Malware Removal: patched.a infection in services.exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by saebasan, Sep 20, 2012.

  1. saebasan

    saebasan Private E-2

    I am running Windows 7 Home Premium 64-bit. AVG first alerted me to the patched.a virus in services.exe on 9/17/12. I have run all the preliminary scans as directed in the forums and still have a problem. I am attaching the log results here.

    Thank you in advance for your help.
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Welcome to MajorGeeks, saebasan

    http://img805.imageshack.us/img805/9659/rktigzy.gif Use RogueKiller to remove malware
    • Reopen RogueKiller.exe by right-mouse clicking it and selecting "Run as Administrator".
    • Press Scan.
    • When the scan is finished: press Delete.
    • RogueKiller may need to reboot your computer in order to finish the requests for deletion - Please do so at this time.
    • Reboot and run one more additional Scan with RogueKiller and attach the latest log here for review.

    __

    http://img205.imageshack.us/img205/1894/otl.gif Please download OTL by OldTimer.

    • Save it to your desktop.
    • Right mouse click on the OTL icon on your desktop and select Run as Administrator
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
      Code:
      activex
      netsvcs
      drives
      %windir%\system32\drivers\*.sys /lockedfiles
      
    • Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
     
  3. saebasan

    saebasan Private E-2

    New scans completed successfully. RogueKiller removed some stuff, but still getting an AVG alert about the desktop.ini file.

    RogueKiller and OTL logs attached.
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

    http://img205.imageshack.us/img205/1894/otl.gif Fix items using OTL by OldTimer

    Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
    Code:
    [COLOR="DarkRed"]:otl[/COLOR]
    IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
    IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678
    IE - HKLM\..\SearchScopes\{F577304E-2F56-43D0-826A-636D617B7B09}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
    IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
    IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3C5F0F00-683D-4847-89C8-E7AF64FD1CFB}: C:\Program Files (x86)\RelevantKnowledge
    O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
    O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
    O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll ()
    O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    O3 - HKU\S-1-5-21-3057082182-863259840-583182947-1001\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
    [2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
    [2012/09/20 19:13:59 | 000,004,608 | ---- | M] () -- C:\Windows\assembly\GAC_32\Desktop.ini
    [2012/09/20 19:13:59 | 000,006,144 | ---- | M] () -- C:\Windows\assembly\GAC_64\Desktop.ini
    [2012/09/21 19:03:49 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{02383c03-fbfa-1dbe-3749-eefc618eea54}\U
    @Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:57B4E612
    IE - HKU\S-1-5-21-3057082182-863259840-583182947-1001\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
    [COLOR="DarkRed"]:services [/COLOR]
    [COLOR="DarkRed"]:files[/COLOR]
    C:\Windows\Assembly\GAC_32\Desktop.ini
    C:\Program Files (x86)\Free Download Manager\iefdm2.dll
    C:\Users\doug\AppData\LocalLow\PriceGong
    C:\Windows\Assembly\GAC_64\Desktop.ini
    C:\Windows\Installer\{02383c03-fbfa-1dbe-3749-eefc618eea54} /d
    C:\Program Files (x86)\Free Download Manager\iefdm2.dll
    C:\Program Files (x86)\Free Download Manager\FUM\fumcore.dll
    C:\Program Files (x86)\Free Download Manager\FUM
    C:\Program Files (x86)\Free Download Manager /d
    C:\Program Files (x86)\uTorrentBar\tbuTor.dll
    C:\Program Files (x86)\uTorrentBar /d
    [COLOR="DarkRed"]:commands[/COLOR]
    [emptyjava]
    [emptyflash]
    [reboot]
    
    Now click the http://img3.imageshack.us/img3/407/otlrunfix.png button.
    If the fix needed a reboot please do it.
    Click the OK button (upon reboot).
    When OTL is finished, Notepad will open. Close Notepad.
    A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    Attach this log to your next message. (How to attach)
     
  5. saebasan

    saebasan Private E-2

    Fix complete. Here is the new log.
     

    Attached Files:

  6. thisisu

    thisisu Malware Consultant

    http://img406.imageshack.us/img406/3189/windowsrepair.gif Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now open Repair_Windows.exe
    • Go to the Start Repairs tab.
    • Press the Start button
    • Create a System Restore point if prompted.
    • In the Repair Options window, choose the following repairs:
      • Reset Registry Permissions
      • Repair Windows Firewall
    • Place a checkmark in Restart/Shutdown System When Finished
    • Fill in the Restart System bubble
    • Now click the Start button.
    • Be patient while the tool repairs the selected items. Your computer should automatically restart when finished.

    __

    http://img97.imageshack.us/img97/8120/fss.gif Please download Farbar Service Scanner and run it on the computer with the issue.
    • Make sure all the options are checked
    • Press Scan.
    • It will create a log (FSS.txt) in the same directory the tool was run.
    • Please attach FSS.txt to your next message. (How to attach)
     
  7. saebasan

    saebasan Private E-2

    FSS log attached
     

    Attached Files:

    • FSS.txt
      File size:
      3.3 KB
      Views:
      4
  8. thisisu

    thisisu Malware Consultant

    • Download each of the 3 files below onto the desktop of the computer with the issues:
    • Now double-click each of them, one at a time, and allow each one to merge into the Windows registry.
    • Let me know if you received a successful message for all three files.
      • If all were successful, reboot your computer and rescan with Farbar Service Scanner. Attach its latest log.
      • If they weren't successful, let me know but rescan with Farbar Service Scanner too.

    __

    Afterwards, let me know what problems remain.
     
  9. saebasan

    saebasan Private E-2

    All three files successfully merged with the Registry. The rescan from FSS is attached.

    As far as I can see, I have no further issues at this time. My automatic AVG scan completed succcessfully last night and I am not currently getting any error messages.

    Unless you are aware of something from the logs, I think we are done.

    I do have one cleanup question. There is currently a "desktop.ini" file on my Desktop. Is that supposed to be in this location?

    Thank you for all your help. Let me know if there are any last steps I need to take.
     

    Attached Files:

    • FSS.txt
      File size:
      2.4 KB
      Views:
      3
  10. thisisu

    thisisu Malware Consultant

    It doesn't hurt whether it's there or not. It's a hidden file system file that you can currently see since we had you toggle "View hidden and system files" in the early part of the procedures.

    You're welcome. I don't see any further issues :)

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key http://i1106.photobucket.com/albums/h363/debojyotidas/Windows_Logo_key.gif and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds