Help Please! Stubborn Scumware won't die!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dazed&confused, Sep 11, 2004.

  1. dazed&confused

    dazed&confused Private E-2

    Hello,

    I am fairly new at this and posting for the first time, so please be gentle. (lol :) )

    I am trying to clean a friends computer that was loaded with scumware. I am trying to follow the recommendations in the article about basic spyware and virus removal. Here are the vital stats:

    Windows XP Home
    Intel P4 2.4 GHz
    512 Meg Ram
    System updated except for SP2
    Norton Internet Security 2004 with Antivirus 2004 = updated
    SpySweeper = updated
    Ad-Aware Personal SE = Updated
    SpyBot Search and Destroy = Updated
    System Restore = off
    Hidden/System files, known extensions are shown
    Network Security & Workstation Netlogon Services = Not found

    I have scanned numerous times with the programs listed above, and with several of the online scanners that I have seen mentioned on this site (Trend Micro House Call, RAV, Bit Defender, WindowsSecurity.com Trojan Scanner). These scans seem to have gotten rid of most of the parasites, but there are a few stubborn ones that I can't seem to get rid of. The problems I can't seem to get rid of are as follows:

    Mediaticketsinstaller.ocx identified as Adware.cdt by Norton and as Adware.Mediatick.A by BitDefender

    WinadX.dll=>(Upx) infected: Trojan.Downloader.Winupdt.A identified by BitDefender

    TFTP204, TFTP3044, TFTP3352, TFTP3884 - All identified as Backdoor:IRC/Sdbot.dam#2 by RAV

    SpyBot identified DSO Exploit, but, after researching this site, I understand that, as long as Windows is up to date, this is not a big deal.

    There are also a couple of questionable files on the startup tab of msconfig that were not identified by the scans, but I think they are suspect. Hopefully you can tell me what these are and how to get rid of them if they are bad. They are:

    fukerz.exe
    wuammgr32.exe

    I am prepared to run HijackThis if/when necessary, but I will await your request to do so, and will post the log at the appropriate time.

    Sorry for the long post, but I wanted to provide as much information as possible. Thanks in advance for your assistance. You guys are great!

    --dazed&confused--
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. Boccemon

    Boccemon First Sergeant

    What wonderfully perfect post!!! Thank you. It was a pleasure to read this.:)
     
  4. dazed&confused

    dazed&confused Private E-2

    Thanks for the speedy response! Again, I say you guys are great. :)

    Thank you for the information about wuammgr32. I read the recovery method on the Sophos website, but I will wait to try it until you guys have a chance to review my HJT log and provide feedback/guidance. I am a little nervous about messing with the registry by hand (at least without the guidance of a seasoned pro).

    Has anyone heard of the other file I mentioned (fukerz.exe)? I think it probably needs to go too, but I am not sure what it is, or how to get rid of it.

    I also noticed in the HJT logfile that McAfee still seemed to have something loaded. It shouldn't because it has been uninstalled. Norton Internet Security replaced it.

    Anyway, here is my HJT logfile. Take a look at it and see what you think. Thanks again for your help.

    --dazed&confused--
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First make sure of the following:
    1) You have disabled system restore (but do not reboot when asked too, we will reboot later): http://forums.majorgeeks.com/showthread.php?t=31668

    2) Make sure you have enable viewing of hidden files: http://forums.majorgeeks.com/showthread.php?t=37650

    Let's begin by running HijackThis and putting check marks on the following lines BUT DO NOT CLICK FIX UNTIL you terminate all browser sessions including the one you are reading right now. Then after clicking fix, immediately reboot into safe mode:
    O2 - BHO: (no name) - {39DD3B2B-EA48-2CE6-D705-63550FD9704B} - C:\WINDOWS\System32\quoknbmp.dll (file missing)
    O4 - HKLM\..\Run: [Microsoft Update] wuammgr32.exe
    O4 - HKLM\..\Run: [SmallAndSecure] mssecure.exe
    O4 - HKLM\..\Run: [fukerservice] fukerz.exe
    O4 - HKLM\..\RunServices: [Microsoft Update] wuammgr32.exe
    O4 - HKLM\..\RunServices: [SmallAndSecure] mssecure.exe
    O4 - HKLM\..\RunServices: [fukerservice] fukerz.exe

    Now reboot in safe mode and delete the following:
    c:\windows\system32\fukerz.exe
    c:\windows\system32\wuammgr32.exe
    c:\windows\system32\mssecure.exe

    If you do not find those files there, also look in:
    c:\windows
    c:\windows\system
    c:\documents and settings\username\Local Settings\Temp (where username is you user name)

    If still not found use advanced search options as follows:

    How to use windows XP search mechanism to look for hidden files:
    If you use Search, you need to do the following:
    Click Search and the Select "All files and folders"
    Enter the filename in the "All or part of the file name:" box
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    - Search system folders
    - Search hidden files and folders
    - Search subfolders

    Then click the Search button.
    If found, right click on the file and then select Delete.

    After deleting all those file, empty you recycle bin and also go to c:\windows\Prefetch and look for lines with any of those bad filenames in them and delete them too.

    Then reboot in normal mode.

    Let me know how this goes. Post a new HJT log attachment. If everything is resolved we will re-enable system restore.
     
    Last edited: Sep 11, 2004
  6. dazed&confused

    dazed&confused Private E-2

    Thanks chaslang. I followed your directions and HJT seems to have taken care of the three issues you noted. You are great! I have attached my current HJT log below for your verification.

    I also ran all of the same antivirus/spyware detection programs again after following your directions, and they still noted a few issues. I thought I would get your opinion on them. The details of my scans are posted in the second attachment. I ran a search for the questionable files on the Registry and found four Keys that mentioned them, but I can't find the actual files anywhere on the system. I have listed the keys at the bottom of my scanner log file. Let me know what you think I should do with them (if anything).

    Thanks again for your assistance. I don't know what I would have done without your help. :)

    --dazed&confused--
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Did you make sure you had enabled viewing of hidden files? http://forums.majorgeeks.com/showthread.php?t=37650

    How did you look for the files:
    1) did you use Advanced Search settings I gave
    2) or did you use Windows Explorer to navigate to the files

    I would recommend booting in safe mode and doing the following:

    Delete these two files:
    C:\WINDOWS\Downloaded Program Files\MediaTicketsInstaller.ocx
    C:\WINDOWS\Downloaded Program Files\WinadX.dll

    In the registry go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage:
    and delete the below two entries in from the right pane:
    C:/WINDOWS/Downloaded Program Files/MediaTicketsInstaller.ocx
    C:/WINDOWS/Downloaded Program Files/WinadX.dll

    If those entries are also list in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
    delete them from there too. For both the ModuleUsage and SharedDLLs registry keys make sure that you only delete the two entries for MediaTicketsInstaller.ocx and WinadX.dll and nothing else.

    Are the below file the ones you could not find? Did you look in safe mode wit hidden files, folders and system files viewable?
    C:\WINDOWS\SYSTEM32\TFTP204
    C:\WINDOWS\SYSTEM32\TFTP3044
    C:\WINDOWS\SYSTEM32\TFTP3352
    C:\WINDOWS\SYSTEM32\TFTP3884

    Try running McAfee Avert Stinger: http://www.majorgeeks.com/download4063.html
    You should be able to run this in normal boot as well as safe mode if necessary.

    Then rescan with RAV & BitDefender again. Let me know the results.
     
  8. dazed&confused

    dazed&confused Private E-2

    Thanks again, chaslang. You have been a great help! :)

    I searched in safe mode and double-checked my selection for "show Hidden/System files" and made sure to choose to show all extensions prior to search, but I still could not find the files. I tried searching both ways, with Advanced Search settings, and manually with Windows Explorer. Those files are nowhere to be found.

    I can't figure out what is going on with this system. Even though I couldn't find them with a Search, Norton and BitDefender both still found MediaTicketsInstaller.ocx, and BitDefender still found WinadX.dll as well.

    I deleted the Registry keys that contained those two files while I was in
    safe mode, and restarted a couple of times, then went back into Regedit
    to make sure they stayed deleted. I think the Keys are gone for good.
    I haven't seen them come back. Does that mean that it is safe to assume that they are not running anymore?

    Stinger did not find anything but RAV still found the four other files I
    mentioned earlier. Here is the summary:

    Scan started at 9/13/2004 10:27:26 PM

    Scanning memory...
    Scanning boot sectors...
    Scanning files...
    C:\WINDOWS\SYSTEM32\TFTP204 - Backdoor:IRC/SdBot.dam#2 -> Infected
    C:\WINDOWS\SYSTEM32\TFTP3044 - Backdoor:IRC/SdBot.dam#2 -> Infected
    C:\WINDOWS\SYSTEM32\TFTP3352 - Backdoor:IRC/SdBot.dam#2 -> Infected
    C:\WINDOWS\SYSTEM32\TFTP3884 - Backdoor:IRC/SdBot.dam#2 -> Infected

    Scanned
    ============================
    Objects: 34014
    Directories: 2435
    Archives: 2810
    Size(Kb): 1454754
    Infected files: 4

    Found
    ============================
    Viruses found: 1
    Suspicious files: 0
    Disinfected files: 0
    Mail files: 63

    I figured it would still find them, because I haven't deleted them yet. I found them with my search, but I was hesitant to delete them because they are in the System32 folder with several other files similar to them and an .exe file that was described as "Trivial File Transfer Protocol App" by Microsoft. I wasn't sure what this program did, and I was afraid deleting the four files would render the program inoperative (not to mention causing errors with the system). Do you think it is safe to delete them?

    As always, thank you very much for your help. I am open to any suggestions at this point. I am starting to think a format/re-load may be the only option for a clean computer at this point. Whatever these things are, they sure are stubborn.

    Thanks again,

    --dazed&confused--
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After deleting the registry keys are Norton & BitDefender still finding MediaTicketsInstaller.ocx and BitDefender still found WinadX.dll?

    If yes, that is because Microsoft (in their somewhat typical stupidity) does not show files in the Downloaded Program Files folder. Please download and install ExplorerXP: http://www.majorgeeks.com/download4201.html

    And use it to look in that folder for those files. If found, delete them.

    Delete the below 4 files, they are not part of tftp.exe (which is a valid program).
    C:\WINDOWS\SYSTEM32\TFTP204 - Backdoor:IRC/SdBot.dam#2 -> Infected
    C:\WINDOWS\SYSTEM32\TFTP3044 - Backdoor:IRC/SdBot.dam#2 -> Infected
    C:\WINDOWS\SYSTEM32\TFTP3352 - Backdoor:IRC/SdBot.dam#2 -> Infected
    C:\WINDOWS\SYSTEM32\TFTP3884 - Backdoor:IRC/SdBot.dam#2 -> Infected
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I just determined the ExplorerXP has a bug. It shows the files in that directory but if you try to delete the file the program has an error and aborts.

    Let's just use the command prompt to do this. Do the following:
    Click Start, Run, and in the open box enter "cmd" without the quotes then click OK
    In the command prompt window that comes up enter the following sequence of commands:
    cd "c:\windows\Downloaded Program Files" <--- you need the quotes here
    del MediaTicketsInstaller.ocx
    del WinadX.dll

    If you get an error trying to delete those files, do this and then repeat the above two del commands:
    attrib -s -h -r MediaTicketsInstaller.ocx
    attrib -s -h -r WinadX.dll

    Let me know how this works out.
     
  11. dazed&confused

    dazed&confused Private E-2

    chaslang,

    Thank you! Thank you! Thank you! :) :) :) You are the greatest! You have helped me straighten this mess out. I am forever greatful.

    I think all the scumware has finally been removed. The command line removal of those files worked great. I have run all the scans, and they came up clean. Hopefully this computer is done now (for a while anyway). I just hope my friend doesn't let it get like this again.

    Thanks again for all the help.

    --dazed&confused--
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome! And here is a canned speech some of which you may already have:

    Make sure you get your system protected from reoccurrence of issues like this. Here are some simple steps you can take to reduce the chance of infection in the future. I strongly encourage you to do them all.

    1. Visit Windows Update:
    Make sure that you have all the Critical Updates recommended for your operating system and IE. The first defense against infection is a properly
    patched OS.
    a. Windows Update: http://v4.windowsupdate.microsoft.com/en/default.asp
    Do this at least once a month.
    b. Never add any site to your Trusted Sites Zone.

    2) Anti Virus: make sure you have one and keep it updated. Here are some good free ones:
    http://majorgeeks.com/download1968.html Avast
    http://majorgeeks.com/download886.html AVG
    The top two hands down. Better than Norton or McAfee!
    Only run ONE AV!

    3) Firewall: if you don't have one get one of these below. The last two are free versions:
    Don't care if your on dial up or High Speed....you must have a firewall
    http://majorgeeks.com/download738.html Kerio Personal Firewall
    http://majorgeeks.com/download3356.html Sygate Personal Firewall Free
    http://www.majorgeeks.com/download388.html ZoneAlarmFree

    4) Get a Temp File/Cookies/index.dat cleaner
    http://majorgeeks.com/download4191.html CCleaner (Crap Cleaner)

    5) SpyWare Prevention (These prevent, they are not scanners. Scanners are listed later.)
    http://majorgeeks.com/download2859.html SpyWare Blaster
    http://majorgeeks.com/download3045.html SpyWare Guard

    6) SpyWare Scanners/Removers
    http://majorgeeks.com/download2471.html SpyBot (Use the Immunize feature. I don't activate the TeaTimer)
    http://majorgeeks.com/download506.html Ad-aware SE
    http://www.majorgeeks.com/download4283.html VX2 Cleaner Plug-In for Ad-Aware
     
  13. dazed&confused

    dazed&confused Private E-2

    Yes. I have already given them "The Speech" about safe surfing, keeping programs updated, and scanning on a regular basis. :) I also printed out your previous reply and gave it to them so they would have your suggestions. Hopefully they will take your advice. If not, I may have to call on your expert advice again.

    You have been a great help. Thanks again for all your help. I couldn't have done it without you.

    --dazed&confused--
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're most welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds