Need Virus Removal Advice & Registry Question

Discussion in 'Malware Help (A Specialist Will Reply)' started by dood1emom, Sep 5, 2009.

  1. dood1emom

    dood1emom Private E-2

    Hi,

    Got hit with the nasty bunch of trojans et al going around (think got hit from zedo?) Am postiing from laptop, pulled the dsl connection on the infected pc.

    Having same problems getting removal tools to work as others. Primary AVG Free dead, then installed & ran SuperAntiSpyware ... got to run, said it found and removed 25 threats then rebooted, now dead & can't get a log to post. Can install but not run MalwareBytes. Already had HJT on system - it's dead.

    Some of the viruses/trojans were a.exe, msa.exe, probable variants of Vundo ... It seems that many have been removed by the initial SAS run. But I am trying to work thru malware removal guide, but can't get anything to work. Since permissions seem to be edited & my Event Viewer Log shows up until when SAS ran that "wuauserv registry key denied access to SYSTEM account programs so the Service Control Manager took ownership of the Registry key" would I be correct in assuming other unfound registry changes certainly aren't helping ... would running a registry cleaner be a good idea?

    Will try to run some removal programs in SafeMode, but at this point it's starting to get a little over my head ... some pointers appreciated.

    BTW, while the nasties got dropped all over the system, I see an xvhu and a hpbyv now dumped on C: that are from the exact time that I got hit ... no scans have latched onto them yet, but I know they're no good.

    Will try to post any logs I can get later today.

    Thank you,
    dood1emom
     
  2. dood1emom

    dood1emom Private E-2

    Tools run, need help with logs

    Hi,

    Got hit with virus/trojans while checking gmail 9-3-09. After much trial and error I think we've got all the tools run & logs attached. System is disconnected from internet. We did resort to some renames to get everything ran and logs produced. Logs attached.

    I also attached an initial AVG threat that found 9 infected files. When I got hit I immediately saw an hpbyv.exe and an xhue.ex in my c: drive. Other suspect items were msa.exe, a thru e.exe's, 876.exe.

    I am quite sure the system still isn't clean and don't know what to do next. Upon rebooting, I get error messages that kabifoti.dll and jisagoyi.dll are missing and when ever I access my HP_Admin folder I get a "Feature unavailable while ... not connected". Also still see a suspect file "1554803941" on c: Prior Event Logs now wiped, but I was getting a message about wuauserv not having proper priviledges (hope I remember that right) and I noticed a text log somewhere that was showing some of the priviledges revoked by virus/trojan.

    Please let me know what to do next. Thank you, Dood1emom
     

    Attached Files:

  3. dood1emom

    dood1emom Private E-2

    Re: Tools run, need help with logs

    Hi it's me again-- oh fudge, I think I may have missed the "msconfig must be set for normal startup mode". please let me know if i need to rerun tools. Sorry.
     
  4. dood1emom

    dood1emom Private E-2

    Re: Tools run, need help with logs

    Sorry, forgot to upload the rest of the logs. Here they are.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.

    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.


    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:

    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  6. dood1emom

    dood1emom Private E-2

    Hi Tim,

    Thank you for your reply. Sorry - getting the hang of posting in forums - I mistakenly started a new thread/post with logs already attached: I believe I also made that error of running what tools I could get to run (we had to rename some of them to get them to run) in just selective startup mode - I missed the "msconfig must be set for normal startup mode" step. My second post was "Tools run, need help with logs" 09-06-09, 23:27. What logs I got are attached to it. Did not run anything in Safe Mode. No longer getting the "kabifoti.dll and jisagoyi.dll are missing at bootup, but still have suspect "1554803941" on c: that was generated on date/time of infection. Also, something has generated a 0kb dat file on desktop. Did eventuallly get HiJackThis to run. I am attaching. Have school function tonight, won't be back for a few hours. Oh, after running various tools, Windows looks like the Auto Update has been turned back on, but I think IE8 is no longer set as default browser - think registry mave have been changed. Thanks again for all the help. Will rerun anything tonight if I need to because of msconfig error.

    dood1emom
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: Tools run, need help with logs

    I am only seeing a few things that need attention.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now run CCLeaner and make sure these have been removed:
    C:\Documents and Settings\HP_Administrator\Local Settings\temp\36c05e02-09ca-4657-b973-d474b834dbc7.tmp
    C:\Documents and Settings\HP_Administrator\Local Settings\temp\cf017b09-e27f-4d13-b572-c1f36f74e53f.tmp

    Tell me what issues you are still having.
     
  8. dood1emom

    dood1emom Private E-2

    Re: Tools run, need help with logs

    Hi Tim,

    Ran MGTools to make the changes you suggested. Noticed a Service GPCCFGEVA - Unknown owner in Docs & Settings\Hp_Admin\locals\temp\GPCCFGEVA.exe file missing. Is this okay to delete also.

    Ran CCleaner.
    C:\Documents and Settings\HP_Administrator\Local
    Settings\temp\36c05e02-09ca-4657-b973-d474b834dbc7.tmp
    C:\Documents and Settings\HP_Administrator\Local
    Settings\temp\cf017b09-e27f-4d13-b572-c1f36f74e53f.tmp

    These files were NOT removed. Also still see ~DF7B2F.tmp, IadHide5.dll and debugf.txt files, but I think these are ok. Still have the suspect "1554803941" 4kb file on C: that was generated at time of infection and 0kb settings.dat on desktop, although that file could be from when some of the tools were run.

    When I chose Set Program Access & Defaults, I can edit custom setup to select IE as my default browser, but upon reentry, the setting is always changed back to "use my current web browser." Have no idea if anything is wrong there because I pulled the DSL connection until desktop is disinfected. Do I need to check for any registry changes?

    Taskman shows multiple svchost.exe's running, but one has 30 user objects, mem usage 25,000 K. Have no idea if this is okay, but I did change to normal startup, so everthing is loading.

    The last two strange things are anytime I click thru to the HP_Admin folder, a "Windows Live ID Internet Connection ... could not be completed" message appears. I was getting "Feature Not Available ... because offline" message until I unchecked "Work Offline" in IE8. Have no idea if something is still trying to get connected or has changed settings somewhere. And at time of infection, system was intermittantly opening HP Help & Support Center. When I now open the program, it just doesn't seem "right." Accessing the tools area, should allow me to click for "My Computer Information", "Network Diagnostics" or various Tools, but all menu items seem to be dead. When led me to check "All Programs, PC Help & Tools, Connectivity Support Tools (icon seems messed up) and Support Tools is now looking for missing "supporttools.hta".

    Thanks for your help & input
    dood1emom
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please keep all of your posts in this thread, otherwise it becomes very confusing.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  10. dood1emom

    dood1emom Private E-2

    Hi Tim,

    Thank you for merging my threads - sorry for newbie to forum goof.

    Ran MGTools anaylse.exe and fix. Attached logs.zip. Was able to finally get Malware Bytes to run this weekend - it fixed a registry item that was preventing auto updates, so I think ok there. Still have weird "1554803941" file in C: and settings.dat on desktop. Windows Live ID still trying to connect when I access HP_Admin folder. Would the link http://smallvoid.com/article/winnt-help-support-service-config.html repair my "Help and Support" Center? Also was able to uninstall and reinstall AVG 8.5 Free to get it functioning til I decide what AV to use. Also see that "Manage Add-Ons" in IE8 messed up, but I've already had to reinstall it once b4 because it's been flakey.

    Thanks for advice.
    Dood1emom
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the MBAM log to your next reply so I can see what it found.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    -
    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  12. dood1emom

    dood1emom Private E-2

    Hi Tim,

    Thanks again. Attached neglected MBam log. Ran Avenger and CCleaner as instructed. No problems running anything.

    Son installed Zone Alarm for added security. AVG running smoothly. I disabled the "Windows Live ID Internect Connection" popup when perusing the Admin Docs & Settings by deleting the item "My web sites on MSN" from the NetHood subfolder (thanks Google). That probably got dropped onto the system during a rather recent, but b4 virus infection IE8 repair/reinstall.
    IE8 is still crashing if I access "Manage Add-Ons", but I think it was messed up b4 virus, so I'll just reinstall it soon. No strange redirects or unusual activity seem to be going on, just Zone Alarm seems to have slowed bootups.

    The only annoyance I can find is that all of the links or menu clickables in the "Help and Support Center" are dead. I know they were working correctly b4 virus because we very recently ran Sys Info, etc., in preparation for near future RAM and video card upgrade. It's small potatoes, I know ... all the tools seem to work through the various All Program Menu items, it's just any easy way around the system. If it means anything, the H & S Ctr sometimes tosses out a message that an IE script error occurred, do I want to continue scripts ... that hcp://system/scripts/navbar.js is missing. I have found zilch about that message!

    Last questions: my 2 kids have non-admin accounts on the system. Initially ran CCleaner on them as instructions suggested. Nothing seems suspicious on their accounts. Should I run anything on those accounts. Made sure many security items, such as file sharing, etc., are tightened. What should the Data Execution Prevention settings be? Our system has selected the option "Turn on DEP for all programs and services except those I select - IE and MS Help and Support Ctr" BUT those boxes are not selected.

    Thanks again,
    dood1emom
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I missed one file that needs to be removed. Please use windows explorer to find and delete:
    C:\WINDOWS\system32\memopoto

    Now empty out the following folder ( you will not be able to delete items from today):
    C:\WINDOWS\temp\

    Otherwise your logs are clean. I would suggest that you pursue the other issues in the software forum.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds