malware problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by Tino1960, Jan 29, 2008.

  1. Tino1960

    Tino1960 Private E-2

    Hello All,

    It seems that I have been infected with the spooldr trojan. Up till now the only program that tells me this is the message after sending an error report to Microsoft when my laptop restarted after a bsod.
    I have read some threads and tried all that but the problem still persist. Now also my Word.exe seems infected and a repair from office CD crashed halfways.
    Attached are the Cobofix log, AVG log and the MGtools log.

    Please help
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the READ & RUN ME in step 1 to stop using MSconfig to control startups. You must be in normal startup mode and remain there.

    Also you are not using to current version of MGtools from the READ ME. Please download it from the link in the below thread and follow the instructions for using it.

    Using MGtools

    Then attach a new MGlogs.zip file.

    Based on what you have attached thus far, I'm not seeing any malware problems. If you are finding spooldr.exe with some scanner, please attach a log that shows what and where it is being found. Perhaps it is only in System Restore.
     
    Last edited: Jan 31, 2008
  3. Tino1960

    Tino1960 Private E-2

    Chaslang,

    Thanks for your reply.

    Attached you can find the new log.

    During the cleaning process I did the last days caused my Word program to become corrupt. I tried to do a repair with the Office CD, but during that the update crashed as before. Then I did a repair from XP first and then a repair of office. This went without any failure or message and all seems to work until I tried to update Windows. The Iexplorer is now back to version 6 but reches the MS update site and downloaded all updates but it is impossible to perform an autoinstall. All updates failed to install. I can install them one by one from C:\windows\SoftwareDistribution\Download.

    Another thing I noticed: In the Hijackthis.log there is a file in the running processes called: C:\Windows\Temp\QG41A8.exe. Looking in that folder shows this file with a dog icon. This file seems to have a different name after each restart.

    Is this some malware file?

    I hope you can make something out of this story.

    Tino
     

    Attached Files:

  4. Tino1960

    Tino1960 Private E-2

    Chaslang,

    Thanks for your reply.

    Attached you can find the new log.

    During the cleaning process I did the last days caused my Word program to become corrupt. I tried to do a repair with the Office CD, but during that the update crashed as before. Then I did a repair from XP first and then a repair of office. This went without any failure or message and all seems to work until I tried to update Windows. The Iexplorer is now back to version 6 but reches the MS update site and downloaded all updates but it is impossible to perform an autoinstall. All updates failed to install. I can install them one by one from C:\windows\SoftwareDistribution\Download.

    Another thing I noticed: In the Hijackthis.log there is a file in the running processes called: C:\Windows\Temp\QG41A8.exe. Looking in that folder shows this file with a dog icon. This file seems to have a different name after each restart.

    Is this some malware file?

    I hope you can make something out of this story.

    Tino
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not make duplicate posts or bump your thread. It will not help you get an faster answer. In fact it will make it tak longer. See the below sticky thread:

    Don't Bump! It Only Hurts You!!!


    Doing a Windows repair was not a good idea and may have made your problems worse. You will have to work out any continuing issues with this in the software forum as these are not malware problems.

    No it is part of Trend Micro OfficeScan.


    Your logs still do not show any signs of malware; but I do question what all of the below from last November are. Do you know? I assume they may be part of these: Lexware Info Service and Lexware reisekosten 2007?
    Code:
    "C:\WINDOWS\system32\"
    dnt27vc8.dll  15 Nov 2007      303104  "dnt27VC8.dll"
    dntvm2~1.dll  15 Nov 2007       86016  "dntvm27VC8.dll"
    dntvmc~1.dll  15 Nov 2007       90112  "dntvmc27VC8.dll"
    lxbasi~2.dll  16 Nov 2007      180224  "LxBasics65VC8.dll"
    lxbtr6~1.dll  13 Nov 2007      241664  "LXBtr65VC8.dll"
    lxci12.dll    13 Nov 2007       81920  "LxCI12.dll"
    lxcurr~1.dll  13 Nov 2007       61440  "LXCurr12VC8.dll"
    lxdasi~2.dll  13 Nov 2007      188416  "LXDasi65VC8.dll"
    lximpo~2.dll  13 Nov 2007      319488  "LxImport65VC8.dll"
    lxmail~1.dll  13 Nov 2007      131072  "LxMail30VC8.dll"
    lxprnu~1.dll  15 Nov 2007      208896  "LXPrnUtil10.dll"
    lxter2~1.dll  13 Nov 2007      716800  "lxter20VC8.dll"
    lxtool~2.dll  13 Nov 2007     1191936  "LXtool65VC8.dll"
    lxtpsw~1.dll  13 Nov 2007       27648  "LXTPSW20VC8.dll"
    lxuise~1.dll  13 Nov 2007       81920  "LxUISettings10VC8.dll"
    lxxtre~1.dll  13 Nov 2007     1556480  "LxXtreme40VC8.dll"
    lxxtre~2.dll  13 Nov 2007     5701632  "LxXtreme50VC8.dll"
    pxttoo~2.dll  13 Nov 2007       69632  "PXTTool65VC8.dll"
    zvkonl~2.dll  13 Nov 2007      552960  "zvkonline65VC8.dll"
     
    Last edited: Feb 2, 2008
  6. Tino1960

    Tino1960 Private E-2

    Hi Chaslang,

    Sorry for the duplicate post and thanks for the explanation of the "DogIconed file".

    Here is an update of my problem. You were right that things got worse.
    I put back an image (made before all of this started, but still infected!:eek:) and startet all over again with cleaning and scanning.
    During this proces my PC crashed with a blue screen and rebooted. After a while a window appears were I can sent an error report to microsoft.
    That site replied with the following text:

    Windows Error Reporting


    Alert: Microsoft has detected software on your computer that might be malware

    The software that might be malware is named spooldr.sys.


    The files for Spooldr were not found on my PC in normal nor in safe mode.
    I have tried several scanners and uninstalled them before trying the next.

    XoftSpySE found an adwareloader but didnot identify the name or type
    SpyHunter found Trojan.Vundo in igfxui

    Attached are log.txt from Combofix and two MGlogs one in safemode and the other in normalmode.

    I hope you can help me!

    Tino
     

    Attached Files:

  7. Tino1960

    Tino1960 Private E-2

    Chaslang,

    Here is an update about my problems.
    The files you mentioned in your last post seems to be from the lexware program.
    Because you donot saw malware programs in my last logs, I did some updates to my systemprograms to have the latest versions of drivers.
    Then I did the cleaning again and made some logs.
    The logs from combofix, kaspersky online scan and MGtools are attached.
    In the Kaspersky file there was som infection mentioned in a installable file for VNC client. I already have deleted that manually.
    The systemrestore has already been toggled.

    Can you look at these logs please and tell me if there is any sign of malware?

    Thanks for all your help.

    Tino
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    VNC clients are not problems as long as you are the one that installed them.

    Why? Now you have no restore points to return to. But if you reimaged your drive back to a point in time before all this began, it is again unlikely that you are having malware issues unless your image was made while your PC was infected.

    If you are using SpyHunter you should uninstall it now as it is not a recommended program to use. Then delete the below folder if it still exists:

    C:\Program Files\Enigma Software Group

    XoftSpySE is not highly recommended either, but is not as bad as SpyHunter.


    There still are no real malware issues in your logs. I do have to ask what the below is for though:

    C:\WINDOWS\system32\WorkAfterReboot.exe


    And you should delete the below files:
    C:\WINDOWS\qfe81.tmp
    C:\WINDOWS\qfe7A.tmp
    C:\WINDOWS\qfe73.tmp
    C:\WINDOWS\qfe6F.tmp
    C:\WINDOWS\qfe66.tmp
     
  9. Tino1960

    Tino1960 Private E-2

    Hi Chaslang,

    Thanks again for looking into my logs.

    It is still strange to me that after a crash and sending the error report to MS
    the message is that there is malware named spooldr.sys when there isn't.

    I did what you asked and removed the items. Then I ran Ccleaner again.
    This also took care about the Work...exe file.
    Than I started a TrendMicro Office scan with only the D: (data) partition selected.
    When reaching about 10% the PC crashed again, but this time without error report after reboot.
    Then I did a second attempt to scan but this time a full data scan and again the PC crashed. Also without an error report message.

    Installed is now Spyware Doctor. Will this influence the Trend scanner somehow?

    I don't know how to proceed now, because I am not sure that the PC is clean or if there is some XP/hardware problem.

    Do you have suggestions?

    Tino
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not necessarily strange. Perhaps it was already removed. Is it still being detected? Where was it detected? It is quite possible that it was only in System Restore and when we do our final steps, anything in System Restore will be removed.

    This is more than likely not due to malware. You just have the inability to scan your whole hard disk. It could be hardware problems. Your PC shows no signs of malware and also you said you just recently reimaged so it is again unlikely to be malware unless what you reimaged from was infected. Based on your logs, you are clean. But we can run a couple other scans to see if anything else is hiding that does not show in the current scans. It is possible that the spooldr.sys is hiding via a rootkit like infection.

    Run this Running GMER to detect rootkits and attach the requested log.

    Also run this Using ESET's Online Scanner and attach the requested log.


    Is it a paid version of Spyware Doctor or a trial? If only a trial, uninstall it as it is not going to help you fix any problems and will only slow your PC down.
     
    Last edited: Feb 4, 2008
  11. Tino1960

    Tino1960 Private E-2

    Hello again,

    I did what you asked and removed SpywareDoctor, it was a trial. What scanner do you recommend btw?
    The gmer process was straight forward without any problem.
    The eset online scan has made problems in normal mode. I have tried it twice and both times crashed the pc. Then I did it in safemode in two runs without any problem. This program didnot find anything.
    Both logs are attached.
    If there is some hardware/XP conflict how can I detect it? Every now and then the PC crashes without warning and defined action.

    Thanks for all your help!

    Tino
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post in the Software or Hardware Forum. They will probably ask for an Eventlog and any error messages being seen.

    These last logs are also clean. In my previous message I asked the below questions but you did not answer them.

    Based on what I have seen thus far, you have no malware to for us to remove. Thus, if you are not having any other malware problems, it is time to do our final steps. The link below will answer your question on what we recommend.
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  13. Tino1960

    Tino1960 Private E-2

    Hi Chaslang,

    Thanks for all your help.
    My problem seems to be hard/software related. My laptop still crashes sometimes, but as I understand it now, not because of malware.
    After a crash I used to have the possibility to send a report to microsoft.
    Maybe during all the cleaning this option is disabled somehow. and that was the only place where the spooldr.sys was found!

    Thanks again and I will post in another forum.

    Tino
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds