Nasty and ugly infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by Bad Panda, Nov 20, 2008.

  1. Bad Panda

    Bad Panda Private E-2

    This PC had an ugly infection of both viruses and spywares. Super Antispyware alone found 3867 different entries...everything else only found about 500 each.
    Anyway, there is still an infection here that I have been unable to remove. They have McAffee which has been useless except for stopping my attempts to run the tools. I put on Avast and it appears to be unable to correct something in a temp folder. I disabled McAffee for now, but really need someone to look at these logs and see what they can find.
    Thanks!!!
     

    Attached Files:

  2. Bad Panda

    Bad Panda Private E-2

    Had to break the log into 2 parts. Sorry.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The scans did most of it. :)

    The system could use a bit more ram:
    Code:
    Total Physical Memory    512.00 MB    
    Available Physical Memory    97.96 MB
    
    Let's just do this:

    Now download The Avenger by Swandog469, and save it to your Desktop.

    Please use add/remove programs to uninstall:
    Viewpoint Media Player

    Please disable all anti-virus and anti-spyware programs while we do the following ( be sure to re-enable when we are finished):

    Now :
    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  4. Bad Panda

    Bad Panda Private E-2

    Avast keeps popping up with the following file it is unable to delete:
    C:\DOCUME~1\Owner\LOCALS~1\Temp\wmedia106.exe
    and another one that it doesn't seemto be able to get rid of. Any suggestions?
    I'm still working on the steps provided. Almost done.
     
  5. Bad Panda

    Bad Panda Private E-2

    Oh, by the way, the RAM had already been ordered for this thing. 512mb...sheesh.
    Here are the logs...
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Better.....now please disable the guest account in user accounts.

    You need to uninstall McAfee if you are running Avast.

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Now we need to use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\system32\clusppih.dat  
    C:\WINDOWS\system32\mnmdgveq.dat  
    C:\WINDOWS\system32\mnmdou.dat    
    C:\WINDOWS\system32\mscorye.dat   
    C:\WINDOWS\system32\tapipkrf.dat
    C:\DOCUME~1\Owner\LOCALS~1\Temp\wmedia106.exe
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    You need to tell me exactly what other file avast is reporting.

    Now run CCleaner --> both the cleaner and the issues, making the backup when prompted.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
     
  7. Bad Panda

    Bad Panda Private E-2

    Here are the logs.

    "You need to tell me exactly what other file avast is reporting." Avast was uninstalled. However, the file that Avast was reporting was listed in the previous post:

    C:\DOCUME~1\Owner\LOCALS~1\Temp\wmedia106.exe
    I went and browsed to the folder and deleted it. That problem solved.

    Thanks
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The way you had phrased it made me think it was indicating more than one file.....however we have a few more that have cropped up:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Let's try avenger again.....

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  9. Bad Panda

    Bad Panda Private E-2

     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Arrggg....and once again:

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  11. Bad Panda

    Bad Panda Private E-2

    Hope this one is better than the last one!
    By the way, yesterday when I attempted to delete the temp files I couldn't...even though they were older than 24 hours. Today all worked fine. Any easy explaination on why or was it a chair-to-keyboard interface error? :-o
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not disable the guest account nor did you run the tool to disable windows messenger.

    Something keeps regenerating the malware, so let's do this:

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now go to Bitscan link: agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.

    Also attach the avenger log and a new MGLog.zip
     
  13. Bad Panda

    Bad Panda Private E-2

    You did not disable the guest account nor did you run the tool to disable windows messenger. - - The guest account is OFF. If there is another guest account other than the one listed in the USER ACCOUNT section of control panel please direct me to it. Also, I did run the tool to disable Windows Messenger. I selected the option to disable it for all users. I just reran it and deleted it.
    I'll rerun the items and repost as soon as the reboot is finished.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not meaning to be a prig...it was just that your logs indicated that they had not been done. :)
     
  15. Bad Panda

    Bad Panda Private E-2

    Not meaning to be a prig-- Don't sweat it...I didn't take it that way. I only know troubleshooting via phone...via posts like this must be a pain, especially when people are doing ID-10-T errors.
    Bitdefender keeps failing when it updates and then won't run. I'm on my third try now. I don't know why it is failing...any other suggestions?
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  17. Bad Panda

    Bad Panda Private E-2

    Good morning Tim...sorry about the delay. Went away over the Thanksgiving holiday and didn't touch this thing.
    Housecall came up with one item, a trojan which it deleted, and 5 cookies which I couldn't get any information on. There is no log from Housecall unfortunately.
    Should we be calling this one good or keep plugging?
    Hope you had a nice Thanksgiving!
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file and tell me how things are running. :)
     
  19. Bad Panda

    Bad Panda Private E-2

    Things seem to be running well...compared to how it was anyway. I need to defrag it, but I'll wait until you give the all-clear.
    Regards,
    Panda
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download Blacklight Beta.

    * Download blbeta.exe and save it to the Desktop.
    * Once saved... double click blbeta.exe to install the program.
    * Click accept agreement and Click scan
    This app too may fire off a warning from antivirus. Let the driver load.
    Wait for it to finish.
    * If it displays any items...don't do anything with them yet. Just hit exit (close)
    * It will drop a log on Desktop that starts with fsbl....big number

    Please post contents of the BlackLight log.
     
  21. Bad Panda

    Bad Panda Private E-2

    If I read the program correct, it was clean. Here is the log...
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please put copies of the current files into a ZIP file and have it attached:
    Code:
    "C:\WINDOWS\system32\"
    admparsa.dat  Nov 28 2008         260  "admparsa.dat"
    hlp95elc.dat  Nov 28 2008        1592  "hlp95elc.dat"
    mp43decp.dat  Nov 28 2008         260  "MP43DECP.dat"
    msaudiwe.dat  Nov 25 2008         157  "msaudiwe.dat"
    ulibmhg.dat   Nov 28 2008         260  "ulibmhg.dat"
    
     
  23. Bad Panda

    Bad Panda Private E-2

    Here ya go....
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'd like to see the result of running this:
    Dr.Web CureIt

    We may have to then start looking at your running processes to see what is triggering these files.
     
  25. Bad Panda

    Bad Panda Private E-2

    Had a few problems but here is your list. I have not been able to reboot the computer as indicated in the steps because I can't move the uncurable yet.
     

    Attached Files:

  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have no delete or move options? You don't have to worry about the files found in the system restore files....nothing will fix them other than toggling system restore.
     
  27. Bad Panda

    Bad Panda Private E-2

    I tried the select all option and it doesn't do anything. Several items have deleted or incurable.moved next to them...but many others don't have any information under the tab Action. Those are the ones I can't do anything with.
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please tell me which ones they are.
     
  29. Bad Panda

    Bad Panda Private E-2

    Several of them deal with a listing of C:\documents and settings\owner\desktop doctor1.5.1.exe. There is also c:\program files\support.com\temp\fullagent.exe.
    Several in the restore directories.
    Is that what you needed?
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to toggle system restore to remove the files in your system restore folders.
    Then after doing that, run both SAS and MBAM and get me a new MGLogs.zip.
     
  31. Bad Panda

    Bad Panda Private E-2

    Here is the log. They took quite a while to complete...
     

    Attached Files:

  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would suggest you find and delete them....unnstall Desktop Doctor.
    And also find and delete:
    Code:
    C:\WINDOWS\system32\"
    admparsa.dat  Dec  8 2008         707  "admparsa.dat"
    hlp95elc.dat  Dec  8 2008        3980  "hlp95elc.dat"
    mp43decp.dat  Dec  8 2008         707  "MP43DECP.dat"
    msaudiwe.dat  Nov 25 2008         157  "msaudiwe.dat"
    perfc009.dat  Nov  3 2008       65044  "perfc009.dat"
    perfh009.dat  Nov  3 2008      410574  "perfh009.dat"
    ulibmhg.dat   Dec  8 2008         707  "ulibmhg.dat"
    
    Now run Dr.Web again and attach the log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  33. Bad Panda

    Bad Panda Private E-2

    Getlogs got a "language error" when I ran it. If the log appears incomplete, let me know and I'll go through the uninstall process and restart it.
     

    Attached Files:

  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean. But I would like you to do this:

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Then run CCleaner --> both the cleaner and the issues ( be sure to do the backup when prompted) ....now let me know if you are still having issues.
     
  35. Bad Panda

    Bad Panda Private E-2

    CCCleaner found 183 registry entries. Other than that, everything is working fine. Thank you very much Tim. I appreciate all the effort in this! Merry Christmas!

    Panda
     
  36. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are quite welcome.....it was a tough one. Safe surfing. :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds