Some Malware problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by Burning_Monkey, Nov 14, 2006.

  1. Burning_Monkey

    Burning_Monkey MajorGeek

    I was having a bunch of malware problems with a machine. I followed the Readme and here is the logs that were produced. Seems that every thing is cleaned up but I would like an expert to take a look and see.
     

    Attached Files:

  2. Burning_Monkey

    Burning_Monkey MajorGeek

    Here is the second round of log files that are requested in the Readme. If there is anything else that I need to do, or if there was something that I didn't do right, please let me know and I will correct that issue as fast as humanly possible.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [Cckfdglf] C:\Program Files\Qkun\Axinq.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Qkun <--- the whole folder

    Now run Ccleaner.
    Now reboot in normal mode

    Now attach a new HJT.


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. Burning_Monkey

    Burning_Monkey MajorGeek

    Every thing seems to be running fine now. Earlier I was having issues with having to kill explorer.exe and restart it, but those issues seem to have been resolved.

    I uninstalled CounterSpy since the constant warning messages confused the actual user of this computer. Figured with as old as this machine is also, I didn't need yet one more thing running in the background to slow things down even more. But CounterSpy does do a very good job.

    As you requested, I have attached a new HijackThis log.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have some issues!

    Please run this procedure: WareOut Removal and attach the requested log afterwards.


    Then run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: (no name) - 3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.62 85.255.112.233
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.62 85.255.112.233
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.62 85.255.112.233

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode
    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT
    Make sure you tell me how things are working now!
     
  6. Burning_Monkey

    Burning_Monkey MajorGeek

    The WareOut readme said to attach the log file from it and you also specified a new ShowNew log file to be generated so I have attached both those and the new HijackThis log file as well.

    The only thing remarkable that happened with this run of cleaning was that after 3 tries, I still couldn't get HJT to remove the R3 searchhook that you specified needed to be removed. I tried to remove it as administrator, but it didn't show up when I ran HJT as admin. I am at a loss as to what to do there. The other 3 entries where fixed on the first try though and every thing seems to be running a lot better than it was when I started this process.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. Burning_Monkey

    Burning_Monkey MajorGeek

    I have attached the requested log files as well as the log file generated from FxNetOpt.

    While I was running HJT I tried to remove that search hook again, but it still refuses to be removed. Other than that every thing went very well and there are no new issues to report.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure that you have shutdown ALL browsers before trying to fix it??? Also shutdown Symantec! You also have not done the Reset of Web Settings exactly as requested. If you did, www.majorgeeks.com would show as your home page. If you don't do this, we cannot see that you are actually doing the Reset.
     
  10. Burning_Monkey

    Burning_Monkey MajorGeek

    This time all Symantec processes where shut down from the services menu and I shut down the Antivirus also. Ran all three items again and got the same results as before with the R3 search hook. The only thing that was in operation that I know of was the individual program that I was using. I had nothing else open at the time. Any programatic problems would be from something running in the background or the like.

    Also MajorGeeks.com will not allow me to upload the log file from FxNetOpt, probably because it is the exact same results.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try this! Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now Download the Registry Search Tool

    Unzip to your Desktop and double click on regsrch.vbs
    (if you have script protection in your antuvirus program, please allow this to run)

    In the dialog that opens enter the following:

    CFBFAE00-17A6-11D0-99CB-00C04FD64497

    Press 'OK'

    The search will run for a while then alert you when it is finished. Press 'OK' and copy the contents of the WordPad window and attach it to this thread.
     
  12. Burning_Monkey

    Burning_Monkey MajorGeek

    Here is the requested log file from the search. I added the registry entry that you requested also.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's run another registry patch.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop (yes overwrite the previous file). Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Not repeat the procedure in message number 11 with Registry Search Tool and attach the new log.
     
  14. Burning_Monkey

    Burning_Monkey MajorGeek

    Sorry about the lag time in my repy, I was on vacation and my coworker couldn't do this for me.

    Here is the requested log file.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now attach a new HJT log.

    How are things running at this time?
     
  16. Burning_Monkey

    Burning_Monkey MajorGeek

    Here is the requested HJT log file.

    Every thing seems to be running real good here. Way better than before.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's great!

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  18. Burning_Monkey

    Burning_Monkey MajorGeek

    Well thank you very much for a job well done.

    As usual the help was excellent.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds