be more specific and tell me exactly what you are referring too.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds