infostealer.gampass

Discussion in 'Malware Help (A Specialist Will Reply)' started by gregdil, Jul 21, 2008.

  1. gregdil

    gregdil Private E-2

    hello,

    my boss took his laptop on a business trip to china and korea about a month ago. shortly after he returned, he started telling me about problems with SAV constantly popping up and cleaning a file called "infostealer.gampass".
    SAV always cleaned the infection but they kept resurfacing constantly.
    unfortunately he needed the laptop to use for work, so the problem kept
    getting worse and worse, to the point where the "system" icon could not
    be accessed from the control panel, and none of the services were being shown in the services control...finally, this weekend all the network connections (wireless = no wzc and ethernet limited connectivity), and internet explorer just stopped working all together, DEP errors were popping up constantly, and the computer started locking up (this weekend)...so today i followed all the procedures in the READ ME AND RUN FIRST, and things seem to be back to normal again with this laptop (at least for now!!!)
    i will attach the logs, i think i followed the instructions pretty well, but between troubleshooting the laptop and writing e-mails for work i might have missed a couple a two three things...anyway, my major conern is that this laptop gets logged onto a network file server everyday, and i am more worried that what was on the laptop has found its way into our file server...
    when i checked the SAV logs on the server, it was finding and cleaning W32.almanahe.B from .exe files on some of the shared drives...i wonder if i should run the READ AND RUN ME on all the computers in my office now?

    thanks in advance!!!

    greg
     

    Attached Files:

  2. gregdil

    gregdil Private E-2

    hello again,

    the logs for combo fix and mgtools are attached...
    logs for SAS and malware bytes were included
    with the first post!!!

    thanks again!!!

    greg
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Sorry for the delay! We are extremely busy and only a couple of us are removing malware.

    This may take some repetition but let's see how much we can get in the first go around. ;)

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O21 - SSODL: DesktopWin - {DA191DE0-AA86-4ED0-4B87-292A3D48BE99} - C:\WINDOWS\AppPatch\DesktopWin.dll
    O24 - Desktop Component 0: Desktop Uninstall - C:\WINDOWS\warnhp.html

    After clicking Fix, exit HJT.




    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).




    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    I strongly recommend that you do not power down or reboot this PC after posting the above logs. Wait for my next message to see where things stand.

    Also it would be very good idea not to connect it to a network for two reasons:

    1. You could be infecting other computers on the network
    2. The other computers on the network (including the server) may already be infected and could be reinfecting you.
     
    Last edited: Jul 24, 2008
  4. gregdil

    gregdil Private E-2

    hello chaslang,

    i know you guys are busy and i really appreciate your help;
    you guys are really good so it is definitely worth the wait!!!

    laptop was working quite well after doing the read and run me first;
    problem was that it was spawning the W32.almanahe.B onto shared
    drives when it was logged onto our file server...

    ran through everything mentioned in your reply;
    i understand it may require several iterations...

    - the registry editor script was successful...
    - logged the laptop onto the server and so far no reports of W32.almanahe.B being reported by SAV on the server...(very encouraging)!!!

    attached are the log files...
    i have prefixed them with today's date just to differentiate
    them from other previously submitted logs...

    thanks for all your help!

    greg
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some new items showed up after you posted your first logs but before you ran my fix. Thus the infection is respreading due to these new items. Here is a new fix that includes the new items as well as old items since they may have been recreated.

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now doubleclick the fixME.reg patch on your Desktop form last time and allow it to be added to the registry.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jul 23, 2008
  6. gregdil

    gregdil Private E-2

    hello chaslang,

    laptop seemed to work fine after first fix;
    especially, i was happy to see that our server did not detect
    any presence of W32.almanahe.B after the laptop was logged
    onto it...however, after leaving the laptop 'locked' for several
    hours that we left the office, i was surprised to find it frozen
    upon returning...so i am glad to have your new fix!!!

    i did run the 2nd fix and the logs are attached...

    nothing strange happening so far, and no warning of
    the W32.almanahe.B on the server after logging the
    laptop onto it...

    logs from the 2nd fix are attached...

    thanks a lot for your help!

    greg
     

    Attached Files:

  7. gregdil

    gregdil Private E-2

    hello again,

    maybe spoke too soon...laptop locked up again after about 20 minutes of basically sitting idle...will try to put it through some more paces later tonight...

    greg
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I had a typo in one of the driver names to remove so we need to fix things again. Many of the below were not in your previous logs but since the infection could still exist, it also could have started spreading again so it is best to just fix everything.


    Some new items showed up after you posted your first logs but before you ran my fix. Thus the infection is respreading due to these new items. Here is a new fix that includes the new items as well as old items since they may have been recreated.


    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now doubleclick the fixME.reg patch on your Desktop form last time and allow it to be added to the registry.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. gregdil

    gregdil Private E-2

    OK...

    boss was putting laptop thru its paces last night, and encountered BSOD at one point...not sure which error code or what he was doing...he is too impatient; will get him to document stuff if it happens again...
    but, he brought the laptop to the office today and has not complained...
    sooooo.....

    ran through this new fix and logs are attached...
    registry updated successfully...
    will keep you posted on how the laptop is running...

    thanks for all your help!!!

    greg
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay based on those logs I was right......it had started spreading again. You should seriously consider checking other PCs on the same network or any home networks that this PC was connected to. It could be spreading the infection to other PCs or other PCs could be reinfecting this one. If the other PCs are infected and reinfecting this laptop, it is a waste of time to keep cleaning the laptop unless the other PCs including the server are cleaned.

    Other than the below, this PC is currently clean.



    Copy the bold text below to notepad. Save it as fixSGP.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. gregdil

    gregdil Private E-2

    OK...will run that new fix on the laptop tomorrow...

    in fact, i had already run the read and run me first on our file server,
    except for combofix which would not function because the server
    OS (server 2003 SBS) was incompatible...

    do i start a new thread to review the server logs?

    i was planning on doing the read and run me first on all the computers
    in our office (there are 9 of them)...is it OK to ask you to help me fix
    that many computers? it seems unfair to everyone else that may be posting
    on this site...

    if so, is there some way i can "contribute to the cause"?
    these are business computers after all!!!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but make sure you reference this thread for our information.

    We can work on them all but it may get confusing working on so many at the same time even though they will each be in a new thread.

    We do have PayPal accounts. ;)
     
  13. gregdil

    gregdil Private E-2

    hello,

    ran the fixSGP.reg fix and it merged successfully...

    new log file is attached...

    will do!!!

    wow, that's great!!!
    i can reference each computer by it's network name in each new thread!!!

    i am more than willing to contribute...seriously!!!

    thanks for everything!!!

    greg
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Send me a PM with an email address and I will send you the details.

    The logs for this PC are now clean. Does the Symantec software you have installed include a firewall? I'm guess it does not based on what I saw in your logs.



    If you are not having any other malware problems with this PC, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  15. gregdil

    gregdil Private E-2

    will follow those last instructions...
    and the ones for "how to protect yourself from malware" as well!!!

    tried to send PM but it would not let me!!!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry! I forgot about the restriction. Send an email to chaslang at majorgeeks.com

    You forgot to answer my question about the firewall.
     
  17. gregdil

    gregdil Private E-2

    no firewall with the symantec software...
    will send the e-mail...
    thanks again!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then consider installing one since the Windows firewall you are using is not adequate as stated in the How to protect yourself link I gave to you.

    I responded to your email.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds