Help - Worm and Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by kmp4life, Feb 9, 2008.

  1. kmp4life

    kmp4life Private E-2

    :cryMy problems started 02/07/08. My symptoms are my laptop on startup after the Windows logo comes up (OS is XP) I can see the task bar at the bottom but thats it. Task manager is disabled some how and the mouse pointer is a constant hour glass.

    Infections I have found so far:
    trojandownloader.xs
    w32/ircbot.worm!ms05-039

    I'm no pro, but can follow instructions so I've read items on this forum and have done the following:

    Installed STNG380.exe from McAfee(have additional laptop that I'm xfrg files using jump drive - infected laptop will only work in safe mode)

    Installed ComboFix, Spybotsd152.exe, avgas, mgtools.exe (which i get this error: 0xc0000135 and says i am missing C:\documents and settings\administrator\desktop\procdll.txt)

    I've also ran avenger using various scripts that I have found on this forum (which are attached to). I have not ran ATF Cleaner yet

    attached are my logs created by the things I've ran.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 2"
    Java 2 Runtime Environment, SE v1.4.2_03"
    Java 2 Runtime Environment, SE v1.4.2_09

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  3. kmp4life

    kmp4life Private E-2

    Quick question before I do what you have told me too. I have too operate my laptop in safe mode and in safe mode the add\remove programs function is not enabled. How do I uninstall the programs you are telling me to uninstall? Do I just need to find there uninstall.exe file and do it manually?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We will do the JAva removal later ...just go ahead and do the other items.
     
  5. kmp4life

    kmp4life Private E-2

    I think this may have worked. I'm now about to reboot my computer in regular mode. I did notice in safe mode that my task manager access did come back after completing your instructions, so BIG THANKS!!!!:D So now the true test. Attached are my logs per your request and for your review.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are from Monday ...not Wednesday (today). Please run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  7. kmp4life

    kmp4life Private E-2

    You gave me the instructions on 2-10-08 and I asked a question which you replied on 2-11 and thats when I followed your instructions. I posted the logs afterwards, I havent done anything today or yesterday but wait for your feedback.

    I am attaching screen shots of errors i received when i ran the MG tool on Monday.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The reason I asked was because nothing appears to be fixed...the HJT log still has the entries we wanted removed ....Are you doing the fix in safe mode as administrator? And did you disable all of your security software before you ran it?
    Go ahead and do the fix I gave you again ....and then re-attach the new logs after doing it.

    Where you in normal or safe mode when you tried to run the MGTools\getlogs.bat?
     
  9. kmp4life

    kmp4life Private E-2

    Ok attached are my logs from me running the instructions you gave me again. Sorry about the delay, finally had time to do it today.

    And I still get the same error messages that i mentioned in previous posts.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  11. kmp4life

    kmp4life Private E-2

    Attached are my logs from doing the instructions in the previous post. I still got the same error messages as before and this file was not listed in the scan that analyse.exe ran - O4 - HKLM\..\Run: [wvupxvbx] C:\knqjhade.bat
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You copies the Avenger fix to remove all under the "Files to delete" setting ...I wanted you to copy it all ...let's do it again exactly as it is written (to include the "Folders to delete"):

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt
     
  13. kmp4life

    kmp4life Private E-2

    Avenger is giving me error can not create zip file. The error code 1813. Sorry its been a few days, was out of town on business. I manually went to look for the folders its trying to delete and couldnt find them if this helps any.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you saying that all the files and folders I asked you to remove are gone?

    Please run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  15. kmp4life

    kmp4life Private E-2

    Here is the new log file. I'm still missing the procdll.txt file, will I ever get this back?
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK..since you are having problems with Avenger ...let's use ComboFix to do the next step:

    Please use add/remove programs to uninstall:
    My Way Search Assistant
    Spyware Doctor 5.5 --> unless paid for version.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    Files::
    C:\Documents and Settings\cgbuxrmb.txt
    C:\Program Files\nvwddjlu.txt
    C:\cfhluyoj.txt
    C:\craggwxu.txt
    C:\fsavqcpn.bat
    C:\mqqhdrjx.bat
    C:\smkejycn.bat
    C:\xjeumlsl.bat  
    C:\xltqqmri.bat
    C:\zia01580      
    C:\zia03160     
    C:\zia03312
    C:\WINDOWS\lbayvygw.txt
    C:\WINDOWS\system32\drivers\flwrpopi.sys 
    C:\WINDOWS\system32\drivers\hmhpxxqi.sys
    C:\WINDOWS\system32\drivers\mymqaudy.sys  
    C:\WINDOWS\system32\drivers\nwfvqlgk.sys  
    C:\WINDOWS\system32\drivers\ohjvwone.sys  
    C:\WINDOWS\system32\drivers\uaubtvdq.sys  
    C:\WINDOWS\system32\drivers\wisraxxt.sys
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "dmpukcfl"=-
    "bqvysdlg"=-
    "aoqywlss"=-
    "oykflsyt"=-
    "eyyxfvvl"=-
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from ComboFix.
     
  17. kmp4life

    kmp4life Private E-2

    I got all the way to the step to run combo fix and it told me combofix has expired and to update. Do you know where i can install a new version?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There were problems with the latest version of COmboFIx....it may have been fixed and downloadable now. Please try it again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds