still seem to have whataboutadog after read & run me

Discussion in 'Malware Help (A Specialist Will Reply)' started by markslade, Nov 26, 2007.

  1. markslade

    markslade Private E-2

    here are the logs. Guess I need to call trend and find out why this got on my machine!!!???
    Thanks
    Mark
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on what I see in your HJT log, we need you to run another tool and attach the log. You have a trojan named Downloader-BEW see http://vil.nai.com/vil/content/v_143361.htm


    Download and run FindAWF by noahdfear.
    • Please download FindAWF by noahdfear.
    • Save to your desktop.
    • Double-click the FindAWF icon.
      • If a Security Alert shows, allow the program to run.
    • As instructed, press any key to continue.
    • Use the following option: Press 1 then Enter to scan for bak folders
    • The scan may take a while, please be patient.
    • When done, a text file, Find AWF report is produced.
    • Please attach the Find AWF report in your next post.
     
  3. markslade

    markslade Private E-2

    awf report attached.....
     

    Attached Files:

    • awf.txt
      File size:
      3.8 KB
      Views:
      4
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First delete the below folder if found:
    C:\Program Files\Java\jre1.6.0_01

    Now Disable Spybot's TeaTimer
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!

    Now please download DelDomainsand unzip it to your desktop. Do not run it yet.
    • Find the files from deldomains.zip on your Desktop and RightClick on the deldomains.inf file and select Install.
    Next, we need to run FindAWF again.
    • Double-click the FindAWF icon.
      • If you receive any security alerts and/or warnings please allow the utility to run.
    • As instructed, press any key to continue.
    • Use the following option: Press 2 then Enter to restore files from bak folders
    • A text file opens called: files.txt
    • Click below the line and paste the following list of files to be restored:
    • Next, close and click Yes to save the changes.
    • Once files.txt is saved, FindAWF does the following:
      • It attempts to terminate the process represented by each filename on the list, if running
      • Deletes the rogue file from the parent folder, if present
      • Copies the original file to the parent folder
    • When done with the above, it automatically runs a new scan and opens a new log.
    • Please attach the new FindAWF log to your next message.
     
  5. markslade

    markslade Private E-2

    Deleted java folder....disabled tea timer(sorry...didn't realize it was on).....2nd AWF log attached...
    Mark
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note: The O15 lines I'm asking you to remove with HijackThis may no longer be there. The below is just a precaution.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\bak\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O15 - Trusted Zone: *.doginhispen.com
    O15 - Trusted Zone: *.whataboutadog.com

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  7. markslade

    markslade Private E-2

    all steps completed. Trend Micro is still showing it blocked an attempted contact at qksz.net.....but the last time that occured was 12:40 this afternoon....nothing since.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your logs you are clean. Are you still having problems?

    Did the fixME.reg patch add into the registry successfully? Did you receive a success message? Try again if unsure.

    Also do the below.

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
      [*]It will create a folder named HostsXpert in whatever folder you extract it to.
      [*]Run HostsXpert.exe by double clicking on it.
      [*]click the Make Writeable? button.
      [*]click Restore Microsoft's Hosts File and then click OK.
      [*]Click the X to exit the program
     
  9. markslade

    markslade Private E-2

    I believe all is well. Trend hasn't reported anymore attempts to log onto the qksz site.....or the other ones. I couldn't remember if I received the message for the reg fix....so I ran it....got the success message.
    Will try your last instructions in the am.
    You guys really need to take donations for the work you do!!!
    Many Thanks
    Mark
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  11. markslade

    markslade Private E-2

    OK...all steps completed. About 20 minites ago Trend stopped an attempt to connect to that site again...qksz.net. This was before I completed the last steps. Will watch and see.....
    Thanks
    Mark
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That site is not consider a problem. See this: http://www.siteadvisor.com/sites/qksz.net
     
  13. markslade

    markslade Private E-2

    Thanks...I did a search after my last post and read a bunch about it. Funny....apparantly Trend uses CJ for their ads!!
    Thanks again!!
    Mark
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds