malware that's being sent to all my messenger contacts

Discussion in 'Malware Help (A Specialist Will Reply)' started by punygiant, Dec 13, 2007.

  1. punygiant

    punygiant Private E-2

    I'm not sure if this is the right place to post this, but it seemed like the best bet. Last night, a friend and I were chatting on Windows Live Messenger v8.1. She sent me a file (or at least I thought it was her) She sent me a zip file of photos. She had received a similar file from another friend and didn't open it, yet it started sending to all her contacts, myself included. It started doing the same thing to my contacts, tho I was stupid and did open it. I ran AVG, Spybot SD, Lavasoft Ad-aware, and Hijack this. None of them showed any problems, yet I'm still receiving complaints from my contacts that I'm trying to send them the file. So far that's the only thing I know for sure is happening, the propogation of the file thru my Messenger contacts. I don't know if its running anything on my computer, tho it seems as tho it has to be.

    This was the exact message (and filename) that was sent from her to me... From what I'm hearing from other friends, it seems to change the message and filename each time it sends to my contacts.

    I just made this picture in photoshop. It AWESOME for your desktop. I should charge people to use it lol.
    XXXXX sends f339xfr15e.zip

    Her antivirus (avg) is telling her that its backdoor.rbot... Mine, however isn't telling me this.

    I have exhausted all other options, and I am turning to the experts for help. Please tell me this is something simple and I'm just missing it...
    Thank you in advance for all help
     
    Last edited: Dec 13, 2007
  2. punygiant

    punygiant Private E-2

    sorry for this, but here are the log files required...
    (hopefully)

    ps i can't figure out where my avg log is, and thus how to attach it... when i find it, i'll add it as well
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Do the below while I look thru all of your logs.

    Now Disable Spybot's TeaTimer as requested in the READ and RUN ME
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.2_05
    Java(TM) SE Runtime Environment 6 Update 1
    Spybot - Search & Destroy 1.3 <-- 3 years out of date
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you finish the instructions in message number 3 before doing the below.


    Let's begin by removing the malware service that is probably your main problem.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to at9es3beue
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteat9es3beue into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    I now also suggest you delete the below from your Desktop
    Code:
    "C:\Documents and Settings\puny\Desktop\"
    BACKUPS       Dec 13 2007              "backups"
    hijack~1.exe  Dec 12 2007     1308216  "HiJackThis_v2.exe"
    hijack~1.log  Dec 13 2007        7617  "hijackthis.log"
    NEWFOL~1      Dec 11 2007              "New Folder (3)"
    NEWFOL~2      Dec 11 2007              "New Folder"
    spybot~1.exe  Dec 12 2007     7467056  "spybotsd15.exe"

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  5. punygiant

    punygiant Private E-2

    Ok, I un-installed everything mentioned in post 3 and then rebooted... When windows started back up, it looked as tho I was in safe mode. the Task Bar lost all windows xp look, and I cannot connect to the internet at all... (I am currently on another computer posting this)

    What did I do wrong? It seems worse than before now :confused
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing in step 3 could do anything like this. All you were doing was turning of Teatimer and uninstalling a load of old software.


    See if you can do step 4 anyway. Even if you have to do it in safe mode.
     
  7. punygiant

    punygiant Private E-2

    I tried to do the next step, but i couldn't find at9es3beue anywhere in services.msc. I skipped that step and went on to the HJT step and tried to see if I could get it to delete at9es3beue (as an NT service) and it told me 'The service 'at9es3beue' is enable and/or running. Disable it first, using HJT itself or the Services.msc window'

    I can't go any further as I cannot access the internet on the computer thats having problems. Also because of this, I haven't been able to download/install the newest Java Runtime Environment mentioned in post 3. Other than that, all I have done is the stuff mentioned above.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because it is running but they could be masking the real name to make it more difficult to locate.


    Everything? Does that mean you did the step with Avenger?

    Can you dowload things onto your other PC and then somehow copy them to the problem PC?

    On the PC with the problem, can you get System Restore to run?
     
  9. punygiant

    punygiant Private E-2

    So what's my next step in regards to this?

    I'm trying that right now with both the new Java Runtime Environment as well as Avenger.

    I was under the impression from the READ & RUN ME FIRST procedures that I should have turned System Restore off, so I did. Should I turn it back on? It wouldn't be able to restore me to earlier tonight, since I had it off then, would it?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't worry about Sun Java right now. You can always get it later.

    Absolutely not! It does not say that. It specifically stated that only after all malware is removed to turn off system restore. The reason for this is just for situations like you are having now. It is a fall back point.

    If you have turn System Restore off and it has been off all of this time, then you have no restore points to fall back too.
     
  11. punygiant

    punygiant Private E-2

    Ok, then that was my mistake, I misread the instructions... I may end up having to run the recovery disk that came with my computer to fix this problem, unless you can suggest something else. First, however, I'm trying to finish all the other steps you've given me to fix the initial problem.

    I am currently running CCleaner from the instructions you put forth. After that I believe its C:\MGtools\GetLogs.bat, then post the logs from Avenger and MGtools... I will post those as soon as i can.
     
  12. punygiant

    punygiant Private E-2

    New Avenger and MGlogs log files
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's quite possible. I'm not sure whay got your PC into this state because just uninstalling those programs cannot do this.


    Please see if you can do the below so we can attempt get that service stopped. I had given you the wrong name for services.msc. The one for Deleting with HijackThis was correct. Here is the full correct procedure .

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Print Spooler Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteat9es3beue into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but and reboot when it tells you it needs to.

    After reboot tell me if there is any change to your problems.

    I have to get some sleep now. I have to get up in about 3.5 hours for work.
     
  14. punygiant

    punygiant Private E-2

    Ok, I got HJT to do what it was supposed to this time (Delete the NT service) I rebooted, but the 2nd problem (looking and acting as tho I'm in safe mode, even tho I know I am not) hasn't been fixed. It looks like I'm gonna have to dig out my computer's recovery disk afterall... I just wish I knew which of the many things I've done to it, trying to fix the malware problem, has caused this secondary one.

    I cannot truly test if the initial problem has been fixed yet, because I cannot get on the internet to test Windows Live Messenger.

    Thank you for staying up with me tonight, also.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure exactly what you mean. Do you have Desktop icons and a Start button in the system tray? Are you sure that you just don't need to change your screen resolution? Right click the Desktop and select Properties. Then click Settings and adjust the slider for you Display settngs to the correct resolution you normally use.
     
  16. punygiant

    punygiant Private E-2

    Sorry for the delay in response.

    It seems as tho something I've done in the attempt to remove the malware caused my computer to not load services.msc correctly. I have since fixed that problem, as well as a few others caused by it... One of which was being unable to connect to the internet, thus the lack of response. I think everything is back to normal now, I haven't got any of my MSN contacts telling me that I'm trying to send them files anymore (my original problem) however, if you want/need any log files to check out for sure, please let me know and I'll get them for you. Otherwise, thank you very much for your help chas. :)
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. It would be a good idea just to look at a final log.


    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds