How to get rid of reappearing bca4eda.$$$?

Discussion in 'Malware Help (A Specialist Will Reply)' started by stormweasel, Oct 3, 2008.

  1. stormweasel

    stormweasel Private E-2

    Hi

    I have problem with the following files:

    C:\WINDOWS\Temp\bca4e2da.$$$
    C:\WINDOWS\Temp\ed47fa.$
    C:\WINDOWS\Temp\fa56d7ec.$$$

    They are decleared trojan by sdfix, and according to my google research, it's right.
    Although sdfix deletes them, whenever I run it, they keep coming back after rebooting. I tried it with disabled System Restore, but it didn't work either.

    I would be grateful if you could give me advice. Thanks in advance.

    There's the required logs.
     

    Attached Files:

  2. stormweasel

    stormweasel Private E-2

    And there's the MGlogs.zip, and added my last sdfix report also.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please run this Using Dr.Web CureIt and attach the requested log afterwards. Then reboot.

    After reboot, please download the following & save to your Desktop




    GMER's MBR.exe
    • Double click on the MBR.exe file to run it.
    • A log will be produced & saved to the desktop, called MBR.log.
    • Attach this log to your next message.
    Now reboot again and see if you are allowed to delete the below files:
    C:\WINDOWS\Temp\bca4e2da.$$$
    C:\WINDOWS\Temp\ed47fa.$
    C:\WINDOWS\Temp\fa56d7ec.$$$


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • DrWeb.txt log
    • MBR.log
    • C:\MGlogs.zip
     
    Last edited: Oct 5, 2008
  4. stormweasel

    stormweasel Private E-2

    Hello chaslang

    After running Cureit, I got a not so pleasent experience. The scan found a virus in my boot system named Maos Boot (if I remember well), then, after I allowed the program to clean it after a reboot, the partitions on my main hard drive seemed to be destroyed. The computer could not load the XP and even Partition Magic was not able to detect any of my partitions.
    Fortunately I managed to acquire a boot cd with a program called Partition Table Doctor, which helped me rebuild them succesfully.

    I did the cure it scan again (so the log I sent you came from this scan) and the whole system looks clean of Maos, so the only thing I can think of is that destroying this beast caused the system crash after the successful cleaning. I hope, I'm right.

    The three files with the $$s could be deleted without any problem, and after a few rebooting they seemed to be disappeared permanently.

    P.S. Cureit declared my mgtools, sdfix and combofix files (both the archives and the some of the extracted) infected. I suppose these are false positives.
     

    Attached Files:

  5. stormweasel

    stormweasel Private E-2

    I just realised that the cureit log is so enormously large(around 34mb), that I can't make a zip file from it which is not larger than 1mb. any idea?
     
  6. stormweasel

    stormweasel Private E-2

    I got this solution, don't know whether it suits you.

    I splitted the cureit log file into 3 parts with Windows Commander 4.03, than made a zip from each part. I hope that will work.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes these are false positives.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
    O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - (no file)
    O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)

    After clicking Fix, exit HJT.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    Java(TM) SE Runtime Environment 6 Update 1
    Now reboot.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Are you having any other malware problems?
     
  8. stormweasel

    stormweasel Private E-2

    My computer seems to be clean, thank you very much for your patience and assistance.
    Keep up the good work! I'm glad that I've found this site.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds