Ultimate Cleaner Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by dalan, Feb 24, 2008.

  1. dalan

    dalan Private E-2

    Hello,

    A couple of days ago I got infected with the malware "Ultimate Defender". I kept getting a ton of popups telling me I had a virus, trojan, etc. I knew it was a phony virus but that didn't help me much in fixing the problem. The malware even shut down Task Manager so I was unable to stop several of the processes the malware was causing to run.

    After messing with my computer for several hours (and I mean several), I found three files in the C:\Windows directory that shouldn't be there:
    1. fsxloqf.exe
    2. admgcx.dll
    3. bdmanager.dll

    Instead of deleting the files I renamed them. After renaming them and running gpedit.msc to get Task Manager working again my computer seemed to be OK. I ran HijackThis and "fixed" two entries that had to do with the .dll files (admgcx.dll and bdmanager.dll) - both 021. Since I'm not real familiar with HijackThis I probably should have left things alone.

    The next day I realized my audio drivers weren't working. After spending another several hours messing with that (and posting it here), I found that I had a system restore point two days before I encountered the Ultimate Cleaner malware and restored my computer to that time. Then my audio worked fine.

    Anyway, the reason I'm posting this is that I was hoping someone could look at my MGlogs.zip log and see if I have any traces of this "Ultimate Cleaner" malware left on my computer.

    BTW, I also sent the "infected" files to McAfee's Avert for evaluation. Not sure if that will help any, but I guess it can't hurt.

    Regards,
    dalan
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Next time you have any issues with malware, please run the complete READ & RUN ME procedure and attach all of the requested logs. While MGtools is very useful to us it is not a comprehensive malware scanning tool. That is why the READ & RUN ME runs several procedures.

    You are using MSconfig to control startups and you should not be doing that. See the below:

    Dealing with Startup Processes


    Do you know what the below files are for?
    Code:
                              
    "C:\Program Files\"
    sss.dat       Feb 22 2008         120  "sss.dat"
    "C:\"
    pth.bat       Jan 15 2008         263  "pth.bat"
    pth1.bat      Jan 15 2008         226  "pth1.bat"
    Did you add the below info to your hosts file?

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6 Update 1
    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now delete the below files[/b]
    C:\WINDOWS\admgcx.dxx
    C:\WINDOWS\bdmanager.dxx
    C:\WINDOWS\fsxloqf.xxx

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\HP_Administrator\Local Settings\Temp


    As requested in the READ ME, please download and install CCleaner
    • Now run Ccleaner with the default options (that means don’t change anything) to clean out temporary files.
    • Only use the default settings on the Windows Tab and select Run Cleaner. Do not run any other options from other tabs.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.

    Make sure you tell me how things are working now!
     
  3. dalan

    dalan Private E-2

    Can you please point me to the READ & RUN ME page? Thanks! Also, thanks for the info on MSconfig. I rarely use it but I did use it a while back since I didn't know any other way to stop programs from loading or running on startup.

    I know what the two batch files are. I use them to modify my path if I go to the command line. However, I don't know what the "sss.dat" file is. Windows Explorer reports that it is a Nero file but I removed Nero over a month ago. The date looks very suspicious. For now I have renamed the file.

    No, I did not add this info to my hosts file. I suspect it's from an Apple utility called "iDisk". My brother is a Mac freak and he has what's called an "iDisk". You need a program from Apple to access an iDisk with a Windows machine. You can read more about it at this link: http://www.mac.com/1/idiskutility_download.html. I see there's a new iDisk utility out for Windows XP. Their old iDisk utility never worked very well - maybe the newer one will. Anyway, what should I do with these entries? Can I let analyse.exe delete them?

    Done....

    I was unable to install or download Sun Java Runtime Environment 6 Update 4 from the link you posted. I had to settle for Java 6 Update 3. As for Firefox, I prefer to stay with IE7 for now. I had a bad experience with Firefox in the past.

    Done.....except I think I "fixed" one too many things. I had four items checked and "fixed" them. After "fixing" them, I did another system scan and found "O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)" was still there. Then I "fixed" it by itself. Not sure what I accidentally "fixed" the first time but everything seems to be working fine.

    I'm keeping these files for now. I sent them to McAfee's company called "Avert" for analysis. I have kept them renamed and moved them to a temporary holding folder for now.

    Done....

    Done...attached is my MGlogs.zip after running GetLogs.bat. Thanks for your help so far!

    dalan
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Everytime you come into this forum and no matter what page in the forum you are on, all of the sticky (also call pinned) threads are right at the top of the page. You should have looked at them before posting. The READ & RUN ME is one of them. Look to see what I mean but I will also give you a direct link.

    READ & RUN ME FIRST. Malware Removal Guide

    That is all of what you should have completed before posting.


    Okay leave it that way and if you don't notice any problems running anything on your PC over a period of time, then delete it.


    You can do this with analyse.exe and if you find out you need them, there is a backup mechanism on a Misc Tools page of HijackThis that you can restore from.

    Why? What problem did you have?

    The fix of the BHO line may have failed the first time. This happens quite often and is also one of the many reasons why the procedure states to make sure you exit all browsers before clicking fix. If even 1 IE browser is open it can block fixes. It looks like you missed fixing the below too:


    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot


    If McAfee does not know about Zlob/SmitFraud infections by now then they never will. These are old news. But it does not hurt to send to them, however you should rename them back to the proper filenames before sending them.

    Your logs are clean other than the files you are saving for McAfee.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  5. dalan

    dalan Private E-2

    Yeah, I know what a "sticky" is. I missed it somehow. Sorry about that.
    Every time I picked my OS (Windows), I got some kind of error - I don't remember what it was now. Anyway, I was able to install Java 6 Update 4 this time. When I installed it, I also ended up with SE Development Kit 6 Update 4. Do I really need this?

    Yeah, my thoughts exactly! However, I thought I would give them the benefit of the doubt and send them the files.

    This keeps coming back:
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    Any idea why?

    I think I have everything else cleaned up now so I will do the final steps. Thanks for your help. I really appreciate it.

    dalan
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you don't need the Dev Kit. This means you did not download and install from the link I gave you because you would only have gotten the Runtime Environment if you used the link I gave.


    Either some component of your protection software is blocking the change, or the registry key has had its permissiones changed so that you cannot remove it. It is not malware, it is just a totally unecessary startup which is a waste of System Resources.

    If you still have ComboFix, you could try the below which may work.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "TkBellExe"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Did that work?
     
  7. dalan

    dalan Private E-2

    When I tried to run ComboFix as you suggested, I got this error message from McAfee:

    McAfee has automatically blocked a potentially unwanted program from running on your computer.

    Details
    Name: RemAdm-Proc-Launch!171

    More Info
    Potentially unwanted programs include spyware, adware, and other programs that might create additional security or privacy risks to your computer data and personal information. They are often downloaded in conjunction with a program that you want.

    Process: C:\Documents and Settings\HP_Administrator\Desktop\ComboFix.exe
    Process Name:
    File Path: C:\32788R2FWJF\psexec.cfexe

    If you do not recognize this potentially unwanted program, McAfee recommends that you remove it. If you recognize this potentially unwanted program, trust it, then rerun the program that triggered this alert.

    Options:
    Remove this program
    Trust this program
    Close this alert


    I let it continue to run the first time (I did not select any option) but apparently McAfee blocked or quarantined the log. I tried it again after making sure I had the correct ComboFix program and got the same error message from McAfee. This time I did NOT let it continue to run and selected "Remove this program". McAfee removed ComboFix.exe from my desktop the second time. I don't need any more problems and I'm very leery about running ComboFix!

    Well, I went back and looked for anything ComboFix had left behind since it did display a log when it finished the first time and I found a log in the C:\QooBox folder named ComboFix2.txt. I am attaching that file.

    BTW, just what is ComboFix supposed to accomplish? I went to their website ( http://www.bleepingcomputer.com/combofix/how-to-use-combofix ) and I'm still at a loss as to why I would want to use this program to get rid the entry in my registry. I know this darn entry is a Real Player entry. Can't I just edit the registry manually? If so, how do I do it manually?
     
  8. dalan

    dalan Private E-2

    I couldn't attach the log when I edited my previous post so here it is (attached)

    Dalan
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ComboFix is okay to run. The READ & RUN ME procedure even explained to you that you may notice things from your antivirus. It stated the below:

    McAfee is a bigger problem then ComboFix. ;)


    Yes that is the quarantine folder where ComboFix saves copies of everything it removes.

    In this last case I was attempting to have it remove the registry key that you could not remove with HijackThis. ComboFix has more power to do things like this. McAfee may be the reason why you could not fix that registry key. In general ComboFix is a tool that removes hundreds of different malware issues from a PC automatically and it has the power to take a script file that we create to do things we want it to do.

    If you shutdown, McAfee and run ComboFix with the CFScript.txt file, it should remove the item from RealPlayer. Manual steps will require other tools and will be more complicated for you since you will have to be doing manual registry editing. However you can try doing the below with McAfee disabled and perhaps this will work.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  10. dalan

    dalan Private E-2

    I thought it worked but after rebooting it came back. Maybe I'll just leave it for now. Thanks for all your help.

    dalan
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it is not a major problem anyway. It is just a waste of resources. You could check within the program for an option to disable it from loading at startup. The other option is to just uninstall RealPlayer if you don't use it. I don't have it installed and never miss it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds