Done read and run and then found kazaa

Discussion in 'Malware Help (A Specialist Will Reply)' started by matt-don, Mar 12, 2008.

  1. matt-don

    matt-don Private E-2

    My problems started with bravia (I think) and have been continuing ever since (about 4 days). Avg has deleted/quarantined 30 files since then, mainly pepatch and some trojans.

    Yesterday I had the time and completed the 'read and run me 'process and it looked like I had no outstanding issues . Then last night I ran the asquared online trojan scan and it found kazaa. In my idiocy I deleted it from quarantine so cannot give the full name.

    In addition to all of this system restore is showing my secondary hard drive (F) as monitoring but not showing the c: drive at all. My clock settings have remained changed by combofix (I think) so that it displays as 2008-03-12.

    I just started avg again and it says C:\windows\system32\drivers\etc\hosts has changed. It also says that c:windows\system32\shell32.dll has changed but it has been reporting this for a couple of months. I did research the shell32 entry when it first occured and found that this is supposed to be 'normal' for avg.

    Any help will be much appreciated.

    Cheers
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the log from SUPERAntispyware. You attached a log from Active Sync which we do not need.

    This is due to ComboFix not running 100% to completion.

    You can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.

    Your logs only show one item of concern so let's fix it and also we can clean up some unnecessary stuff (not malware) with HijackThis:


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com (file missing)
    O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - file://E:\ols\cd-db\fscax.cab

    After clicking Fix, exit HJT.


    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
     
    Driver::
    adxapie
     
    File::
    C:\DOCUME~1\Matt\LOCALS~1\Temp\adxapie.sys
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!


    If you continue to have malware detections, you will have to save a log of exactly what and where things are being detected.
     
    Last edited: Mar 14, 2008
  3. matt-don

    matt-don Private E-2

    Hi Chalsang,
    I have attached the files that you have requested. I am sorry that I had attached the wrong file and possibly wasted some of your time.

    Last night my iTunes profile completely dissappeared and cannot be found. I don't know if that is related or not.

    I see that you have quoted me on 'System restore' but there is no text from you. Am I missing something?

    I will run SuperAntispyware again and see what happens. I can't run (and have not been able to for a while) an online scan with Bitdefender. Is malware preventing this?

    Thank you very much for your time and effort, I would be completely lost without your help.

    Regards

    Matt
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Unrelated.


    I was going to ask if you had it enabled on both drives.

    I doubt it.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    aiuwghcsrfwe
    KService
    
    FileLook::
    C:\WINDOWS\SYSTEM32\TG_DUMP0708.DLL
     
    File::
    C:\WINDOWS\SYSTEM32\DRIVERS\aiuwghcsrfwe.sys
    Folder::
    C:\Program Files\Kontiki
     
    Registry::
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. matt-don

    matt-don Private E-2

    Hi Chalsang,
    I have enclosed the files.
    I have also includeda picture of system restore. This is what I see when I right click 'my computer', click properties, click the sytem restore tab on got to settings. I cant see how I include the c:\ drive or turn it on.

    Thank you very much for your help.

    Regards
     

    Attached Files:

  6. matt-don

    matt-don Private E-2

    For some reason the jpg did not load the first time.

    Regards.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I suggest that you start a thread in the Software Forum for this. Make sure you explain what the F drive is and that the C drive is your Windows boot drive. Also if you are using any special partition tools or dual boot.....etc then make sure you explain this too.

    Your logs are clean. Are you having any other malware issues?
     
  8. matt-don

    matt-don Private E-2

    Hi Chalsang,
    I have just run asquared's online trojan scan again. It has repeated that it has found:

    Trace.Registery.KaZaA

    Trace:Key:HKEY_CURRENTUSER\software\kazaa

    This was supposed to have been quarantined by it last time.
    I have never installed KaZaA.

    Thanks

    Matt
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a major issue and I don't know why A-squared does not just fix it. It is just a left over registry key. You could try using the below patch which should remove it unless the registry key is locked due to being own by another user.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  10. matt-don

    matt-don Private E-2

    Hi Chalsang,
    Eveything seems to be fine now. No malware alerts or issues. :)

    I am also now able to access the BBC iplayer. :) I could not do that before. Kontiki issue I guess.

    I posted in software about C: being missing in system restore. No solution as yet.

    Thank you so very much for your excellent help. I don't know what I would have done without it. :) :) :)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. Uninstall COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN
      • Now type cf /u in the runbox and click OK.
      • Note: The space between the cf and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds