got bugs...can't shake 'em .... win32/polycrypt and others!

Discussion in 'Malware Help (A Specialist Will Reply)' started by asti, Dec 22, 2007.

  1. asti

    asti Private E-2

    my dear friend gave me her laptop, a vaio by sony, running winXP

    there's all kinds of stuff swimming about in here I have no idea how to get a grip on it!
    I have done:
    super anti-spyware, ATF cleaner, look-2-me destroyer, spy sweeper, AVG, combofx and spybot SD
    will attach logs of what I have....

    last run through of AVG shows stuff still here, living and causing havoc!

    I'm not a Geek...but can point & shoot where told.....( MY PC's are linux/linspire...out of the box...and have had no issues....7 + yrs now and running - naked as they say, with NO virus protection )
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please uninstall HJT as it will be properly installed when you do the following:

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. asti

    asti Private E-2

    OK, think I did everything on the list, new hjt log attached....
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry but you have not done what Tim asked you to do. No place in those instructions does it request a HijackThis log. Please follow the instrucions he gave to you and only attach the logs that are requested.
     
  5. asti

    asti Private E-2

    My fault,sorry.....have several logs on the same CD, meant to put up the mgtools log. will doso after work.....:eek:
     
  6. asti

    asti Private E-2

    I haven't done a procedure right, I can't find the MG log...sorry...will be back if I get it right

    Thanks and Happy Holidays
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need more than the MGlogs.zip file. You need to follow all steps in the READ & RUN ME and then attach the requested logs which are:

    - ComboFix
    - AVG AntiSpyware
    - MGlogs.zip
     
  8. asti

    asti Private E-2

    Previous anit-virus deleting

    Might be the wrong area for this, sorry if it is.......
    in going through the correct steps....there is previously used programs on here SpyBot S&D and Antivir XP with quarentee folders..(among others)...can I just delete all of these?

    Also, I went through the XP cleaning, and had to go through the using MGTools,
    do I need to delete the first install of MGTools and re-install it?
    It is not saving the Zip files AS MGLogs.zip
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Previous anit-virus deleting

    I assume this message is part of what you should be working on in your other thread here:

    http://forums.majorgeeks.com/showthread.php?t=146519

    Please remain in one thread. I will merge this back with our 1st thread.

    No you should not be "deleting" Spybot and Antivir. If you meant to say empty their quarantine's then yes you should empty their quarantines. Spybot calls it Recovery.

    If you already ran MGtools.exe, you don't need to run it again unless you have an old outdated version which I doubt. MGtools.exe is a self extracting installer and it automatically runs the scans that are part of MGtools. Once MGtools has been run the first time, subsequent new scans are obtained by double click on the below file:

    C:\MGtools\GetLogs.bat

    This .bat file will run all the scans and create a new C:\MGlogs.zip file. If you are not seeing the C:\MGlogs.zip file get created, you need to make sure that you are not getting any of the error messages described on the MGtools.exe download/instructions page.
     
  10. asti

    asti Private E-2

    Thanks for moving the thread, I wasn't sure, since it was related, in nature, yet wasn't.....in a way as well...
    I did mean the folders, thanks for clarifying that point, however, the spybot SD had been installed several years ago and wasn't used since 2004 so I did delete it, the antivir is outdated and wasn't functioning; just the firewall, thusly this laptop was surfing 'naked'
    I have removed all the programs I put on here, so to enable a fresh start off the directions here. ( this laptop is NOT connected to the internet at any point until it is safe to do so )
    I DID run into some trouble with the MGtools, I did get the error messages...but it continued to run anyway, everytime I checked the OK box to stop it, the cursur began to flicker again, and run....once it was finished...I then added the extra items per suggestion....and ran it again.....it is THIS point I am not sure about...if it is running FRESH or off of the old information.....so will start all over I think, might be easier.....?

    Thank you Very much.....Merry X-Mas!!!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then yes you can delete anything from the old programs since you are no longer using them.

    No this does not work properly this way.

    If you added the fixes, then you can just run the GetLogs.bat file that was mentioned. You do not need to reinstall using the MGtools.exe file. So at this point you still need to run ComboFix, AVG Antispyware and C:\MGtools\GetLogs.bat and then you need to attach the below logs:
    • C:\ComboFix.txt
    • AVG Antispyware log
    • C:\MGlogs.zip
     
  12. asti

    asti Private E-2

    This is the info thus far.....I am having an issue with Spybot S&D...but will report again later on that..... ( might be MY fault on the download )
     

    Attached Files:

  13. asti

    asti Private E-2

    OK, it wasn't my fault this time..... :D

    spybot S&D .....
    Server name or address could not be resolved...... apparently this laptop needs to online in order to get this downloaded?

    Is there an alternate source that I can burn a CD off of?

    Thanks!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some of your software appears to not be loading/running properly. AntiVir is one of them. It looks like someone remove some of the startups for it. You should uninstall it. Reboot. And then reinstall it.

    What is this Spruce program that I see installed? If you don't know then uninstall it.

    Did you set your start pages to be about:blank like the below shows? If not, add these two lines to the HijackThis fix below.
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Internet Explorer Assistant 1.0
    J2SE Runtime Environment 5.0 Update 10
    Java 2 Runtime Environment, SE v1.4.0_03

    Now let's fix what appears to be a Haxdoor Infection.

    Download haxfix.exe and save it to your desktop.
    • Double click on haxfix.exe to install haxfix. (standard installation path is c:\program Files\haxfix)
    • Checkmark "Create a desktop icon"
    • Click "Next"
    • When the installation is completed, make sure that the checkmark "Launch HaxFix" is placed
    • Click "Finish"
    A red "dos window" (dos box) will open with the below options:
    1. Make logfile
    2. Run auto fix
    3. Run manual fix
    E. Exit Haxfix
    • Select option 1. Make logfile by typing 1 and then pressing Enter
    • Haxfix will start scanning the computer. When it is finished a logfile will open: haxlog.txt > (c:\haxfix.txt)
    • Attach this logfile to your next message.
    Now run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O16 - DPF: {11B2C0D3-DFFB-11D3-9253-00500498D7E5} - http://reged.mshow.com/(j5xuqgiqtz510h55scqiyv55)/ShowSetup5.cab
    O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. This will create a new MGlogs.zip file. Now attach the below logs:
    • C:\haxfix.txt
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  15. asti

    asti Private E-2

    OK, working on your instructions, however, an issue:
    I can't uninstall the antivir program...it seems to be missing some sort of (uninstall) .dat file
    (and my humble apologies for not getting the whole name)

    and, even though It is 'disabled' of sorts, it appears to be active and is tossing up windows about letting the haxfix.exe work......but it went through the motions, log attached.......

    working on the Avenger now.....


    ( A bit of background on the owner of this laptop....knows nada about PC's and the desktop is cluttered with all kinds of stuff, pages saved, as she doesn't know how to make bookmarks...and uses IE to boot...I plan to "set things" up for her, but can't really afford to loose much that is ON this PC since her and hubby have business(s) related stuff on it....)
     

    Attached Files:

  16. asti

    asti Private E-2

    the missing .dat file is AVUNINST
    (cannot remove AntiVir from your hard drive)
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then just try reinstalling it from this: AntiVir Personal Edition 7

    Make sure you do not let it block the running of Haxfix.

    Run Haxfix again and this time select option 2: 2. Run auto fix

    Attach the new log from Haxfix
     
    Last edited: Dec 28, 2007
  18. asti

    asti Private E-2

    MGTools issue:
    the application failed to intialize properly (0xc0000135), click on OK to terminate...
    I did.....then, thought again, and went through it again, then I hit upon the X to shut the box down...and the process ended.....
    however...it DID say there was a log.....attached.....

    As is Avenger.....

    Behavior:
    Shut down time is about 80 (one thousandz) and reboot about 70 - 72 (one thousandz)
     

    Attached Files:

  19. asti

    asti Private E-2

    Wil tackle this completion tomorrow, as I have been up for WAY too many hours, and am seeing double right now, THANK you for your assistance!!
     
  20. asti

    asti Private E-2

    I went and located a program called unlocker and have removed the antivir from the laptop
    I have attached a fresh MGzip for review

    Thank you!
     

    Attached Files:

  21. asti

    asti Private E-2

    I got my hands on the Spybot S & D updater ( from MajorGeeks no less, LOL ) and am running it now.....
     
  22. asti

    asti Private E-2

    :confused

    Spybot is finished, 6 problems found...... 2 of which are : Virtumonde.crack and MalwareAlarm the other 4 have to deal with windows security center being disabled......
    I "fix checked" on the first two, and added the others to the excluded list
    shall I proceed with the steps on the Virtumonde aka Trojan Vundo Removal thread?

    There seems to be a bunch of items in the immunize area....is there a way to make a log of this?
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You never did what I requested in message number 17. Please complete those instructions.

    I'm not sure what you are trying to say about things being in Spybot's Immunnize area. This is normal. That is what the pupose of the Immunize feature is.


    Do not run VundoFix? It will not find anything. Spybot is probably just reporting some registry keys that for unknow reasons it cannot fix when they are always very easy to remove. Attach a log from Spybot if it is still showing problems? But did you try fixing them?


    Note: Your MGlogs.zip file is showing no problems.
     
  24. asti

    asti Private E-2

    Sorry, I forgot to add I DID run the Haxfix again, under option 2 and it said it found nothing, and went back to the initial screen......

    On Spybot, I did "fix" the Virtumonde.crack and MalwareAlarm, then went ahead and purged them...
    Spybot report (done today) " Congratulations! No immediate threats were found. "
    the speed of the loading / unloading of WinXP is about 30 - 35 seconds.....a bit longer shutting down.....

    Thank you..... Thank you!!!!

    :wave
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds fairly normal! In fact many people would be extremely happy if that is all theirs took.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds