Help Remove Maleware with Hijackthis and etc (part1of2)

Discussion in 'Malware Help (A Specialist Will Reply)' started by santoro, Mar 11, 2007.

  1. santoro

    santoro Private E-2

    Hello
    Problem-Computer (Dell Laptop XP home 1.1GHz, 256MB ram, IE 6.0) probably infected by virus/trojan/maleware. I notice the PC was on and network light was runnig even though I was not runninng any program (no updatew from MS in progress). Symantec Antivirus v8.1.x runs every week. I run Spybot Search & Destroy as well as Ad-Aware and eUsinngs Registry Cleaner every week or so and the MS updates are regularly done.

    What I did so far-
    The free virus scan from trendmircros' www.antivirus.com started and ran for a while then quit and closed IE. I ran Panda ActiveScan which ran over night and was still running. There was a compression bomb (42.zip) which keeps your scan bussy by decompressing into 16 files each of which decompresses into 16 more files and so on. Eventually it decompresses to 4 Tera Bytes. So at this point I figure something bad must have gotten into the PC and placed that there as camouflage. I deleted the compression bomb. I ran Microworld Antivirus which reported linkmedia Trojan and possible Fujacks type worm infile system.

    I then found Major Geeks forum and followed the instruction found in
    "READ & RUN ME FIRST. Malware Removal Guide "
    Some of the reported items where
    infected with :Behaves Like:win32.fileInfector
    Adware/oemji window registry
    spyware/media-motor registry
    cookie/Tribalfusion
    I have attached the log files requested in the removal guide to this message and "Help Remove Maleware with Hijackthis and etc (part2of2)" as thee are 4 logs and only 3 attachments per message (there was no log for CounterSpy).

    I would appreciate any guidance/suggestions in removing this BUG on the PC. Anyway of telling where it came from??
     

    Attached Files:

  2. santoro

    santoro Private E-2

    Help Remove Maleware with Hijackthis and etc (part2of2)"
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why was there no log for CounterSpy? Did it find anything? Has your trial period already expired or been used in the past? If so, you should have used AVG Antispyware.

    Also where is the requested log from BitDefender?

    Note:Fujacks can infect every executable type file on your PC!!!!! You need to have an antivirus program that can repair this infection. I'm not sure which antivirus programs will work on this since I have not had the infection to try it on. However I do know the McAfee fixes it since I used McAfee on a friends PC to fix his problem with Fujacks.
     
    Last edited: Mar 12, 2007
  4. santoro

    santoro Private E-2

    Sorry about the missing file. There was nothing detected so I did not include the Bitdender and the counterspy in safe mode does not indicate a way to save the log.
    So for completeness I have rerun all the steps and generated a whole new set of logs. There are 6 logs so I will spreadthem out over 2 messages. (correction when I try to attach the activescan.txt file it says it is already attached. The file contents are
    Incident Status Location
    Adware:adware/oemji Not disinfected Windows Registry
    Spyware:spyware/media-motor Not disinfected Windows Registry Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\admin\Cookies\admin@tribalfusion[2].txt

    I will attach the remaining 3 files (activescan.txt included if possible) to the next message.
     

    Attached Files:

  5. santoro

    santoro Private E-2

    Part 2 with attchments for analysis

    Thanks for any help
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 7
    J2SE Runtime Environment 5.0 Update 9

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\logo1_.exe
    C:\WINDOWS\rundll16.exe
    C:\WINDOWS\zts2.exe
    C:\WINDOWS\rundl132.dll
    C:\WINDOWS\SYSTEM32\iifgfgf.dll
    C:\WINDOWS\SYSTEM32\vcmgcd32.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now run Ccleaner

    Now you should toggle System Restore per the instructions in step 8 of the READ & RUN ME.

    Now I suggest that you make sure you have the current updates for your Symantec Antivirus. Then you should run a full system scan and let me know if any problmes are found. If so, note then name of the file as well as the virus/trojan name

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  7. santoro

    santoro Private E-2

    Hello
    I followed the last set of instructions and have attached the logs to this message. I updated to symantec anti virus corperate ediation 10.1 and updated the virus definitions. The virus scan indicated no infections. The strange thing is that www.antivirus.com (trendmicro) online virus scan starts Ok and seems to be "prepairing" when without warning the internet explorer closes. It does not say "IE not responding" or any other normal type of freeze. It just goes away. Previously I had run Microworld Antivrus and it reported linkmedia trojan and possible "Fujacksptype worm in file system". Is Microworld antivirus a trustworth program in your opinion? The fact that a 42.zip compression bomb was found on the system also seems to say bthat something was hiding on the system.
    Would it be advantagious to boot from a floppy or cd and run an antivirus from the disk? Looking at my notes I relise I forgot to mension a strange thing. The PC is using XP home with the user icons shown when the system boots nromally. The icons shown users are 'admin', 'david' and 'kathy'. The strange thing happens when booting into safe mode. There is 'admin', 'david', 'kathy' AND 'Administrator' which is not password protected. In a ormal boot I went to users and ther is no 'Administrator' account. I put a password on this strange 'Administrator" account in safe mode. In normal boot mode is it possible I am being shown a false set of user icons? I was up to 2:30 am last night trying to remove this thng in the system and have spent somany hours working through the procedures. I know reformating the drive and starting over would probably be the fastest way to get the syetem back to clean but I would prefer to not do that and besides this is a learning oppertunity. I was not planning on learning the ins and out of malware removal but it seems like a good thing to know.
    So any suggetstions on the next step? Is Microworld Antivirus a good or poor tool? What do you thing of the 'Administrator' account in safe mode?
    Thanks for your help
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow all of my instructions. You still have J2SE Runtime Environment 5.0 Update 11 installed. This is out of date and should be uninstalled. Then install the current version from the link I gave you.

    Many people run into problems running a variety of the online scanners. The problem is usually due to a setting on the users PC or due to other software they are running that it blocking proper operation. Sometimes an antivirus program or firewall can cause problems.

    Microworld Antivirus is an okay application but it is way over priced especially for what it is. Also if you don't buy it, it is nothing but a scanner. It does have a few issues with false positives too. Why are you running it anyway? If you don't trust Symantec why do you have it installed?

    Previously I had run Microworld Antivrus and it reported What do you thing of the 'Administrator' account in safe mode?[/quote]The Administrator account is normal and in a default setup it will only appear in safe mode. It is good that you password protected it now. That was a major security hole that could allow hackers full access to your PC.


    Your logs are now clean. Are you having any current malware problems? If not, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. santoro

    santoro Private E-2

    Thanks for all the help.
    Sorry about the Java 5 install. I just went to the sun website and downloaded it through the web and then checked the installation with Sun's online tool. I thought I would get the most up to date stuff that way.

    I am using symantec antivirus because the university I attend lets students use a copy for home PCs. I was worried that the www.antivirus.com scan was quieting as it scanned. I have used their online scanner on many other PCs and it never quiet in the middle of a scan. After that, 42.zip was discovered on the HD and I thought that symantec had been compromised.

    Again, thanks for teh help.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I said many people run into problems with online scanners and most frequently it is due to settings on their PCs or other software being run. Also not having the current Java version has been know to cause problems too. Try shutting down all of Symantec, Trojan Remover, and your firewall and see it it runs. Also delete any existing files (like C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys )for TrendMicro before running the scan again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds