Trojan-Downlaoder.Bat.Ftp.r

Discussion in 'Malware Help (A Specialist Will Reply)' started by eg man, Mar 6, 2009.

  1. eg man

    eg man Private E-2

    Antivir found virus crypt.xpack.gen and i soon discovered that if came back right after i deleted it. Kaspersky found 2 viruses

    I have been fighting net-worm.win32.kido.ih for 3 days and am not sure what success i have had. I have used combofix a few times,many anti malware and antivirus programs.

    Kaspersky scan and gone from 2 viruses to 1. The net-worm.win32.kido.ih is gone but the trojan-downloader.bat.ftp.r is in file name C:windows\system32.cmd.ftp seems to still be infecting my computer accoding to Kaspersky. Malwarebytes, AVG, antivir and others do not find the trojan downloader on my system.

    combofix says that i am running antivir even after i have removed programs.

    I have downloaded the patch from mircosoft ms08-067

    Yesterday I did everything in the Read ME Run me First.

    What to do next to see if i am malware free.

    So appreciate any help
    Eric

    I could not figure out where malwarebytes log was, so here it is.

    Malwarebytes' Anti-Malware 1.34
    Database version: 1822
    Windows 5.1.2600 Service Pack 2

    3/5/2009 10:33:08 PM
    mbam-log-2009-03-05 (22-33-08).txt

    Scan type: Quick Scan
    Objects scanned: 74352
    Time elapsed: 12 minute(s), 19 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 1 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://www.sidestep.com/get/k00719/sb02a.cab

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. eg man

    eg man Private E-2

    First, Thank You, Thank You

    Computer seems to be running great. This is my personal computer and I use it for work, so I really want it virus malware free.

    Many of these computer fixes were new to me and many I still don't understand. So thanks for walking me through the steps.

    I did not realize that i should not have a lot of files on my Desktop. I have cleaned it up.

    Combofix still says that i am running antivir with it deactivated. A few days ago Combofix said I was running Antivir even after i had removed program. The Combofix popup box looks like this.

    Combofix has detected the following real time scanner to be active:

    AntiVir PersonalEdition Classic Virus Protection
    AntiVir PersonalEdition Classic Virus Protection
    AntiVir PersonalEdition Classic Virus Protection
    AntiVir PersonalEdition Classic Virus Protection
    AntiVir PersonalEdition Classic Virus Protection

    I screwed up and was in select mode at start up. I am now in normal startup.

    I could use some help figuring out what and how to delete the start up menu. Also any help on malware prevention.

    I appreciate all the help.
    Eric
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the new MGlogs.zip file that I requested before we can continue. Make sure you are in normal startup mode before getting this log. Your combofix log showed you were using MSconfig.

    I'm not sure what you are referring too?
     
    Last edited: Mar 12, 2009
  5. eg man

    eg man Private E-2

    I thought I had attached MGlogs.zip to my last message, sorry. I just tried to attach MGlogs, but it said it was already attached to this message. What do i need to do.

    Sorry, i need to proof read better. I meant, I could use some help figuring out what to delete in the start up menu and how to delete it.

    I appreciate all the help. Thanks again.
    Eric
     
  6. eg man

    eg man Private E-2

    I figured this attachment out, Sorry again. I am usually not this stupid.

    I have learn a lot. Thanks

    Eric
     

    Attached Files:

  7. eg man

    eg man Private E-2

    Last night my computer started to run very slow. It was on all day and i used it much of the day, internet , excel, and a java based application.

    When I turned my computer off it took a long time, then a box appeared that said shutting down file, I could not read it fast enough, but it that had a .exe extension. I turned the machine back on and then shut it down, but did not see the same box again.

    Antivir showed nothing.

    Help, what should i do..

    Thanks so much for volunteering your time.
    Eric
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean, but I suggest you do the below.


    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\Eric\Local Settings\temp


    Also to address some of the slowness issues you can do the below, but please realize that these are not malware issues. It is just software that you are running at startup that are not necessary. But also note that you could really benefit from doubling your memory to have 1 GB. You only have 512 MB right now which is really not adequate anymore. If you update to Win XP SP3 you may even see more of a slow down. And if you don't update to SP3, you are going to have outstanding security holes.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

    After clicking Fix, exit HJT.

    Now reboot your PC.

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the new C:\MGlogs.zip file
    Make sure you tell me how things are working now!
     
  9. eg man

    eg man Private E-2

    Again, thanks so much, I am thankful for your time and help.

    Computer seems to be working just fine.

    Can I use HJT to fix - 04 - global startup\efax messenger plus\dllcmd32.exe
    I never use this and deleted efax a while ago.

    Any thoughts on why would combofix say that I am running Antivir after i delete it?

    Thanks again.

    Eric
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome.

    Yes.

    You have not uninstalled Avira. It is installed and running according to the log you just attached. And if you uninstall it, you will not have an antivirus program installed.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  11. eg man

    eg man Private E-2

    I completed everything on the list up to uninstalling hijackThis. From the control panel, i click on Change/Remove an received an Uninstaller Error:

    An error occurred while trying to remove HihackThis 2.0.2. It may have already been uninstalled. Would you like to remove HijackThis 2.0.2 from the Add or Remove programs list?

    I clicked no.

    C:MGTools is still there and so is analyse HijackThis in the the MGTools folder.

    What should I do now.

    Thanks again,
    Eric
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Yes! And then finish the rest of the instructions. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds