Mustafx2.exe and kurva.dat

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lars, Jan 15, 2008.

  1. Lars

    Lars Private E-2

    Worked through the Malware FAQ.

    Combofix, Spybot, and AVG Spyware all won’t run. Spybot used to run previously, but doesn’t since infection.

    MGtools did, log attached.

    Problems started last week when I clicked on a website. AVG Free and Ad-Aware currently identify the problems, but do not fix.

    Have created dummy files for mustafx.exe and mustafx2.exe and have set to read-only system files in C:\WINDOWS and C:\WINDOWS\system32 to hopefully prevent access or further problems while I work on removal.

    Currently AVG and Ad-Aware are only detecting kurva.dat

    Mustafx2.exe and mhxfa.exe both show up in msconfig Startup, btw

    Any help would be much appreciated, thanks in advance.
     

    Attached Files:

  2. abri

    abri MajorGeek

    Hi Lars!
    Welcome to Major Geeks!


    The instructions which follow are lengthy but not difficult. The question is more whether you can do them all or not. Please read through them so you understand the logic to the steps and if you have any questions just ask. I will be asking you to disconnect from the internet and doing several steps while you are disconnected.

    Let's begin here:

    Can you run CCleaner? If so, please run it at the default setting with the Windows tab on top.

    Next I would like for you to do the following. If something isn't possible, just continue.


    1) Go to How to Protect Yourself from Malware and find the links for Antivirus programs. Download the installation program for Avast, but do not install the program. Remember where the installation program is so you can locate it later on.

    2) Next I would like for you to download The Avenger by Swandog46, and save it to your Desktop.
    [*]Extract avenger.exe from the Zip file and save it to your desktop. We will run it later.

    3) Now, please print out these instructions so you can disconnect from the internet. After you print these out, please shut down your computer and physically disconnect it from the internet. Then reboot and disable all antivirus and antispyware programs before you fix anything.

    4) Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [mustafx2] mustafx2.exe
    O4 - HKCU\..\Run: [Microsoft Windows Adapter 5.1.3214] C:\Documents and Settings\Chris\Application Data\mhxfa.exe
    O20 - AppInit_DLLs: kurva.dat

    After you click fix, just close hijackthis.

    5) Next, please run Avenger (which is on the desktop)
    • Run avenger.exe by double-clicking on it. (it should already be extracted)
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    6) Now, please uninstall AVG Antivirus via add/remove programs.

    5) Run CCleaner at the default setting.

    7) Find the installation program for Avast and allow it to install.

    7) Reconnect to the internet and allow Avast to update. Then have Avast perform a system scan and have it fix whatever it finds. If it quarantines the files from the above infections, delete these from the quarantine and run CCleaner again.

    4) Install the current version of Sun Java from: Sun Java Runtime Environment

    6) If you do not use Windows Messenger (not to be confused with MSN Messenger!!) I would like you to run Disable/Remove Windows Messenger

    8) Please run C:\MGtools\GetLogs.bat and attach the fresh MGlogs.zip it generates along with the Avenger log.


    Let me know how things are running now?

    abri
     
  3. Lars

    Lars Private E-2

    Ok, have followed all steps.

    Avenger generated a syntax error in one line.

    mustafx2 now runs again in a dos box on startup, with a system error message that pops up in another box.

    Logs attached.
     

    Attached Files:

  4. abri

    abri MajorGeek

    Hi Lars!

    Please go to post 2 and rerun Avenger only this time use the contents of this box:

    When you finish, please run CCleaner and then attach the Avenger log to the next post.

    abri
     
  5. Lars

    Lars Private E-2

    I assume you meant follow steps 1-5 of your original post, so that's what I did.

    These two still show up in MGtools\analyse.exe

    O4 - HKLM\..\Run: [mustafx2] mustafx2.exe
    O20 - AppInit_DLLs: kurva.dat

    Told it to fix.

    Ran Avenger, log attached.

    Doesn't look like it worked. mustafx2 still there on reboot.
     

    Attached Files:

  6. abri

    abri MajorGeek

    Hi Lars,
    Oh, my numbers are very bad. I only meant for you to go back to post number 2 and rerun Avenger. The other steps I think you already did.

    Let's try the following now.

    1) Download and install Erunt. Use it to create a backup of your registry.

    2) Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. Tell me if you get a success message or not.
    3) Now, please download RegSrch.zip

    Unzip the archive to your desktop and double click on the VBS file.
    (If your AntiVirus alerts, allow the script to run.

    Now enter kurva.dat
    Save the results to a file called rskurva.txt

    Repeat the above search for mustafx2 and mustafx and give the results the names rsmustafx2.txt and rsmustfx.txt respectively.

    Attach the results with your next post.

    abri
     
  7. Lars

    Lars Private E-2

    fixME.reg merged ok

    AVG picked up a couple of new ones this morning. Deleted them from the virus vault. Looks like some are coming in through the XP system restore points, so I turned that off for now.

    Here's the latest from RegSrch.
     

    Attached Files:

  8. abri

    abri MajorGeek

    Hi Lars,
    Please run the GetLogs.bat which is in the MGTools Folder under C. Double click on it to run it and when it's finished it will tell you to close it by hitting any key. Then look for the logs directly under C. MGlogs.zip
    Attach them here.
    Thanks.
    abri
     
  9. Lars

    Lars Private E-2

    Here you go.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Per the READ & RUN ME, you must NEVER install multiple antivirus programs. Either uninstall Avast or AVG7.5 now before going any further.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O20 - AppInit_DLLs: kurva.dat

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Also delete all files ain the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\Chris\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  11. Lars

    Lars Private E-2

    Well, I think you got it. System seems to boot normally.

    Logs attached for your review. Please advise if you think this system is now secure.

    And thank you very much!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not quite. Some of the files came back. Let's try this another way.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    O4 - HKLM\..\Run: [mustafx2] mustafx2.exe


    After clicking Fix, exit HJT.


    Now print the below instructions because at a point during them you MUST (this is can be critical) shutdown all browsers. I will tell you when to exit the browsers during the muti-part procedure.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it:
    Code:
    Catch::
    C:\WINDOWS\kurva.dat
    C:\WINDOWS\mustafx2.exe
    
    File::
    C:\WINDOWS\kurva.dat
    C:\WINDOWS\mustafx2.exe
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it.
    • Then attach the below new logs:
      • C:\ComboFix.txt
      • C:\MGlogs.zip
     
  13. Lars

    Lars Private E-2

    This line was not found by Mgtools.

    O4 - HKLM\..\Run: [mustafx2] mustafx2.exe


    Ran your script, logs attached.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  15. Lars

    Lars Private E-2

    Done, done, and done.

    Thank you very much Sir!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds