Malware.SFM!.ABFEE1EE cannot remove

Discussion in 'Malware Help (A Specialist Will Reply)' started by Emm316, Apr 8, 2007.

  1. Emm316

    Emm316 Private E-2

    Hi,

    I have performed all the tasks in the Malware removal guide.

    Bit Defender online scan found the problem:
    DeepScan:Generic.Malware.SFM!.ABFEE1EE

    it has infected multiple files. Bit Defender says that it has deleted them all except 1, but they all come back.

    5 logs attached, AVG and BD were run in safe mode, all the rest were run in normal mode.

    Panda kept locking up, so I do not have a log for it.
     

    Attached Files:

  2. Emm316

    Emm316 Private E-2

    here are the other 2 logs.

    please help.

    The thing that made me suspicious, was an .exe file in my documents that was made to look like a folder. Its name is HotXXX.
    I tried to delete it, but it would just keep coming back.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Start by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    F3 - REG:win.ini: run=C:\RECYCLER\lsass.exe

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\Administrator\csrss.exe
    C:\RECYCLER\lsass.exe

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
  4. Emm316

    Emm316 Private E-2

    Thankyou for such a fast and detailed responce,

    I followed the instructions, and I think we are successful!

    Ill go through what happened:

    When running the fixME.reg I got an error:
    cannot import fixME.reg: The specified file is not a registry script.
    You can only import binary registry files from within the registry editor.

    The only thing that I can think of, is that when I saved it, it had an option called "encoding", it was on "ANSI" so I just left it.
    The other options were: "Unicode", "Unicode big endian" or "UTF-8"

    Anyway, i continued on with the other steps, and they have appeared to fix the problem.

    When I ran HJT,
    "F3 - REG:win.ini: run=C:\RECYCLER\lsass.exe" was not listed in the list anymore,
    so I just selected "R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page ="
    and then clicked fix (after shutting browsers etc)

    Then Pocket Killbox successfully cleaned all the temp files etc, and when I pasted the list of files to delete on reboot,
    it said it was an empty array, so they must have all been deleted already.
    I then reboot the computer and scanned with Bit Defender, which found no infected files!!

    I have attached the requested logs.

    Thanks again TimW, you are a genius.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    * On the page that opens, scroll down to MsInfo Service
    * then right click the entry, select Properties and press Stop Service.
    * When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    * Click OK until you get back to Windows.

    * Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste MsInfo Service into the box that opens, and press OK
    * If you receive any error messages just ignore them and continue.
    * Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Now re-Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O23 - Service: MsInfo Service (MsInfo) - Unknown owner - C:\RECYCLER\MsInfo\MsInfo.exe (file missing)

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
  6. Emm316

    Emm316 Private E-2

    When opening the properties of MsInfo Service, I got an error titled:
    Services
    Configuration Manager: The specified device instance handle does not correspond to a present device.

    but the properties window still opened up, it was already stopped, so I just disabled the startup.

    then everything went according to plan, until I was in HJT for the deletion of:
    O23 - Service: MsInfo Service (MsInfo) - Unknown owner - C:\RECYCLER\MsInfo\MsInfo.exe (file missing)

    The item was not listed, so I couldn't delete it.

    The registry modification worked, and I reset the computer.
    Then I got the 3 logs which are attached.
    Am I clean?
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean. You may uninstall any programs we had you download.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  8. Emm316

    Emm316 Private E-2

    Thankyou so much, you guys at major geeks are seriously saving people's lives.

    I have gone through the protection guide, and everything ran smoothly.

    thanks again.

    Emm
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome....safe surfing!!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds