Help removing some crazy random word thing.

Discussion in 'Malware Help (A Specialist Will Reply)' started by chickenelmo, Jan 28, 2007.

  1. chickenelmo

    chickenelmo Private E-2

    Hi there.

    I have managed to get on my system some adware or spyware that uses multiple random words and creates its own files in application data and so forth. I also have a few other bits and peices as well.

    I have just gone through all of the before asking for help scans and after scanning this crazy random word thing is still there.

    Here are the log files for you to take a look at, they can probably tell you more than I can about it.

    all I know is that there is something called messhide.exe in a file called book funk atom flap and I keep getting pop ups.

    Thank you for your help in advance.
     

    Attached Files:

  2. chickenelmo

    chickenelmo Private E-2

    and the second lot.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Last edited by a moderator: Jan 29, 2007
  4. chickenelmo

    chickenelmo Private E-2

    my apologies for that. I did not realise i needed updated versions.

    here are the logs for the new versions.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How could you have old version if you only joined the forums on 01-28-07 . Where and when did you get the other versions from?
     
  6. chickenelmo

    chickenelmo Private E-2

    Hi there,

    I have been on these boards previously with another malware problem and was helped by you chaslang. I had the name dj_meditate or something, I had to make a new name as I could not remember what my name was and my emails have all changed sine then. This was about mid last year I think.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download FixWareout by LonnyRJones from one of the two below links and save it to your desktop.

    http://downloads.subratam.org/Fixwareout.exe

    http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

    * Run Fixwareout.
    * Click Next,
    * then Install,
    * make sure Run fixit is checked
    * and click Finish.
    * The fix will begin; follow the prompts.
    * You will be asked to reboot your computer; please do so.
    * Your system may take longer than usual to load; this is normal.

    When you run fixwareout, just follow the prompts, you will need to restart when prompted.

    After rebooting (restart) back into normal boot mode, make sure you have all web browsers closed.

    * Go into Control Panel -->Network Connections.
    * Right click on your connection
    * and click Properties.
    * On the Properties page, highlight Internet Protocol(TCP/IP)
    * Click Properties. This will bring up another page.
    * Select Obtain DNS Server Automatically.
    * Click the ok button. The page will close.
    * Press ok on the page in front of you.
    * Restart the computer.
    * Reconnect to the Internet using Internet Explorer.
    * Now come back here and attach the log from fixwareout. It is located at c:\fixwareout\report.txt


    Delete these files:

    C:\WINDOWS\iun6002.exe
    C:\Documents and Settings\All Users\Application Data\BOOK FUNK ATOM FLAP


    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [Atomflapsizeweb] C:\Documents and Settings\All Users\Application Data\BOOK FUNK ATOM FLAP\MessHide.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DC170927-3E91-4A95-9663-24E2DDE04D3C}: Domain = qld.bigpond.net.au
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = qld.bigpond.net.au O17 - HKLM\System\CS1\Services\VxD\MSTCP: SearchList = qld.bigpond.net.au
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = qld.bigpond.net.au O17 - HKLM\System\CS2\Services\VxD\MSTCP: SearchList = qld.bigpond.net.au
    O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = qld.bigpond.net.au
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = qld.bigpond.net.au


    After clicking Fix, exit HJT.
    Run CCleaner.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT

    Be sure to tell us how things are running.
     
    Last edited: Jan 30, 2007
  8. chickenelmo

    chickenelmo Private E-2

    ok here is the log from the fixwareout. on to the next lot now.
     

    Attached Files:

  9. chickenelmo

    chickenelmo Private E-2

    ok now that has been all done.

    here are the reports as asked for.

    The comp seems to be running a bit faster now, but I have only just finished doing what you asked so I can not say just yet.

    Can you tell me what it is that I had on my pc? I have never seen it before.

    I hope there is nothing wrong now.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sophos Anti-Rootkit will scan your computer for files that have been hidden using rootkit technology.

    Many of the newer malware infections use this technology to hide themselves and to make them more difficult to remove.


    Installation
    Download Sophos Anti-Rootkit 1.1 and save to a location you will be able to find such as your desktop​


    Run sarsfx.exe by double clicking on it.​


    Click Accept to agree to the EULA​


    Click Install (if you wish to change the default installation location do so here but remember where you install to, the default is C:\SOPHTEMP)​


    Once it finishes copying files, exit the installer​
    Running the scan
    Navigate to the location that you installed the software to (Default: C:\SOPHTEMP)​


    Run sargui.exe by double clicking on it.​


    Ensure that all three of the options are checked​


    Click Start Scan


    Once the scan is complete, close Sophos Anti-Rootkit by closing the scan window and clicking Exit in the main window​


    DO NOT CLICK 'CLEAN UP CHECKED ITEMS' OR ATTEMPT TO HAVE SOPHOS ANTI-ROOTKIT FIX ANYTHING UNLESS SPECIFICALLY INSTRUCTED TO IN THE THREAD YOU ARE WORKING ON
    Finding the logsClick on Start --> Run

    Type in %TEMP%\sarscan.log and press enter

    The log file will open in the default editor (probably Notepad)

    Click File --> Save As and save the file to your desktop or other location for easy retrieval.

    Then attach new logs for:
    GetRun
    ShowNew
     
    Last edited by a moderator: Jan 31, 2007
  11. chickenelmo

    chickenelmo Private E-2

    hi there.

    ok that has been done and here are the logs.

    I have also attached the log for that anto-root kit as I did not know wether you needed it or not.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Uninstall these old versions of Java:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 7
    J2SE Runtime Environment 5.0 Update 9

    Reboot and install the new version:
    Java Runtime 6

    Tell me how things are running.
     
    Last edited by a moderator: Feb 1, 2007
  13. chickenelmo

    chickenelmo Private E-2

    hi there,

    I could not fix the registry file with that program as it would not let me check it to fix however I have deleted the 3 java updates and installed the new java 6.

    How should I fix this registry file?

    Also how come I have a diferent message in my email compared to what is here?


    cheers.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's a false positive. The registry is fine. You need to tell us how things are running now.
     
  15. chickenelmo

    chickenelmo Private E-2

    it seems to be running fine, it is a lot smoother now. I have left internet explorer open for a while now (i use firefox) and I have had no pop up ads.

    Hopefully all is fixed now
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If everything is working well, then it is time to finish up. Please uninstall any programs that we had you download for the analysis.
    Turn off system restore, re-start your computer and turn it back on.

    Then be sure to read How to Protect yourself from malware.

    Safe surfing!!:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds