Please Help ! Hijack log posted here

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by garyjwilson, Jun 2, 2011.

  1. garyjwilson

    garyjwilson Private E-2

    Hi,

    Can anyone please help. My system was infected a couple of days ago with what I believe AVG identified as "Zlob.n". I managed using Malwarebytes AVG and combofix to get rid of the majority of the virus but my system is still far from ok.
    The main issue I have is no internet (wireless dongle system). However in safe mode with network the internet is fine. Hence my ability to post on here. I have tried every reset advice and fix utility on the net but still no joy. I think the virus may have attacked some of my user permissions etc. in the registry as I had to use a permission reset tool to get AVG back on. Firefox wont even start up and I have just uninstalled internet explorer and it will not let me re install it.

    Internet explorer network diagnostics was saying my winsock was corrupt but I have used several utilities to replace and check and they are now saying it is fine. Internet explorer did not, so I uninstalled it and now can not get it to install again.

    Anyway I have downloaded Hijack this and enclosed the log as an attachment . Any advice is greatly appreciated.

    Kind Regards

    Gary
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. garyjwilson

    garyjwilson Private E-2

    Root repeal and malwarebytes logs attached

    Internet Explorer,Outlook Express and a large number of programs do not now show in start / programs list. They show fine in safe mode though. ????

    Can someone please point me in the right direction here.
    By the way I am running XP pro which has an event log could this be useful. If so can I access it and post the log here ???

    thanks

    Gary
     

    Attached Files:

  4. garyjwilson

    garyjwilson Private E-2

    Here is my PsList logs for Safe Mode and Normal Mode also
    I disabled everything in normal mode in MSCONFIG so that the running processes were identical and it still never worked ????
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I need to see logs from running SUPERantispyware, Combofix and MGTools please. Do not run things twice in both normal and safe modes, just normal mode will suffice, we only have people scan in safe mode when normal mode is problematic or not accesible. ;)
     
  6. garyjwilson

    garyjwilson Private E-2

    Ok here are the logs
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I had a very busy weekend, only just got round to this now.

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode.

    Fair warning, screensavers are a great way to get infected ;) Watch where you download these from.
    • Messenger Plus! 5 <--- Also another way to get infected...this invites in lop amongst other things. Uninstall it.
    • Java(TM) 6 Update 24 <--- Outdated, uninstall.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    C:\windows\system32\Data
    C:\windows\system32\Defaults
    C:\windows\system32\Win9X
    File::
    C:\Documents and Settings\Gary\Local Settings\Application Data\{01724771-1F1A-4837-99AF-F989F81B84DF}
    C:\Documents and Settings\Gary\Local Settings\Application Data\{029D6900-4323-4610-A494-A74FD79DB55F}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{04CECC55-7033-4A21-8184-5CFCC419E04A}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{0ADB64FF-B2B1-40E9-94C6-D4B4FB928BB7}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{1901E9EF-14B8-4BC8-BBB4-24680B3EB4F5}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{1FE952EE-6B5E-486F-B084-85CE713D77B0}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{21911D8F-264D-4853-8931-23DB1CE4B6B7}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{27B5F4EC-88D9-47EB-8B77-9F3439A1C930}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{34C3A9C9-51D5-4B5C-9BE8-760018B5F2AC}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{4A1ACB12-E83F-4EC8-B493-4E9D09ADE650}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{5072882B-900D-49AC-9601-7AA30E8F5F9B}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{515D3F8E-DE77-42D5-A135-720723C5545F}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{51E36073-7ACD-4504-9EA5-5630DA8BAE5A}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{54739D40-591C-4225-BDE8-AA9B804D65FF}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{6087F9D9-F645-427F-BE25-533701970285}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{68889F3C-D9ED-461E-A28A-1D8CDF33B0DE}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{6F1A6F41-32E7-472E-8D01-32099943BCAD}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{73790BA8-4D4A-4266-BE34-AD64D68EDF46}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{77A81914-F27C-4C70-8386-5D2C95FBF82A}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{7D31C265-038A-4057-B2F3-BA80DEE36CDC}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{860D18EC-C0C9-4A4D-902C-57E0EB74132A}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{8E82A016-7C25-4A20-906E-CA496400E4F6}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{904465DD-818F-4FD6-844D-484844612805}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{91DB8355-DA85-4E45-A432-82C02A429443}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{9593B3A8-E57D-4D8A-BF9C-F07787403F49}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{9B2E9BFE-04BA-4134-B7BF-3C849BA7F78D}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{9F630CE3-329B-4653-938F-0B8903626E19}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{A0332676-CE3F-458D-9B03-5DE12FFDE4A9}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{A1F6EF39-6DAA-4DCA-8317-002405A3F6BD}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{A36D66E4-B001-4385-94DE-FAA17A29C6CF}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{A3C7EA96-9AD8-4E29-B02F-B017FFEE9A53}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{AA5B17D8-AEAE-462A-B60C-75F3CBA99B0A}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{AC12AA5D-8346-4879-B066-18DEB1802546}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{ADB508B8-C769-406D-B35A-45E7C1496026}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{B671274C-C6F9-4DB0-8F33-3E4EC8E4FA99}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{BCB4FDD0-5667-4158-9697-E1CE85D0B92E}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{C04A9ADC-4DB5-436F-9934-7E76ECB1D579}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{C4D802C4-0B30-4C30-94EA-9195C059CA1C}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{C96C4ABF-6147-4A64-BDE2-B410A3F131E2}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{CE7E77FE-E835-4744-82B7-003F446C7512}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{D1483524-B04E-425F-A3EB-AE728FF0C4C3}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{DBEE8E5D-48B2-4E6B-9A14-F7C40ADE1488}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{DF9F396D-611C-411F-A463-4752A8B598DD}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{ED3AD4C2-74A5-4E12-B67F-93FB5A647B82}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{EE803DA2-E6DA-42B3-8C2B-2DB39BC2A563}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{EFBBEA18-6F49-4553-AE34-8B72B4FE35E3}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{F434248E-D2CD-43A1-8C4F-5684A74A1DA1}"
    C:\Documents and Settings\Gary\Local Settings\Application Data\{F472BE09-6F73-4307-8209-960439EE2CDF}"
    c:\documents and settings\All Users\Application Data\xml3AB.tmp
    c:\documents and settings\All Users\Application Data\xml3AA.tmp
    Registry::
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}]
    Folder::
    C:\WINDOWS\system32\drivers\Avg(2)
    c:\RECYCLER(2)
    C:\windows\E
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  8. garyjwilson

    garyjwilson Private E-2

    Hi,

    Followed your instructions. Re enabled all start up items in MSCONFIG, Disabled Malwarebytes and SAS and uninstalled AVG so that combo fix would run.
    Combofix ran at the second attempt. (froze at first attempting to create a restore point.
    After reboot I ran TDS killer and it ran clean except for the following
    (this file was locked )

    suspicious object
    local file
    service
    service name: sptd
    service type: kernel dricer (0x1)
    service start:Boot (0x0)
    file c:windows/system3/drivers/sptd.sys
    MD5: d390675b8ce45e5fb359338e5e649329

    I then rebooted and installed the new java and ran MGtool log (attached.)

    My system seems a lot more stable now in normal mode. Was previously freezing all the time since the virus and wouldnt let me click anything on the task bar most of the time too.

    However I am still only able to connect to the internet in safe mode.
    Internet explorer starts up now but mozilla wont even load. Double clicking on the icon starts the timer for a few seconds but no load.
    When I shut the system down I get a blue close box stating do you wish to shut down firefox.
    My internet in normal mode is connecting to my router (showing excellent connection) but wont connect to the network....

    I have attache the MG log as advised.

    Thanks for you help so far

    Regards

    Gary
     

    Attached Files:

  9. garyjwilson

    garyjwilson Private E-2

    Hi Kestrel,

    Just to let you know.
    On second and third reboot into normal mode I am back to square one.
    Computer keeps freezing and locking and can not access the task bar at all sometimes. Simply shows the sand timer when you hover over anywhere on it.

    thanks

    Gary
     
  10. garyjwilson

    garyjwilson Private E-2

    Hi Kestrel,

    One more thing. When I first rebooted the internet connection icon on my taskbar started flashing away as though I had a full connection as the computer was loading up. By the time it was fully loaded it had stopped flashing. Is it possible that my computer connected to a rogue site and downloaded something to counteract your fix ????

    thanks

    Gary
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just a thought...you have Internet Lock 5.3 installed. This is nothing to do with your internet problems is it?? Do you still have issues if you uninstall it?

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    
    :files
    C:\Documents and Settings\Gary\Local Settings\Application Data\{264C288B-D882-4DC4-A727-B3004B3019CA}
    C:\Documents and Settings\Gary\Local Settings\Application Data\{CFAEB261-C1C7-49B0-B380-BEC1FB85C591}
    C:\Documents and Settings\Gary\Local Settings\Application Data\{D7819602-A159-48C3-B2EE-39E48CA28E1C}
    C:\windows\E
    
    :Commands
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  12. garyjwilson

    garyjwilson Private E-2

    Hi Kestrel.

    Fantastic. Uninstalled internet lock and skype and its working.
    You are a star. Do I need to bother with the OTM stuff now ??

    Once agian thanks a million

    Gary
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yep. You still need to do OTM. :)
     
  14. garyjwilson

    garyjwilson Private E-2

    Hi Kestrel.

    Ran OTM as per instructions. System asked to reboot.
    Logs attached.
    Also not sure if its related but I got a malwarebytes notification blocking an outgoing request from my pc to malicious site 212.113.37.236. (Looked it up and its in Ukraine. Dont know where it was from on my pc though.

    thanks again

    Gary
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete these files:

    C:\Documents and Settings\Gary\Local Settings\Application Data\{86732824-AF40-45B4-A081-6534EC2DCC2E}
    C:\Documents and Settings\Gary\Local Settings\Application Data\{C4AE01BD-1E22-4793-A6BD-84C112CC4803}

    Tell me what problems remain.
     
  16. garyjwilson

    garyjwilson Private E-2

    Hi Kestrel,

    Deleted the two files as instructed.
    Only problems now are that I am still getting random malwarebyte notifications of system outgoing blocks to malicious sites. Seems to stop after reboot and then start again after the next reboot.
    Also now have a very very slow boot up.
    Used to take about 30 seconds to get to desktop. Timed it last boot and it took 4 and a half minutes to get to desktop. My load up screen for my Asus Rock used to last 3 or 4 seconds this is now well over a minute. It was so long I thought the system had locked up.
    Not sure if this is related to anything but look forward to your advice.

    Regards

    Gary
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, MBAM is just doing its job, it will block IP addresses in it's database of malware serving websites.

    What is this file? C:\windows\E

    Could you please get it into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    log retrievable @ C:\collect.zip
    Something to further discuss in another section of the forum because it is not malware related. 30 seconds to desktop? Wow you were lucky!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  18. garyjwilson

    garyjwilson Private E-2

    Hi Kestrel.

    Ran the collect zip script but could not loacate a c:collect.zip file.
    So I zippd it myself and attached.

    Re. Slow boot.
    The reason I mentioned it was because it has only occured since the fixes were started. I didnt know if this was due to mlogs, tds killer etc etc.
    I do have a powerful system AMD phenon 9650quadcore with 4 gig ram running xp pro and it was honestly only 30 seconds or so to desktop display and start items begining to load.

    Thanks for your continued assistance

    Regards

    Gary
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What we have done and the scans we have run cannot cause a slow down, perhaps you can review what is running at start up, and trim that down by using third party software such as StartupCPL for instance. AVG is also a known resource hog. You have a-squared installed which I do not rate these days, you could uninstall that and rely on MBAM and SAS instead.
    You are most welcome!

    vShare Plugin
    <--- Is this something you knowingly installed? If you do not use it be rid of it, uninstall it.


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.


    What is this file? If you do not know, attach it or have it scanned like the files further down my post.
    • C:\windows\system32\c_71311.nl


    Remnants from Internet Lock below, you can delete it.

    • C:\WINDOWS\system32\drivers\InetLock.sys


    Try and zip this using the method previously described, otherwise zip it yourself.

    C:\WINDOWS\system32\drivers\nebkrp.sys


    Please go to virustotal and upload the following files for analysis, and let me know the results.
    • C:\WINDOWS\system32\drivers\nebkrp.sys
    • C:\WINDOWS\system32\drivers\update.sys

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    • C:\Documents and Settings\Gary\Local Settings\temp
    • C:\WINDOWS\temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well while it is true that the scans themselves are not the problem, it is due to MSconfig not being used anymore. Remember in message 7 the below was requested as part of out normal process
    28 startup processes were being disabled with MSconfig and now need to be controlled via some other method since MSconfig should not be used to do this. This is the reason for your startup time change. It was not due to the scans.

    Thus Kestrel13! is on the right track telling you that that if you want to reduce startup time, you need to reduce your startup processes. Just don't use MSconfig. The READ & RUN ME gave you the below link:

    Dealing with Startup Process
     
  21. garyjwilson

    garyjwilson Private E-2

    Hi Kestrel...

    Re instructions provided.

    uninstalled vshare plugin
    disabled anti spyware and avg (best I could) and ran mgtools analyse
    fixed
    02 and 09 entries as listed
    but 018 entry protocol. vsharecrome was not listed

    file c:windows / system32 /c_ 71311.nl was zipped and is attached.

    file Inetlock . sys was deleted

    C:\WINDOWS\system32\drivers\nebkrp.sys is attached

    selected all files in folder
    C:\Documents and Settings\Gary\Local Settings\temp
    and then pressed delete. It deleted everything (quite a lot) except for files it said were in use
    WCES log
    WCES com
    LVCOMSX com
    DF138C.tmp
    DFFD98.tmp
    DFFD93.tmp
    DFFE7d.tmp
    DFFE88.tmp
    DFFF8a.tmp
    DFFF95.tmp
    Wcesviewlog
    DF260E.tmp
    DF6f87.tmp

    were all that were left.


    Deleted all files in C:\WINDOWS\temp
    Again message stated files in use could not be deleted. Files left were

    Perflib_Perfdata_dat (17 of them with different number / codes )
    plus...... terdo.txt and WGAErrLog.txt

    Uploaded the two files to virus total

    First one C:\WINDOWS\system32\drivers\update.sys
    came back 0% out of 43


    Second one C:\WINDOWS\system32\drivers\nebkrp.sys.
    came back
    File name: nebkrp.sys
    Submission date: 2011-06-08 04:46:31 (UTC)
    Current status: queued (#32) queued (#32) analysing finished


    Result: 2/ 42 (4.8%)
    VT Community

    goodware
    Safety score: 75.5%
    Compact Print results Antivirus Version Last Update Result
    AhnLab-V3 2011.06.08.01 2011.06.08 -
    AntiVir 7.11.9.94 2011.06.08 -
    Antiy-AVL None 2011.06.07 -
    Avast 4.8.1351.0 2011.06.07 -
    Avast5 5.0.677.0 2011.06.07 -
    AVG 10.0.0.1190 2011.06.07 -
    BitDefender 7.2 2011.06.08 -
    CAT-QuickHeal 11.00 2011.06.08 -
    ClamAV 0.97.0.0 2011.06.08 BC.Heuristics.Rootkit.B-11.MV
    Commtouch 5.3.2.6 2011.06.08 -
    Comodo 8990 2011.06.08 -
    DrWeb 5.0.2.03300 2011.06.08 -
    eSafe 7.0.17.0 2011.06.06 Win32.TrojanHorse
    eTrust-Vet 36.1.8372 2011.06.07 -
    F-Prot 4.6.2.117 2011.06.08 -
    F-Secure 9.0.16440.0 2011.06.08 -
    Fortinet 4.2.257.0 2011.06.08 -
    GData 22 2011.06.08 -
    Ikarus T3.1.1.104.0 2011.06.08 -
    Jiangmin None 2011.06.07 -
    K7AntiVirus 9.105.4781 2011.06.07 -
    Kaspersky 9.0.0.837 2011.06.08 -
    McAfee 5.400.0.1158 2011.06.08 -
    McAfee-GW-Edition 2010.1D 2011.06.08 -
    Microsoft 1.6903 2011.06.07 -
    NOD32 6188 2011.06.08 -
    Norman 6.07.10 2011.06.07 -
    nProtect 2011-06-08.01 2011.06.08 -
    Panda 10.0.3.5 2011.06.07 -
    PCTools 7.0.3.5 2011.06.08 -
    Prevx 3.0 2011.06.08 -
    Rising 23.61.01.03 2011.06.07 -
    Sophos 4.66.0 2011.06.08 -
    SUPERAntiSpyware 4.40.0.1006 2011.06.08 -
    Symantec 20111.1.0.186 2011.06.08 -
    TheHacker 6.7.0.1.225 2011.06.08 -
    TrendMicro 9.200.0.1012 2011.06.08 -
    TrendMicro-HouseCall 9.200.0.1012 2011.06.08 -
    VBA32 3.12.16.0 2011.06.07 -
    VIPRE 9519 2011.06.08 -
    ViRobot 2011.6.8.4499 2011.06.08 -
    VirusBuster 14.0.71.0 2011.06.07 -
    Additional informationShow all
    MD5 : e6d35f3aa51a65eb35c1f2340154a25e
    SHA1 : aabbd57e20d2e7041f9e7abce6cfd8a53c366537
    SHA256: 3da4f51682e7d42c5569f1fb1adc6295182962e36f748219e1d0c8f2389ba516
    ssdeep: 768:Bosx0q2ph6P2Jpz8ftoSUiJP7hYTCMrhwYKUzY4q:j076P2Jpz8ftBUMPaCMrhwY
    File size : 54016 bytes
    First seen: 2009-09-18 00:44:25
    Last seen : 2011-06-08 04:46:31
    TrID:
    Clipper DOS Executable (33.3%)
    Generic Win/DOS Executable (33.0%)
    DOS Executable Generic (33.0%)
    VXD Driver (0.5%)
    Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
    sigcheck:
    publisher....: n/a
    copyright....: n/a
    product......: n/a
    description..: n/a
    original name: n/a
    internal name: n/a
    file version.: n/a
    comments.....: n/a
    signers......: -
    signing date.: -
    verified.....: Unsigned

    PEInfo: PE structure information

    [[ basic data ]]
    entrypointaddress: 0xC505
    timedatestamp....: 0x4A9EE5B5 (Wed Sep 02 21:37:57 2009)
    machinetype......: 0x14c (I386)

    [[ 5 section(s) ]]
    name, viradd, virsiz, rawdsiz, ntropy, md5
    .text, 0x480, 0xBD9F, 0xBE00, 5.83, 9474f39576a0e15bdbaa2ea3355f0a4a
    .rdata, 0xC280, 0x126, 0x180, 3.78, 375b710d9f213cfced30e9fdb29567e1
    .data, 0xC400, 0xC0, 0x100, 0.33, 786971ca2b109729eda604b44d6c72ad
    INIT, 0xC500, 0x3C8, 0x400, 5.20, eea49a93a73afb6afc178455582133c6
    .reloc, 0xC900, 0x9EC, 0xA00, 6.62, bddd5a40c508bfc84ec87de5f8e6a5d3

    [[ 1 import(s) ]]
    ntoskrnl.exe: ZwWriteFile, RtlUpcaseUnicodeChar, ZwClose, ZwCreateFile, RtlInitUnicodeString, _wcsicmp, ZwQueryValueKey, ZwOpenKey, ZwDeleteKey, swprintf, ZwEnumerateKey, ExFreePoolWithTag, DbgPrint, ExAllocatePool, RtlPrefixUnicodeString, memcpy, RtlDeleteRegistryValue, ZwSetValueKey, RtlWriteRegistryValue, ZwEnumerateValueKey, ZwSetInformationFile, ZwQueryInformationFile, ZwQueryDirectoryFile, ZwOpenFile, KeTickCount, KeBugCheck, MmGetSystemRoutineAddress, ZwFlushKey, PsTerminateSystemThread, KeSetPriorityThread, KeGetCurrentThread, RtlCheckRegistryKey, KeDelayExecutionThread, ZwReadFile, PsCreateSystemThread, PsGetVersion, KeBugCheckEx

    Symantec reputation:Suspicious.Insight


    VT Community

    13
    User:LT1

    Reputation:3318 credits

    Comment date:2010-09-29 17:53:30 (UTC)
    Tags: Malware,


    Thanks again

    Gary
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Have you ever used Avenger? Software similar to Combofix where bad files are compiled into a script and then run as a fix. That's what I think this file relates to so just delete it as it is not needed anyway.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  23. garyjwilson

    garyjwilson Private E-2

    Thanks for all your help Kestrel.

    All uninstall instructions carried out. (never knowingly used Avenger so dont know what that was about)

    Dont know why but today AVG asked for a reboot out of the blue and the slow start up is gone !!!!!.
    Only issue I have is malwarebytes telling me that it is stopping my system making outgoing attempts to contact rogue sites but I can live with that.

    Once again thanks for all your help

    Gary
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well it just sounds to me like MBAM is doing it's job, do you have the paid for version?
     
  25. garyjwilson

    garyjwilson Private E-2

    Hi Kestrel,

    I am using the Malwarebytes Pro with real time protection.
    Prior to virus I used to get the odd notification from inbound blocks from malwarebytes which I assumed was Malwarebytes doing its job.
    Outgoing blocks would seem to indicate that something on my P.C. is trying to contact rogue sites with the obvious inference that it may then download something malicious back onto my P.C.
    I have enclosed the malwarebytes log for 09/06/11. to show you just how many blocks it is making and the Ip's concerned. Ukraine, Netherlands etc are listed on some of the early ones I tracked.

    Regards

    Gary
     

    Attached Files:

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I will ask Chaslang to take a look at the log and see what he thinks.
     
  27. garyjwilson

    garyjwilson Private E-2

    Hi Kestrel,

    Re malwarebytes outgoing block issues.
    Through a process of elimination I have discovered the problem is caused by Utorrent. I have uninstalled using "Total Uninstall" and reinstalled, a fresh copy, as I do use it.
    The alerts started again upon reinstalling even though I was not downloading or uploading anything. Would you know if this is an error or dangerous for my computer, apart from the obvious of ensuring that any downloaded files are scanned first before use.

    thanks

    Gary
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That was going to be my first suggestion. ;) I saw utorrent in your logs.

    When you complete the final instructions that Kestrel13! posted, you will see that P2P and torrent programs are frowned upon. They are dangerous as they open up the door to your PC to let all kinds of problems in from anywhere in the world. You are allowing ANYONE to connect to you. You don't have to be actively downloading. All you have to do is allow the utorrent program or other P2P program to run. And you run yours immediately upon startup. i.e, you load the below:

    O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"


    If you must use it then do not allow it to run at startup and only use when you are using it and then shut it down immediately when you finish. Leaving it running is like leaving the keys in your running car in the Bronx, New York.
     
    Last edited: Jun 10, 2011

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds