AACCKK!! Trojaned/Malwared out the yingyang

Discussion in 'Malware Help (A Specialist Will Reply)' started by lajmd, Mar 5, 2009.

  1. lajmd

    lajmd Private E-2

    Newbie to the post, but hopefully I have done my homework before I posted here. So here goes -- All of this CRAP started on Monday evening. I was downloading a file that must've been infected. A bit torrent file. Am I stupid or what? The screen went to blue and then all hell broke loose. The upshoot was that I kept getting error messages (DOZENS of them) that sovupuda.dll was not a valid Windows image.

    Being the naive idiot that I was I thought it was a .dll problem so I used a registry cleaner to "fix" things. HAH! said God! And so then all my desktop icons became .lnk icons. Then I realized I had a major problem. Duh!

    At that point I realized it was a far bigger problem and only then combofistarted doing my homework. I was able to download and get Combofix to run, Spybot search and destroy, AVZ and Malwarebytes Anti-Malware. As you can imagine I was able to catch QUITE a few problems and destroy a fairly heft amount of malware, spyware and trojans. Strangely I was NOT able to get SAS to run. Everytime I tried to run that it would say I had an error with the "H" drive and would abort. I tried renaming it to no avail. I did run a tweak for the desktop icons, but the weird thing is when I reboot they are okay and then about 1/2 hour later they revert back to not working. Not that they go back to the .lnk but they just won't allow me to open programs OR the computer from the desktop and when I right click the menu I get is incorrect - I can only cut, paste, and check properties rather than run the program as a choice. I am going to attach the logs I have from my various runs. The order I ran them was Combofix first, then AVZ, then Spybot, then Malwarebytes, then Combofix again. I did the Spybot, Malwarebytes, and Combofix based on the sticky about how to clean an XP system and YES I followed all the rules laid out. I still am not sure that I am clean. When I reboot I am still getting some errors and I think I might still be infected with mofayade.dll and tobirugo.dll problems. I also get some error messages when I reboot that are not allowing my ATI Catalyst Control Center to work nor can the Amazon Unbox player work either. Also I am getting a rundll error.

    Please help!! Thanks in advance for reading this tale of woe!! I am sending a total of five logs. Three with this post and two with the next post. These are attached in order of how I ran the different programs. Check for the next post where I will put the logs for Mbam and Combofix 3. I haven't run SAS because of the problem I had loading it and I haven't run MGTools yet either.
     

    Attached Files:

  2. lajmd

    lajmd Private E-2

    Second post with two more logs - AACCCKK!!

    SEE FIRST THREAD ENTITLED AAACCCKK!! Trojan/Malwared out the Yingyang

    Here is the second post with the last two logs. Any and all help will be GREATLY appreciated! Should I run the MG Tools at this point or what?
     

    Attached Files:

  3. lajmd

    lajmd Private E-2

    AACKK- Last post with MG Tools log attached

    I finished the rest of the things needed to help me by running the MG Tools from the c: root. The log for that is attached. I hope this helps you all figure out my myriad of issues. Again, THANKS SO MUCH!!!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    First we need to take care of some issues that you missed while running the READ & RUN ME.
    1. You must disable Spybot's Teatimer as requested in the READ & RUN ME. See this: How to disable Spybot's TeaTimer
    2. You have multiple antivirus programs installed. You need to either uninstall McAfee or Verizon Internet Security Suite immediately and then you MUST reboot. We may have to take additional steps later to finish fixing things due to installing multiple security programs as they may not remove properly now.
    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 10
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 11
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6 Update 1
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Did you purchase the below? If not, I suggest uninstalling these immediately.
    Uniblue DriverScanner 2009
    Uniblue SpeedUpMyPC 2009
    Uniblue System Tweaker

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O15 - Trusted Zone: http://*.cinemanow.com
    O15 - Trusted Zone: http://*.mcafee.com
    O15 - Trusted Zone: cms.nasa.gov
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. lajmd

    lajmd Private E-2

    Hi chaslang,

    Couple of hiccups occurred as I went down the list of directions you sent:

    First of all, I am unable to uninstall the Verizon Internet Security Suite which I would prefer to uninstall rather than McAfee. This was installed when I got Fios and without my knowledge. When I try to uninstall it I am told that I have to reboot before I can. I reboot and I try again and get the exact same message. Any tricks to getting it uninstalled? If push comes to shove, I'll uninstall McAfee but I figured I'd ask. I don't like having a program on my computer than I can't get rid of!

    Secondly, I am able to uninstall all JAVA updates except the following:

    J2SE Runtime Environment 5.0 Update 10
    Java 2 Runtime Environment, SE v.1.4.2_03

    when I try to get rid of these I get this error: "Error 1327. Invalid Drive H:\"

    Based on these two problems I didn't know whether or not to continue the fixes.

    This is what I've done so far:

    I have disabled Teatimer (which I had clicked NOT to install, but I guess it installed anyway).

    I am in the process of cleaning up my desktop as well. My bad.

    I removed Windows Messenger and all other Java updates and also removed Viewpoint Media Player.

    I also removed all the Uniblue products.

    This is where I stopped until I hear back from you on the two troublespots I listed above.

    THANK YOU SO MUCH for all your help! I'll await your reply!

    LAJMD
     
  6. lajmd

    lajmd Private E-2

    And more...

    I decided to continue to do as much as I could.

    I cleaned up the desktop leaving only those icons that go directly to a program execute.

    I retried deleting the Java again and was successful. I still could not delete the Verizon Internet Security Suite.

    I ran MG Tools analyse.exe. I checked all BUT the line 015 Trusted Zone: cms.nasa.gov because this is a Content Management System I use for work. If I need to go back and "check" that and rerun that step I will, but I thought I should check first because I do need to be able to run that CMS for my job.

    I opened notepad and copied the info and then ran it with Combofix.exe (file attached).

    I rebooted and then downloaded the updated Java.

    I ran Ccleaner.

    I ran MG Tools\GetLogs.bat (file attached).

    It seems to be running much better but I guess I still need the attached files analyzed to make sure that all the malware is gone now.

    THANKS AGAIN!!

    LAJMD
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    You also have a 3rd item with antivirus which is Fix-It Utilities 7 Professional. You need to uninstall this now since it has installed Authentium AntiVirus.


    Then try uninstall the below again:
    Verizon Internet Security Suite
    Verizon PC Security Checkup

    If they do not uninstall, try using the below software to uninstall them:
    Your Uninstaller! 2008


    Your MGlogs.zip file shows that one application is not getting a proper log. Please refer to Error Message Type 1 in this link Using MGtools and apply that fix.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. lajmd

    lajmd Private E-2

    THANKS ONCE AGAIN! You are a MIRACLE WORKER! I have uninstalled both the Fix-It Utilities and the Verizon mess! I found a fix on the Verizon forum on how to uninstall their virus stuff so I finally got rid of that!

    I applied the Fix on Error Message 1 and I have attached my log from the GetLogs.bat.

    Strangely, though, at the end of this I did get an error message "Process DLL.exe" error followed by "Registered JIT debugger not available." Not sure what this is or means, but it happened at the end of the GetLogs.bat application.

    Sorry it took me so long to get back to you. VERY BUSY WEEKEND out with the cub scouts.

    Things seem to be working fine now. I can't thank you enough for all your help!:clap

    lajmd
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Something is still preventing it from working properly and I would like to try and figure out what.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.


    Not a major issue since we don't need the log from Processdll.exe right now. It could be a problem with your .NET installation or it could be due to a software conflict. I have heard of some people with DELL PCs having this problem until they uninstalled the Dell Support software, but I don't know if this is your problem or not. Some people also said repair their .NET Framework installation helped. See: http://support.microsoft.com/?id=824643 Seems that many people have seen error messages like you got but no one really has the exact fix.
     
    Last edited: Mar 18, 2009
  10. lajmd

    lajmd Private E-2

    I copied the output from running showme to a notepad file and have attached it.

    I've also attached the MGlogs.zip

    Hope this helps! Thanks for everything!!

    lajmd
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmmm! That's a new one.


    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    locate *.exe /NR <-- this will try to run the locate command which is part of MGtools. There is a space before the * and before the /. If it works, the output should look like the below
    Code:
    C:\MGtools>locate *.exe /NR
    C:\MGtools\
       analyse.exe    Thu Jul 12 2007  10:56:14p  A....        401,720   392.30 K
       catchme.exe    Fri Jun 13 2008   5:09:08p  A....         28,672    28.00 K
       driver~1.exe   Tue Oct  7 2008   2:22:08a  A....         30,720    30.00 K
       getdet~1.exe   Mon Oct 30 2006  11:17:58a  A....        245,760   240.00 K
       grep.exe       Mon Apr 14 2003  12:00:00a  A....         80,412    78.53 K
       ltime.exe      Tue Oct 28 1986  11:51:06a  A....         13,184    12.88 K
       process.exe    Thu Jun  5 2003   8:13:46p  A....         53,248    52.00 K
       proces~1.exe   Tue Aug  1 2006   8:14:52a  A....          6,656     6.50 K
       sed.exe        Thu Aug 31 2000   8:00:00a  A....         98,816    96.50 K
       swreg.exe      Sun Dec 16 2007   5:36:08p  A....        156,160   152.50 K
       swwhoami.exe   Sun Dec 16 2007   5:47:26p  A....         66,048    64.50 K
       vfind.exe      Fri Dec 28 2007   2:42:12p  A....         49,152    48.00 K
       zip.exe        Thu Jan 13 2005   9:41:50p  A....        126,976   124.00 K
    13 items found:  13 files, 0 directories.
       Total of file sizes:  1,357,524 bytes      1.29 M
    Do you see this output or did you get another error message like you had before? Like below:

    The process cannot access the file because it is being used by another process.


    SN64.bat <-- this will try to run another command which is part of MGtools which is a 64 bit compatible version of ShowNew.bat. Let me know if this gets any error messages. Attach the C:\MGlogs.zip file which will be updated by this.
     
    Last edited: Mar 20, 2009
  12. lajmd

    lajmd Private E-2

    When I run the script exactly as you have outlined, the only thing that happens is that the command goes right back to:

    C:\MGtools>

    Nothing else.

    lajmd
     
  13. lajmd

    lajmd Private E-2

    Just realized about the last part. I ran the SN64 and did not get errors with that. I have attached the MGlogs.zip

    THANKS!

    lajmd
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your new log is clean so at this point it appears all your malware has been fixed. But you should do the below.

    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Lynn\Local Settings\TEMP


    I'm still just curious about why the locate command will not run.

    Strange. It seems like you cannot run a .com file.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    mode <-- this will try to run the mode.com command which is part of Windows. If it works, the output should look something like the below for your user account.

    Code:
    C:\Documents and Settings\Lynn>mode
    Status for device LPT1:
    -----------------------
        Printer output is not being rerouted.
     
    Status for device COM2:
    -----------------------
        Baud:            1200
        Parity:          None
        Data Bits:       7
        Stop Bits:       1
        Timeout:         OFF
        XON/XOFF:        OFF
        CTS handshaking: OFF
        DSR handshaking: OFF
        DSR sensitivity: OFF
        DTR circuit:     ON
        RTS circuit:     ON
     
    Status for device COM1:
    -----------------------
        Baud:            1200
        Parity:          None
        Data Bits:       7
        Stop Bits:       1
        Timeout:         OFF
        XON/XOFF:        OFF
        CTS handshaking: OFF
        DSR handshaking: OFF
        DSR sensitivity: OFF
        DTR circuit:     ON
        RTS circuit:     ON
     
    Status for device CON:
    ----------------------
        Lines:          2010
        Columns:        80
        Keyboard rate:  31
        Keyboard delay: 1
        Code page:      437
     
    C:\Documents and Settings\Lynn>
    
     
    Last edited: Mar 27, 2009
  15. lajmd

    lajmd Private E-2

    Sorry it too me so long to get back to you! I've been hammered at work. Anyway, I was able to get the mode to work on the commmand line and have attached the output. THANK YOU SO MUCH FOR EVERYTHING!!

    lajmd
     

    Attached Files:

    • mode.txt
      File size:
      667 bytes
      Views:
      1
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Well that did not show me anything to help figure out why the locate program would not run. :( Anyway your logs were clean and you should do the below now.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds