malware removed (?) ports still open

Discussion in 'Malware Help (A Specialist Will Reply)' started by TheViper, Dec 26, 2006.

  1. TheViper

    TheViper Private E-2

    My computer was infected with winfixer, Agent 739, Agent 751, Trojan Generic, and Vundo.100. Trojan Hunter found and deleted them (or so I thought). A TH scan shows 5 open ports - [Port 5402/TC is open (matches BackConstruction.210, BackConstruction.25, BladeRunner.080, DeepThroat.300, and Mneah.100) Port being used by process qcacore.exe/PID 2496]. I am not computer savvy and would appreciate any help.

    Computer still runs very slow and periodically the mouse becomes unusable. I have went through the steps and tried VundoFix V6.2.13. The logs are attached, except for PandaActiveScan. Used link for your website but window that comes up was way off center and I could not read it or get it straightened out.
     
  2. TheViper

    TheViper Private E-2

    malware removed (?) ports still open other attachments

    SpyBots found nothing - CounterSpy found 3 WinFixA (I think) and fixed. Panda could not use.
     

    Attached Files:

  3. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    You have a fair amount of malware infections and will need to complete the guide below as laid out and attach the logs requested, IF you cannot run a step please let us know why and what errors were generated if any, even if one of the scans finds nothing still attach the log.


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  4. TheViper

    TheViper Private E-2

    Trying this again. I am sorry for the first messed up post.
     

    Attached Files:

  5. TheViper

    TheViper Private E-2

    OtherAttachments for TheViper

    Here are the other attachments. Could get connected to the last message I sent.
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You have an out-dated version of Adobe Acrobat installed. Download the latest version of Acrobat from Adobe.

    Using Add or Remove Programs in the Control Panel; uninstall the following:
    Now Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    You have old version of ShowNew and GetRunKeys; download both again.

    Reboot.

    Post fesh HijackThis, GetRunKey and ShowNew logs.
     
  7. TheViper

    TheViper Private E-2

    AAttached are the logs for Hijack This, GetRunKey and ShowNew. I thank you for your quick response and appreciate the help.

    Why did I use the E2 or whatever for a message icon? I don't know.:eek:

    I cannot get 3 files attached now - only 2, when I try to upload the third file, one of the first 2 disappears.:cry
     

    Attached Files:

  8. TheViper

    TheViper Private E-2

    Hopefully - the third upload!!
     
    Last edited: Jan 10, 2007
  9. TheViper

    TheViper Private E-2

    You are probably thinking no wonder she has problems with her computer and you are correct. I am losing it!
     

    Attached Files:

  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox

    Now Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click Delete Selected Temp Files
    Then after it deletes the files click the Exit (Save Settings) button.

    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue..

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Post A fresh HijackThis Log.
     
  11. TheViper

    TheViper Private E-2

    Thanks again for the help. I did receive the message PendingFileRemanedOperations prompt along with Regisstry Data has been removed by External Process! New HJT log attached.


     

    Attached Files:

  12. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Windows Messenger is running in the background on this computer, and represents a security risk. Remove Windows Messenger by running Uninstall Messenger. If you are using this as your IM client then replace it with MSN Messenger.

    Your HijackThis log appears to be clean of malware.

    How is your computer running?
     
  13. TheViper

    TheViper Private E-2

    THANK YOU! THANK YOU! THANK YOU! You people are wonderful for for using your expertise to help others. My computer is running much better. Thank you again. J Vipond

     
  14. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    If you are not having any other malware problems, it is time to do our final steps:
    • If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    • If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    • If we used SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    • If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    • If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    • If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    • You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    • If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    • After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds