rogue "antispyware" download

Discussion in 'Malware Help (A Specialist Will Reply)' started by yanqui, Mar 24, 2008.

  1. yanqui

    yanqui Private E-2

    this issue got cleaned up but came back so it's something that was written to execute at startup or something like that. The cmputer isn't running badly, but we know we got rid of a lot of crap. Logs are attached, and thanks in advance.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 11"
    J2SE Runtime Environment 5.0 Update 6"
    Java(TM) 6 Update 2"
    Java(TM) 6 Update 3"
    Java(TM) SE Runtime Environment 6 Update 1

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.
    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  3. yanqui

    yanqui Private E-2

    I'll get ready to do those things, with one exception, and that's Java. I recognize the security flaws in teh older versions of Java, but, unfortunately, plugging those holes disables some of the processes in some of our software. Until we can get those software developers to work around those plugs, we're stuck at the older versions of Java.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That's fine ....go ahead and do the rest. :)
     
  5. yanqui

    yanqui Private E-2

    here are the most recent logs. I ran SuperAnti again and again, and it kept catching things, so some of the stuff Avenger was suppsoed to find it didn't. BUT--My desktop is back to normal, but I still can't use the taskbar. It's still greyed out. Logs are attached, and thanks agian.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    A few things left to remove:

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Tell me exactly what is being reported and the exact path to it.

    And did you set this policy:
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "DisableTaskMgr"=dword:00000001

    If not:
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  7. yanqui

    yanqui Private E-2

    We're getting there! No, I hadn't set the task manager disable policy; that was one of the first problems we noticed. That's fixed. Here's what avenger reports:

    "No rootkits found!

    File "C:\WINDOWS\telefonos.txt" deleted successfully.
    File "C:\WINDOWS\textos.txt" deleted successfully.
    File "C:\WINDOWS\ntnut.exe" deleted successfully.
    File "C:\WINDOWS\uccspecb.sys" deleted successfully.
    File "C:\WINDOWS\WPCMAPI.INI" deleted successfully.
    File "C:\WINDOWS\system32\WER8274.DLL" deleted successfully.

    Completed script processing."

    By the way, the fingerprint software server on this laptop is gone. Did we do that? It would be a thinkvantage or thinkpad program, and I think it's something like fss--something.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I see it in your add/remove program list...so you may have to re-install it.

    Are you having any other problems?
     
  9. yanqui

    yanqui Private E-2

    Nope, back to normal, found it, repaired it, doing the final cleanup steps I've saved from previous experiences here and setting up this machine for "safe surf."

    thanks a million!
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome ....surf safe...:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds