obfuskater virus help

Discussion in 'Malware Help (A Specialist Will Reply)' started by drdjmcd, Oct 7, 2007.

  1. drdjmcd

    drdjmcd Private E-2

    My son's computer got this virus. Ihave downloaded and run Hijack this per instructions on this site- attached is the log file.
    Now what?
    Thanks in advance!!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please follow the instructions in the Read and Run First sticky and attach the requested logs...HJT should be the last log to attach.

    Find and delete: (My web search -- the whole folder)
    C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe


    In the meantime:
    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT.

    Now attach the requested logs from the Read and RUn.
     
  3. drdjmcd

    drdjmcd Private E-2

    Thanks for the help!

    I am running the program/reccomendatins from the sticky post on general things to do first.

    I cannot delete:
    Find and delete: (My web search -- the whole folder)
    C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe

    I get an error message saying that I need to have system adminstraor privledges but they appear to be gone on this computer! I am assuming it happend via this (or another virus) but I cannot log on with administrator rights!

    I have deleted the rec entries in Hijack this. I am still in the process of running SpyBot before running it again.

    I will post the entries of the next run as soon as I get it.

    thanks again-
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try deleting it in safe mode.

    These are what we need:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  5. drdjmcd

    drdjmcd Private E-2

    Okay I have gone through the programs and ahve the attachments for you. I still cannot access any of the administrator privledges-even when logged on as Administrator in Safe Mode.

    Hope this information helps. If you need more let me know. You may notice that I ran Bitfneder after Panda Scan in the logs. I actually ran it first but saved the report as HTML, not .txt. When I was getting ready to post this reply I realized my mistake and re-ran bitfender so I could get the report as a .txt.
    You will notice that Counter Spy would not run so I ran AVG in its place.

    Thanks again!
     

    Attached Files:

  6. drdjmcd

    drdjmcd Private E-2

    Here are the other requested logs:

    I was able to delete the requested file in SAfe Mode.

    Any options besides re-installing Windows?
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your GetRunKeys log is empty ....did you get an error message when you ran it?
    Please note these instructions for fixing any errors: GetRunKeys

    Also your ShowNew log is not showing the uninstall program list...
    Download the attach GetUnKeys.zip to your PC someplace you can locate it. Then extract all the files from the ZIP. Locate the GetUnKeys.bat file using Windows Explorer (right click the Start button and select Explore to open Windows Explorer) and double click on it to run it. It will create a file named GetUnKey.txt in the root of drive C: (C:\GetUnKey.txt) . This log will also popup in a notepad window which you can just close. Upload the GetUnKey.txt file here as an attachment.

    Getting Uninstall Programs List From The Registry

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach new logs for:
    ShowNew
    GetRunKeys
    GetUnKey
    HJT
    Avenger
     
  8. drdjmcd

    drdjmcd Private E-2

    Okay I think I got everything done the right way.

    Sorry about the bad logs- I must have not run the programs the correct way ( don't know how I screwed that up!) but this time all of the logs appear to have information so hopefully this will help.

    This computer has been incrediably slow so I downloaded some of the programs to a USB drive on my desktop and then have moved them to this laptop via the drive. Can I run the programs directly from the USB drive or should I get them on the C: drive of this laptop first?

    I think I got the slow problem figured out- in the Task manager I noticed the QTTask.exe was running (using 99% 0f the CPU) and even when I ended the process it kicked back up. After uninstalling Quick Time and rebooting the probelm appears to be fixed. I don't know if that was related to the virus(es) or just another problem.

    Anyway thanks for all the help-

    What next?

    djm
     

    Attached Files:

  9. drdjmcd

    drdjmcd Private E-2

    Here are the rest of the attachments requested
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 1"
    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 5"
    J2SE Runtime Environment 5.0 Update 6
    Viewpoint Media Player
    SmartShopper
    Reboot and install:
    Java Runtime 6

    Now ....do you do online banking? If so, please alert your bank that your passwords may be compromised!

    Disconnect from the internet ---> physically unplug and do the following:

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach new logs for:
    ShowNew
    GetRunKeys
    HJT
    Avenger
     
  11. drdjmcd

    drdjmcd Private E-2

    I cannot Add/Remove programs due to "restictions in effect on this computer. Please contact your System administrator"

    This comes up in Safe mode, when logged on as Administrator.

    Know of any way around?

    djm
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download GMER and save it to your desktop:
    • Unzip (extract) it to your desktop.
    • Disconnect from Internet and close all running programs.
    • There is a small chance this application may crash your computer so save any work you have open.
    • Double-click gmer.exe to run it.
    • Let the gmer.sys driver to load if asked.
    • If it gives you a warning at program start about rootkit activity and asks if you want to run a scan... click NO.
    • Click the Rootkit tab.
    • Make sure all the boxes on the right of the screen are checked, EXCEPT for "Show All".
    • Then click the Scan button. Wait for the scan to finish.
    • Once done, click the Copy button.
    • This will copy the results to the clipboard. Open Notepad and press CTRL + V to paste the log, and save it to your desktop. Attach this log to your next reply.
    NOTE: If you're having problems with running gmer.exe, try it in Safe Mode. This tool works in Safe Mode whereas many other rootkit revealers do not.



    Do the rest of my previous post and attach the logs...
     
    Last edited: Oct 10, 2007
  13. drdjmcd

    drdjmcd Private E-2

    ARRRGH!!!

    When I run GMER it appears to run fine- take 15-30 min and comes up with a list of items. However when I press COPY the program closes and when I press control V in Note pad nothing has been copied! I tried to click on SAVE once to save a .log file but that too is empty! Is there a setting I need to change in GMER to get it to not close and to allow me to copy the log or what am I doing wrong!! Should I highlight everything in the log then click copy? I have tried in both Safe mode and regular- same problem.

    Sorry to be so stupid- this computer is getting under my skin! I probably shoudl do a reinstall of Windows(would it let me if I tried?) but now my ego is involved- I want to fix it to prove I can (with your help)

    As always any suggestions are welcome
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes....try highlighting and then Control + C and paste into notepad.

    You can also try running....AVG Anti-Rootkit

    Did you do the rest of the fix that I gave you?
     
  15. drdjmcd

    drdjmcd Private E-2

    Sorry to be so long in getting your suggestions done-

    So here is where I stand-
    Could not unistall any of the programs you rec.
    Did install Java ver. 6
    could not copy/paste out of the log file for GMER so I ran AVG rootkit instead- it did find a file: C:\WINDOWS\system32\drivers\runtime2.sys
    Can I have AVG remove this?

    I did the registry and everything else in your post.

    Attached are the latest logs


    Thanks again for all your help!
     

    Attached Files:

  16. drdjmcd

    drdjmcd Private E-2

    here is the Hijack this log and I think I posted the wrong avenger log so here is the most currnet avenger log
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Definitely!!!

    Then get off the web....turn off all of your active anti-virus and spyware programs and do the fixes again that I posted:
    Disconnect from the internet ---> physically unplug and do the following:

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.



    Now attach new logs for :
    ShowNew
    GetRunKeys
    HJT
     
  18. drdjmcd

    drdjmcd Private E-2

    Done!

    O4 - HKLM\..\Run: [startdrv] C:\WINDOWS\Temp\startdrv.exe
    did not show up this time in Hijack this. the Smartshopper showed up again so I deleted them again.

    Here are the latest logs:
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Smartshopper is still there ....

    Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt
    Attach the avenger log.
     
  20. drdjmcd

    drdjmcd Private E-2

    Done

    Here is the Avenger Log
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean. You may uninstall any programs we had you download (including CounterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  22. drdjmcd

    drdjmcd Private E-2

    Unfortunately I still cannot get administrative rights on this computer. When I click on Properties under my computer I get
    " The operation has been canceled due to restrictions on this computer. Please contact your system administrator."

    I get this all users!

    Is there a hidden guest account that has been altered?

    Any batch programs to identify all the users on the computer?
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Boot into safe mode ...do you still have a problem there with the default admin account?

    Check each user account in safe mode and reset the permissions.
     
  24. drdjmcd

    drdjmcd Private E-2

    Logged on in Safe Mode. Logged on under each user including Administrator and I get the same message. Coincidentally the control panel is no where to be found anywhere on any of the users (Safe or regular mode).

    Anyway to undo it?

    Thanks again
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run combofix.exe
    Double click combofix.exe & follow the prompts.
    When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    And also HJT.

    Attach both logs.
     
  26. drdjmcd

    drdjmcd Private E-2

    YOU GOT IT!!

    I can find the control panel, see user accounts, change properties....


    have attached the logs so maybe you and the "geeks" can learn something.

    I appreciate all your help- now i will read up on what to do to avoid this situation in the future. Especially for my office. What do you think of Windows Live Messenger. I am not much of a IM guy but my kids and their friends do a fair bit and probably more in the coming years. Is there a better/safer IM program?

    Thanks again and where do I go to donate $$ to support this forum?
     

    Attached Files:

  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We tried removing the wsnpoem in an earlier post ...oh, twell ...glad that got it ...

    Only problem I still see is :
    O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\system32\shdocvw.dll

    You should do a search for SmartShopper and remove all of it ...is it in your IE toolbars or addins?

    Use windows explorer to find and delete:
    C:\WINDOWS\system32\shdocvw.dll

    If everything is running well ...follow the link to How to protect yourself ....

    :)
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No this should not be deleted! It is a required system file.


    It is Shell Doc Object and Control Library which isa library used by Windows applications to add basic file and networking operations.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds