Viruses, Worms, and Vulneralbilites

Discussion in 'Malware Help (A Specialist Will Reply)' started by a2a, May 15, 2007.

  1. a2a

    a2a Private E-2

    Hello and Thank You all for being here...

    Well it seems to have taken 5 days to be able to get this far...Well the first three were trying to find Microsoft updates that could help. But why would there be, with Vista out why would they want XP to work? So I hope I did everything correctly according to the read first page..
     

    Attached Files:

  2. a2a

    a2a Private E-2

    The rest...CC Cleaner which I ran first doesnt seem to have created a log, nor could I find one from Panda Scan....Hope I wasnt supposed to...Peeking around in text files I did seem to notice alot of .ini text files...and strange notes from NT user, which would just say too dirty with weird characters in it... Any suggestions?
     

    Attached Files:

  3. a2a

    a2a Private E-2

    well noticed this nasty bugger [Anti-Virus Update Scheduler] C:\ir87l.exe...any cleaners that will take care of it????
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We did not ask for one from it and don't need one.

    Yes the READ ME tells you in step 6 to create this log. We need it. Also you need to run BitDedender and attach that log as requested in step 6 just before running Panda.

    Also you must go back and run AVG Antispyware. You Ignore everything it found. There is no sense in running the scans unless you fix what they find. Run it again and Quarantine or Delete what it finds. Attach a new log.

    Also do the below:
    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Mozilla Firefox (1.5)
    Mozilla Firefox (1.5.0.10)

    Make sure you reboot after uninstalling the above!

    Then install the current version of FireFox from: Mozilla Firefox


    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\windows\system32\taskmg32.exe
    C:\Program Files\BearShare\BearShare.exe
    C:\ir87l.exe

    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.
    After reboot locate the below folder and delete if found:
    C:\Program Files\BearShare

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
    Last edited: May 15, 2007
  5. a2a

    a2a Private E-2

    Well I am not sure if I have made any progress here. I ran into a few difficulties with a few of the processes that were listed. First, the the uninstaller would start and then it would get error 1316, so eventually I had to service first then it would allow the uninstall. Then AVG anti spyware, as I now recall the other night also having difficulties would not run without changing my computer to 16 bit color, and this is even after removing it and re-installing it. So once again I did not run this. I did however run the scanner on the AVG anti-virus and it did remove a trojan horse dropper agent...?? Then did bitdefender in safe mode after rebooting, it ran and did not find anything. However after rebooting and doing the panda scan, the program would not start, and when initially trying to delete temp files I was not allowed, said needed admin. So I just moved forward to the next step. Copy and pasted registry. THen on to the kill box, which went well until the instructions stated to paste ALL in the kill box which I was thinking meant at once which it would not do, strangely enough it would not paste into killbox, however just out of curiosity it would paste into an open notepad, but with the C removed it worked, however one line at a time. And I did not get this request. PendingFileRenameOperations And I was unable to locate C:\Program Files\BearShare...Did the CCleaner.. and following are the two files I do have for you... I did go look for the panda scan and bdscan files and I am at a loss locating them... And actually out of curiosity I did re run the panda scan as it just finished and it did not save a file again, I am not sure what it is I am doing wrong but I can tell you in the past week it has been about all I have been doing, running scans on this machine.. So I am curious if I have made any progress because while searching I am still noticing desktop.ini files all over and also little notes from ntuser????
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you install AVG7.5 Antivirus??? You did not have it installed before and I did not ask you to do this. You are now in direct violation of step 3 of the READ ME since you already had Avast installed. You must uninstall one of these immediately. Installing another antivirus while one is already installed can cause all kinds of problems. You should never do this!! In addition, I just noticed that you have Windows One Care Live installed. This also contains an antivirus which means you actually have three installed! Do you have a subscription to Windows One Care that you keep up to date? If so, you also need to uninstall Avast. If not, you need to uninstall Windows One Care.

    This is not a malware problem. Nor is it a problem with AVG Antispyware. Sounds like you have problems with your Windows setup or drivers.

    Does your account have administrator priviledges?


    They don't exist unless you create them as explained in the READ ME. If they don't find anything, there is nothing to create.

    As I stated above, it does not save anything. You have to save the log yourself per the directions in the READ ME.

    Unless you are finding desktop.ini files in every folder on your PC , they could just be normal. W32.FUJACKS type infections could cause excessive and infected desktop.ini_ files on your PC but I would expect Avast (and AVG7.5 that you just ran) to find that if it existed. It could be confusing you since you never saw them before until enabling viewing of hidden and system files per step 2 of the READ ME. I have no idea what you mean by "little notes from ntuser" . Exactly what are you talking about.


    You did not attach the new HijackThis log I requested.

    Your other logs appear to be clean! Are you having any malware problems?
     
  7. a2a

    a2a Private E-2

    The HiJackThis Log

    ntuser note pads are like this
    regf  Òmû˜Ç    p  C : \ D O C U M E ~ 1 \ A D M I N I ~ 1 \ N T U S E R . D A T ,œÈrDIRTÿ

    and this

    regf" " ÂQî°ˆ}Ç      d s e t t i n g s \ a l l u s e r s \ n t u s e r . d a t Backdoor:Win32/Rbot Backdoor:Win32/Rbot Backdoor:Win32/Rbot Backdoor:Win32/Rbot Backdoor:Win32/Rbot Backdoor:Win32/Rbot ^Y=×DIRTÿðçá\ D e v i c e \ H a r d d i s k V o l u m e 1 \ D o c u m e n t s a n d S e t t i n g s \ A l l U s e r s \ n t u s e r . d a t a t
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ntuser.dat files are not Notepads!!! They are files! They are the registry information for each user on your PC and they are required. Or are you referring to some other files? Give more specific and exact file names and include paths. ntuser note pads does not mean anything to me.

    You did not answer my two questions:
    And also:

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: (no name) - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - (no file)
    O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - (no file)
    O4 - Startup: .lnk = ?
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} -

    After clicking Fix, exit HJT.

    Now reboot in normal mode

    Now attach a new HJT log.
     
  9. a2a

    a2a Private E-2

    I know you didnt tell me to but you will notice I did download a new firewall as that is what led me to believe I had malware, that and after having my system change, my computer not loading updates,and my config being changed, files sharing wouldnt work, and after leaving my computer run all day noticing the remote desktop in the recently used program. And TrendMicro's Housecall said I had about 12 different variants of worms and 16 vulnerabilities. And that is what led me to this site only after using Black widows instructions on recomended setting and deleting all MS Office programs, and loading the antivirus programs and malware removers. Hence the multitudes of programs I had on my computer. When I was first infected I was using Avast but that wouldnt update hence the others. A-squared HiJack Free led me to believe I had a virus called Anti Virus Update, and that was what was keeping avast from updating. I am still getting programs that are trying to write to drive but avast is now blocking them. Should svchost.exe be writing to C drive on startup? Because I have been blocking it. So I thought I had malware, I cant say I know. Beside I think AgoBot was malware and that was in my initial log. Let me ask you, do you think I have malware?

    And to answer your questions, Yes I am Admin on my computer.

    And to be truly honest I dont know if its malware, I did think I had been hacked, but I dont know what to believe. Besides, I am thinking I should have just respun my box at the very beginning of this entire ordeal.

    Thanks for all your help Chas Lang, I dont know how you do it, helping everyone that comes here. I know that after the last ten days, I myself after working 65 hours a week and coming home trying to fox this computer, am exhausted. So once again, I dont know how you do it
     

    Attached Files:

  10. a2a

    a2a Private E-2

    And I did get this message after running HijackThis:
    Unexpected error ocurred!
    Erroe #52(Bad file name or number) in Sub GetLongPath(?.exe).
    Please send a report to merijn@spyware.com, mentioning what you were doing and what version of Windows you have.

    Who is merijn?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The last HijackThis log you just attached was from 10/9/2006. Please attach a current HijackThis log that was just obtained! Make sure it is installed and renamed properly as requested in step 7 of the READ ME or I will jsut be asking you to install it properly and attach another new log.

    Where are your getting this ntuser.dat.log file that you attached? Where was it located on your PC?

    Merijn is the person who wrote the HijackThis program. Don't worry about sending the info to him. This is a well known/documented bug that just happens sometimes.


    Is PeoplePC something you use? Is this related to your ISP? It is considered adware.
     
  12. a2a

    a2a Private E-2

    The Hijack this program was downloaded last fall when I had problems then, it is renamed as per instructions. The ntuser.logs are in docs&settings all users, there is also a suspicious looking one in all users that now seems to be used by something and will not allow access. And no peoplepc is no longer my isp.
    There was a net1.1 framework hotfix that seemed new that I installed this morning. I still cannot get updates and I am hoping it is not due to the fact I made changes over a week ago according to Black Widow, I think that is what his/her name was.. But with the msconfig not accepting any changes, it did help with my programs as far as my startup is concerned. I only hope I did not cover anything up.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't care when it was downloaded. I was just telling you that the last log you attached was not a current log.

    Also you have not renamed it as requested! Nor did you install it where we requested.

    You have:

    C:\HijackThis.exe

    and it should be:

    C:\Program Files\HJT\analyse.exe

    However the log you posted, shows no malware. So based on this and previous steps we have done, you are clean!

    Okay I just wanted to be sure of that. They are part of the user's registry as I mentioned earlier. Each user account name will have ntuser.dat and ntuser.dat.log. Leave these alone or you will make your PC unusable for each user account the you touch these in.

    Then uninstall all software related to them and then fix any leftover items from PeoplePC that you see in your HJT log.

    You probably mean BlackViper and this has nothing to do with malware and is not a topic for this forum.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds