InfoStealer.Gampass???

Discussion in 'Malware Help (A Specialist Will Reply)' started by Ark, Jul 15, 2008.

  1. Ark

    Ark Private E-2

    When I was browsing the internet today, my norton anti-virus program poped-up from the task bar and said "InfoStealer.Gampass has been blocked and that my computer is now safe"... I was a bit confused... but 10 seconds after my entire computer froze... nothing worked... I tryed ctrl+alt+del, everything... nothing worked... so I just used to power button to turn it off and reboot.

    But everytime I log in on the internet now, 10 or 15 minutes later the norton warning pops-up again, and my computer freezes again 10 seconds later (unless I cut off internet connection right away...)

    So can someone get me started on what I should do first... Do you guys need any other info in order get started on solving this problem? Thanks in advance.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. Ark

    Ark Private E-2

    ok, I did all the clean-up processes for my OS and here are all of the logs:

    I don't know if the problem got fixed in the process, but I hope someone can tell me from the logs that I posted.

    I also have the MGlogs.zip which I can post if needed, I just couldn't post it on this reply becuase of the 3 file attachment limit.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach it in a second message as stated in the READ & RUN ME instructions which said
    I don't know if you noticed or not but you have many many more problems than InfoStealer.Gampass. Your antivirus was missing a lot of problems.
     
  5. Ark

    Ark Private E-2

    oh boy... I didn't know there were that many... I can't do a format because I'm overseas with my laptop and I didn't bring my XP, or drivers cd. Will I be able to clean my laptop some other way?

    I've attached the zip file as well...
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of Sun Java:
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKCU\..\Run: [system34] C:\WINDOWS\SoftwareProtection\Windows External Security Update.exe
    O21 - SSODL: DesktopWin - {DA191DE0-AA86-4ED0-4B87-292A3D48BE99} - C:\WINDOWS\AppPatch\DesktopWin.dll

    Also I strongly recommend that you also fix the LimeWire startups. Only run this when you want to use it. Do not always have it running!
    O4 - S-1-5-18 Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (User 'SYSTEM')
    O4 - .DEFAULT Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (User 'Default user')
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. Ark

    Ark Private E-2

    alright, I did everything you told me and it all went smoothly... the fixme.reg file was succesfull... but my laptop still freezes randomly after 10 - 15 minutes of surfing time, whatever is causing that is still here. I hope we can get that fixed as that's the main thing that's bothering me, thanks for all the help so far and here are the logs you wanted:
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We have a little more cleaning to do.



    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now double click the same fixME.reg patch you saved to your Desktop last time and allow it to be added to your registry.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.


    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. Ark

    Ark Private E-2

    I again did all you told me and everything again worked normally... the .reg file was once again succesful.

    One thing did happen when I was running the Getlogs.bat file... This happed in all 3 times I ran Mglogs... The following error message pops-up: it's titled "ProcessDll.exe - Commom Language Runtime Debugging Services"

    'Application has generated an exception that could not be handled.

    Process d =0xdb0(3504), threadid=0x53c(1340)

    Click ok to terminate the application
    Click cancel to debug the application'


    I always click cancel and then cancel the whole debugging thing to not interfere with the program. I think this is in the logs I posted anyway but just wanted to ask if this was normal... And lastly can you tell me if things are improving, don't know if you can tell that from the logs, if not that's alright. Again I appriciate the help very much.

    here are new logs:
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually it would be better to click OK but we don't need the procdll.txt file now anyway, so don't worry about it.

    You have a few more files to remove. Rather than making up a longer fix with ComboFix, let's see if you can just simply delete the below files:

    C:\WINDOWS\system32\comremo.dll
    C:\WINDOWS\system32\ezcron.dll
    C:\WINDOWS\system32\myasemt.dll


    Let me know if you can get them deleted. Reboot afterwards and make sure that they have not come back. Let me know the results and also tell me how things are working.
     
  11. Ark

    Ark Private E-2

    alright, I've deleted all 3 files, rebooted, and they were still gone...

    The problem is though, my computer still continues to freeze after 10 - 15 minutes of surfing on the internet... infact I'm writing this message for the second time as my laptop froze on the first...

    Was I supposed to be clean after deleting those 3 files? Or is there still more that I'm supposed to do?

    I'm starting to think that whatever's making my laptop freeze is not spyware or a virus, but something that a virus damaged or messed up? :confused Whatever it is, it's still a problem... and it's really starting to bug me :(

    But again thanks for helping me this far, and I think you helped me get a lot of stuff fixed... a lot of stuff that I didn't even know existed lol, hopefully we can get this internet freezing thing fixed as well... damn whoever makes these bloody virusses lol
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While I'm not sure the infection is the cause of your freezing, we still are not done with removal. Some items have still come back and I'm going to give you a new fix. This fix will include things that may arlready be removed. But I want to keep them in the fix just in case they have returned since you posted your last logs.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. Ark

    Ark Private E-2

    alright, I did everything you told me but there was 1 thing that gave me a bit of a scare. After I ran Avenger, it asked me to reboot, I clicked yes and Windows shut down... when it was loading back up, instead of my desktop, a blue screen came up with the following message:

    'Stop: c000021a {Fatal System Error}
    The Windows logon system process terminated unexpectedly with a status of 0x00000402 (0x00000000 0x00000000).
    The system has shut down.'

    I had to press the power button to shut it down and when I turn on my laptop again it booted normally, and the avengers log poped up as you said.

    After that I looked for the files manually as you told me and all but three files had been deleted, these files were still there:

    C:\WINDOWS\AppPatch\AcSpecf.dll
    C:\WINDOWS\AppPatch\AclLayer.dll
    C:\WINDOWS\AppPatch\DesktopWin.dll

    When I tried to delete these files manually the following message came up:

    'Cannot delete "Filename": Access denied'

    So pretty much those 3 files are still there... if you have another method for trying to get rid of them I'm willing to try it...

    Here are the logs:
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay this particular trojan can be annoying to remove because it creates many, many files and registry keys and the files constantly change names. We need to find all of the files and registry keys. I'm going to give a bigger fix further down that includes all the ones I know of at this time. They may not all be on your PC, but it does not hurt to check anyway.

    First I want to try and fix the error you were getting while running GetLogs.bat. It is looking like we may need the procdll.txt file after all.

    Please install the .NET Framework software from Microsoft by clicking the Download button in the below link and then running the dotnetfx.exe file once it is downloaded.

    http://www.microsoft.com/Downloads/details.aspx?FamilyId=262D25E3-F589-4842-8157-034D1E7CF3A3&displaylang=en


    Now run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O20 - AppInit_DLLs: ezcron.dll myasemt.dll fackwir.dll caotxb.dll comremo.dll googleons.dll welycz.dll jsnoer.dll ceshleo.dll joliom.dll
    O21 - SSODL: DesktopWin - {DA191DE0-AA86-4ED0-4B87-292A3D48BE99} - C:\WINDOWS\AppPatch\DesktopWin.dll

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.
    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.




    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Burak\Local Settings\Temp


    Now copy the bold text below to notepad. Save it as fixIT.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run ATF Cleaner again like you did back in message # 8!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).







    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jul 23, 2008
  15. Ark

    Ark Private E-2

    I've done every step up to the Avenger one successfully... when I tried to execute avenger and error message came up with the folliwing message:

    'Error: Invalid registry syntax in command;
    "HKEY_CLASSES_ROOT\CLSID\{DA191DE0-AA86-4ED0-4B87-292A3D48BE99}"
    Only registry under the HKEY_LOCAL_MACHINE hive are accesible to this program.
    Skipping line. (Registry key deletion mode)'

    So I aborted... If you want I can just click ok... but it looks like it will not delete the registry in the classes_root. Should I execute anyway?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that. I meant to edit that out of the Avenger part and add a separate patch for that. I'm going to edit the previous Avenger fix and add the registry patch to it, so start again with the Avenger piece and contine.
     
  17. Ark

    Ark Private E-2

    alright, I did everything... the only thing that there was a problem with was the processDll.exe error again, even thought I downloaded and installed the Net. Framework software it still came up...

    And also I can't attach the logs for some reason... I'm using the library's internet right now, and I guess they don't allow uploading... If you can give me an e-mail address to send them to I can try to send it to there... sorry about that.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Was it the same exact error message or a different error message?


    How did you attach them in the past? Just do it the same way. Also make sure that you are attaching new logs and not the same old logs. Look for error messages in the Manage Attachments window to see what they say if getting any errors. These messages are not real obvious.
     
  19. Ark

    Ark Private E-2

    Well when I click "Manage Attachments" nothing happens... I moved over to another city just yesterday and the only internet access I have here is of the libraby's next door... unfortunately I think they have some kind of filter to stop me from uploading things on the forum... and yes the processDll.exe error was the exact same one that I posted earlier.

    The good news is I think that last fix you gave me fixed everything... I've been using the internet for at least 40 minutes now and still no freezing... Also the AcSpecf.dll, AclLayer.dll, and the DesktopWin.dll files no longer come back after I reboot...

    If you can give me an e-mail address to send you the logs that's great and I can probably send them to you... but if you can't out of privacy or any other reason I understand, you'll just have to wait 2 weeks until I return home and be able to post them here.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What browser are you using? Try another browser like if IE is not working. Or if already using FireFox, try IE..


    We don't post email address in the public forum because spambots will pick them up and we don't want any more spam. Also we don't work via emails since it requires more work for us connecting to something else to download the emails and then they actually have to get added to the forum by us so that the thread is more complete and more helpful to anyone ever having a similar problem. However I will send you a PM with an email address you can use so we can get this finished up.
     
  21. Ark

    Ark Private E-2

    Thanks chaslang, sent the logs to the e-mail adress.


    Edit by chaslang: Logs attached to this message
     

    Attached Files:

    Last edited by a moderator: Jul 22, 2008
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I attached your logs to your last message. Let's continue with your cleanup.

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button.
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Now re-run Spybot and run the Immunize feature to reimmunize.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll (file missing)
    O21 - SSODL: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixOLG.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run ATF Cleaner

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  23. Ark

    Ark Private E-2

    ugh, I've got bad news... these files are back:

    C:\WINDOWS\AppPatch\AcSpecf.dll
    C:\WINDOWS\AppPatch\AclLayer.dll
    C:\WINDOWS\AppPatch\DesktopWin.dll

    I don't know how they came back but somehow they did... my internet frose again as well. It's weird becuase they were gone for 2 days straight, and without doing anything they pop-up again... Also when I ran analyse.exe this was also back:

    O21 - SSODL: DesktopWin - {DA191DE0-AA86-4ED0-4B87-292A3D48BE99} - C:\WINDOWS\AppPatch\DesktopWin.dll

    And also this came up as well:

    O20 - AppInit_DLLs: jsnoer.dll

    I didn't do the clean up you just posted yet as I thought that the return of this might affect it. Should I go through with it anyway and leave this to last?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run the fix in message # 15 down to and including the ATF Cleaner step.

    Then run the fix from message # 7 but start at the step with HijackThis and continue thru to the end of that fix and attach the new logs from Avenger and MGlogs.zip. Note that the HijackThis line for AppInit_DLLs may not look the same as given in message # 7 but fix what you do see. NOTE: I have modified the Avenger fix again to include new items that I know about for this infection. So make sure you use the new info in the Avenger fix and not the same fix you did last time.

    Does your Symantec software have its own firewall built-in?

    Are there other user accounts on this PC that are getting used?
     
    Last edited: Jul 23, 2008

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds