Trojans--adoginhispen, bskitoday

Discussion in 'Malware Help (A Specialist Will Reply)' started by hockeymom18, Feb 13, 2008.

  1. hockeymom18

    hockeymom18 Private E-2

    It appears my son has these on his PC, bad things is I didn't know that until tonight and backed up his PC to an external drive last weekend (PC was making a loud noise and sounded like hardware failure was coming). Attached is log from Find AWF. Any help removing would be appreciated.

    Running Windows XP service pack 2, IE 6.0, and Norton.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Most people who have these problems have other issues too. So please run the below so we can work up a complete fix.

    Question: Why do you have all those backup folders for Logmein? Do you need them? It is confusing the results from FindAWF.
    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. hockeymom18

    hockeymom18 Private E-2

    I have no idea why all the folders for Log Me In, last night when I ran that scan was the first time I had seen them. I know that recently Norton has been saying that Log Me In is a trojan on his PC, yet I don't have that problem with other PC's I run it on that also have Norton.

    I am working through the process you sent me, will post logs when I have them. Should be later today as I'm taking the PC to work with me to work on it.
     
  4. hockeymom18

    hockeymom18 Private E-2

    I ran the tools that you suggested and everything seems to be working much better, but could you please check the logs to make sure I have gotten rid of everything.

    Thanks so much!!!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Would it be a major problem to uninstall LogMeIn on this PC for now while we clean this up? And then you can reinstall we finish the clean up. It may simplify our cleaning steps and in additon, it is quite possible (as Norton states) that it is infected anyway.
    • Please download FindAWF.exe by noahdfear.
    • Save to your desktop.
    • Double-click the FindAWF icon.
      • If a Security Alert shows, allow the program to run.
    • As instructed, press any key to continue.
    • Use the following option: Press 2 then Enter to restore files from bak folders
    • A text file opens called: files.txt
    • Click below the line and paste the following list of files to be restored:
    • Next, close and click Yes to save the changes.
    • Once files.txt is saved, FindAWF does the following:
      • It attempts to terminate the process represented by each filename on the list, if running
      • Deletes the rogue file from the parent folder, if present
      • Copies the original file to the parent folder
    • When done with the above, it automatically runs a new scan and opens a new log.
    • Please attach the new FindAWF log to your next message.
    Uninstall the below software:
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 0 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/chuzzle/popcaploader_v6.cab

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    File::
    C:\WINDOWS\Downloaded Program Files\CpnMgr.dll
    C:\WINDOWS\Downloaded Program Files\CpnMgr.inf
    C:\Program Files\iTunes\iTunesHelper.exe3473239928
     
    Folder::
    C:\Program Files\Java\jre1.5.0_06
    C:\Program Files\AIM6\bak\aim6.exe
     
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "WinLoad"=-
    "Winload32"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    • also the log from FindAWF
    Make sure you tell me how things are working now!
     
  6. hockeymom18

    hockeymom18 Private E-2

    Sorry for the delayed reply, I had left the PC at work over the weekend. Ran all the things you advised this morning and things seem to be running good with it. You may notice in the logs that Norton is not listed, I removed the old version and will be reinstalling with version 10.2 as soon as I finish this message.

    Please let me know if there is anything else I need to clean-up. Thanks for all your help!! Just to let you know I keep system restore turned off on all my machines (I notice you tell people to toggle the system restore).
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Many of the things we were trying to fix did not get properly fixed. I'm not sure why. Perhaps Norton was getting in the way. Anyway we will try fixing things again but we will use some other methods this time. Also please answer a question. Do you know how to copy files from one folder into another folder? I may need to have you do this later.

    Please shut down all protection software as best as possible so we can avoid issues with it blocking the below fixes.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Double-click the FindAWF icon.
    • If a Security Alert shows, allow the program to run.
    • As instructed, press any key to continue.
    • Use the following option: Press 2 then Enter to restore files from bak folders
    • A text file opens called: files.txt
    • Click below the line and paste the following list of files to be restored:

    • Next, close and click Yes to save the changes.
    • Once files.txt is saved, FindAWF does the following:
      • It attempts to terminate the process represented by each filename on the list, if running
      • Deletes the rogue file from the parent folder, if present
      • Copies the original file to the parent folder
    • When done with the above, it automatically runs a new scan and opens a new log.
    • Please attach the new FindAWF log to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    • also the log from FindAWF
    Make sure you tell me how things are working now!
     
  8. hockeymom18

    hockeymom18 Private E-2

    Thanks again, I followed your instructions and ran the other program. I have attached the logs. Things seem to be running good. Please let me know if there is anything else I need to do.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry but I left out some quotes around files names in the procedure for FindAWF and it did not work properly because of this. Please do the below steps again where I now included the quotes.

    Double-click the FindAWF icon.
    • If a Security Alert shows, allow the program to run.
    • As instructed, press any key to continue.
    • Use the following option: Press 2 then Enter to restore files from bak folders
    • A text file opens called: files.txt
    • Click below the line and paste the following list of files to be restored:

    • Next, close and click Yes to save the changes.
    • Once files.txt is saved, FindAWF does the following:
      • It attempts to terminate the process represented by each filename on the list, if running
      • Deletes the rogue file from the parent folder, if present
      • Copies the original file to the parent folder
    • When done with the above, it automatically runs a new scan and opens a new log.
    • Please attach the new FindAWF log to your next message.

    Now run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines (some may already be gone) but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
    O15 - Trusted Zone: *.doginhispen.com
    O15 - Trusted Zone: *.whataboutadog.com
    O15 - Trusted Zone: *.whataboutarabit.com
    O18 - Protocol: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} - D:\CDS300\__CDS2.dll (file missing)
    O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Michele/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

    After clicking Fix, exit HJT.

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\MGlogs.zip
    • also the log from FindAWF
    Make sure you tell me how things are working now!
     
  10. hockeymom18

    hockeymom18 Private E-2

    Hi I ran the things you said again, the logs are attached.

    The only things I currently see that are odd is on boot the Windows logo is not in the middle of the screen (this started after the very first set of instructins) and is not a huge deal. The second thing is it seems really slow on boot-up, this could be becasue my son has TONS of videos and pictures on his comptuer as he uses it to make skateboard videos.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We have a little more to do. The issues with speed are most likely due to what you are running.

    Run avenger.exe by double-clicking on it.
    Check the 'Input script manually' box.
    Click on the magnifying glass icon.
    Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Michele\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\MGlogs.zip
    • also the log from FindAWF
    Make sure you tell me how things are working now!
     
  12. hockeymom18

    hockeymom18 Private E-2

    Sorry for the delayed reply, I have been very busy at work and this was the first chance I had to get back to his PC.

    I did the steps you told me too and have attached the logs. Everything seems to be working okay. Please advise if there is anything else I need to do.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds