Bloodhound.Packed.Jmp Gone, Hidden Files Still Invisible

Discussion in 'Malware Help (A Specialist Will Reply)' started by tehfeeds, Apr 6, 2008.

  1. tehfeeds

    tehfeeds Private E-2

    I know this is probably a silly problem to most, but I'm really having a hard time with it...

    Symantec AntiVirus recently detected Bloodhound.Packed.Jmp on my laptop more than once. A friend advised me to run Windows in Safe Mode, then open up Symantec AntiVirus, run LiveUpdate and do a Full Scan. Sure enough, that took care of the malware. However, a problem still persists; I noticed that when I first got the malware infection, I couldn't view hidden files no matter how many times I select the "Show hidden files and folders" radio button from Explorer > Tools > Folder Options > View. Even though the malware seizes to be on my laptop, the hidden files problem is still there (I also can't uncheck "Hide protected operating system files").

    Help? Please? :(
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. tehfeeds

    tehfeeds Private E-2

    I followed all procedures. Here are the logs.

    NOTE: ComboFix did not run properly; I renamed it, double-clicked on it, but all it did was open up a seemingly-blue screen in ms-dos prompt for a split second and that was it. No log, no nothing.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. tehfeeds

    tehfeeds Private E-2

    I followed all the aforementioned steps and ran CCleaner from all my laptop's profiles, including the Administrator profile that is only available in Safe Mode. I can toggle the checkbox for hiding the system files now, but I still have trouble showing hidden files (the radio button resets to "Do not show hidden files and folders" as soon as I exit).

    Here are the logs you requested...
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to your runkeys.txt log (in the MGlogs.zip file) the options are set properly. Your log shows the below.
    GetRunKey.bat automatically sets these options when it starts and then later it retrieves them to make sure they were set. After you have run GetLogs.bat, what does the radio button show.

    Make sure you are not blocking things from being changed with Symantec.


    Your logs are clean, but let's try something else.

    Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. tehfeeds

    tehfeeds Private E-2

    It shows neither radio buttons are selected; basically, both buttons for showing hidden files and not showing them are blank. That's weird! I'm afraid of choosing one of the radio buttons, it might go back to being stuck on not showing hidden files and folders.

    I'm pretty sure Symantec is not blocking anything.

    Here are the files you requested...
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If it is showing them as not selected, then all is good and you don't need to change them.

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    5. If we had you run Avenger, you can delete all files related to Avenger now.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. tehfeeds

    tehfeeds Private E-2

    UPDATE: As of 4/12/2008 at 10:31:42 AM [GMT+3], my Symantec Risk History shows 13 counts of an Infostealer.Gampass threat under filename mvxm.cmd, original location is E:\ (which is the external hard disk I own that I just hooked up an hour or so ago).

    What should I do? :-|

    By the way, I unplugged my external hard disk right away and am thinking about simply formatting it and repeating the READ ME RUN ME steps all over again and posting logs. Does that sound like a good idea?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First update your Symantec Definitions as they may be out of date. Then reboot and run a new scan of both your fixed disk drive and your external drive. If Symantec is still finding problems, you will have to be much more specific on exactly where it thinks these problems are. And also if Symantec does not fix the problems, you need to complain to them. You may also want to see the below thread were another person had issues with this being detected by Symantec and it appeared to be incorrect based on the info that Symantec provides on Gampass:

    http://forums.majorgeeks.com/showthread.php?t=154465
     
  11. tehfeeds

    tehfeeds Private E-2

    Well, I think I finally got rid of all malware on the external hard drive as well. Since it connects through a USB port, I simply ran Flash Disinfector on it, then went and explored it. I found a fishy folder with random numbers and letters in it; when I opened it, it had a wcu folder with some weird files that had even weirder filenames (e.g. ASPNET.msp and Netfx20a_x86.msi). I simply zipped up the file using WinRAR and made sure I checked "Delete files after archiving" then deleted the ZIP file. It worked! And I haven't gotten any more warnings from Symantec AntiVirus.

    I'm going to run your previously-mentioned final steps and tell you how it goes.
     
  12. tehfeeds

    tehfeeds Private E-2

    Clean as a whistle!

    Thank you so much, chaslang. I'm definitely recommending this website to everyone I know.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These were not problems. They are from installing Microsoft .NET Framework.

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds