Hi-Jack This v2.0.2 08/05/09

Discussion in 'Malware Help (A Specialist Will Reply)' started by scottie916, Aug 5, 2009.

  1. scottie916

    scottie916 Private E-2

    I am a "pretty careful" user, but every once in a while.....

    So, here I am looking for some assistance. I use iS3:Stopzilla v5.x, McAfee Anti-Virus Plus (AV 13.11, FW 10.11, SC 9.11) all up to date. I also use MalwareBytes v1.40 (found a couple of things), SpyBot Search & Destroy (clean).

    But, my PC still runs VERY SLOW in "normal mode", a little faster in "safe mode w/networking". In "normal mode" a McAfee scheduled scan w/maximum CPU usage around 5:30am takes 12+ hours to complete?!?!

    I recently "patched" my IE v7.x with MS's patches due to big security holes found a couple of weeks ago. Before this, PC was "screaming" along.

    PC Specs....
    AMD Athlon 64 x2, Dual-Core 3800+, 2.0 GHz, 2000 MHz System Bus
    2 gigs of RAM
    nVidia GeForce 6150LE GPU (w/latest driver)

    I am also attaching my HJ This log from the "safe mode w/networking" boot.

    Would appreciate any & all help!
     

    Attached Files:

  2. scottie916

    scottie916 Private E-2

    Addendum....

    I will be submitting an item, by item list of what I performed via the "Malware removal steps" that have been written.

    Hopefully, it will get me some help as I believe I am still infected with something thanks!

    -Scott
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.
    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First. If TDSSserv is not found, just continue on with the READ & RUN ME.
    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:
    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  4. scottie916

    scottie916 Private E-2

    Chasang,

    Please pardon my stupidity. I am pretty confused by your reply, can you explain a little differently?

    So here is my step-by-step "log" of what I did:

    (safe mode)
    - uninstalled Viewpoint Media Player w/ Revo uninstaller (reboot finished delete)
    - Updated Java to new version
    - Reboot reported "Recovered from serious error" (blue screen)
    - Check for SAS updates (none)
    - Update Java to 6.15
    - AOL v9.1 displays "Flashplayer security warning", unsure - I ignore it.
    - restart w/CHKDSK c: /F (PC takes 10+ minutes to shutdown)
    - CHKDSK c: /F (no issues)
    - reboot PC (very slow, takes 5-7 minutes)
    - MSconfig (all are checked), "Access denied need Admin"
    - Clean XP (D/L SAS, I have StopZilla, no issues)
    - D/L Combo Fix to desktop (NOT RUN)
    - D/L MGTools to c:\ (NOT RUN)
    - Install SAS (OK)
    - Update
    - Diagnostic yes issues found)
    >> 0 memory items out of 708
    >> 0 registry items out of 6942
    >> 2 file items (error doctor setup.exe)
    >> 6 out of 10 rating (Smith Fraud type "extortiion ware")
    >> clicked NEXT
    >> MS Visual C++ runtime error R6025; pure virtual function call
    >> OK; SAS closed
    - HDD light still "burping" along
    - McAfee AV Scan running (cancelled it)

    - Reboot into "Normal Mode"
    >> Had to "end program-layered window"
    - Windows shutting down, took about 10 minutes

    - Reboot into "Safe mode w/networking" to rerun SAS in safe mode
    - "stuck" @ blue progress bar (bootup) on WinXP screen
    - Power OFF/Boot into "safe mode w/networking" after about 10 minutes
    >> HDD light stays on steady
    - choose [owner] as logon
    - Rerun SAS w/updates @ 7:00am (full scan)
    - Found cookies & Trojan

    - Reboot into "Normal mode"
    >> took about 10 minutes to shutdown/restart
    >> startup slow, (10:50am - 11:25am)

    - Power off/on
    >> F8 using last known good settings

    Attached are the following logs.... (I hope)

    SAS, 08/06/09 @ 3:06a, runtime 3:28:42 (issues), core/trace rules: 4041/1981
    SAS, 08/06/09 @ 8:52a, runtime 1:54:08 (issues), core/trace rules: 4041/1981
    SAS, 08/07/09 @ 4:00p, runtime 5:21:56 (issues), core/trace rules: 4043/1983
    SAS, 08/08/09 @ 2:41a, runtime 3:57:14 (issues), core/trace rules:
    4045/1985
    SAS, 08/09/09 @ 7:54a, runtime 3:09:19 (clean), core/trace rules:
    4046/1986

    Hi-Jack This.... (I hope)

    Scan saved at 5:04:42 PM, on 8/5/2009, Safe Mode w/Networking
    Scan saved at 5:30:22 PM, on 8/9/2009, Safe Mode w/Networking

    I Hope all of this information helps.

    You assistance is appreciated very much!!!

    -Scott
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No not really. Those steps are very detailed so that they can guide users of all levels from beginning to end and you need to follow them. You should have obseved that in no place in those instructions do we ask for a HijackThis log. In fact we specifically state not to post one. You need to run only what we asked you to run. We did not ask you to run chkdsk. You need to finish running Malwarebytes, ComboFix and MGtools and attach the logs we asked for.
     
  6. scottie916

    scottie916 Private E-2

    08/18/09 - SAS, Combofix, MGTools

    chaslang,

    Thanks for your replies. I apologize for going "out of order". As I printed out & read the directions, running the ComboFix and/or the MGTools, I thought was a no-no unless we are explicitly told to do so???

    Your last message seems to "authorize" me to run these two tools?

    Am I to run them?
    SAS does not find anymore after repeated scans with new DAT files.
    PC still boots really slow and takes 10+ minutes to shutdown.

    Understandably, I am pretty "scared" to run these tools when I do not have a 100% reliable backup of my C: drive.

    Thanks, I await your reply.

    -Scott
     
  7. scottie916

    scottie916 Private E-2

    08/18/09 - ComboFix Log run

    Chaslang....

    I installed CF following the steps provided:

    * Critical update required
    - I, OK'd

    * CF shall now restart
    - it did

    * McAfee warned of a registry change
    - I approved of all of them

    * CF "warns" of a tainted version and may need to re-download
    - I, OK'd

    * CF Disclaimer
    * CF created a restore point

    * CF found the MS Recovery Console was not installed
    - I OK'd its installation
    * EULA
    - I clicked Yes

    * CF begins its scan
    * McAfee "warns" that the firewall & AntiVirus are turned off
    * CF ran to completion
    * SEVERAL windows errors were reported requesting to be sent to MS
    * CF generated a report (attached)

    * CF closes, returns me to the desktop
    - I had to "restore my active desktop", did not work.
    * Restarted PC
    * StopZILLA, on reboot, found 28 infections:
    - Trojan: Catchme (22 entries)
    - Cograc: Adware (2 entries)
    - System Policies: HiJacker (4 entries)
    * Removed & rebooted PC

    ( After reboot, tried to run AOL (yukk, I know)...
    - Blue Screen
    "Driver_IRQL_NOT_LESS_OR_EQUAL"
    * 2nd time I have seen this message
    - nothing new added/installed except for my Belkin "G" Router
    * Suggests I disable memory options (caching or shadowing)
    * 0x000000D1 (0x00000064, 0x00000002, 0x00000000, 0x8490B44C)

    >>> I am going to move forward and run the RootRepeal (step 4)
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: 08/18/09 - SAS, Combofix, MGTools

    No! They are part of the normal cleaning instructions just like the other steps. There is nothing saying that you need permission to run them. You just need to follow all stpes given in the procedure upto and including the attaching of the requested logs.

    You are not supposed to be running any scans more than once. See the instructions.

    We cannot help you without logs, but backing up your important data is always a very good idea since malware can be very nasty and the act of removing can sometime cause a PC to become unbootable. This is rare but it can happen.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: 08/18/09 - ComboFix Log run

    You need to run all of the below and attach the logs. These were all part of the instructions.

    • Malwarebytes Anti-Malware
    • Root Repeal
    • MGtools
    Then you need to explain what malware problems you are still having.
     
  10. scottie916

    scottie916 Private E-2

    08/22/09

    Chaslang,

    Thanks for the "hand holding".

    I have completed all of the steps and am attaching the MGTools log file: MGlogs.zip.

    I am attaching the Combofix log: ComboFix.txt, 47k, created: 08/18/09

    NO LOG for RootRepeal Kit?

    Previous posts have included SAS logs.
    Previous posts have included Anti-Malware logs.

    Currently... NO SAS items have been found.
    Currently... NO Anti-Malware items have been found.

    Thanks!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not put your PC into Normal Startup mode with MSconfig as requested in step 4 of the READ & RUN ME. You need to do this now.

    Yes there is supposed to be a log. See the instructions for running it and get us a log. You saved 2 of them. We need the larger one
    Code:
    "C:\"
    Aug 18 2009      16  "RootRepeal report 08-18-09 (20-04-44).txt"
    Aug 18 2009    2244  "RootRepeal report 08-18-09 (20-15-49).txt"

    You still have not explained what malware problems you are having.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 2

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - (no file)
    O23 - Service: KODZJ - Unknown owner - C:\DOCUME~1\OWNER~1.YOU\LOCALS~1\Temp\KODZJ.exe (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Aug 26, 2009
  12. scottie916

    scottie916 Private E-2

    08/26/09 - update.

    Chaslang, got your last message and have completed all of the steps. Please note the below comments from the run:

    * changing to "Normal Startup" always returned a msg ".. requiring ADMIN account .." to make these changes. THE OPTION SEEMED TO CHANGE, although.

    * AFTER checking the O2 & O23 items, HJT REQUIRED a restart to complete the changes. I clicked [YES] to reboot.

    * AFTER reboot, I cut & pasted the "KILLALL::" text.
    * SAVED the txt file & dragged over ComboFIX on my desktop.
    * FOLLOWING prompts, following notes:
    - Current Date is: ~. ComboFix has expired. Click [YES] to run in REDUCED FUNCTIONALITY MODE.
    - I clicked [YES]
    - Preparing to run.....
    - New Restore point...
    - Scanning... Stage_49 (McAV balloon msg pops up)
    - Deleting files (kgpcpy.cfg)
    - REBOOTING

    * AFTER auto-reboot CCleaner auto runs as part of startup

    * Ran GetLogs.bat

    Attaching the following logs:
    - C:\ComboFix.txt
    - C:\MGlogs.zip
    - C:\rootrepeal report 08-18-09 (20-15-49).txt

    ================
    iS3 StopZilla has recognized the "CatchMe Trojan" and is running its own FULL SCAN.

    MY ISSUE(s)... is that the WinXP SP3 shutdown takes 10+ minutes to complete. AND... the WinXP SP3 startup takes 5-7+ minutes to complete.

    I am also "thinking" that the Belkin Router I installed (but failed) with their "help desk" having me configure it via the router's IP directly may also be causing a BIG issue. I cannot uninstall the Belkin Router file(s) as there is NOT an entry to uninstall with in the control panel.
    =================

    Thanks for your help!!!
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you needed to update as implied in my instructions that said
    The fix will not work if you run in reduced funtionality mode. Please try again beginning with the ComboFix steps and first download the current version of ComboFix. You will have to attach the logs again at the end.

    StopZilla does not know what it is talking about. CatchMe is a rootkit scan from GMER and is used by ComboFix and many other tools.

    May just be due to what you are running. Most likely culprits McAfee and StopZilla. In fact StopZilla is probably not a good idea to have installed since you have McAfee's Security Suite installed. But first we need to finish your malware removal before deciding anything about this.

    I'm sorry but this is not a malware forum topic and most routers do not really require and software to be installed anyway for them to work. Typically you can just access them via your browser and configure the settings you need via an HTML interface.
     
  14. scottie916

    scottie916 Private E-2

    Chaslang,

    Thanks for all of your help. I am now using SAS with any friends PCs who report to me they are having issues. As far as my PC... I had to break down and replace the MB. Seems the ECS v1.0 board ended up "dying" to where it just would not POST.

    With all this fixed, I am keeping myself updated with SAS, AMW, SZ, AVG and making sure to run regular scans to keep up / ahead of the game.

    With all of this stated, I still found some of the instructions a little difficult to follow - at times - I would like to suggest that some items I pointed out be considered for updates / corrections to the overall steps provided.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Replacing the mother board will not remove any malware from the hard disk. Did you format and reinstall?
     
  16. scottie916

    scottie916 Private E-2

    Yes.

    MD replaced.
    HDD reformatted & reloaded with a full WinXP Media Edition 2005 w/SP3.

    They installed AVG 8.x (30-day trial) which they say is the "best". I prefer McAfee along with the SAS & MB and my StopZilla...

    The BIG issue from the rebuild is that the "techs" did not backup/restore a folder belonging to a user "DEL" which had 1000's of pictures. They claim "DEL" made them think Dell computers and since this was not a Dell, it did not need to be backed up...

    They have "offered" to rescrub the drive to try and recover files, folders, images like how the "active@delete" utility does it.

    Do you have an opinion?!?!?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Very unlikely to be successful.

    Remember that the free versions of SAS & MBAM provide no protection.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds