10.22.07 Help requested.

Discussion in 'Malware Help (A Specialist Will Reply)' started by buildbyflying, Oct 22, 2007.

  1. buildbyflying

    buildbyflying Private E-2

    I've had a virus since last week which infected my computer after I dl'd a codec for a non-working video from digg.com. Turns out there was no video, just a malicious attack.

    So, after running Kaspersky, Panda, Ad-Aware, Spybot, CounterSpy, the Microsoft Updated Malware removal tool... the most annoying aspects are gone but there's still the issue of the stolen admin access.
    I read about some tools that restore admin privledges, but I thought I'd post before I did anything drastic.

    Current symptoms include: a desktop image that states I have a virus (not set as the backdrop), no admin access.

    I hope I did all this correctly, but there seems to be at least two pages on this forum alone explaining what to post and how.

    Thanks in advance.
    Kevin
     

    Attached Files:

  2. buildbyflying

    buildbyflying Private E-2

    Note: I have since removed Kaspersky, and leave Panda running (unless the readme requested i turn it off). Counterspy runs as well, in lieu of Ad-aware, Spybot... I also ran CCleaner as requested, followed the readme... etc.

    I didn't load AVG as I've already used two anti-viruses, so I've attached the Panda log instead.

    Thanks.
     

    Attached Files:

  3. abri

    abri MajorGeek

    Hi buildbyflying,
    Do you have administrative authority on your computer? Can install new software?

    Please go to add/remove programs and uninstall the following
    Then REBOOT your computer and after you've rebooted, install Java Runtime Environment vs. 6.3


    Now please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Finally, please do the following: your HijackThis was not installed correctly and you didn't change the name. It needs to be reinstalled under C:\Program Files\HijackThis. Once you've installed it, go to this folder and find the file hijackthis.exe and right click on it and select rename. Then rename it analyse.exe and rerun a new scan and post a new log.

    After you have completed ALL of the above in the correct order, please attach the following logs.
    • ShowNew Log
    • HijackThis Log


    abri
     
  4. abri

    abri MajorGeek

    Buildbyflying!

    Another instruction to add to the last one: HijackThis is installed on the desktop. Please reinstall it to C:\Program Files\HijackThis
    Then look in the HijackThis folder and find the file named hijackthis.exe. Right-click on it and select "rename" and rename it analyse.exe. Then please rerun it and submit the hijackthis.log to us. The one run from the desktop doesn't give us the information we need.

    Thanks.
    abri
     
  5. buildbyflying

    buildbyflying Private E-2

    Did everything as requested. I didn't remove Java6 runtime 2, because the computer doesn't want to connect to the network now.
    (If I should plz let me know.)
    The ShowNew log is in the mgtools rar. (I thought you might want all the reports.)

    p.s. I erased hijackthis and reinstalled it in the C:/Program Files directory. I renamed the .exe file to analyse.exe before running it.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to install MGtools.exe as requested on the download page. You put it on drive D and it must be installed on the drive where Windows is installed which in your case is drive C. Due to this, it is not running properly and is not automatically creating the logs that it should be creating (one of which is and automatic creation of the HijackThis log).
     
  7. buildbyflying

    buildbyflying Private E-2

    ok, so I hope this is right. I deleted MGtools from the D: and reinstalled it from the FAQ onto C:
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's better!

    Note that you do not need to attach a separate newfiles.txt log. It is included in the ZIP file along with the runkeys.txt, a HijackThis log and two other logs we often use. At any point where new logs are needed, all you have to do is go to the C:\MGtools folder, locate the GetLogs.bat file and double click on it. It will create ALL new logs and put them into a new C:\MGlogs.zip file for easy attachment.

    I'll get you started on a fix while Abri is not around.



    Uninstall the below software:
    Java(TM) 6 Update 2
    Web Savings from Ebates

    Did you install a CounterSpy trial program while trying to fix your problems? If it is only a trial, uninstall it now.


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    O2 - BHO: qiawpbjj.msdn_hlp - {026B5895-3E8E-49A9-8EEE-B52A326DA962} - C:\WINDOWS\system32\qiawpbjj.dll
    O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
    O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
    O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
    O2 - BHO: Flash Module - {CD2F34B8-D2A1-4573-855A-464E276BA89D} - sockver1.dll (file missing)
    O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\RunServices: [MS Services] mssvc.exe
    O4 - HKLM\..\RunServices: [Explorer] Explorer.exe
    O4 - HKLM\..\RunServices: [Microsoft Security Controlers] fxsecues.exe
    O4 - HKLM\..\RunServices: [System Event Manager] secsvc.exe
    O4 - HKLM\..\RunServices: [Microsoftf DDEs ContrDL] runm.pif
    O4 - HKLM\..\RunServices: [Crnsava] scrnsave.pif
    O4 - HKLM\..\RunServices: [Microsoftf DDEs ContDLL] rune.pif
    O4 - HKLM\..\RunServices: [Microsoftz tasn Control] aixl.exe
    O4 - HKLM\..\RunServices: [SERV PacK2] masmn.exe
    O4 - HKLM\..\RunServices: [SOUNDMAN Microsoft Help] soun.pif
    O4 - HKLM\..\RunServices: [VID INTERNET WEB DRIVERS FOR WIN32] phqghu.exe
    O4 - HKLM\..\Policies\Explorer\Run: [vpnxgv] C:\DOCUME~1\kevin1\LOCALS~1\Temp\vpnxgv.exe
    O4 - HKUS\S-1-5-18\..\Run: [LOCAL INTERNET WEB DRIVERS FOR WIN32] phqghume.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [LOCAL INTERNET WEB DRIVERS FOR WIN32] phqghume.exe (User 'Default user')
    O16 - DPF: {E831AA9C-C980-4F16-B252-09AAF40D0E9B} (Kdfense9 Control) - http://kings.cachenet.com/kdfx218/kbstar/kdfense9.cab
    O16 - DPF: {F1F07506-6CB4-44AC-8615-66D1234EFD05} - http://www.hanabank.com/plugin/INISafeWeb50.cab
    O16 - DPF: {F61919F5-1292-4447-A904-1943D72ACF04} (CertCheck for KB Control) - http://img.kbstar.com/cab/certCheck.cab
    O20 - Winlogon Notify: adcbefdeddb - C:\WINDOWS\

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now run the C:\MGtools\GetLogs.bat program and attach the new C:\MGlogs.zip file.

    Make sure you tell me how things are working now!
     
    Last edited: Oct 24, 2007
  9. buildbyflying

    buildbyflying Private E-2

    THe comp's running much better. No signs of foul-play. The admin acct is now gone as well.
    However I noticed that the avenger program couldn't erase some files... is this bad?

    again, thanks.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What do you mean the admin account is gone? We were not trying to delete the admin account and nothing we did should have delete it. Did you mean to say something else?


     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Attach the C:\Avenger.txt log so we can see. Often this just means that the files did not exist so they could not be deleted.

    Did you run ATF-Cleaner? It does not appear to have worked. Your C:\Documents and Settings\kevin1\Local Settings\Temp\ folder is loaded with old temporary files that should have been removed.

    Delete all the below files that somehow did not get cleaned up in the root folder of drive C:
    Code:
    "C:\"
    caisslog.txt  Oct  2 2007       40483  "caisslog.txt"
    xcuexpsh.txt  Oct 19 2007         200  "xcuexpSH.txt"
    xcupol~1.txt  Oct 19 2007         310  "xcupolsys.txt"
    xcupol~2.txt  Oct 19 2007         470  "xcupolexp.txt"
    xcuproto.txt  Oct 19 2007         588  "xcuproto.txt"
    xlmbho.txt    Oct 19 2007        8984  "xlmBHO.txt"
    xlmdef~1.txt  Oct 19 2007         760  "xlmdefpre.txt"
    xlmdns0.txt   Oct 19 2007       13402  "xlmdns0.txt"
    xlmdns1.txt   Oct 19 2007       13330  "xlmdns1.txt"
    xlmdns2.txt   Oct 19 2007       13330  "xlmdns2.txt"
    xlmpol~1.txt  Oct 19 2007         682  "xlmpolexp.txt"
    xlmpol~2.txt  Oct 19 2007         576  "xlmpolsys.txt"
    xlmsha~1.txt  Oct 19 2007         554  "xlmshared.txt"
    xlmshell.txt  Oct 19 2007         370  "xlmshell.txt"
    xlmssodl.txt  Oct 19 2007         902  "xlmssodl.txt"
    xlmsysc.txt   Oct 19 2007    10846925  "xlmsysc.txt"
    xmodul.txt    Oct 19 2007       16676  "xmodul.txt"
    xmscfg.txt    Oct 19 2007        1492  "xmscfg.txt"
    xrkey00.txt   Oct 19 2007        1655  "xrkey00.txt"
    xrkey01.txt   Oct 19 2007         678  "xrkey01.txt"
    xrkey02.txt   Oct 19 2007         228  "xrkey02.txt"
    xrkey04.txt   Oct 19 2007         236  "xrkey04.txt"
    xrkey05.txt   Oct 19 2007        4830  "xrkey05.txt"
    xrkey06.txt   Oct 19 2007         230  "xrkey06.txt"
    xrkey07.txt   Oct 19 2007         234  "xrkey07.txt"
    xrkey08.txt   Oct 19 2007        1026  "xrkey08.txt"
    xrkey09.txt   Oct 19 2007         246  "xrkey09.txt"
    xrkey10.txt   Oct 19 2007         334  "xrkey10.txt"
    xrkey12.txt   Oct 19 2007         577  "xrkey12.txt"
    xrnotif.txt   Oct 19 2007        7656  "xrnotif.txt"
    xrquery.txt   Oct 19 2007         937  "xrquery.txt"
    xrquery2.txt  Oct 19 2007         752  "xrquery2.txt"
    It also appears that you did not uninstall the below as requested:
    Java(TM) 6 Update 2
    Web Savings from Ebates
     
  12. buildbyflying

    buildbyflying Private E-2

    1. what I was saying about the admin acct was that it's not showing when I log out and log in. It just shows kevin1 which is me.
    perhaps it was presumptuous to say it was gone. Sorry for the confusion.

    2. I ran atf cleaner. and I just ran it again. but thinking back i wonder if erasing ie6 would prevent the program from removing the temp files. i removed IE6 when the virus first started throwing up random windows. Is there any other way to get those files off? Reinstall IE6?

    3. I forgot to delete the java2 update. it's done now. However, I"ve never been able to fully remove the ebates web...thing, because I had removed the program before and now it says, "could not find the main class. program will exit."

    4. I'm attaching the avenger log I should have attached before along with new batch logs.

    5. I deleted the files from the c: dir as requested.

    thanks again
     

    Attached Files:

    Last edited: Oct 27, 2007
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure that reinstalling IE6 will fix this issue; however you should reinstall IE because it is an integral part of Windows and is required on many websites including Microsoft. Without IE, you will not be able to keep your PC properly updated with Microsoft.

    Running the below should remove it.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Since ATF-Cleaner is not working properly, goto the below folder and delete everything yourself:

    C:\Documents and Settings\kevin1\Local Settings\Temp\

    Windows will just stop you from deleting a few files from the current date because they will be in use.



    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds