Help... I am back, and not for a good cause

Discussion in 'Malware Help (A Specialist Will Reply)' started by ishani, Dec 24, 2007.

  1. ishani

    ishani Private E-2

    As per the instructions, i post my thread and attach the files.
    1 - I have a virus that keeps popping in the AVG, cannot stop it even if healing the threat
    2 - Explorer windows get stuck
    3 - It took me 5 hours just to run through your simple and well explained steps, had many problems with spybot, and the scan took 2hrs...
    4 - In AVG, though I clicked "Automatically generate report..." etc. When the scan finished and all viruses quarantined, I cannot see any reports. so pls tell me how to solve this problem if you need the avg report
    5 - Please try to reply quick. It is 1:30 am here and I will stay up all night if I need, but I must fix the problem

    Thank you, thank you. Thank you!!!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have follow ALL of the instructions from the How to protect yourself link last time you were here. It may have helped you to avoid this VERY VERY BAD infection.

    Start by disabling the Guest user account which is a security risk and opens the door for intruders.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 2


    I'll be post the rest of the fix soon.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay here is the rest of the fix. As you will see, your PC is a mess!!!!



    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes. Also if you see any other similarly named processes beginning with k119 and ending with .exe then kill them too.

    C:\WINDOWS\system32\k11985026359.exe
    C:\WINDOWS\system32\k11985032589.exe
    C:\WINDOWS\system32\k11985037129.exe
    C:\WINDOWS\system32\k11985042002.exe
    C:\WINDOWS\system32\k11985044139.exe
    C:\WINDOWS\system32\k11985052969.exe
    C:\WINDOWS\system32\k11985057659.exe
    C:\WINDOWS\system32\k11985072169.exe
    C:\WINDOWS\system32\k11985074589.exe
    C:\WINDOWS\system32\k11985081619.exe
    C:\WINDOWS\system32\k11985093389.exe
    C:\WINDOWS\system32\k11985095669.exe
    C:\WINDOWS\system32\k11985098009.exe
    C:\WINDOWS\system32\k11985102609.exe
    C:\WINDOWS\system32\k11985104889.exe
    C:\WINDOWS\system32\k11985117639.exe
    C:\WINDOWS\system32\k11985124369.exe
    C:\WINDOWS\system32\k11985135709.exe
    C:\WINDOWS\system32\k11985138009.exe
    C:\WINDOWS\system32\k119851499916.exe
    C:\WINDOWS\system32\k119851566916.exe
    C:\WINDOWS\system32\k119851588416.exe
    C:\WINDOWS\system32\k119851610516.exe
    C:\WINDOWS\system32\k11985163118.exe
    C:\WINDOWS\system32\k119851631612.exe


    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SSLDyn] C:\WINDOWS\SSLDyn.exe
    O4 - HKLM\..\Run: [WINSvr32] C:\WINDOWS\WINSvr32.exE
    O4 - HKLM\..\Run: [AVPSrv] C:\WINDOWS\AVPSrv.exE
    O4 - HKLM\..\Run: [upxdnd] C:\WINDOWS\upxdnd.exe
    O4 - HKLM\..\Run: [msccrt] C:\WINDOWS\msccrt.exe
    O4 - HKLM\..\Run: [MsIMMs32] C:\WINDOWS\MsIMMs32.exE
    O4 - HKLM\..\Run: [cmdbcs] C:\WINDOWS\cmdbcs.exe
    O4 - HKLM\..\Run: [Kvsc3] C:\WINDOWS\Kvsc3.exE
    O4 - HKLM\..\Run: [NAVMon32] C:\WINDOWS\NAVMon32.exE
    O4 - HKLM\..\Run: [MsPrint32D] C:\WINDOWS\MsPrint32D.exe
    O4 - HKLM\..\Run: [mppds] C:\WINDOWS\mppds.exe
    O4 - HKLM\..\Run: [PTSShell] C:\WINDOWS\PTSShell.exe
    O4 - HKLM\..\Run: [NVDispDrv] C:\WINDOWS\NVDispDRV.EXE

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  4. ishani

    ishani Private E-2

    Hi!
    1 - In the C:\MGtools\analyse.exe - process manager : I could not find all the files you mentioned, only some, but when I killed one, popped a few more, and if I kill more, others disappeared
    2 - In the avenger, I could not fit all the list, and had to compromise on 3/4 of it. I didnt want to do again for the ones that didnt fit, as I didnt know how, without damaging the report for you
    3 - I rebooted after that
    4 - I didnt install the new Java as I did not complete the tasks according to your instructions, so I need to know what to do
    5 - I closed the computer and writing this from another one as the avg keeps prompting and healing more of these k119....exe but now they seem to be in avenger (I mean their path comes from c:Avenger/....k119...exe Something like that)
    Waiting for further instructions
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you don't get all of the files into the Avenger fix at one time, the fix will not work.

    Let's just try something different.

    • Boot into safe mode and run Windows Explorer.
    • Goto the C:\WINDOWS\system32\ folder and delete all of the files beginning with k119 and ending with .exe yourself.
    • If any of them say they are running, use the process manager of analyse.exe (HijackThis) like in my last message to kill them all. Try selecting all k119 type processes at once time and killing them.
    • Also delete the below files while in safe mode:
      • C:\WINDOWS\system32\LotusHlp.dll
      • C:\WINDOWS\system32\drivers\daefalat.sys
      • C:\WINDOWS\system32\drivers\ivwrujbt.sys
      • C:\WINDOWS\bcfomu.exe
      • C:\WINDOWS\cnslpb.exe
      • C:\WINDOWS\fzdmlq.exe
      • C:\WINDOWS\"jotgpr.exe
      • C:\WINDOWS\jqeqwz.exe
      • C:\WINDOWS\LotusHlp.exe
      • C:\WINDOWS\orjchj.exe
      • C:\WINDOWS\pinvyf.exe
      • C:\WINDOWS\tlugdt.exe
      • C:\WINDOWS\vtbbqa.exe
    Then boot into normal mode and tell me what happened. Also attach a new MGlogs.zip file from running GetLogs.bat again.
     
  6. ishani

    ishani Private E-2

    OK, done your last post instructions.
    When in Safe mode, I dont have the problem of the trojan jumping everytime in AVG. Actually now in normal mode the threat window is stuck as well, usually it countdowns 30 seconds before it heals and prompts for another one.
    Tell me how to proceed, I leave the computer on this time.

    Thanks
    Ishay
     

    Attached Files:

  7. ishani

    ishani Private E-2

    Let me know how to proceed please, thank you!
     
  8. ishani

    ishani Private E-2

    Hi, please let me know how to proceed
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to read the stickies, especially this one: Don't Bump! It Only Hurts You!!!

    These unnecessary messages cost you 16 hours of additional waiting time.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now let's remove a rogue service.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to C0489BF1
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [ciyugxee] C:\bslbjkmv.bat
    O4 - HKLM\..\Run: [uahlgbhv] C:\ffowcmsp.bat
    O23 - Service: C0489BF1 - Unknown owner - C:\WINDOWS\system32\1CF1AF35.EXE (file missing)

    After clicking Fix, exit HJT.


    Now delete the below files if found:
    C:\Documents and Settings\meital shani\My Documents\$ap3c.tmp
    C:\Documents and Settings\meital shani\Local Settings\Temp\is-2LO8R.tmp
    C:\bslbjkmv.bat
    C:\ffowcmsp.bat
    C:\WINDOWS\system32\1CF1AF35.EXE
    C:\WINDOWS\LotusHlp.exe
    C:\avenger.txt
    C:\ComboFix.txt

    What is the below file? If unknown, then delete it too.
    C:\Documents and Settings\meital shani\Desktop\m.xls

    Now delete the below folders:
    C:\Documents and Settings\meital shani\Desktop\AVENGER
    C:\Avenger
    C:\ComboFix
    C:\qoobox

    Now reboot.

    After reboot, run Ccleaner!

    NOW run MSconfig and put your system into Normal Startup mode as requested in the READ ME.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.

    Make sure you tell me how things are working now!
     
  11. ishani

    ishani Private E-2

    Ok , done.
    1 -In C0489BF1, it was already disabled, so I just stopped it
    2 - I didnt find O23 - Service: C0489BF1 - Unknown owner - C:\WINDOWS\system32\1CF1AF35.EXE (file missing)
    Maybe it has to do something with me running avg prior to receiving your instructions
    3 - I dont see any prompts from avg in the past few hours as before

    Thanks and sorry for the reposts... Will not happen again
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  13. ishani

    ishani Private E-2

    Thank you very much!
    * Could you tell me that you see for sure if also drives D and E were cleaned?

    * When I had the problem started 2 days ago, I immediately backed up the files and disconnected an external hard drive which I had connected. Later I connected the ext HD to another computer and while trying to access it I ran into the virus again...!!!! It seemed not as bad as the other computer and I think it was cleaned, I attach a log for you to tell me please if I am ok here. (Again, these attachments is for the second computer connected to an external HDD which was in the 1st computer which you were helping me the past 2 days)

    I have some questions about which softwares you recommend me to buy and if it is better to buy than use the free ones, but let me first make sure that I am clean..

    Thanks
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those logs are not going to tell me anything about drives D and E. They are primarily scans of drive C only.

    If you backed up your PC while it was infected, then whatever you backed up may well be infected. This is no different then why we toggle System Restore after cleaning. We do this to remove possible infected restore points so that you cannot restore malware by using an infected restore point. Since your backups may contain infections, they cannot be trusted.

    Are the logs you attached from the same PC we just cleaned? Or are they from another computer? I was not sure from your message but it looks like this is another PC? If so you should have begun a new thread for the new PC and you should have run ALL of the READ & RUN ME. You are running MSconfig to control startups so I cannot properly evaluate your logs. You must do all of the READ ME and start a new thread and attach all of the requested logs. Note: I do see a Lovegate Trojan.
     
  15. ishani

    ishani Private E-2

    Ok, thanks.
    So lets concentrate on the original computer.
    If I need, I will contact you regarding teh other computer throught a new thread.

    Do you recommend me to buy the the avg antispyware which I installed as trial?

    I never installed the Java new sofftware, should I do it now?

    Thanks

    Ishay
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you like it, yes you can purchase it. It is a good program. Or you can just use free tools.

    Yes.



    Remember your other PC does appear to be infected and also on this other PC you need to uninstall AVG Antispyware and get it installed properly. You must install programs in their proper default folders which is normally under C:\Program Files. You current have it installed like this:

    C:\Documents and Settings\Administrator\My Documents\AVG Anti-Spyware 7.5\avgas.exe

    This is a very bad idea. It is a program not a document and installing it this way makes it look suspiciously like malware trying to pose as the real application. In addition, no one else on the PC can properly access the program because it is install only where the Administrator user account can access it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds