Flec006 troubles

Discussion in 'Malware Help (A Specialist Will Reply)' started by stevejouanny, Nov 28, 2008.

  1. stevejouanny

    stevejouanny Private E-2

    Hello there,

    My friends computer has contracted this nasty. The first thing I did was to come here, and I found this thread:

    http://forums.majorgeeks.com/showthread.php?t=148513

    This seemed a very sensible thread. Now, I have followed each step until this one:

    'Run C:\MGTools\analyse.exe'

    I cannot go any further because the program opens for about a second then it closes. It says in the thread that this is essentially HiJack This. So I copied the latest version of HJT onto a CD (from an uninfected computer, naturally) and then installed HJT onto the infected computer. When I tried running it, the screen displayed: 'This is not a valid Win32 application'.

    If I can get past this, I am on the way to progressing to the other steps, but I know of the importance of doing things step by step - and I do not want to go any further until I can run HJT. Are there any ways around this problem?
     
  2. stevejouanny

    stevejouanny Private E-2

    Ok, an update -

    I've been able to run Hijack This and fix and kill the process as detailed in the thread, no thanks to MG responses.

    As an addendum, its pretty grievous that a serious issue like this has had fewer attention given to it than a poxy MSN issue...or an about:blank redirect - neither of which can empty someone's bank account! I was not even welcomed. My suspicion is that I wasn't responded to because I did not post any logs. Well, I can't in all fairness because the logs come from the infected computer and not the one I'm using to correspond, so I'm unable to put logs on here, as I want to keep problems to a minimum (the logs could be infected too). I will not attribute to malice that which can be attributed to indifference, but I would have preferred a response either way.

    (And yes, I did search this forum for previous Flec006 threads, neither of which specifically addressed the problem I had).
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Oh hello there :wave and welcome to Majorgeeks.com

    Every fix we carry out is tailored for THAT machine only, so it's essential you do not use another's thread as a base to solving you problems.


    We work oldest to newest threads first, so this is why the other "poxy" msn and about blank issues were being dealt with. We all work here on a voluntary basis and devote and dedicate our own free time to helping people such as yourselves. A little courtesy wouldn't go amiss, although I understand you are frustrated and want help. :)

    So are you now able tp upload the 4 requested logs? Those being:

    • SUPERantispyware
    • MalwareBytes
    • Combofix
    • MGlogs.zip

    Thanks for your patience
    Kestrel13!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    further more:
     
  5. stevejouanny

    stevejouanny Private E-2

    Thanks Kestrel.

    I've attached a Malware Bytes log, and a MGLogs.zip - I read the tutorial on ComboFix, and I daren't use it - it sounds like a very gung-ho program. Perhaps you'll have to reassure me - SuperAntiSpyware found nothing.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    Before we move on I would like for you to attach the following log from SUPERantispyware:

    Thanks
    Kes13!
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1) Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    2) I recommend that after Avenger has been run and the system has been rebooted (which Avenger should normally do) that you update MBAM to the current database and run a new scan. Make sure you fix anything it finds.

    3)

    • Get me the new MBAM log
    • along with avenger.txt
    • and MGlogs.zip


    Thanks
    Kestrel13!
     
  8. stevejouanny

    stevejouanny Private E-2

    As requested - I've uploaded the anti spyware log.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks :) Now continue on with the post #7 instructions. I will be here waiting when you are ready.
     
  10. stevejouanny

    stevejouanny Private E-2

    Thanks again Kestrel for your patience. Here are the logs as you requested.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1) Please disable TeaTimer: see the below for how to do this:

    How to disable Spybot's TeaTimer


    2) If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    3) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)


    After clicking Fix exit HJT.


    4) Now we need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    
    KILLALL::
    
    File::
    C:\WINDOWS\isRS-000.tmp
    C:\WINDOWS\system32\wintems.exe
    C:\WINDOWS\\system32\drivers\hldrrr.exe
    
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\german.exe]
    "wintems"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\drvsyskit]
    "hldrrr"=-
    
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.



    5) Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).


    6) Now Run Ccleaner!

    7) IMPORTANT! Please go to start > Run > type in msconfig and hit enter:

    Make sure that on the "general tab" you select the radio button for NORMAL start up.

    8) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix

    9) Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.

    Thanks
    kes
     
  12. stevejouanny

    stevejouanny Private E-2

    Hello Kes,

    I've done all the steps you asked - and have attached new logs. I'll be awaiting your reply when you can get around to analysing them.

    Thanks again.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK:) I shall get back to you ASAP, thanks for your patience during this time.
    Kestrel13!
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix again
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    
    KILLALL::
    
    
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "SUPERAntiSpyware"=-
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{03a2d417-9780-11dd-b759-001150141cae}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5afce34c-99d2-11dd-b764-001150141cae}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8b7613fa-2bd6-11dd-b63c-001150141cae}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ca279518-7dcc-11dd-b6dc-001150141cae}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ca279519-7dcc-11dd-b6dc-001150141cae}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cfcdbe04-8414-11dd-b6f4-001150141cae}]
    
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now look for and delete the below files on all hard disk partitions and also on all removeable media (like flash drives or USB drives) that you use on this PC. Also check other PCs where this removeable media has been used.


    • autorun.exe
    • nideiect.com


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:

    • C:\ComboFix.txt
    • C:\MGlogs.zip

    Make sure you tell me how things are working now!

    Thanks
    Kestrel13!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds