Malware Mess

Discussion in 'Malware Help (A Specialist Will Reply)' started by borntobefree, Jul 2, 2008.

  1. borntobefree

    borntobefree Private E-2

    Should I just wipe out my drive?
     

    Attached Files:

  2. abri

    abri MajorGeek

    Hi borntobefree,
    Welcome to Major Geeks!


    You should NOT wipe the drive! Your computer got SP3 with no problem, which means your computer was recently in a very good state, and I don't see glaring malware problems leaping out of your logs. What problems are you having? Please describe them. If it looks like you have malware, you should go through the instructions in the READ & RUN ME FIRST and attach the requested logs so we have the information we need to work with.

    Thanks so much!
    abri
     
  3. borntobefree

    borntobefree Private E-2

    Thanks for the quick response. I have only included the logs with issues, the others were totally clear. I'm pretty sure I have ran all the cleaning you requested.

    The problem is that I am finding tons of my text and website files converted to zip files. And in the last 3 days the puter has slowed down for the first time. I use goulds cleanup and keep the caches clean etc. I'm not picking up viruses with ZA Pro.

    Probably just wishful thinking that it is something as simple as malware.

    Thanks again friend.
     

    Attached Files:

  4. abri

    abri MajorGeek

    Hi borntobefree,

    Please delete everything windows will allow you to delete from the following folder:

    C:\Documents and Settings\HP_Owner\Local Settings\Temp\

    Then I would like for you to run a rootkit scan to see if anything shows up:

    Running GMER to detect rootkits


    I checked your logs for changes on July 1st and 2nd and it looks like there might have been a failed Zone Labs update and there's a new entry for a text file regarding your modem. I don't know what would explain your txt files and website files being converted to zip files, but this sounds like the result of a tool. Have you added any tools recently or started using them for the first time when this started to occur? Any upgrades of software you'd been using?

    There's one folder I would like to know more about. Please right-click on the folder and check properties for any information about this folder and then open the folder (but don't open any files) and tell me if there is anything in it:

    C:\WINDOWS\system32\unknown


    Then please run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (Note: if using Vista, don't double click, use right click and select Run As Administrator). Select Do a system scan only). In the box that opens, find the following entries and put a checkmark next to them (if you need some of them to be in the trusted zone, leave them). After check-marking them, close all your open browser windows and click on FIX: It is optional to fix these, so decide if you need for them to load at startup.

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

    After you click fix, just close hijackthis.


    Did you install web design software from Mabry Software? Combofix deleted a file from this.

    Please attach the GMER log when you're finished.

    abri
     
  5. borntobefree

    borntobefree Private E-2

    Thanks again abri,

    Deleted what I could from C:\Documents and Settings\HP_Owner\Local Settings\Temp\

    Could not delete:
    IADHIDE5.dll from BACKWEB
    _hphtra07.log
    DF83DC.tmp
    hpodvd09.log

    GMER Log attached.

    The culprit that is changing the txt files to zips would be FZ (Free Zip). I removed it.

    C:\WINDOWS\system32\unknown* was empty, I deleted it.

    Ran MGtools\analyse.exe and removed them from startup.

    I don't recall installing anything from Mabry Software. I have used Web Expression for some time. Just in case I will search regedit and remove any leftovers.

    Thanks again amri. Have a great Evening
     

    Attached Files:

  6. borntobefree

    borntobefree Private E-2

    abri,

    I responded to your last post but don't see it? Don't want to spam, so will upload again in the morning if it doesn't show.

    Thanks,
     
  7. abri

    abri MajorGeek

    Hi borntobefree,

    Be careful about removing entries from the registry.

    Looking at your slowness problems a bit:

    Your desktop is very cluttered. Please delete or move any setup or installation programs you have there. It looks like your default download place is the desktop. If you are using Firefox as a browser, there is a setting in the tools / options where you can have it prompt you about the destination for downloads. That option is on the main ab under options. It helps to make a folder called Downloads so you know where to find things. It's not a good idea to install programs directly to the Desktop unless this has been specifically recommended by the software.

    In your combofix log you have a file which was removed called MabryObj.dll. If you look at the following website from Symantec, you can see that it is added by a spyware program which does keylogging, screenshots, and other things. However, it is also listed as a file of "Mabry Software: Founded in 1992, Mabry Software, Inc. is a Seattle, Washington based vendor of reasonably priced Microsoft Windowsr programming components". There is a lot of inconsistent information about it. The following Symantec article has a description of what files are put on the computer, of which MabryObj.dll is one of them.

    http://www.symantec.com/security_response/writeup.jsp?docid=2004-070516-0957-99&tabid=2

    I want to see if I can find anything more about it. The one file has been removed from your computer, and the question is more, what software you have that it was part of and if you put that software in your computer yourself. If you find any further files in your computer from the above list at the Symantec website, which are associated with this MabryObj.dll, I would like to know the date they were put on your computer as this would help most in identifying which piece of software they could be part of.

    abri
     
    Last edited: Jul 3, 2008
  8. borntobefree

    borntobefree Private E-2

    Morning abri,

    I found this file MabryObj.dll.vir in C:\QooBox\Quarantine\C\WINDOWS\system32
    file is dated Sunday, April 29, 2007, 8:30:42 AM

    I found the following in regedit:

    HKEY_CURRENT_USER\Software\Mabry
    FTPX 89FC-BLMQ085TP8XN

    Mabry.FtpRecordset.1 under CLSID FtpRecordset OLE DB Provider. One of the folders in this string is inprocserver C:\WINDOWS\system32\FTPx.dll

    Mabry InternetFTP/X COM Object
    Mabry.FtpXObj.1
    Mabry.FtpXObj
    Mabry Internet FTP/X Control
    Mabry.FtpXCtl.1
    Mabry.FtpXCtl
    Mabry.HttpXCom.1
    Mabry.HttpXCom
    FtpRecordset OLE DB Provider
    CURVER Mabry.FtpRecordset.1
    HKEY_CLASSES_ROOT\Mabry.FtpXCtl
    HKEY_CLASSES_ROOT\Mabry.FtpXCtl.1
    HKEY_CLASSES_ROOT\Mabry.FtpXObj
    HKEY_CLASSES_ROOT\Mabry.FtpXObj.1
    HKEY_CLASSES_ROOT\Mabry.HttpXCom
    HKEY_CLASSES_ROOT\Mabry.HttpXCom.1
    HKEY_CLASSES_ROOT\TypeLib\{AEBBD4A6-6992-11D3-B4CB-0020AFD69DE6} 1.0 Mabry StreamObjects Library

    Checked all my programs and can not find any I use that are connected to this Mabry.

    I also cleaned up my beautiful desktop LOL:-D

    Thanks again for all the free professional help abri.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you still having any problems? You need to do the below registry patch.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  10. borntobefree

    borntobefree Private E-2

    Thank you chaslang,

    The fixme.reg worked fine. Also followed all the other directions. Everything is working great. What a chore this has been. Thanks to you and all involved.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome from me and Abri. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds