Small.bgx apparently won't go away

Discussion in 'Malware Help (A Specialist Will Reply)' started by MikeS, Mar 21, 2008.

  1. MikeS

    MikeS Private E-2

    Hi all...
    I got totally banged by just about every trojan and virus imagineable, from the Zango suite to Smitfraud to everything inbetween.
    I've gotten rid of almost all of it.
    But I think that:
    1. There are still remnants of Trojan-Dropper.win32.small.bgx in the system - every time I start up the ctfmon.exe entry is in the registry and is running in processes - even though I've disabled the *legitimate* ctfmon.exe process that runs from Office. I delete the entry and the process and they come right back.
    2. I think there's still a backdoor open somewhere - since McAfee (and the damned AOL virus scanner that I can't figure out how to disable) keep reporting that they've found new viruse files that they've deleted or disabled (the last one was Bifrost, about 10 minutes ago).
    Logs are attached.
    Thanks for your help - and I know someone will get to this when they can, but if it matters, we have a newborn baby and every minute I had planned to steal away to the computer to work, I'm dealing with viruses and unable to get any work done at all :-(
    Thanks :)
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    UninstallSpyHunter

    Is Weather Services something that you installed? If not then uninstall it too.

    Is your copy of Spyware Doctor a paid version or free trial? If free, uninstall it too.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWSabout.htm
    O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. MikeS

    MikeS Private E-2

    Will do and will report back, thanks.

    But one question, I know that you don't approve of Spy Hunter - my understanding is that the "problem" with it is their marketing approach.

    My question is: it has a feature on it that I've found helpful: it monitors the registry and asks before letting any entries be written or modified, alerting me to any malicious program trying to write to the registry. Is that feature not worth having the program?

    (Both the Spy Hunter and Spyware Doctor are paid versions).
     
  4. MikeS

    MikeS Private E-2

    OK - have run everything.

    BUT NOTE:
    When I ran analyse.exe it did not show one of the items in your list:
    O4 - HKCU\..\Run [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    BUT....that item is still in my registry when I look now :-(
    and the process is still running...and the item is back in my startup menu.
    My guess is that whatever is "hiding" it reinstalled it when the system rebooted after HJT ran.

    The logs are attached.

    The machine is mostly OK so far, although the AOL scanner popped up a block of BiFrost after everything was finished running.
    And obviously that registry issue is still a problem.
    I'm going to try to get some sleep before the baby wakes up. If I run into more problems before you respond, I'll post them.

    Thanks for the fast response.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    More than that. It has never been effective at finding and removing real malware problems and has always had problems with false positives. There are many better choices of tools to use especially if you are willing to pay.

    I still would not recommend using it. There are better alternatives. Even using the free Teatimer in Spybot is a better choice. And you should not be using two realtime blocking tools anyway since they can clash.

    When did you install SpyHunter? Before or after this infection?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not answer my question about Weather Services.

    Yes but now it appears to be the real one based on the logs you attached. Check the date, time, and size of the C:\WINDOWS\system32\ctfmon.exe file now and what do you see. It does not show in your newfiles.txt log now and it did previously because it was new and was the wrong size. Since it does not show in newfiles.txt now, it means the file is now older than what we look for and I would expect that your system may have restored the original. You cannot just stop this from running, you have to follow Microsoft's instructions to disable this. See the below link:

    http://support.microsoft.com/kb/282599


    Where? Also I did not notice that you had AOL's Antispyware program installed. Again I would not suggest having multiple realtime antispyware blocking programs installed so exactly what are you referring to from AOL. Is it just an online scan?

    What registry issue?



    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. MikeS

    MikeS Private E-2

    Sorry - thought I had, it was late at night. Yes, I installed it, it's the Weather Channel suite of services.

    Gotcha...done.

    I assume it's an online scan they run automatically when AOL is on the machine - I have just found the screen where you can disable it (but haven't done so yet, because of the BiFrost question), which in typical AOL fashion isn't easy to find. It also doesn't tell you the location of what it finds and as far as I can tell it doesn't produce logs, it just "blocks" files - so I don't know where it found the alleged problem files :-(

    The one related to the cfmon.exe entry that didn't show in analyse.exe - I assume it falls into the same category as nowbeing the "real" entry, the same as the cfmon process...and that it's now no longer an issue.

    --------------

    Scans run...logs attached...only problem so far is another AOL block of BiFrost...will report if any more crop up.

    Assuming that things are now fine....your recommendations as to what I should now be running? (McAfee, SuperAntiSpyware, other?)

    Thanks again :)
     

    Attached Files:

  8. MikeS

    MikeS Private E-2

    Also realized I hadn't answered this one in my tired stupor - sorry about that. I installed it after the infection.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then I cannot help you with it because we are not seeing any valid indications of an infection. If AOL is not telling you what or where it is finding something and it is not fixing it then it is nor worth using. In addition, you have Spyware Doctor and should not need anything from AOL which would most likely be less competent than Spyware Doctor.

    Does the below folder exist? If yes then delete it:
    C:\Program Files\Bifrost


    And just to be on the safe side, let's run the below and get the log.

    Using Sophos Anti-Rootkit



    All of our recommendations are in the How to protected yourself from malware sticky thread which will also be included in final instructions which I will post after seeing the Sophos log if it is clean.
     
  10. MikeS

    MikeS Private E-2

    no, not there.


    Run and one file found. Log attached.

    Gotcha. Thanks again.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then at this point you appear to be all clean and I suggest you do the below. Perhaps after toggling System Restore, the issue that AOL is finding will go away.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. Uninstall COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN
      • Now type cf /u in the runbox and click OK.
      • Note: The space between the cf and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  12. MikeS

    MikeS Private E-2

    Before "finishing" everything and restoring the system, I ran SUPERAntiSpyware again, and found a number of items, all in C:\SYSTEM VOLUME INFORMATION\_RESTORE, all apparently registry items.

    There were 9 Rootkit.Runtime3/Mutant items (all .sys files) and 13 Trojan-Unclassified/FTP-Fake items (all .dll) files.

    Should I just delete and all will be ok? Or is there more I should do?
     
  13. MikeS

    MikeS Private E-2

    I meant to include the log. Here it is.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Had you followed my instructions, these would already be gone as they would have been remove when you did step 12. ;)
     
  15. MikeS

    MikeS Private E-2

    sorry, didn't mean to be difficult :(

    when i try to remove cf.exe from my deskktop (combofix.exe renamed as in the instructions) with cf /u from the run box, I get an error message saying "Windows cannot find cf".
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What happens if you use cf.exe /u instead
     
  17. MikeS

    MikeS Private E-2

    I tried that too...didn't work.

    Meanwhile, 30 minutes after deleting the other backups and programs in your list, including ones I used before I found Major Geeks (deleted killbox backups, deleted SD Fix, deleted SmitFruad Fix, deleted MGtools and related) --- I now have a BackDoor-AWQ.b file found by McAfee, and Prockill found by AOL (I wasn't going to change anything, including the AOL settings, until we were done here). In looking, I now see a folder in C:\ called QooBox that I never noticed there before and has some of the infected files as well as CFscript files).

    In the process of reinstalling programs I need to do new scans and logs now...argggh. (BTW, I've checked several times, and all ports are closed, and no other machines on the network are infected).
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where? Was it in system volume information? What file did it point out?

    Not malware. It was used by ComboFix and or other programs.

    If ComboFix had uninstalled properly this would already be gone. ;) It is just where combofix stores backups.

    No you should not need to. You may not be detecting anything to worry about.


    Does the below work to uninstall ComboFix?

    C:\Documents and Settings\main\Desktop\cf.exe /u

    If not, is cf.exe still at the above location?
     
  19. MikeS

    MikeS Private E-2

    file was spool.exe - location was C:\Documents and Settings\Local Service\Local Settings\Application Data - and I don't see the file there (yes, hidden files are visible) - McAfee said not able to delete or quarantine.

    no, I had already tried that, too, still says can't find file :-(

    yes it is.

    I also had Spybot S&D running (started before you said probably not necessary to generate new logs) and it found a registry change in Microsoft.Windows.SecurityCenter.TaskManager - not sure if that matters or not but figured I'd mention it.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So McAfee says it is BackDoor-AWQ.b ??? Here is a link to the this trojan description on their own website. http://vil.nai.com/vil/content/v_100938.htm It does not mention anything to do with that file. However, that file still does not belong there. Let's see if it really is there. Download and install this: ExplorerXP

    It is very easy to use. It is similar to Windows Explorer but much better as far as showing what is really on your hard disk. Use ExplorerXP to navigate to the C:\Documents and Settings\Local Service\Local Settings\Application Data and see if it shows the spool.exe file. If so, see if you can delete it.




    Try renaming cf.exe back to combofix.exe
    Could you rename it? If so does the below work?

    C:\Documents and Settings\main\Desktop\combofix.exe /u
     
  21. MikeS

    MikeS Private E-2

    ExplorerXP doesn't show it either.

    Nope, same result. I also tried doing it with quotes around the location and it finds the program, but tries to run it, not delete it.

    I also had Spybot S&D running (I had started it before your post saying it's probably not necessary to generate new logs) and it found a registry change in Microsoft.Windows.SecurityCenter.TaskManager - not sure if that matters or not but figured I'd mention it.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then odds are that it is not there.


    Okay let's do it the easy way.;)

    • Click Start, Run and enter cmd and click OK to open a command prompt
    • Type cd Desktop at the command prompt and hit enter.
    • The prompt should change to show you are on at your Desktop folder now.
    • If still named combofix.exe, enter combofix /u at the prompt an hit enter.
    Any luck


    Changes to the regisry happen all the time for many valid reasons. It does not make it a problem. This is just a notification from Spybot.
     
  23. MikeS

    MikeS Private E-2

    OK.

    Done. I was going to try that earlier but was afraid to try it unless you told me to ;)

    OK, gotcha.

    Thanks again, hopefully this will be my final post before the one to say "thanks so much and hope I don't have to bother you again " ;)
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If McAfee finds anything after clearing our System Restore per my instructions, get their current update, and then boot into safe mode and run a fullscan and see if anything is found and removed.
     
  25. MikeS

    MikeS Private E-2

    Everything looks clear for the last day - think it's over and done with.
    Thanks so much for your help and patience, and I hope I don't have to bother you again :)
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds