"Advanced Performance Platform Cashtitan" persists.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mark999, May 10, 2011.

  1. mark999

    mark999 Private E-2

    Hello,

    I've searched the forum and I followed the directions I found for removing malware, which was a reply to this named bug for another post.

    My problem began about a week ago and it is a pop error for my AVG 9.0 anti-virus software. It simple states that it has encountered any error and needs to close. Every attempt to close the software failed.

    Today I decided to uninstall and then reinstall AVG 9.0 build 663. During the initalizing for the install AVG give me a warning about the "Advanced Performance Platform Cashtitan" software and strongly recommends it's removal in order for AVG to work properly.

    Sorry, but I cannot remember exactly what I was doing when this error first began to appear.

    I followed all the instructions carefully, and this whole process has taken several hours. I have attached all logs within this message. There are only four because MGtools did not create a zip file. I ran it twice to be sure. The DOS prompt flashed on and off very quickly, so I wasn't even sure if it did anything. The folder containing all the various files is there and populated, however, there is no MGTools.zip

    My operating system is Windows XP Home Edition Version 2002 Service Pack 3.

    I thought I had no more problems and went to the step of turning off the system restore. It didn't ask to reboot and I have not. I simply began the process of reinstalling the AVG software and got another warning of the conflicting software (malware). That's when I came here to post this message.

    Thank you in advance for any assistance.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please do this, click Start, Run and enter cmd and click OK. This will open a command prompt window. In the command prompt window, enter the below commands each followed by the enter key. Note there is a space after the cd

    cd \MGtools
    GetLogs.bat

    Do you now have a C:\MGlogs.zip? If so please attach it. Otherwise... you will have to run the below.

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  3. mark999

    mark999 Private E-2

    Still no MGtools.zip after running the GetLogs.bat from the MGtools directory.

    Attached are the two OTL files.

    Thanks!!!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    FireFox::
    FireFox-: ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\1lajir5q.default\
    FF - prefs.js: keyword.URL - hxxp://www.scanquery.com/?tmp=nemo_results_removelink&prt=ScnqryPB&keywords=
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    Run this and attach the results.

    Using ESET's Online Scanner

    Tell me how things are running now?
     
  5. mark999

    mark999 Private E-2

    I saw no errors. These commands did produce two reports which I can post if necessary.

    I also performed the TDSSKiller and ESET's Onlline Scanner. See Attached.


    My PC now has a noticeable improvement in speed, especially during boot up. Since I was only seeing a reference to "Advanced Performance Platform Cashtitan" during an attempt to reinstall old AVG software I decided to get rid of that software and update to the new AVG anti-virus protection software, which installed just fine with no indications of the previous software (malware) conflict.

    It appears that the problem has been resolved, unless the latest logs indicate otherwise. I guess now it's time to cleanup all these desktop tools and reports?

    Thanks for all the help. This site is awesome!
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes please :)
     
  7. mark999

    mark999 Private E-2

    I guess I missed the zip file last night. I was looking for it within the MGtools folder and it was in C:\ with the executable program. Sorry about that.

    I re-ran MGtools and attached the zip file.

    Even if I have screwed up now my PC is still far better than it was!
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Click Start, Run, and copy and paste the below into the Run box and click OK.


    This should bring up your preferences file for FireFox in a notepad window. Look for lines containing the below information and delete the whole line where it appears.

    After deleting those lines, click File, and select Save. If you cannot save the file, close all browsers first before saving.

    Did you set the below proxy yourself?

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =http://127.0.0.1:4664/&s=CPXC3gXJiRLeSOElpXMmElRPJpo

    If not:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/&s=CPXC3gXJiRLeSOElpXMmElRPJpo

    After clicking Fix exit HJT.

    Run Combofix again simply by a double click.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just an FYI. The below still need to be removed.

    Uninstall Conduit Engine

    Delete the below file:
    C:\WINDOWS\system32\ConduitEngine.tmp

    And to remove Cashtitan from Add/Remove Programs, the below registry patch can be used:



    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  10. mark999

    mark999 Private E-2

    I have successfully completed all the tasks, including uninstalling Conduit Engine and performing the fixme.reg.

    Attached is the latest ComboFix.txt and Mglogs.zip.

    Note: While I was attempting to disable/close the recent version of AVG anti-virus software in order to run combofix, I encountered the same issue with the old version. No error messages like before, however, the program simply would not close. I had to try and uninstall it and it stalled during that process. I had to abort the uninstall which left the program fragmented. I had to reinstall it again so I could try to uninstall it again. I was successful on the second attempt at uninstalling it and combofix ran successfully.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to delete the below file:
    C:\WINDOWS\system32\ConduitEngine.tmp


    Are you having any more malware problems?
     
  12. mark999

    mark999 Private E-2

    I did delete it. Just forgot to mention it here.

    No more problems. I decided to not use the AVG AV software and, instead, went with some free tools recommended here.

    I'm using the following:

    • Avira Anti-virus
    • Comodo Firewall
    • Spybot- SD Resident

    Are there any other protection tools I should be using? Also, what are the next steps to finishing these resolutions? I think I have to rerun defogger and remove some of the tools and reports.

    I just noticed that the most recent logs have not been viewed yet. I will wait until I hear back from you guys before I make any changes. All I have done is add the protection software mentioned above and I downloaded them from this site.

    I'd like to say THANK YOU very much to Kestrel13! and chaslang for all the help. :)

    A site that helps people for the sake of helping people - who'd have thunk it? Just awesome!
     
    Last edited: May 12, 2011
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    It was still in the logs you attached.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. mark999

    mark999 Private E-2

    I think I remember that I had seen that I missed that step after running combofix. At any rate, the file has been removed. Hopefully, the step being performed after combofix wasn't a problem. :confused

    This software was not in add/remove programs.

    I have now completed all of the final steps. The only thing that remains is the MGtools.exe and the Mgtools folder. I saw no uninstall.bat file and it's not in the add/remove software. Should I simply delete this folder and it's contents, then delete the .exe file?

    Thank again! :)
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See step 8 of my final instructions.
     
  16. mark999

    mark999 Private E-2

    I performed step 8 just as originally instructed. It did remove some of the files, as MGclean.bat itself no longer existed afterwards. However, the folder and most of it's contents did remain, as well as the exe file.

    I simply deleted the folder and the program. If there are left over rogue files...oh well. I hope to upgrade to a new PC soon anyway.

    Thanks for all the help!!! :wave
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure how this could be since MGclean.bat itself is not deleted. It is only gone once the C:\MGtools folder is removed which is the very last step that MGclean.bat performs. Also MGtools.exe is removed from the root folder and/or the Desktop long before this when MGclean.bat first starts running.

    Either way since you remove the left overs manually, it does not matter anymore.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds