Multiple Trojans

Discussion in 'Malware Help (A Specialist Will Reply)' started by sny29, Oct 3, 2010.

  1. sny29

    sny29 Private E-2

    My computer has given me a number of issues over a long period of time. I'm giving myself over to MajorGeeks for help. The steps have been completed and logs to be attached.

    Items to note:
    I found 'Antivirus 2010' in my Add/Remove Programs. I'm quite skeptical of that program but I am unable to remove it. It says this:
    "An error occurred while trying to remove Antivirus 2010. you do not have access to //./globalroot/systemroot/system32/userinit.exe. you can specdify the new uninstall program below." Then it asks me to 'Browse' for the file. I have no idea where to look.

    Next, when running ComboFix, i got an error that looked like this:
    Service: agp440
    File: C:/WINDOWS/system32/DRIVERS/agp440.sys

    I couldn't seem to get a log from Root Repeal. I select both drives and got an error message that said: "Unrecognized partition-type 6 (0x6)!" The program stalled without any logs and showed 'Initializing Please Wait..." I tried to re-run it and the same thing happened. It sat on 'Initializing' for quite a long time before I closed it. I've attached both logs just in case but I believe they're both empty.

    MGTools had the 'failed to initialize properly (0xc0000005)' - similar to what was shown in the MGTools instructions example. I clicked OK and let it proceed, but wanted to point out that this popped up 10 times.
    MGTools also showed an error that said "Unalbe to find a version of the runtime to run this application."

    All requested logs attached. Looking forward to your help!
     

    Attached Files:

  2. sny29

    sny29 Private E-2

    RRLogs - 2 as described above.
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks, sny29.

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    dr.m
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, sny29

    You have not installed the last service pack for XP... why?

    Other than the tools our guide instructed you to save there, I strongly recommend that you clean up this account's Desktop immediately leaving only shortcut links. [ C:\Documents and Settings\ross\Desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    *Delete this file as it is not where you were instructed to save it and it is no longer needed.
    C:\Documents and Settings\ross\Desktop\Cleanup\MGtools.exe

    Do you know what this file is? c:\windows\system32\drivers\svwki.sys

    Step 1:
    Please look in Add/Remove Programs (Programs and Features if using Vista or Windows 7) for the following and uninstall if found. If you get any errors just make a note and continue on.
    Consider updating this outdated browser Mozilla Firefox (3.0.19) to the current Mozilla Firefox 3 3.6.10 Final

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Step 2:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 3:
    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    AWF::
    c:\program files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe
    c:\program files\Common Files\Symantec Shared\bak\ccApp.exe
    c:\program files\Common Files\Symantec Shared\Security Center\bak\UsrPrmpt.exe
    c:\program files\DIGStream\bak\digstream.exe
    c:\program files\ESPNRunTime\bak\DIGServices.exe
    c:\program files\Google\GoogleToolbarNotifier\1.2.908.5008\bak\GoogleToolbarNotifier.exe
    c:\program files\Intel\NCS\PROSet\bak\PRONoMgr.exe
    c:\program files\IObit\Advanced SystemCare 3\Bak\ymetray.lnk
    c:\program files\iTunes\bak\iTunesHelper.exe
    c:\program files\Java\jre1.5.0_03\bin\bak\jusched.exe
    c:\program files\Java\jre1.5.0_09\bin\bak\jusched.exe
    c:\program files\Lexmark X6100 Series\bak\lxbfbmgr.exe
    c:\program files\Microsoft AntiSpyware\bak\gcasServ.exe
    c:\program files\Microsoft Money\System\bak\mnyexpr.exe
    c:\program files\Musicmatch\Musicmatch Jukebox\bak\mimboot.exe
    c:\program files\Norton SystemWorks\bak\cfgwiz.exe
    c:\program files\Norton SystemWorks\Norton Ghost\Agent\bak\GhostTray.exe
    c:\program files\QuickTime\bak\qttask.exe
    c:\program files\SymNetDrv\bak\SNDMon.exe
    
    FileLook:: 
    c:\windows\system32\drivers\svwki.sys 
    
    Driver::
    mfefeatk01
    mfefeatk02
    mfefeatk03
    mfefeatk04
    
    File::
    c:\windows\Mtusilugoqo.bin
    c:\windows\asakoyup.dll
    C:\windows\system32\drivers\xqrbhan
    C:\windows\system32\drivers\mfefeatk01
    C:\windows\system32\drivers\mfefeatk02
    C:\windows\system32\drivers\mfefeatk03
    C:\windows\system32\drivers\mfefeatk04
    C:\WINDOWS\Mtusilugoqo.bin
    
    Folder::
    C:\Documents and Settings\ross\Local Settings\Application Data\jijweamdt
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Rgaze"=-
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "bofabotxxx.exe"=-  
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 4:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 5:
    Now run the below:
    Microsoft FixIt - Reset Internet Explorer settings
    • Download this Microsoft FixIt and save it to the desktop.
      • Double click on MicrosoftFixit50195.exe and select I Agree then click Next
      • Follow the on-screen prompts.
      • You can delete the MicrosoftFixit50195.exe when it's finished.
      • The next time Internet Explorer is launched you will be prompted to re-apply settings again, this is normal.
    • Note: Any add-ons will require to be reapplied after the above reset.

    Step 6:
    Let's do this as an additional measure:
    Download HostsXpert and then follow the below steps.

    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program

    Step 7:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip file to your next reply.

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
    Last edited: Oct 5, 2010
  5. sny29

    sny29 Private E-2

    I don't know why I don't have the latest service pack. Is this not something I would have gotten from Automatic Updates? (I really don't know what I'm doing!)

    I apologize for saving the 'Cleanup' folder to the Desktop. I didn't realize that was contained within the 'Documents and Settings' folder. I moved it to C:\Cleanup.

    I don't have the first clue what the 'c:\windows\system32\drivers\svwki.sys' file is.

    Step 1
    As noted in my original post, I did see the 'Antivirus 2010' in Add/Remove Programs. I am unable to remove it. Please see previous post to review the error message I received. I did try it again but Add/Remove Programs wouldn't even bring up a list of programs.

    Step 2
    Completed the Analyse instructions. Soon after it was completed, I lost the ability to open any programs. Didn't seem to be frozen, just wasn't responsive to any attempts to open programs and it kicked me offline - couldn't re-establish connection.

    I had to restart due to the inability to open programs. Working now, but did I negate anything I did with Analyse?

    Step 3
    Complete.

    Step 4
    Complete.

    Step 5
    I tried running Microsoft Fix It twice. After checking 'I Agree' and clicking 'Next', I get a screen that says 'Click the Reset button after clicking Next'. I click 'Next'. It then says: 'This Microsoft Fix it failed to process'.
    This happened 2x.

    Step 6
    Complete.

    Step 7.
    Complete. Same error messages as the first post.

    Thanks for your help!
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, sny29

    Let's continue first with the malware removal.

    Yes, if you have Automatic Updates enabled. XP SP3 was released to the public on May 6, 2008.

    Try using Your Uninstaller! 2010

    Step 1:
    We need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    AWF::
    c:\program files\Intel\NCS\PROSet\bak\PRONoMgr.exe
    c:\program files\iTunes\bak\iTunesHelper.exe
    c:\program files\Musicmatch\Musicmatch Jukebox\bak\mimboot.exe
    c:\program files\QuickTime\bak\qttask.exe
    
    Driver::
    xqrbhan
    
    File::
    c:\windows\system32\drivers\xqrbhan
    
    Folder::
    c:\program files\Microsoft AntiSpyware
    c:\program files\Norton SystemWorks
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "McAfeeUpdaterUI"=-
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 2:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 3:
    Please run this online scan:
    Using ESET's Online Scanner

    Step 4:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip file and the ESET Online scan resultsto your next reply.

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
  7. sny29

    sny29 Private E-2

    Got computer current on Windows Updates including Service Pack 3.

    Your Uninstaller! 2010 seemed to do the trick by getting 'Antivirus 2010' removed from the Add/Remove Programs list.

    Step 1
    Complete. Log attached. Note: I did get a message saying 'PEV.exe encountered a problem'.

    Step 2
    Complete

    Step 3
    Complete. Log attached.

    Step 4
    Complete. Log attached.

    Thanks again!
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome, sny29.

    We're about ready to finish up here in the removal forum, I'll send you off to the Software Forum for any remaining issues.

    *If you didn't set this proxy- fix it by using C:\MGtools\analyse.exe
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Remove this leftover by using Windows Explorer - navigate to and delete:c:\program files\Common Files\Symantec Shared

    Then run this tool > re-boot and run it again:
    Norton Removal Tool 2011.0.0.15

    Then, open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!.
    -------------------------------------------------------------------------------
    Your logs look good! If you are not having any other malware problems, it is time to do our final steps. DO NOT neglect performing every step given.
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif

    Support MajorGeeks!
     
  9. sny29

    sny29 Private E-2

    Thank you very much!!

    Above steps completed.

    Is there anything specific you're suggesting I ask the Software support forum?

    One thing I do know I'll need to ask is how to remove McAfee Enterprise. I can't find any evidence of it being installed, but Windows keeps telling me it's out of date and the ComboFix uninstall detected it running. The McAfee Removal Tool doesn't seem to work with this Enterprise version.
     
  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome!

    If the tool I gave a link to in post #6 didn't remove it, also try:
    Revo Uninstaller 1.89
    AppRemover by OPSWAT
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds