antivirus soft / bankerfox.a

Discussion in 'Malware Help (A Specialist Will Reply)' started by your_comforting_company, Feb 7, 2010.

  1. same thing everyone else is getting from (apparently) photobucket ads. this got on my kids computer. luckily it's not on this one, but I followed the cleaning instructions in the readme. logs are attached. this is a real nasty virus. not sure if I've gotten it all yet, but I did complete the steps for the xphome machine.
    thanks in advance for any help
    mglogs in next post
     

    Attached Files:

  2. thanks for the help guys. hopefully you can tell by the logs if I got rid of it or not. It definately got one trojan and 811 other malicious files with malwarebytes.. I have my fingers crossed.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The scans took care of things, let's just do this:

    1. What are you using as an anti virus?
    I see you uninstalled Bitdefender? If so we need to clean up from that also.

    2. Please go to Add/Remove programs and uninstall the following software:

    • J2SE Runtime Environment 5.0 Update 12
    • Java(TM) 6 Update 14
    • Java(TM) 6 Update 2
    • Java(TM) 6 Update 7
    • Spyware Doctor 7.0 <--- Is this just a useless trial or paid for? If a trial only then please also uninstall.

    3. Could you please get this: winsys2.exe into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    log retrievable @ C:\collect.zip

    4. Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      c:\windows\system32\winsys2.exe
    • At the upload site, click once inside the window next to Browse.
    • Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
    • Next click Submit file
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

    5. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6


    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    7. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. Thank you very much Kestrel13. Just a status report to answer the questions as I follow the set of instructions you have given.
    I uninstalled Bitdefender, disconnected the computer from the internet and ran all updates manually for all installed tools. Since the cleaning, etc. I have swapped over to AVG's newest free-trial full version. I will most likely be going with Kaspersky when this trial is over.
    spywaredoctor is just a useless trial. I used it as a prelim cleaning tool as advised by another discussion I was reading elsewhere. It will be uninstalled.
    I will post results of these instructions shortly.
    Thanks again Kestrel13!
     
  6. Jotti's Link: http://virusscan.jotti.org/en/scanr...df6b/7545ac19111ba9bda9e445478637d679a19e6a58

    jotti found another backdoor in winsys2.exe... uh oh!
    for some odd reason I cannot attach ComboFix.txtwill try again in the following post.

    thanks in advance for all your help!

    AVG antivirus was installed after the cleaning. (i'm wary of going online with no protection at all) and currently am using the computer that is/was infected. at least it will go online now!

    I'm looking for cleanup instructions to remove the rest of bitdefender. That program is useless junk. the updater doesn't work and it crashes and needs to be reinstalled at least once a week. I will never do business with them again. their support phone number is disconnected and the canada hotline goes to a petrol-cleanup company. I can't believe I paid all that money for a program that isn't even legit...
     

    Attached Files:

  7. the forum says that I have already attached the combofix log in another post in this thread. do I need to run combofix again?

    the report log is labeled either combofix.txt or log.txt attached to above post.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I apologise, I didn't mean for you to attach a combofix log, I meant to disinclude that part in my instructions. Reviewing your logs and will give you a fix soon. Just having a cup of tea.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Why is there a user account on this machine called:


    1. Please go to Add/Remove programs and uninstall the following software if it is leftovers from using the anti-virus at one point.:
    2. Then run the following:

    Please give the Norton Removal Tool (SymNRT) a run > reboot your machine and then run it again for good measure.

    3. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.

    4. Now we need to use ComboFix to get rid of some malware and clear up from BitDefender (and this program is legit, I don't understand why you had issues with their support)
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\system32\winsys2.exe
    C:\WINDOWS\bdagent.INI
    C:\WINDOWS\system32\bdod.bin
    C:\WINDOWS\system32\BDUpdateV1.xml
    
    Folder::
    c:\documents and settings\The Boss\Application Data\BitDefender
    c:\documents and settings\Administrator\Application Data\Bitdefender
    c:\program files\Common Files\BitDefender
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "WinSys2"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    5. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    7. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
    Last edited: Feb 10, 2010
  10. combofix froze on reboot. it just says:

    Preparing Log Report:
    Please do not run any programs until ComboFix has finished.

    I got that far and will post logs once I get past this.
     
  11. combofix is still frozen. should I close it and run again the same as above? It's been hung for over 30 minutes now.

    I do not know why BidDefenderComm is a User Account. It does not show up in the control panel > user accounts. I presume I need to remove this somehow, but since it's invisible, I'm not sure how. I did clean out the temp folders, but combofix is still hung, so I'm not sure what to do. TIA!
     
  12. ok. finally got report. will post from that pc in one min.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    First close out of combofix if it is still hanging, you may well find it has produced a log, if it hasn't we we decide whether to try and re run the script or to use another tool instead.


    I need to travel some way across town soon so will not be back for a response for a little while but shall get back to you tonight at some point. :)

    If combofix has produced a log attach it as well as following my other instructions and attaching the other requested logs. If it doesn't create a log, then wait for me and we will try going a different route.
     
    Last edited: Feb 9, 2010
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    ahhh! Great :)
     
  15. My AVG icon is now missing from the tray. Other than that everything seems okay. The UI says that all parts are running properly, etc. I hope we got the things. I hate to think of all the bad things that might pop up while my kids are on. EEK!
    I really appreciate your time and help Kestrel13.
    Is there some way I can donate to you or the site?
    Thanks again.
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is avg's icon still missing today?
    You're very welcome :)

    If you wanted to you could check out the clothing range! J!NX

    Now then it appears that the install of BitDefender that you once had creates a user account. What it's purpose is I am not sure as I haven't researched it enough, but it's enough to make alarm bells ring IMO. Try this:


    Your logs are clean:

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  17. The Icon is still missing after 3 reboots. No biggie as long as all the stuff is working. I'll be getting Kaspersky VERY SOON so I'll end up uninstalling AVG anyway.
    Along with Kaspersky I'll be buying a tshirt or something to help with this site. I really appreciate your help. Thank you Very Much!!

    I'm running the cleanup procedures now. Is it necessary to remove all these tools? I'd hate to get them all uninstalled and the blasted virus pop back up and have to do it all again... Or can I wait a little while and uninstall them, like say in a week?

    Thanks again for all your help. You guys are the best and I will recommend you to anyone else I find having this problem.
     
  18. In the computer management window, I don't have anything that says "Local Users and Groups". I'm logged onto the Boss account which has admin status.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just try doing this, navigate to the following bold file and double click it to run it:

    C:\Pprogram Files\AVG\AVG9\avgtray.exe

    Does the icon re-appear now?

    Not a problem. :)
    Keep them for a week if you like (I reccommend you keep SAS and MBAM anyway) do NOT touch any of the tools though apart from SAS and MBAM. And then follow my final instructions when you are happy all is still well.
    Perhaps you could post at the BitDefender forums, although I have seen many threads there go unanswered regarding the issue. Let me know how you get on if you decide to post there. Would be interesting to see what they say if they answer you at all.
     
  20. AVG tray icon is back. tyvm!

    I tried calling them on the phone again yesterday and the US hotline is still disconnected and the Canada hotline still goes to a Petrol Cleanup company. I have had issues unanswered on their boards for months. I doubt if I ever get any answers from them as I just don't think they are a functioning company anymore. I will, however, post again regarding this user account issue to see if I can get answers, and I'll let you know If I do so that any future users will be able to get assistance from you guys in removal.

    Everything seems perfectly okay now. I'll let the kids use it again in a few days after being sure that everything is fine. They have some school work they do online so it's a big deal to make sure.

    one more question, If I may. Any reports on the status of Photobucket? Is it still infected or is there any report on the containment of the infected ads? I have well over 200 photos on there and I'm not going back until the issue has been resolved with them.

    thanks again for all your help! You guys get 5 stars in my book!!
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    To help with ads on photobucket I suggest you try another browser:

    FireFox 3.6

    There's a very nice plug in which will prevent most pop up's, unders, and other forms of unwanted advertising:

    AdBlockerPlus

    Also I am a great fan of this add-on:

    Web Of Trust
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds