Privacy Center Infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by racarl, Nov 28, 2009.

  1. racarl

    racarl Private E-2

    I became infected with Privacy Center. RAn SAS several times and couls nor get rid of it. Could not run in SAFE mode, also lost desktop. Used TaskManager to get it to close and finally loaded up ie7 to get to Major Geeks. Then ran W32KDiag, ComboFix and was able to get Desktop to appear. Then ran MGTools, but would not get past zipping Hijackthis.log. Privacy center icon still present on toolbar
     

    Attached Files:

  2. racarl

    racarl Private E-2

    I reran all the READMEfirst tools. Seems to have solved my problem. Attached are files:
     
  3. racarl

    racarl Private E-2

    Found SAS log, see attached

    UPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 11/28/2009 at 11:47 PM

    Application Version : 4.29.1004

    Core Rules Database Version : 4316
    Trace Rules Database Version: 2177

    Scan type : Complete Scan
    Total Scan Time : 00:06:13

    Memory items scanned : 384
    Memory threats detected : 0
    Registry items scanned : 6538
    Registry threats detected : 0
    File items scanned : 1883
    File threats detected : 2

    Trojan.Agent/Gen-ImageDocFake
    C:\DOCUMENTS AND SETTINGS\ROGER\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\I230GK8Q\BBB5[1].PNG
    C:\DOCUMENTS AND SETTINGS\ROGER\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\UIZRP25N\DDD5[1].PNG
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please remember that logs should always be attachments and that you should always attach all logs requested in the READ & RUN ME. Also you should not be running fixes given to another user. You took fixes from this thread: http://forums.majorgeeks.com/showthread.php?t=200344&highlight=OEAddOn.exe

    And created your own CFScript.txt for ComboFix which is a very bad idea. Every fix posted is individually created for that individual PC.

    Are you still having problems? If yes, please attach the logs from Malwarebytes and RootRepeal. Based on the logs you did attach, I believe you have more to do.
     
    Last edited: Nov 30, 2009
  5. racarl

    racarl Private E-2

    You are correct, I didn't know if the CFScript was generic or specifc. I do not seem to be having problems, but I am open to all of your suggestions.

    Sincerely,

    racarl
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then you still need to attach the requested logs from Malwarebytes and RootRepeal. In fact, based on your logs, you did not run Malwarebytes this time. The last time you ran it was Oct 26, 2009 which means you are way out of date with updated and need to update it and then run a new scan. You still have things to fix from Privacy Center which we will do below.


    Uninstall the below old versions of software:
    ewido anti-spyware 4.0 <-- was discontinued years ago and is part of AVG's Antivirus program now.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O4 - HKCU\..\Run: [agent.exe] C:\Documents and Settings\Roger\Application Data\PC\agent.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe (file missing)

    Also we don't recommend you put anything into the Trusted Zone unless 100% necessary so fix the below unless you are sure they are absolutely required which is very rare.
    O15 - Trusted Zone: http://visitor.constantcontact.com
    O15 - Trusted Zone: http://www.extremetrends.net
    O15 - Trusted Zone: *.intuit.com
    O15 - Trusted Zone: http://www.marketwatch.com
    O15 - Trusted Zone: http://a.pollg.com
    O15 - Trusted Zone: http://b.pollg.com
    O15 - Trusted Zone: http://e.pollg.com
    O15 - Trusted Zone: http://g.pollg.com
    O15 - Trusted Zone: http://i.pollg.com
    O15 - Trusted Zone: http://j.pollg.com
    O15 - Trusted Zone: http://k.pollg.com
    O15 - Trusted Zone: http://t.pollg.com
    O15 - Trusted Zone: http://v.pollg.com
    O15 - Trusted Zone: http://*.pollg.com
    O15 - Trusted Zone: http://*.tkqlhce.com
    O15 - Trusted Zone: http://*.turbotax.com

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • RootRepeal log
    • Malwarebytes log
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Dec 3, 2009
  7. racarl

    racarl Private E-2

    I uninstalled Ewido. I ran Mgtools.exe. It does not offer any screens to select the file suggested above, just records a file. Does not allow me to select files or run a "fix" session. After it runs the HijackThis.log, the Command window stays open and does not close.
     

    Attached Files:

  8. racarl

    racarl Private E-2

    I then ran Combofix, for some reason, it also ran from the cmd window. It found a rootkit issue, rebooted and than ran again. During running of Stages, I received an error message saying PEV.exe encountered a problem and needed to close, I selected okay. Attached is the combofix file

    I then ran CCleaner - Run Cleaner.

    You asked for the malawarebytes log and the RootRepeal logs, but did not ask me to run them again? I attached the older versions run earlier in the week.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not ask you to run MGtools. I asked you to run C:\MGtools\analyse.exe
     
  10. racarl

    racarl Private E-2

    I re-ran C:\MGtools\analyse.exe
    Then re-ran ComboFix
    Updated CCcleaner and ran.
    Then ran MGTools\getlogs.bat
    I then ran Root Repeal

    Attached is MGLogs.zip, ComboFix.txt and root repeal.txt
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
    racarl likes this.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds