Request for Help with Attachs 1 of 2

Discussion in 'Malware Help (A Specialist Will Reply)' started by Rob11, Mar 28, 2007.

  1. Rob11

    Rob11 Private E-2

    In cleaning out the startup programs the other day I noticed 3 suspicious files that further research indicated were either viruses or worms:
    - notepad
    - msmsgs
    - lcbydc

    I am running XP SP2 with all latest updates.

    I have gone through all the steps in Read & Run Me First.

    In this post, I have attached logs from
    - Counterspy
    - BitDefender
    - GetRunKey

    Note that BitDefender and PandaActiveScan were clean and did not find any malware. I was not able to produce a report for PandaActiveScan.

    The next post will include the rest of the logs I've generated.

    Thanks in advance for your help.
     

    Attached Files:

  2. Rob11

    Rob11 Private E-2

    Re: Request for Help with Attachs 2 of 2

    Included in this post are the following logs:

    - ShowNew
    - AdAware
    - Hijack This

    I ran AdAware Se as it was on my system. It found 6 bad ones. It was the last scan I did before running HJT.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Request for Help with Attachs 2 of 2

    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now Run HijackThis and select the following lines (if they still exist) but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [hqmse] C:\WINDOWS\system32\lcbydc.exe reg_run
    O4 - HKCU\..\Run: [Cjyuo] C:\Documents and Settings\Alix\Application Data\s?stem\n?tepad.exe
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    We have more work to do based on what I saw in your logs but we need to fix a little at a time or the procedures would be too long.
     
  4. Rob11

    Rob11 Private E-2

    Thanks, chaslang. I ran ComboFix and it found and stated that it disinfected Qoologic.

    I ran HJT and fixed all but 2 lines that were not in the log:
    04 . . . [KernelFaultCheck]
    04 . . . [hqmse]

    I've attached the new GetRunKey, ShowNew, and HJT logs as requested.

    I will follow up this post with the ComboFix log.
     

    Attached Files:

  5. Rob11

    Rob11 Private E-2

    Here is the ComboFix log:

    One other thing, after I ran ComboFix, I received a request through ZoneAlarm from a suspicious program called NirCmd. I denied it and will check this out further. It's not something I've seen before and maybe a method of Malware making an outbound attempt. Let me know if you agree. Thx.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Now uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:WINDOWS\Downloaded Program Files\CONFLICT.1\amm06.ocx
    C:WINDOWS\Downloaded Program Files\CONFLICT.1\mm63.ocx
    C:WINDOWS\Downloaded Program Files\CONFLICT.1\QDow_AS2.dll
    C:WINDOWS\Downloaded Program Files\CONFLICT.2\mm63.ocx
    C:WINDOWS\Downloaded Program Files\CONFLICT.2\QDow_AS2.dll
    C:WINDOWS\Downloaded Program Files\UWFX5_0001_N63M2912NetInstaller.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Now attach a new log from GetRunkey!

    How is everything working now?
     
  7. Rob11

    Rob11 Private E-2

    Ok, downloaded Pocket Killbox. Uninstalled CounterSpy.

    Added the lines you specified to the registry with the fixME.reg file.

    Ran Pocket Killbox and the tool would not accept copying multiple lines. I copied one at a time, deleted, and answered no to Reboot until I copied the last line in the text you provided. Hope this works, as I recall I had the same problem in attempting to copy multiple lines to PK awhile back. I rebooted and received the following message:

    "PendingFileRenameOperations Registry Data has been Removed by External Process!"

    I selected OK, and ended up having to reboot myself. I've attached the latest GetRunKey log. I'm hoping this method of entering files into Pocket Killbox gets the desired results.

    Everything appears to be OK, but I I'll play on this machine awhile in other user accounts to determine whether all is well. Let me know how you want to proceed or if you would like a current HJT log as well.

    Thanks.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure? Did you get a success message when you did this? Based on your logs the patch was not added. Make sure nothing else is running when you do this. Even shutdown ZoneAlarm!!

    The file deletions may not have worked either since Killbox received that error.

    Download and install ExplorerXP Run it and look for the below files and delete it found:
    C:WINDOWS\Downloaded Program Files\CONFLICT.1\amm06.ocx
    C:WINDOWS\Downloaded Program Files\CONFLICT.1\mm63.ocx
    C:WINDOWS\Downloaded Program Files\CONFLICT.1\QDow_AS2.dll
    C:WINDOWS\Downloaded Program Files\CONFLICT.2\mm63.ocx
    C:WINDOWS\Downloaded Program Files\CONFLICT.2\QDow_AS2.dll
    C:WINDOWS\Downloaded Program Files\UWFX5_0001_N63M2912NetInstaller.exe

    Note they may already be gone but we need to check. You cannot use Windows Explorer to do the above. You need ExplorerXP.
     
  9. Rob11

    Rob11 Private E-2

    Yes, I'm sure with the fixME.reg, as I received a confirmation message the first time. I ran it again with EVERYTHING shutdown and disconnected from the network and received another confirmation message.

    Downloaded and installed ExplorerXP. The only file I was able to find was the following:
    C:WINDOWS\Downloaded Program Files\UWFX5_0001_N63M2912NetInstaller.exe

    I deleted it.

    The CONFLICT.1 and .2 directories were empty (0 bytes) and was not able to locate the other files.

    I have attached new GetRunKeys and HJT logs. Again, thanks for your help on this!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The registry patch is not working. Typically this means that something is blocking the changes. Sometimes it is just that you do not own the registry key and cannot delete it. Let's see what we can do about that.

    Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite and copy and paste the below into the address bar and hit enter or click the Go button

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage

    • Now look in the right window pane and you should see each of the below lines
      • C:/WINDOWS/Downloaded Program Files/clearadjust.dll
      • C:/WINDOWS/Downloaded Program Files/CONFLICT.1/amm06.ocx
      • C:/WINDOWS/Downloaded Program Files/CONFLICT.1/mm63.ocx
      • C:/WINDOWS/Downloaded Program Files/CONFLICT.1/QDow_AS2.dll
      • C:/WINDOWS/Downloaded Program Files/CONFLICT.2/mm63.ocx
      • C:/WINDOWS/Downloaded Program Files/CONFLICT.2/QDow_AS2.dll
      • C:/WINDOWS/Downloaded Program Files/mm63.ocx
      • C:/WINDOWS/Downloaded Program Files/UWFX5_0001_N63M2912NetInstaller.exe
    • There may be other items list in the right window pane too but we only care about the ones listed above.
    • One at a time, I want you to right click on each item from the list and select Delete.
    • If it does not delete, right click on the item and then select Properties.
    • In the Properties window, note who is the Owner.
    • Then click the Take Ownership button.
    • Then click Ok to close the Properties window.
    • And try to delete the item again.
    • Repeat this for each item we are tryin to remove.
    Let me know how these steps went. If you were successful in deleting the items, attach a new log from GetRunKey.
     
  11. Rob11

    Rob11 Private E-2

    Registrar Lite went smoothly. I was able to delete each of the files listed in your post above without having to go into Properties and Take Ownership. I re-checked to confirm that each file was removed.

    I've attached the current GetRunKeys log.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good job!

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. Rob11

    Rob11 Private E-2

    Thanks, chaslang. I've finished the cleanup. You provide an invaluable service and given the number of posts on this board every day, it's an understatement to say I'm impressed. The information sharing and advice I find here is peerless. I appreciate the time you spend to make it happen!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! And thanks! :p
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds