Mohbpork.A

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Aion, Nov 29, 2006.

  1. Aion

    Aion Private E-2

    You sure have to do lots before you can post about your problems - It's taken me hours to complete all the scans and get all six logs. :)

    Around 3-4 months ago I took my PC to a repair shop due to msconfig and help not working when I typed the command for them in run. He reintalled WinXP for me (I don't have a copy of the WinXP disc). I didn't have any problems until yesterday when my comp couldn't find msconfig again, meaning I had to search for msconfig to be able to use it - It's on my desktop atm for ease.

    As a result of msconfig not working the easy way, I decided to go to TorrentSpy and download BitDefender 9. It found around 150 system restore files infected by something called Mohbpork.A, leading me to post here and ask you guys for help. The guy who posted here has near enough the same problem (I can't post there due to not them being fussy over the email you register with).

    To save some time, I'll simply list some of my other problems:

    - Can't boot into safe mode by holding F8 during bootup. It's been the same for a long time.
    - Can't select any of the options when my comp doesn't load correctly during bootup. It's been like it for a long time.
    - Explorer.exe crashes/freezes sometimes just after booting up. I have to manually stop it with task manager and start it again with run.
    - Lots of stuff not responding, lots of freezing. I'd be screwed if I couldn't keep using ctrl-alt-del...
    - Quite slow...my comp seems to have speeded up since using CounterSpy.

    I'll attach 7 logs to this and 2 other posts; the 6 you guys had me do and the BitDefender 9 log from yesterday with the Mohbpork.A infections.
     

    Attached Files:

  2. Aion

    Aion Private E-2

    Logs...
     

    Attached Files:

  3. Aion

    Aion Private E-2

    BitDefender 9 log taken the day before doing everything else.
     

    Attached Files:

  4. Aion

    Aion Private E-2

    Update:

    I ran some scans again today to fix something that was hijacking my browser. The BitDefender scan results show that the Mohbpork.A trojan seems to be spreading again after disabling and enabling system restore (I ran the BitDefender scan yesterday not long after doing the system restore stuff). I'll add the new BitDefender log to this post - You can clearly see the change in results between the 3 BitDefender scans before and after doing the system restore stuff.

    On another note, Windows search function keeps crashing with some error when searching for documents. I'm not sure if it's linked to msconfig and help stopping working via run commands.

    Please advise me guys, it took me ages to do all those scans due to my HD having too much on them - I'm waiting until my other problems are sorted before deleting stuff - I wouldn't like to think all of this was a waste of time! :)
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    It more than likely was not necessary to reinstall. Did a valid license copy of Windows get installed or is this a pirate?

    Bad idea!


    See this Disable And Enable System Restore and disable your System Restore. Leave it disabled for now.


    Please run msconfig and verify that it is set for Normal Startup mode.

    Uninstall all of the below old Sun Java versions:
    J2SE Runtime Environment 5.0 Update 3
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.2_12



    Let's start with your WareOut infection.

    Please run this procedure: WareOut Removal and attach the requested log afterwards.

    Now run a new Bitdefender 9 scan! How does it look now?


    Then also attach a new HJT log so we can cleanup leftovers from WareOut.
     
    Last edited: Dec 1, 2006
  6. Aion

    Aion Private E-2

    A couple of other smaller problems I've noticed:

    - The first bootup screen after you turn the PC has the text pushed slightly off screen to the left. This has never happened before in all the years I've owned this PC.
    - msinfo32 doesn't work when typed into the run box...hell, it doesn't work when I search for it and double click it.

    Thanks. :)

    I don't *think* it was, I seem to remember the guy warning it me wasn't. Microsoft/Windows update seems to keep verifying it is a valid copy whenever I visit the website and go through the validation test.

    Ok, I'll disable it again and leave it off.

    I'll be sure to the visit msconfig on my desktop and set at normal startup before doing the scans.

    I deleted all that Java junk the other day whilst browsing and reading some other threads around here.

    I don't have BitDefender 9 on my system anymore, I deleted it not long after doing the scan shown in my 3rd post due it slowing down my system too much. Would the online scan BitDefender 8 be ok? It showed the Mohbpok.A infection yesterday.

    /goes to restart and do the stuff as requested...

    Problem: Fixwareout isn't working for me. My comp stays on 'Welcome! loading personal settings' for longer than usual, followed by my comp only loading my wallpaper. I pressed ok when the wareout thing eventually prompted me to do so, then it just seems to stay forever in my task manager as not responding - I had to keep closing it. Any ideas? >_<

    Mohbpork.A seems to have moved from system restore to system32 on the new bdscan, hopefully this time bdscan deleted the source...
     

    Attached Files:

    Last edited: Dec 1, 2006
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No one here asked you to install and antivirus program let alone two of them. You must only do what we ask you to do and in the order we ask. Yes you did need an antivirus application but now you have both AVG and Avast installed. See step 3 of the READ & RUN ME. Uninstall one.

    Were you running C:\WINDOWS\system32\taskmgr.exe when you got your HJT log? It should not be running otherwise it makes us ask why.

    Then attach new logs from ShowNew and HJT.


    Problems with your screen adjustment are not related to malware. Just fix your monitor settings. You need to decribe in more detail what you mean by msinfo32 does not work. Tell me exactly what happens. Like does it run at all (like does the window even open), when you double click it. If the window opens, does it start to show any info? Does it hang? Etc. Do other programs work when you double click on them from the command line? Like C:\windows\regedit.exe or c:\windows\system32\calc.exe
     
    Last edited: Dec 2, 2006
  8. Aion

    Aion Private E-2

    I installed Avast and ZoneAlarm the other the day after reading one of the threads here that recommends some free anti-virus and firewall programs. Avast I didn't like, it wasn't for me, so I tried to uninstall it and ended up having to delete Avast manually, some of Avast may still be on my system as a result. I just deleted all remaining Avast stuff using Hijackhis.

    About task manager...yes, it is open most of the time due to my current problems. I'll make sure it's closed next time I do the scans.

    Msinfo32 doesn't work, nothing happens when I type msinfo32 into run. Something similar happens when I type help into run, the difference being that a black window with text opens for a second before closing (windows says it can't find helpctr when I click on the 'help and support' icon). Msconfig only works if I find and double click on it, run doesn't work. Regedit and calc work fine, everything seems ok with those.

    Apart from my Mohbpork.A infection, my main problems are explorer.exe crashing and msconfig/help/etc not working as they should. Sorry if I'm trying to get too much out at once. :)
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have a service from Avast running! Let's fix this.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to avast! iAVS4 Control Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteaswUpdSv into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.
    Are you still having virus problems? I don't see any.

    Download the new version of ShowNew and attach a new log from it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds