Gaobot Worm

Discussion in 'Malware Help (A Specialist Will Reply)' started by alphakilo, Jul 25, 2009.

  1. alphakilo

    alphakilo Private E-2

    Hi, yesterday I managed to land myself with what windows diagnosed as a gaobot worm. The system error message mentioned something about b.exe not being able to run.

    I proceeded to carry out all the instructions of your malware removal procedure. When I open task manager now, b.exe and c.exe are no longer running, and so far there have been no random popups every ten minutes, as was the case before I carried out your procedures.

    However, I'm still worried that the problem has not been solved completely, so I'm posting all five log files in these two posts, and hopefully you can help me look through them to see if everything's alright?

    The computer I'm using is my new laptop, so I really hope it can come through clean.

    Thanks a lot.
     

    Attached Files:

  2. alphakilo

    alphakilo Private E-2

    MG Log

    And here's my MG Log.

    Thanks again.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Uninstall the below old versions of software:
    Java(TM) 6 Update 7

    You have a little more to do. Shutdown McAfee and Windows Defender before doing the below.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O3 - Toolbar: QT TabBar - {d2bf470e-ed1c-487f-a333-2bd8835eb6ce} - mscoree.dll (file missing)
    O3 - Toolbar: QT Tab Standard Buttons - {d2bf470e-ed1c-487f-a666-2bd8835eb6ce} - mscoree.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    After reboot your PC. After reboot, install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. alphakilo

    alphakilo Private E-2

    thanks chaslang.

    I'll respond step by step.

    I already installed the newest version of Java yesterday because I had to upload some photos on facebook. But just now I went ahead and uninstalled the older version anyway.

    I then ran HJT, did what you told me, and edited the registry successfully. The subsequent reboot, however, took an unusually long time - is that because of the registry changes?

    After rebooting I directly ran Ccleaner, then MG. I have the log attached here.

    As for how my laptop's running now, I think it's too early to say. Bad thing is, I have no way to tell how fast it can potentially run, as I was hit by the worm before I even got a hang of the laptop.
     

    Attached Files:

  5. alphakilo

    alphakilo Private E-2

    i'm really sorry I had to bump, chaslang, but just a quick word on performance:

    everything seems to be fine, except everything's loading slower on the internet...those things I did - did that set up some kind of internet protection? Cos everything, absolutely everything, is slower. And I'm sure I didn't change anything in regards to internet settings.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No!

    Your log from MGtools is too incomplete to be useful. Please make sure you follow instructions properly. We never asked you to delete the previous MGlogs.zip file or to rename the file but apparently you did. Do not do this. Also you must make sure you allow the scans to finish running as given in the original Using MGtools link in the READ & RUN ME.

    Please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Make sure you let it finish. DO NOT close the command prompt window yourself. It will tell you when it is finished and will say that hitting any any key will close the window.


    Then attach the below logs:
    • C:\MGlogs.zip
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It only affects you not me. ;) It just takes longer for you to get a reply.



    Nothing we did changes your settings nor would it affect performance. It is the software you are loading/running that effects your startup time and your overall performance. Perhaps before you came here you had been using MSconfig to disable many of the startups, but we tell you not to use MSconfig and thus this could have changed your behavior. However you still must not use MSconfig. Take a look at all the stuff you are loading! That is why your PC starts up slowly.
    • Two Google update services
    • All the ThinkVantage junk
    • The TVT backup stuff and in general all the Lenovo junk. Are you really using this?
    • And then add McAfee which is a massive resource hog.
     
    Last edited: Jul 30, 2009
  8. alphakilo

    alphakilo Private E-2

    Hi chaslang,

    I've redone the MGtools scan, and I've attached the log file here. I'm not sure what you were saying about deleting the last log file, because I didn't do that. But the previous time I accidentally doubleclicked GetLogs.bat and didn't select run as administrator, so I had to close the window myself; I suppose that's what did it.

    I'm not particularly familiar with computers, so I'm a bit scared to remove anything that came with the laptop. That's why all the thinkvantage stuff is here. I'd love to make more room in the computer if it doesn't affect anything. Oh and about McAfee - would it be better if I uninstalled that and used AVG instead?
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to your last MGlogs.zip file the registy patch I gave you back in msg # 3 was not successful. Are you sure it said it was successful? Do you still have UAC disabled? Also was McAfee disabled before running the patch?

    The new version of AVG is more of a resource hog than it used to be unless you are careful during the installation and don't allow it to install all the wasteful baggage. I actually prefer Avira AntiVir. You would also need to install a firewall if McAfee was uninstalled. If you are happy with McAfee and the performance of your PC then don't change anything.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds