Ran malware removal procedure but still question about key loggers (logs included)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Smooles, May 30, 2008.

  1. Smooles

    Smooles Private E-2

    Hi, reading this forum has been so helpful and I wanted some advice on getting rid of malware. Two nights ago I got the ctfmona.exe trojan (bugs on the screen/blue desktop/dialog box saying I was infected). I ran a Norton scan which found it and partially removed it than had me manually delete it from the registry. I then I followed the instructions on http://forums.majorgeeks.com/showthread.php?t=35407 and http://forums.majorgeeks.com/showthread.php?t=139313. My computer seems to be working fine, but I'm just really worried there is a key logger hiding somewhere. Other websites have talked about needing to reformat you computer and still not knowing for sure if you've gotten rid of it. I was just wondering if there is any way to know for sure if I'm in the clear? I'm attaching my logs. This may not be important but I thought I should also mention I went through the whole process once and realized I hadn't deleted all old forms of Java so I did deleted them and went through the 5 scans again. For this reason virtually all the scans were clear this second time, when the first they had indeed found malware. Thanks in advance for the help.
     

    Attached Files:

  2. Smooles

    Smooles Private E-2

    Re: Ran malware removal procedure but still question about key loggers (logs included

    last log
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Ran malware removal procedure but still question about key loggers (logs included

    Welcome to Major Geeks!

    In most cases formatting is not necessary; however there really are no guarantees since infections mutate all the time.

    This is important since we actually even specify in the READ & RUN ME to only run it once. We really need to see the first logs to know exactly what had been found. It does not mean we cannot clean what we do see (and there is more to do) remaining but it could prevent us from seeing things we may need to know about. Are these logs from the second run? If so, you still have Java software to remove.

    What is the below program for? Is it something for iPod?
    C:\Program Files\i2hubV2\i2hub.exe


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Development Kit 5.0 Update 14
    J2SE Runtime Environment 5.0 Update 14

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [LSASS Authority] lshosts32.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
    O4 - HKLM\..\RunServices: [AOL Instant Messenger] AlM.EXE <-- this is not aim. The "l" is an "el" not an "eye"
    O4 - HKLM\..\RunServices: [LSASS Authority] lshosts32.exe

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. Smooles

    Smooles Private E-2

    Re: Ran malware removal procedure but still question about key loggers (logs included

    Thanks so much for the reply. First, yes, those logs were from the second time. My mistake. I thought that since I hadn't deleted all forms of Java you would ask me to run it again. I am attaching the logs from the first time. Except I am not attaching the MGlogs.zip because I think the second log replaced the first unless you know how to find the first one or don't need it.
     

    Attached Files:

  5. Smooles

    Smooles Private E-2

    Re: Ran malware removal procedure but still question about key loggers (logs included

    Ok, now on to all the other issues.

    -i2hub was a p2p program for colleges that got shut down about two years ago. I removed it from the control panel probably a year ago. Should I just delete that folder from the Program Files folder?

    -Windows messenger removed

    -Java deleted. Sorry, those weren't on the list of versions that needed to be removed. I needed them for a class but now they're removed.

    -Ran MGTools, one question. Just as you had me delete
    "O4 - HKLM\..\Run: [LSASS Authority] lshosts32.exe"
    and
    "O4 - HKLM\..\RunServices: [LSASS Authority] lshosts32.exe"
    should I also delete both AlM.EXE lines? (You just asked me to delete
    "O4 - HKLM\..\RunServices: [AOL Instant Messenger] AlM.EXE"
    but there is another without "Services")

    -Followed ComboFix instructions. Only question/comment is that in Running ComboFix the reader is instructed to change the name to cf.exe. I changed it back to ComboFix.exe because that is how you referred to it in your post. I guess maybe I shouldn't have changed it back, but I hope that's not a problem and thought I should note it.

    -fixme.reg was successfully added to the registry

    -Ran Ccleaner

    -Ran C:\MGtools\GetLogs.bat

    -New logs below

    Things are still working fine on my computer. Just hoping I'm getting rid of everything.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Ran malware removal procedure but still question about key loggers (logs included

    Can it be uninstall via Add/Remove programs? If so, do that first. Otherwise delete all files and fix the O4 line seen in a HijackThis log. That is the below line:


    O4 - HKCU\..\Run: [i2hub] C:\Program Files\i2hubV2\i2hub.exe -tray


    The list is not comprehensive but Step 1 actually says
    Yes fix the below one too:
    O4 - HKLM\..\Run: [AOL Instant Messenger] AlM.EXE

    Not a problem. The procedures keep having to be modified all the time since malware keeps changing to adjust to how we fix things. One day we may have combofix, then cf, then cfix, then combo-fix. We sometimes just forget to update the boiler plate fixes we post.;) The main thing is that it runs. Some malware detects the combofix.exe file name and blocks it. That is why we rename it.

    After fixing the above two mention O4 lines, your logs will be clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds