Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by Skubala, May 6, 2009.

  1. Skubala

    Skubala Private E-2

    Good Morning,

    I have followed the instructions on the Malware Removal Sticky Thread. Unfortunately, I think my computer still has problems.

    The symptoms that have continued following the scans include:

    1) Internet running constantly in the background.
    2) Automatic Updates turned off; I have tried to change the settings to allow automatic updates, but I get a message that says access denied. I think this has caused me to miss the most recent major update for Windows.
    3) Symantec reports that it is turned off.

    I have attached the requested logs. Please let me know if there is anything else that I should do, or if I have done something incorrectly.

    Thanks!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We have some work to do:

    Please use add/remove programs to uninstall:
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6 Update 1

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Part of you problem is this:
    Total Physical Memory 512.00 MB
    Available Physical Memory 149.70 MB

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. Skubala

    Skubala Private E-2

    Thanks for your help and for your detailed instructions! I followed all of your steps and there were no problems. The registry add was successful. The computer is functioning well as far as I can tell.

    I notice the following things: 1) The Windows Security Alert still indicates that Automatic Updates is disabled and Symantec is turned off (I checked both of these, and they are both enabled. I tried to connect to the Microsoft Update site, and it would not let me download anything because Automatic Updates is disabled.); and, 2) the internet seems to continue to run in the background while I do other things (i.e. the icon on the toolbar indicates activity when I am not working online).

    Can you explain the comment that you made about the computer's memory? Is there a way that I can increase the memory or close the gap between the total physical and available physical memory? Is this a hardware issue such that something has worn out; or, is this a software/hardware issue such that I don't have the correct hardware to run the software that I am trying to run. I don't know much about the technical aspects of computers (i.e. this is a glorified word processor and web surfing machine).
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is normal activity.

    You can go to crucial.com and have them scan your computer for the type of RAM you have and how much RAM your system can use. (Further instructions can be had in the software forum)>

    Now we still have things to do and you must try to do this exactly as I explain it to you.

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now go to start / run / type "services.msc" without the quotes...this will open a window. Scroll down to WIndows Installer Service ---> double click it and set the startup to manual.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now we need to copy some files back to their original folders.
    I will give you an example for what we will do:
    c:\program files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe
    Use windows explorer to find this file...right click what is bold/underlined and click copy.
    Now you will go to this folder and right click and paste:
    c:\program files\Adobe\Acrobat 7.0\Reader\ AdobeUpdateManager.exe
    It will ask you if you want to overwrite the existing file ...choose yes.


    Now do that with each of these copying the exe from the bak folder into the original folder:
    c:\program files\BroadJump\Client Foundation\bak\CFD.exe
    c:\program files\BroadJump\Client Foundation\CFD.exe

    c:\program files\Common Files\InstallShield\UpdateService\bak\issch.exe
    c:\program files\Common Files\InstallShield\UpdateService\issch.exe

    c:\program files\Common Files\InstallShield\UpdateService\bak\isuspm.exe
    c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe

    c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
    c:\program files\Common Files\Real\Update_OB\realsched.exe

    c:\program files\Common Files\Symantec Shared\bak\ccApp.exe
    c:\program files\Common Files\Symantec Shared\ccApp.exe

    c:\program files\Corel\Corel Photo Album 6\bak\MediaDetect.exe
    c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe

    c:\program files\CyberLink\PowerDVD\bak\DVDLauncher.exe
    c:\program files\CyberLink\PowerDVD\DVDLauncher.exe

    c:\program files\Dell\QuickSet\bak\quickset.exe
    c:\program files\Dell\QuickSet\quickset.exe (Here you may need to copy the exe, then delete the bak folder only and paste the exe back into the QuickSet folder).

    c:\program files\DellSupport\bak\DSAgnt.exe
    c:\program files\DellSupport\DSAgnt.exe

    c:\program files\Java\jre1.6.0_02\bin\bak\jusched.exe
    c:\program files\Java\jre1.6.0_02\bin\jusched.exe

    c:\program files\Symantec AntiVirus\bak\VPTray.exe
    c:\program files\Symantec AntiVirus\VPTray.exe

    c:\windows\system32\bak\ctfmon.exe
    c:\windows\system32\ctfmon.exe

    Now, if you were successful with the above we will continue. If not, you need to stop and let me know what problems you had with this.

    Now run CCleaner and make sure this folder is empty (other than temp files from today):
    C:\WINDOWS\temp\

    Now let's use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\temp\56A4420A16B85C03.tmp
    C:\WINDOWS\temp\852C5795BDE04053.tmp
    C:\WINDOWS\temp\EFB1F9580BA813D3.tmp
    C:\WINDOWS\temp\FC37CA455160F7E9.tmp
    
    FCopy::
    C:\MGtools\temp\ndis.sysmg|C:\WINDOWS\system32\dllcache\ndis.sys
    C:\MGtools\temp\ndis.sysmg|C:\WINDOWS\system32\drivers\ndis.sys
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe"
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  5. Skubala

    Skubala Private E-2

    Thanks again for continuing to work with me. I really appreciate all of the time that you are giving me.

    I ran into two problems:

    1) I couldn't find "O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background" in HJT.

    2) I couldn't copy and move c:\windows\system32\bak\ctfmon.exe. I got an error that said the program is being used by another person or program.

    I did not move beyond the point at which you asked me to stop if I was unsuccessful.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Skip that one and try to carry on. We may need to do those in save mode.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Take a break for tonight and let me get you a more simple fix. :)
     
  8. Skubala

    Skubala Private E-2

    I had already begun ComboFix before I saw your final post about taking a break. I only saw it when I logged back on to upload the logs. I hope I haven't complicated the process :-o

    I have attached the two logs you requested earlier.

    Again, thank you so much!
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well.....you managed to do it very well. :)

    Now we have to do the same thing with a few more items. You will need to do what you did with the dell quickset file:
    These:
    c:\program files\Synaptics\SynTP\bak\SynTPEnh.exe
    c:\windows\system32\bak\hkcmd.exe
    c:\windows\system32\bak\igfxpers.exe
    c:\windows\system32\bak\igfxtray.exe
    c:\windows\system32\dla\bak\tfswctrl.exe

    And we missed this one:
    c:\program files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe
    c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

    Once that is done, we need to do a reg. fix for the dell quick set:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell --if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Then re-run COmbo.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!

    We should be finished. :)
     
  10. Skubala

    Skubala Private E-2

    I have completed the most recent steps. Everything is working well. Several new (old) icons have (re)appeared in the toolbar (e.g. Symantec and Dell Support).

    The registry add was successful.

    The computer still indicates that Symantec is turned off. In addition, I tried Symantec's Live Update and, following the update, it indicates that the virus definition file is still from 3/24/2009. Is this something I should worry about?

    Windows Automatic Updates is now on.

    I have attached the logs.

    Continued thanks for your help!
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to hear that! You are clean and when we finish with one more bit of cleaning, you will be done>

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Folder::
    c:\program files\Adobe\Acrobat 7.0\Reader\bak
    c:\program files\BroadJump\Client Foundation\bak
    c:\program files\Common Files\InstallShield\UpdateService\bak
    c:\program files\Common Files\InstallShield\UpdateService\bak
    c:\program files\Common Files\Real\Update_OB\bak
    c:\program files\Common Files\Symantec Shared\bak
    c:\program files\Corel\Corel Photo Album 6\bak
    c:\program files\CyberLink\PowerDVD\bak
    c:\program files\Dell\QuickSet\bak
    c:\program files\DellSupport\bak
    c:\program files\iTunes\bak
    c:\program files\Java\jre1.6.0_02\bin\bak
    c:\program files\QuickTime\bak
    c:\program files\Symantec AntiVirus\bak
    c:\program files\Synaptics\SynTP\bak
    c:\windows\system32\bak
    c:\windows\system32\bak
    c:\windows\system32\bak
    c:\windows\system32\bak
    c:\windows\system32\dla\bak
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Attach the log.

    In the meantime, If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  12. Skubala

    Skubala Private E-2

    I have completed the final steps. The registry add was successful. The computer is working well.

    I still have the above mentioned issues with Symantec; I will contact their help department to see if they can do anything.

    Thank you, again, for all of your help. I will complete the cleanup steps as suggested.

    I have attached the requested log.

    Best wishes...
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your Dell QuickSet did not seem to be readded to the registry run keys. This should not be a problem if you ever want to check you battery options. You would just double click the c:\program files\Dell\QuickSet\quickset.exe.

    Your logs are finally clean, If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds