Caught with FlashPlayer ecard.exe

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by pnelson, May 4, 2007.

  1. pnelson

    pnelson Private E-2

    Got caught out with this one and installed the file to my desktop. Received a couple of error messages when first installed. Have since rebooted (after setting MSConfig Startup Mode as requested in http://forums.majorgeeks.com/showthread.php?t=35407) and the only visible symptom that I can see now is that I cannot open Firefox - the .exe file seems to have disappeared altogether.

    Before discovering MajorGeeks, I did run the Blacklight Trial from F-Secure (http://www.f-secure.com/blacklight/) although it reported that it found nothing.

    Attached are the following:

    GetRunKey log
    ShowNew log
    HijackThis log

    Hope these help - and could really appreciate knowing that my system is cleaned before I reinstall Firefox or go on the web properly!

    Regards


    Patrick
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    To skip steps of the guide or not attach the requested logs will not show all the malware that could possibly be still on your PC, in the case of hijackthis, you read the guide but failed to read the note on renaming Hijackthis to analyze.exe as this is crucial in that some new malwares will nto show in hijackthis unless that step is taken your Hijackthis was run as ~ C:\Program Files\HijackThis\HijackThis.exe

    There are another 3 logs that were requested that could hold some clues, please do follwo the guide as laid out and in the order its written as its an effective way to not only clean the easier malwares out be allow you to generate some logs for the malware experts here to review and assist you in removing any remaining pests.



    Our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. pnelson

    pnelson Private E-2

    OK, I understand - apologies for my impatience earlier.

    I have decided to go through all the steps again.

    So, had a look at removing Malware via Add/Remove programs. I honestly know every program that is on that list - and there is nothing there that is wrong.

    MSConfig Startup Mode - Yep, that's OK

    Also ran CCleaner again, just for good measure

    Made sure that hidden files, system files and file extensions are all viewable

    Only got one anti-virus running (F-Secure for the record) - and only one firewall (Windows Firewall) - there is also a firewall on my router, I believe

    Ran GetRunKey.bat and attached the logfile (runkeys1.txt)

    Ran ShowNew.bat and attached the logfile (newfiles1.txt)

    Ran SpyBot - had all updates, all immunisations done. Turned Teatimer off. Left SDhelper on. Fixed the Ignore Products Bug

    Ran CounterSpy - the logfile said this:
    Scan History Details
    Start Date: 04/05/2007 20:50:36
    End Date: 04/05/2007 20:53:06
    Total Time: 2 Min 30 Sec
    Detected security risks
    No risks were found during this scan.

    Rebooted the computer into safe mode and unplugged it from the Internet and shut down all unrequired apps.

    Ran CCleaner with default options.

    Ran SpyBot again. Removed the stuff that it found (ran it as I did before)

    Ran CounterSpy again and have attached the log file (Counterspy.txt).

    That's three attachments now so will continue in the next post.
     

    Attached Files:

  4. pnelson

    pnelson Private E-2

    Then went on to run BitDefender as asked and have attached the log file (bdscan.txt).

    Next, ran the Panda ActiveScan and have attached the log file (Activescan.txt).

    Rebooted into Normal Boot Mode and ran GetRunKey and ShowNew again. Have attached the logfile from GetRunKey (runkeys.txt).

    Continuing in the next post as have reached three attachments again.
     

    Attached Files:

  5. pnelson

    pnelson Private E-2

    Have attached the logfile from the most recent run of ShowNew (newfiles.txt).

    Finally, because there were still problems listed (e.g., at the very bottom of runkeys.txt, for example), I ran HijackThis following the instructions to the letter and have attached it's log file (hijackthis.log)

    I encountered no problems running anything - although BitDefender reported that one file could not be deleted and the Panda ActiveScan didn't solve a lot of the problems it found as predicted.

    Believe it or not, I'm actually going on holiday now! (Plane leaves in 3 hours) so I'll eagerly check here when I get back. Thanks in advance for all your help.
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    When you get back from Holiday, post fresh logs. As posting a fix using these logs will be based on out of date information, and many forms of malware will morph upon system reboot.

    It is always best to work with fresh logs.
     
  7. pnelson

    pnelson Private E-2

    OK, I have done this. I have followed the instructions again and the attachments are in this post and in the next post.

    My PC is currently in normal boot mode as per the state at the end of the instructions and I have neither rebooted nor restarted. I await further help!

    I cannot, however, attach Activescan.txt from the Panda ActiveScan as when I do, I receive a message saying that "You have already attached this file in thread : Caught with FlashPlayer ecard.exe"

    I tried renaming the file to Activescan2.txt but this doesn't make any difference.

    Regards


    Patrick
     

    Attached Files:

  8. pnelson

    pnelson Private E-2

    Here are the next three attachments.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is no reason to run HijackThis at startup. It is not a spyware scanner or removal tool. Run HijackThis now and unselect the option to run HijackThis at startup. Or alternatively run HJT and fix the below line which loads it at startup.
    O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\HijackThis\HijackThis.exe /startupscan


    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also while in Add/Remove Programs, uninstall FireFox (we will reinstall later)!

    Also delete the below two folders:
    C:\Documents and Settings\All Users\Start Menu\SpyHunter.lnk
    C:\Documents and Settings\All Users\Desktop\Spyhunter.lnk
    E:\Documents\Esther\bsplayer141.832

    Now reboot your PC!

    After reboot run Windows Explorer and locate the below files and delete them if found. The first two should exist since they were in your logs.
    C:\WINDOWS\system32\tracerts.exe
    C:\WINDOWS\system32\winverr.exe
    C:\WINDOWS\system32\Mshyta.exe
    E:\Documents\Esther\bsplayer141.832.zip
    E:\Downloads\WebDev\THE ULTIMATE DREAM! CD1\Software\iMeshV4.exe


    Now also delete the below folder.
    c:\Program Files\Mozilla Firefox

    Then reinstall the current version of FireFox from: Mozilla Firefox

    Now please download the current version (just updated) of GetRunKey.zip from: Using GetRunKey and use it from now on to get logs

    Now attach new logs from
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?
     
  10. pnelson

    pnelson Private E-2

    First of all, thanks for this Chaslang,

    1) Ran HJT and fixed the line below:
    O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\HijackThis\HijackThis.exe /startupscan

    2) Did not uninstall CounterSpy as I actually bought it and installed the full copy.

    3) Uninstalled FireFox

    4) Deleted:
    C:\Documents and Settings\All Users\Start Menu\SpyHunter.lnk
    C:\Documents and Settings\All Users\Desktop\Spyhunter.lnk
    E:\Documents\Esther\bsplayer141.832

    5) Rebooted PC

    6) After reboot ran Windows Explorer and tried to locate the files below to delete them:
    C:\WINDOWS\system32\tracerts.exe
    C:\WINDOWS\system32\winverr.exe
    C:\WINDOWS\system32\Mshyta.exe
    E:\Documents\Esther\bsplayer141.832.zip
    E:\Downloads\WebDev\THE ULTIMATE DREAM! CD1\Software\iMeshV4.exe

    However, I could not find the first three. The only similar files in the C:\WINDOWS\system32 folder were:

    tracerpt.exe
    tracert6.exe
    tracert.exe
    winver.exe
    mshta.exe

    7) Deleted the folder c:\Program Files\Mozilla Firefox

    8) Reinstalled FireFox

    9) Downloaded the current version of GetRunKey.zip

    10) Attached new logs from
    GetRunKey
    ShowNew
    HJT

    Not sure how things are running yet - bit too early to tell :) but am a bit concerned that I couldn't find those three files in the system32 directory.

    Just in case it's relevant, Windows is currently waiting to install some updates which Automatic Updates has downloaded from Microsoft but I have not instructed it to do so yet because I want to resolve this problem first.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They are gone based on your logs! Don't worry about it. Something between message # 5 logs and now that you did must have removed them.

    But what about FireFox that you said would not run. You should have been able to easily test it.

    Wait until we are done.
     
  12. pnelson

    pnelson Private E-2

    :) No problem. What do we do next then?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm still waiting on your answer to a question I asked twice.
    And also on whether you are having any malware problems!


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds