Malware Problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by darkzorb, Jan 1, 2009.

  1. darkzorb

    darkzorb Private E-2

    Hi,

    I came home to my parent's computer for winter break and found that it was infested with lots of malware. No matter what search engine I use, the search result links give me a bunch of ad sites. Though this problem seems to only occur when using my parent's windows user account (btw, I'm running XP SP3). I've gone ahead and did the run through of the Windows XP Cleaning Procedure. SUPER Antispyware and Malwarebytes logs are posted below. Spybot found only tracking cookies, which I removed.

    In between these 3 being run and combofix/MGtools being run, my parents used the computer for a bit, hopefully they didn't mess anything up.

    When I got the computer back, I tried to run combofix.exe, It was running well, and then when it got to creating the log part. I suddenly get a windows notification saying catchme.cfexe has failed to initialize because windows is shutting down. And when I click ok, my computer restarted. Once done restarting and I log back on, the Combofix command prompt window is still up but it's stuck on the "preparing log report. do not run any programs until Combofix has finished" screen. I waited for about an hour and nothing happened so I force closed the command prompt. My clock still seems messed up even after restarting, probably meaning the program never got back to fixing it.

    I tried rerunning combofix, but now it fails to startup. I had the same problem the first time I tried running it, but after rebooting a few times it worked the first time around. This time when I rebooted it still didn't work. I double click the combofix.exe and the progress bar will go across, but then after the progress bar is full and disappears, nothing happens.

    I then ran MGTools, and it got stuck on adding: GetUnkey.txt (188 bytes security) (88% deflated). I let it sit there for 20 min, but nothing happened so I closed it. Then I tried rerunning this program too, but after uncompressing the MGTools, it just stalls on a blank command prompt. I waited for about 10 minutes and then I forced exit the command prompt. I renamed the MGTools folder which I ran the first time to a different name, so that it wouldn't rewrite, and found a GetUnkey.txt file which hopefully is of some use.

    I also tried running GetRunKey.bat to try to get a log file out and then maybe post them without it being zipped, but it failed. No log files were created, it stalls on the running scan and note to ignore registry error screen, and never gets anymore. I look in the folder and it created a temp folder with some txt files, but no runkeys.txt file to be seen.

    I ran all these programs from my my own windows user account (also an admin), not from my parent's infested user account, if that makes any difference.

    I know this means there might not be sufficient logs to analyze the matter. So if you know of a different way in which to acquire these logs I'm willing to give it a try.
     
  2. darkzorb

    darkzorb Private E-2

    Here are the logs that I could acquire.
     

    Attached Files:

  3. darkzorb

    darkzorb Private E-2

    I ran HJT (analyse.exe) from the MGTools, and could get a log from that.
    I also ran shownew.bat from the MGTools, but it didn't finish. It sat on "Looking for new Vundo type infection. Be patient while scan runs" for about an hour before I force closed it. There was an incomplete newfiles.txt file created which I've attached which hopefully is of some use.

    If It's suppose to take over an hour to run these bat files then I'm sorry for any inconvenience as I clearly had no idea what I was doing, and I'll rerun these.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try to figure out why you cannot get MGtools to run properly.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.


    Also to continue with your cleanup, do the below.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: Thunder AtOnce - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - (no file)
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
    O9 - Extra button: (no name) - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - (no file)
    O9 - Extra button: Joyo - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - C:\PROGRA~1\KINGSOFT\XDICT\ieplugin.DLL (file missing)
    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)

    After clicking Fix, exit HJT.

    Also delete the below files since ComboFix left these behind while not running properly.
    C:\WINDOWS\SYSTEM32\CF28965.exe
    C:\WINDOWS\SYSTEM32\CF3446.exe
    C:\WINDOWS\SYSTEM32\cmd.execf

    Also delete the below two folders:
    C:\32788R22FWJFW
    C:\ComboFix

    You can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.
     
    Last edited: Jan 4, 2009
  5. darkzorb

    darkzorb Private E-2

    hey chaslang,

    Thanks for the reply. I actually just ended up reformating, since it seemed quicker and safer. I didn't want my parents accidently doing anything to give away personal information in the time it took to fix the problem. Thanks anyways though!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds