Is this spyware, virus or OK?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lori_mom, Sep 12, 2004.

  1. lori_mom

    lori_mom Private E-2

    Had (have?) a trojan/virus. Used Ad-aware, Spybot, McAfee Virus Scan. With Dell Forum help, was able to get back windows automatic-update that had been deleted by it. Still having trouble with pop-up explorer windows & system seems slow. On our own (I know, a bad idea) Found in Task Manager exe files we suspected, but can find no info on. They are: qjfem.exe & ofgiii.exe Found the paths, both in: C:\Windows\System32 The ofgiii.exe also found in Prefetch. Thinking we found the bad guys, we deleted them. See no harm to our computer, but still having the extra explorer windows pop-up. Dell Forum user then recommended this site from there to find out the info on the suspect files Not expert, so have not tried to download & run Hijack This. Any ideas?
     
  2. Boccemon

    Boccemon First Sergeant

    Hey there lori_mom!!! First, Welcome to MG!! I would like you to go to this thread and do ALL of the tasks that are listed there. There is a chance that your problem will be resolved. If not, after completing these steps, please post back.
    http://forums.majorgeeks.com/showthread.php?t=35407
     
  3. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    As Boccemon said, that tutorial, while a bit long should fix your problem. If it does NOT please upload a Hijack This logfile.
     
  4. lori_mom

    lori_mom Private E-2

    Followed the steps, although some trouble with some of them. Did not go on to HiJack this, not an experienced user (more so now though) TrendMicro's scan could not fix, but identified Trojan DLoader.BX and Boxed.A not identified by any other scan. We searched, found the file listed, and deleted. Popup explorer windows haven't returned since. Are there other things we need to look for since the scan could not fix it? Never found any info on the original suspect files we deleted.
     
  5. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    There you go! Nice work. I think your smarter then you give yourself credit for.

    Yes, what we really need now to see whats going on is a Hijack This log file. Basically, download it, extract it to its own directory (C:\ProgramFiles\HijackThis for example), press scan, then save log and save as a txt file like hijack.txt. In this thread choose manage attachments and upload it.

    If any of this is confusing, just run it and copy and paste it here and I will take care of it from there. Think you can do that?
     
  6. lori_mom

    lori_mom Private E-2

    OK, going to try & give you my Hijack This log.
     

    Attached Files:

  7. lori_mom

    lori_mom Private E-2

    Just wondering about the delay. Did my log not make it, or do I just need to patient longer? I know you have ALOT of logs to check through. Thanks for the help!
     
  8. Kodo

    Kodo SNATCHSQUATCH

    Hey Lori,
    just a few things that I noticed.

    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_f...59a099af4172:cff482a8dc15814f6feed591071fa5ae
    O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
    O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540002} (CInstall Class) - http://www.wildtangent.com/webdrivers/webinstall/shockwave/Install.cab
    O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://install.wildtangent.com/bgn/partners/wtgeneric/tradewinds/install.cab


    WINDUPDATES and WILDTANGENT should be removable from ADD/REMOVE. I wasn't sure about the WINDUPDATES but after looking at their license, I decided that it fit my interpretation of spyware.

    http://www.windupdates.com/license.html
     
    Last edited: Sep 28, 2004
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are a few more problems. The biggest one is:
    O4 - HKCU\..\Run: [Win32 USB2 Driver] svchosting.exe

    This is WORM_SDBOT.HU see the below link:

    http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.HU&VSect=T

    Kill the below process with Task Manager (CTRL-ALT-DEL):
    svchosting.exe

    Then fix the above O4 line with HJT. The boot into safe mode and delete
    c:\windows\system32\svchosting.exe

    Do you use this P2P Networking stuff? I believe it usually comes along with Kazaa. I always remove this. Go to Add/Remove Programs and uninstall it.

    Also kill this process:
    winmep.exe

    Then have HJT fix the following lines:
    O4 - HKLM\..\Run: [Windows Firewall Security] winmep.exe
    O4 - HKLM\..\RunServices: [Windows Firewall Security] winmep.exe
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)

    Reboot in safe mode and delete
    C:\WINDOWS\System32\winmep.exe
     
  10. Kodo

    Kodo SNATCHSQUATCH

    Man, they are clever with all this naming stuff aren't they.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, the work very hard at deception. It is really mind boggling! :eek:
     
  12. Kodo

    Kodo SNATCHSQUATCH

    ok, it's time now that Kodo spins that propeller on his hat.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does it say Majorgeeks on that hat? :D
     
  14. Kodo

    Kodo SNATCHSQUATCH

    Sadly, no.. it says "Anit-Spyware Man's Sidekick" :D
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    LOL!!


    Lori_mom,

    Don't let all this distract you. Go back to messages #8 & #9 and perform the steps given.
     
  16. Kodo

    Kodo SNATCHSQUATCH

    This spyware crap is really peeving me now..
     
  17. lori_mom

    lori_mom Private E-2

    OK- I'm gonna try to do as instructed. Got a job, haven't been on-line to check back here for a few days, but have been told we're getting new warnings from McAfee, so after the fixes recommended, I'd like to post another latest log & see if we got more new bad stuff on.
    Thanks
     
  18. lori_mom

    lori_mom Private E-2

    new log after following instructions.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What warnings are you getting?

    You did not uninstall P2P Networking as I suggested. Is there a reason for that?

    This line is new to your current log:
    O17 - HKLM\System\CCS\Services\Tcpip\..\{888BA9D0-DFC3-487C-A438-C554467C471F}: NameServer = 216.248.102.2 216.148.102.1

    Where did it come from? Do you recognize the owner of the IP address? Is it you ISP?
    216.248.102.2 = [ mail.mepotelco.net ]
    OrgName: netINS Inc.
    OrgID: IOWA
    Address: 312 8th Street
    City: Des Moines
    StateProv: IA
    PostalCode: 50309
    Country: US
    NetRange: 216.248.64.0 - 216.248.127.255
    CIDR: 216.248.64.0/18
    NetName: NETINS-BLK6
    NetHandle: NET-216-248-64-0-1
    Parent: NET-216-0-0-0-0
    NetType: Direct Allocation
    NameServer: NS1.NETINS.NET
    NameServer: NS2.NETINS.NET
    Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
    RegDate: 1999-10-26
    Updated: 2000-05-01
    TechHandle: INS-NOC-ARIN
    TechName: netINS Network Operations Center
    TechPhone: 1-800-205-1110
    TechEmail: noc@netins.net
     
  20. lori_mom

    lori_mom Private E-2

    Thought I followed all the steps, must have missed that one. I'll do it now. Thanks
    Not sure about the warnings, think they may have been worms that it cleaned? Wasn't here when they happened.
    Don't know about the new thing- my isp (internet service provider?) is mepotelco.net Does that help? Sorry, I'm getting your advice cause I don't know too much :)
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes the O17 line is for your ISP. If you take a look at the text I added, the IP address is 216.248.102.2 = [ mail.mepotelco.net ]

    So if you removed the P2P Networking stuff you should be clean now. How is everything working?
     
  22. lori_mom

    lori_mom Private E-2

    went to add/remove programs and removed the P2P networking. Anywhere else it needs to be removed from? Everything seems to be running good- thanks for all the help!
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No that should be it but you could take a look at a new HJT log yourself and make sure it is gone.

    And you're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds