Had multiple infections - Please check logs

Discussion in 'Malware Help (A Specialist Will Reply)' started by Bad Panda, May 22, 2008.

  1. Bad Panda

    Bad Panda Private E-2

    This PC has been through the ringer with Virtumonde, Zlob. Went through the whole PC process listed and reran spybot to see if any of the aforementioned showed. What popped up was Mediaplex, which it says it fixed. Can you check my logs and see what else needs to be done?
    Thanks,
    Panda
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    If you ran the READ & RUN ME, you need to attach the 4 requested logs so that we can help you.
     
  3. Bad Panda

    Bad Panda Private E-2

    I attempted to upload the file but I must have blown it somehow. I ran everything...it was all in the zip file, right?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are 3 other log files you need to attach. They are from:
    • SUPERAntispyware
    • Malwarebytes Anti-Malware
    • ComboFix
     
  5. Bad Panda

    Bad Panda Private E-2

    Okay, here are the logs you requested. Thanks again!!!
     
  6. Bad Panda

    Bad Panda Private E-2

    Logs aren't uploading...not sure why. Let me try again.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You missed a couple things in the READ ME.
    1. You have two antivirus programs installed. Authentium AntiVirus SDK - 2 and McAfee SecurityCenter You must uninstall one of these immediately
    2. You missed uninstalling a few items requested in step 1. The uninstall step below will correct this.
    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2_03
    My Way Search Assistant <-- should have been uninstalled in step 0 of the READ ME
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 0 of the READ ME
    Viewpoint Toolbar <-- should have been uninstalled in step 0 of the READ ME


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    O2 - BHO: (no name) - {0386988B-224B-4345-89D9-C47E20700807} - C:\WINDOWS\system32\ddcAtqNh.dll (file missing)
    O2 - BHO: (no name) - {0f44b230-872a-47c9-bd5c-57137c5cad9d} - C:\WINDOWS\system32\xxyvwULb.dll (file missing)
    O2 - BHO: (no name) - {3f31e632-c9ba-46cf-b31e-c6669fa5cded} - C:\WINDOWS\system32\fccbARIa.dll (file missing)
    O2 - BHO: (no name) - {59A3842D-28C8-415D-AFC1-98E642FE00DC} - C:\WINDOWS\system32\khfEVLDs.dll (file missing)
    O2 - BHO: (no name) - {63930eb8-8917-46d3-aa39-e464e5f1f4e3} - C:\WINDOWS\system32\pmnoMdcA.dll (file missing)
    O2 - BHO: (no name) - {DABC2A42-2D79-4F4D-A495-BE3D4D903A93} - C:\WINDOWS\system32\iifcBsrR.dll (file missing)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O24 - Desktop Component 0: Privacy Protection - (no file)

    After clicking Fix, exit HJT.




    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. Bad Panda

    Bad Panda Private E-2

    Have a problem...I was unable to uninstall Authentium (I couldn't find it) and MyWay. I am continuing with the steps, and will let you know what happens.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is probably part of the software you installed from Verizon. Probably came with one of the below (most likely the last one)
    • Verizon Broadband Toolbar
    • Verizon Online Help and Support
    • Verizon PC Security Checkup
     
  10. Bad Panda

    Bad Panda Private E-2

    Okay, I've gone through and uninstalled the Verizon software. Hopefully that removed the Authentium as well. I've attached current logs.
    The system is MUCH improved. It's older and running on wireless, but so far it appears to be happy.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes Authentium is now gone, but did you forget to uninstall My Way Search Assistant or is it not showing up?

    Your logs are fine other than that.
     
  12. Bad Panda

    Bad Panda Private E-2

    I'm sorry, I forgot to mention that one. There is a failed .dll that prevented the uninstallation. Does that indicate that the program is damaged and/or non-functional?
    the dll is desrcas.dll
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so use the below to remove it.

    Copy the bold text below to notepad. Save it as fixMW.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Then delete the below folder if it exists:
    C:\Program Files\MyWaySA


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     
  14. Bad Panda

    Bad Panda Private E-2

    Registry fix worked. This machine is performing nicely now. Thank you for all your help Chaslang.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds