Help Wanted with Recovery Plan

Discussion in 'Malware Help (A Specialist Will Reply)' started by Agent H, Dec 23, 2008.

  1. Agent H

    Agent H Private E-2

    The information posted in threads to Tasmus were easy to follow and greatly appreciated -- thank you. I have run the preliminary diagnostics and will attach logs, please help with eradication. Thank you in advance for your time and help.
     

    Attached Files:

  2. Agent H

    Agent H Private E-2

    The remaining logs are attached. Thanks again.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me exactly what issues you are still having.

    In the mean time, I want you to Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Now tell me what this is:
    C:\Documents and Settings\randy\Desktop\u7iavi186129.bin --> and why is it on your desktop?

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  4. Agent H

    Agent H Private E-2

    Thank you for the quick response Tim, I appreciate the speed.

    The questioned file on the desktop is a downloaded update from AVG -- I had to begin downloading the updates from AVG.com, due to an invalid control file (CTF) denoted by the update manager, approximately seven days ago.

    Internet connectivity continues to be interrupted with dialog box which denotes Win 32 or Generic Service Host errors. This closes or "hibernates" the connection, the system tray icon shows connectivity but status box displays for nanosecond when right click on icon and any attempt to restart IE or Outlook fails because the system is recognizing connectivity. Unplugging the phone line clears connection and a reboot is necessary to re-establish a connection.

    Resident shield for AVG Free Edition 8 continues to locate Trojan Horses, Worms and Viruses. Initially I would hit heal and AVG would bring up a dialog saying specified file could not be found in 7 out of 10 occurrences. At this stage I move everything to the Virus Vault. Daily scans continue to find infections but only (1) in today's scan. Some of the Infections have included:

    Trojan -- Downloader Agent.APKO, Crypt AYG / AXH / AVL / AVK,
    BackDoor.IRCbot.GIY / GYM, Dropper.Bravix,
    WormGeneric.QMT / _c.YH

    Up to and after running diagnostics, CPU pegged at 100% but appears to have abated since this morning's scan which turned up infection of Crypt.AYG. IE connectivity interruptions with abovesaid remedy.

    This evening, an attempt to double click the AT&T icon to log in and establish a dialup connection, I noticed the AT&T name on the desktop icon was changed to steversss.

    Ran MGTools and attached log.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. But lets do this:

    This procedure explains how to get to the BitDefender Online Scan sites and how to setup and perform an online scan. It also explains how to obtain a log so you can attach it to a message. You must use Internet Explorer to run this scan and make sure your Sun Java version it current. Get Sun Java here: Sun Java Runtime EnvironmentBefore installing the current version, you should uninstall all previous versions first!!!!

    ****NOTE**** DO NOT INSTALL Bitdefender's Antivirus program. Make sure you follow the directions below and run the ONLINE SCANNER only.


    To start the online scan go here: Bitdefender

    • Agree to the license and then select Scan.
      • DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files.

    • Once Bitdefender completes the scan:
      • Click-on the Detected Problems tab. Then select Click here to export the scan report
      • When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt)
      • And then in the File name box enter bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html. If you do not follow these step, you will have an incorrect log or worse a log summary which is useless to us.

    • Post the bdscan.txt file as an ATTACHMENT. See: HOW TO: Attach Items To Your Post
    • If you run BitDefender Online scan and have previously run PandaActive scan, the below false detection may be seen in BitDefender:

      C:\WINDOWS\system32\ActiveScan\pskahk.dll
      Infected with: Generic.Malware.SIMDWYNVdprn.D9407F4E
     
  6. Agent H

    Agent H Private E-2

    Attempts to follow your instructions were mixed -- I had removed Java 6 update 5 and reinstalled JRE through your link; however, (6) attempts (sessions) to run the bit defender online scan were unsuccessful. When I utilized the link provided, nothing would happen upon left clicking the "I agree" box -- I tried this (3) times. I also navigated to the bitdefender.com website and was able to start the scan on two occasions but the online scanner failed because the dialog box said the virus database could not be loaded and nothing was scanned according to the data provided in the dialog box. I attempted to use the link in your post one last time before replying and the "I agree" box would not accept the left click once again.

    Any other recommendations on the bit defender issue and as a follow up -- SAS found several items including the trojans and rootkit which were placed into quarantine and I do not know how to proceed with the quarantined items in SAS or my AVG 8. Some items found in the scans appear to require file replacement from OS install disks due to their status but I'm unsure.

    Thanks again for all your time and help, the time lapse between replies was because I wanted to attempt to run bitdefender's online scan (as instructed) and thought traffic may have been the cause on their website.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am assuming you were using Internet Explorer to do the Bit scan?

    Try using any of these:

    Free Online Scanning Tools - requires a working internet connecion
     
  8. Agent H

    Agent H Private E-2

    Tim,

    I am utilizing IE and after many days / attempts, bit defender scan could be completed. I have attached the log and would appreciate any recommendations. Thanks again for your time, help and consideration throughout the process. I followed the instructions on how to post and thought I was consistent throughout replies, if I am in err please let me know so I can correct any improper attentions to the details. Thanks again.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Bit found one active file and one in your system restore folder --> which we will remove when we do the final cleanup.

    What issues are you still having?
     
  10. Agent H

    Agent H Private E-2

    Tim,
    I am hesistant to respond but at this stage, no problems detected at the superficial level and performances of all recently accessed systems, files or programs have been satisfactory.

    CPU only pegs to 100% sporadically as expected.
    No alerts from AVG 8 resident shield or daily scans since 12/25.

    Do I need to flush out the virus vault on AVG 8 or in SAS's quarantine? Many of the problematic areas were in the Temporary internet Files -- I have started to use the ATF - cleaner found on your site and anticipate no further problems. Several registry problems were found during this process -- can you recommend any freeware for real-time monitoring of the registry and changes to?

    Thanks again for the quick response and help.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to here! .....As to monitoring programs, I would suggest you post in the software section for that info.
    You can delete the files in the quarantine folders if you wish.

    If you are not having any other malware issues, then:

     
  12. Agent H

    Agent H Private E-2

    Tim,

    Would there be any issues with gathering the Combofix, SAS and MGTools into a folder for future considerations? Should have asked in a previous post but didn't anticipate any problems from archiving for future purposes.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Combo will "expire" and not run in a short time. MgTools is always being updated as the malware changes so it too will not be as effective in a short time. You should keep SAS and MBAM updated and use them as backup scanners when you suspect problems. :)
     
  14. Agent H

    Agent H Private E-2

    Tim,
    Ran the cleaning steps and instituted some of the recommendations in the malware guide. System is functioning flawlessly without any hitches or bugs, thanks again for all your help in recovering the system and its functionality. Please close the thread at your convenience if you do not have any additional input, questions or concerns. THANKS AGAIN FOR YOUR TIMELY RESPONSES, ATTENTION TO DETAIL AND THOROUGHNESS IN YOUR REPLIES.

    Steve
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds