Please help! My PC is fubar by a spam bot!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Goonie4life, Jul 30, 2009.

  1. Goonie4life

    Goonie4life Private E-2

    Dear sir or madam,

    I'm a newbie to this so please be gentle! I've been infected with a spam bot for a while and cannot get any anti-virus, anti-spyware, anti-rootkit, etc. to remove the little bugger. I have gone through the majorgeeks cleaning regimen and need help figuring this out. Any help would be greatly appreciated.
    Thanks in advance to all. P.S. Majorgeeks.com is an awesome site!
    I have attached the applicable logs and my computer uses Xp SP2 (since it crashes when I install sp3!)

    3 logs attached this thread. 2 more logs attached in the following thread.
     

    Attached Files:

  2. Goonie4life

    Goonie4life Private E-2

    Here is the 2nd part of the malware removal logs. Thanks you!

     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First. It is a very bad idea to allow all users to have admin. privileges! You need to run SAS and MBAM on each user account.

    Second. You need to put Combo where you were instructed to put it...on you desktop, not here:
    c:\documents and settings\Matthew\My Documents\My Downloads\ComboFix.exe

    Now you need to tell me what is being reported and by what program....I need the exact path.

    What is this:
    C:\cc221.exe --> if you don't know, add it to the fix I give you.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    PGVJTXWA
    
    File::
    C:\Documents and Settings\Matthew\Local Settings\temp\wbk2A.tmp
    C:\Documents and Settings\Matthew\Local Settings\temp\wbk2b.tmp   
    C:\Documents and Settings\Matthew\Local Settings\temp\wbk2c.tmp     
    C:\Documents and Settings\Matthew\Local Settings\temp\wbk2d.tmp     
    C:\Documents and Settings\Matthew\Local Settings\temp\wbk3c.tmp    
    C:\Documents and Settings\Matthew\Local Settings\temp\wbk3d.tmp    
    C:\Documents and Settings\Matthew\Local Settings\temp\wbk6a.tmp     
    C:\Documents and Settings\Matthew\Local Settings\temp\wbk6b.tmp   
    C:\Documents and Settings\Matthew\Local Settings\temp\wbk6c.tmp     
    C:\Documents and Settings\Matthew\Local Settings\temp\wbk6d.tmp     
    C:\Documents and Settings\Matthew\Local Settings\temp\wbk6e.tmp     
    C:\Documents and Settings\Matthew\Local Settings\temp\wbk6f.tmp     
    C:\Documents and Settings\Matthew\Local Settings\temp\wbk70.tmp     
    C:\Documents and Settings\Matthew\Local Settings\temp\wbk71.tmp     
    C:\Documents and Settings\Matthew\Local Settings\temp\wbk72.tmp     
    C:\Documents and Settings\Matthew\Local Settings\temp\wbk73.tmp
    C:\Documents and Settings\Matthew\Local Settings\temp\D3BTS5ZN.htm
    C:\Documents and Settings\Matthew\Local Settings\temp\fdr1112.fdr   
    C:\Documents and Settings\Matthew\Local Settings\temp\fdr5484.fdr
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  4. Goonie4life

    Goonie4life Private E-2

    Thanks TimW and majorgeeks.com for all your help! Here are the new C:\ComboFix.txt and the C:\MGlogs.zip files as requested to get rid of this nasty spambot. I hope it's all correct this time. None of my spyware/antivirus/rootkit detection software has shown that this bot exists, but everytime I send an outgoing e-mail it sends another spam e-mail to the same address in my name! Talk about rude! Sheesh! Any help you can give me would be awesome.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's been a rather long time since you last replied. I am not seeing any malware in your system. You can remove these items:

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now as to your email situation. Malware detected in email databases has to be cleaned up by you. You have a few choices:

    1. delete the whole file which is not an option you normally want to use
    2. load the email folder that contains the infection and delete ALL unnecessary emails (hoping to remove the problem email) and then use the Mailbox Cleanup option to delete all old emails. Then compact the Outlook database to permanently remove data. See http://support.microsoft.com/kb/196990 If you do not cleanup and compact the databases, the deleted emails may still be leaving hidden information in the database that you just cannot see but a scanner may still pickup on it.
    3. create a new folder and move only emails you really need into the new folder and then delete the infected folder.

    Obviously this is assuming you are having problems with Outlook, though the same principals apply to other email programs.
     
  6. Goonie4life

    Goonie4life Private E-2

    Thanks for all your time and perseverance on my e-mail spambot issue. I went and did the registry fix that you suggested and bingo! It was accepted. I also, ran HJT and had it fix the problems you highlighted from the log. It seems that, although, I did not have any browsers open, the

    R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

    keeps coming back in the HJT log even after being "fixed"! I think the spambot jerk might be hiding in the startup or registry. I went onto Bleepingcomputer.com's startup file list and think these HJT files seem a tad fishy(atleast according to bleepingcomputer.com), but would like your expert opinion.

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize

    "Name Filename Status Description
    NvCplDaemon32 anvshell32.exe X Added by the Troj/VB-XU trojan"


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    "QuickTime Task qttask.exe X Trojan that is typically bundled with rogue anti-spyware programs and fake codecs. Once installed, this infection will advertise other rogue anti-spyw ... Read More "


    So, I went ahead and unistalled Microsoft Network(No longer need it) to try and eliminate any rogue e-mail responsible for the spambot. I have Microsoft Outlook Express installed on my computer, but do not know how to uninstall/delete this. Please advise, if possible on this.

    I have several anti-Malware/Anti-virus/anti-rootkit/anti-adware programs and none of them pick up on my spambot, but everytime I send an e-mail through hotmail, the recipient gets this e-mail in my name:

    "Dear friend:
    I would like to introduce you a corporation which mainly sell electronic products.Now the company is doing sales promotion,and all the products are sold nearly at its cost price.What's more,they provide their customers the best service and products which is good in qulity and low in price.It is a good chance for shopping,so improve the shining hour.Its now or never! Regards!
    The web address: www..."

    I did not include the actual e-mail address from the spam e-mail.

    Lastly, I have attempted to Install Windows XP SP3(I have windoes sp2 now) several times, but the system crashed and I had to system restore 3 times! I think the spambot is the reason for the crashes and I would like to install sp3 eventually.

    I sincerely thank you TIMW and majorgeeks.com for all your past and future help. This is one of the best and comprehensive sites on the web! Thanks again! 21 gun salute for you! :major
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    NvCplDaemon is related to your Nvidia graphics cards. The start up item is not a virus.

    QuickTime Task is part of Apple QuickTime. Again not a virus.

    Your email issue with hotmail is something you need to clean out yourself. You need to either delete all of your emails ( which I doubt you want to do) or find the email that is causing this issue and remove it.

    I suggest you post in the software forum for help with installing SP3.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds