I think I need help...

Discussion in 'Malware Help (A Specialist Will Reply)' started by tmgenterprises, Dec 5, 2007.

  1. tmgenterprises

    tmgenterprises Private E-2

    I've been getting a message about the obfuskated downloader from AVG like some others. I have gone through the sticky notes and done everything they said. My computer is better than it was but is still shutting down all of a sudden. Works fine when I'm not online though. AVG antispyware and Spybot S&D both come up clean as of a few minutes ago but I want to be sure I got everything.

    If someone could check out my logfiles and tell me what I need to fix? I don't know which is which in HJT and don't want to screw things up. I'm hoping to get this fixed and not have to reformat.

    Thanks.
     

    Attached Files:

  2. tmgenterprises

    tmgenterprises Private E-2

    More logs to go with previous post

    I appreciate any help!
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    Java 2 Runtime Environment, SE v1.4.2_03
    Reboot and install:
    Java Runtime 6

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Sophos Anti-Rootkit
    will scan your computer for files that have been hidden using rootkit technology.

    Many of the newer malware infections use this technology to hide themselves and to make them more difficult to remove.

    Installation
    Download Sophos Anti-Rootkit 1.1 and save to a location you will be able to find such as your desktop

    Run sarsfx.exe by double clicking on it.

    Click Accept to agree to the EULA

    Click Install (if you wish to change the default installation location do so here but remember where you install to, the default is C:\SOPHTEMP)

    Once it finishes copying files, exit the installer​
    Running the scan
    Navigate to the location that you installed the software to (Default: C:\SOPHTEMP)

    Run sargui.exe by double clicking on it.

    Ensure that all three of the options are checked

    Click Start Scan

    Once the scan is complete, close Sophos Anti-Rootkit by closing the scan window and clicking Exit in the main window

    DO NOT CLICK 'CLEAN UP CHECKED ITEMS' OR ATTEMPT TO HAVE SOPHOS ANTI-ROOTKIT FIX ANYTHING UNLESS SPECIFICALLY INSTRUCTED TO IN THE THREAD YOU ARE WORKING ON
    Finding the logsClick on Start --> Run

    Type in %TEMP%\sarscan.log and press enter

    The log file will open in the default editor (probably Notepad)

    Click File --> Save As and save the file to your desktop or other location for easy retrieval.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and Please attach the sarscan log and:
     
  4. tmgenterprises

    tmgenterprises Private E-2

    Thanks for the help...I really appreciate it. I hate having to reformat. I am attaching the mgtools.zip but the Sophos was clean...no items to fix.

    I did figure one thing out and perhaps you can advise if I need to do more. Windows Defender keeps making comments about a known application making changes for 3 items. One of them I noticed in the HJT logs so I did a little research. Since updating IE to 7, the ctfmon.exe has been running. I disabled it through the control panel according to directions I found. The other things Windows Defender keeps referring to is:

    C:\WINDOWS\system32\drivers\ATWPT2.SYS
    and
    C:\ProgramFiles\WindowsDefender\MpCmdRun.exe

    Do you know if those are related to the first thing or not? I had read that ctfmon.exe could cause the problems I'm having with the extremely slow boot and shut down and sudden shut down issues.

    Thanks again!
     

    Attached Files:

  5. tmgenterprises

    tmgenterprises Private E-2

    Additional info from this morning...

    Windows Defender is still giving me two more messages, both "a system change was made by a known application":

    C:\ProgramFiles\Windows Defender\MpCmdRun.exe
    C:\WINDOWS\system32\drivers\ATWPKT.SYS

    Also, tried twice to run Spybot S&D scan and both times froze PC...had to use reset button to shut down and reboot.

    Arghhhhhhhh...I hope all the malware creators get fleas in very private places!
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MpCmdRun.exe is related to Defender's Command Line Utility and real-time monitoring component which is required for updating the program's signature definitions. MpCmdRun.exe scans for the availability of new signatures from the Microsoft site and then initiates the updating process as new ones become available. During the process MpCmdRun.exe will perform DNS queries to determine the exact IP address before connecting. In order to accomplish this task, the component must have frequent access to the Internet and thus, you may get an alert from your firewall.

    ATWPT2.SYS --- AOL driver that is needed.

    * Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    * On the page that opens, scroll down to Aim Version 6
    * then right click the entry, select Properties and press Stop Service.
    * When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    Now do the same for AOL Update Manager
    * Click OK until you get back to Windows.

    * Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste Aim_6 into the box that opens, and press OK
    * If you receive any error messages just ignore them and continue.
    Now do the same for AOL_Hosts
    * Now exit HJT.
    Reboot if needed.

    Your system is clean!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds