Possible Virus/Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by iggypop65, Feb 2, 2008.

  1. iggypop65

    iggypop65 Private E-2

    I’ve had the following banner appear across the top of web pages in the past couple of weeks.

    “Warning: possible spyware or adware infection! Click here to scan your computer for spyware and adware…”

    When this appears beeping noises come through the speakers at a consistent timeframe. Every two seconds or so. Refresh tends to eliminate it the banner and noise for a period of time, but it show up randomly when new neb pages are visited.

    Ads are also displayed at random times that are sexually explicit, showing near naked women with the play button triangle across the pictures indicating a link to videos. The website ZANGO has popped up as well, which I think was a direct link from the ads. These ads appear to replace legitimate ad banners on sites such as RedSox.com, Boston.com and Comcast.net.

    I’ve gone through the malware removal process and am attaching files from the process. I did not receive a report from the AVG scan.

    I also have not been able to download HJT software.

    I'm running XP SP2, IE 6.0.29, McAfee anti virus and personal firewall, along with spyware detector.

    Help would be mucdh appreciated, two kids 7&5 use this laptop as well.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please remove MGtools.exe from your Desktop.
    C:\Documents and Settings\Jeff\Desktop\MGtools.exe

    It is not supposed to be saved there per the READ ME instructions.

    Is your copy of Spyware Doctor a paid version or free trial? If free, uninstall it now.


    Download and run FindAWF by noahdfear.
    • Please download FindAWF by noahdfear.
    • Save to your desktop.
    • Double-click the FindAWF icon.
      • If a Security Alert shows, allow the program to run.
    • As instructed, press any key to continue.
    • Use the following option: Press 1 then Enter to scan for bak folders
    • The scan may take a while, please be patient.
    • When done, a text file, Find AWF report is produced.
    • Please attach the Find AWF report in your next post.
    Now we need to stop & disable a service. ( It may already be stopped)

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to SDService
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: SXG Advisor - {16167372-A970-4412-B90E-B07CFED45E77} - C:\WINDOWS\dpvtporvqm.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SystemTraySD] C:\Program Files\SpywareDetector\SDSystemTray.exe -AUTO
    O4 - HKLM\..\Run: [SDAutoLiveupdate] C:\Program Files\SpywareDetector\LiveUpdateSD.exe -AUTO
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O4 - Startup: PowerReg Scheduler V3.exe

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    DirLook::
    C:\WINDOWS\system32\bak
     
    File::
    C:\ExecSignature.txt
    C:\SDSignature.txt
    C:\WINDOWS\aswmklt.dll
    C:\WINDOWS\bqxomdo.dll
    C:\WINDOWS\dpvtporvqm.dll
    C:\WINDOWS\elfwgps.dll
    C:\WINDOWS\fvqkfsp.exe
    C:\WINDOWS\system32\SDEarlyDelete.exe
    C:\WINDOWS\system32\SDMonRemoveDB.db
    C:\WINDOWS\system32\SDRemoveDB.db
    C:\WINDOWS\system32\CheckDll.dll
    C:\WINDOWS\system32\CloseAll.exe
    C:\WINDOWS\system\SysSD.dll
     
    Folder::
    C:\Program Files\GamesBar
    C:\Program Files\SpywareDetector
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • FindAWF log
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. iggypop65

    iggypop65 Private E-2

    THANK YOU!

    I'm curious about the cause of the problems I was having.

    I've followed the guide to work through various processes and it has worked well to this point. I'm attaching the requested files.

    Thank you very much for your help and this site. I feel comfortable with PC's but this site really helped me get through this malware issue. (I assume it was malware of some sort, please let me know)

    I've been surfing after completing these fixes and no issues in over an hour of work.

    Thank you again.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have some more to cleanup.

    Next, we need to run FindAWF again.
    • Double-click the FindAWF icon.
      • If you receive any security alerts and/or warnings please allow the utility to run.
    • As instructed, press any key to continue.
    • Use the following option: Press 2 then Enter to restore files from bak folders
    • A text file opens called: files.txt
    • Click below the line and paste the following list of files to be restored:
    • Next, close and click Yes to save the changes.
    • Once files.txt is saved, FindAWF does the following:
      • It attempts to terminate the process represented by each filename on the list, if running
      • Deletes the rogue file from the parent folder, if present
      • Copies the original file to the parent folder
    • When done with the above, it automatically runs a new scan and opens a new log.
    • Please attach the new FindAWF log to your next message.
    Delete the below folder if it still exists:
    C:\Program Files\Java\jre1.6.0_02

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • FindAWF log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. iggypop65

    iggypop65 Private E-2

    OK, the files from the most recent processes are attached. So far so good. No issues within an hour of surfing and researching on the WEB.

    Thanks again - let me know if there's more.

    iggypop65
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you forget to do the below in my last message? If looks like you forgot. Please do it now.
    Now we need to use ComboFix to some folders.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    Folder::
    C:\Program Files\iTunes\bak
    C:\Program Files\Spyware Doctor\bak
    C:\Program Files\McAfee.com\Agent\bak
    C:\Program Files\QuickTime\bak
    C:\WINDOWS\ehome\bak
    C:\WINDOWS\system32\bak
    C:\WINDOWS\system32\bak
    C:\Program Files\Google\GoogleToolbarNotifier\bak
    C:\Program Files\Google\Google Desktop Search\bak
    C:\Program Files\Panicware\Pop-Up Stopper Free Edition\bak
    C:\Program Files\Synaptics\SynTP\bak
    C:\Program Files\Adobe\Reader 8.0\Reader\bak
    C:\Program Files\Common Files\Real\Update_OB\bak
    C:\Program Files\Java\jre1.6.0_02
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. iggypop65

    iggypop65 Private E-2

    I didn't forget to run it, but this time I chose to remove windows messenger. THe files you requested are attached. The machine has been running well with the exception of a blue screen two days ago which caused a freeze. I shut the laptop off and it came up normal the next morning.

    Thanks,
    iggypop65
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds