what is wefed.biz

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kernow, Dec 16, 2004.

  1. kernow

    kernow Private E-2

    hi everyone hope some of you may be able to help
    problem: abouut 5 weeks ago i had to disconnect my modem and disable my ethernet adapter to troubleshoot a problem i then opened IE and a window opened stating "you or a program is trying to connect to the internet :wefed.biz" when i reconnected to the internet i looked it up and found it was related to the bagz32 worm family i ran specific bagz detection software and various anti virus and spyware programs although i have always had both norton firewall and anti_vir on my computer nothing was detected except the regular cookies by adaware i also ran hijack this but nothing unusual was in the results either
    After setting norton to detect the wefed.biz connections and monitiring them through norton firewall i decided to block the connection in either direction on all ports thats when my real problems have started. All automatic security updates for anti virus, norton, windows , kerio ,adaware, spybot, spywareblaster,and avg have stopped working and unable to detect the internet connection however all browser functions work as normal and i can manually download all the updates apart from windows which is nearly totally automated
    i am getting approx 125 attempts per hour to connect to wefed.biz all blocked i then tried to connect to the website and immediately got hit with a dropper worm when i permitted connections again if i allow connection to wefed.biz i now get regular virus attempts and what seems to be remotely started viruses which appear to run over the internetmostly of the bot variants, popup ads for patchnow.exe, xpfix.com and my computer gets a remote call to shut down via "lsa.shell"
    all updated virus removal software doesnt find any virus at all and spyware programs have not discovered any trojans just the occassional cookies hijack this also shows nothing
    so can any one help me in finding what wefed.biz is about and where it would be located in the file system theres nothing in the registry either and hkeyLM run parameters dont have anything unusual in them gong to give it a week or 2 before formatting network drives and starting again
     
  2. kernow

    kernow Private E-2

    does anyone know if there is new variants of the bagz worm or is anyone else having problems with popups and system shutdowns where they cannot stay connected to the internet and problems with updates
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you download stuff? If so you should please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    Also consider running the items in the section titles: Alternative Scans - If still having problems

    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    You may want to take a look at this too:
    http://secunia.com/virus_information/13095/bagz.f/
     
  4. kernow

    kernow Private E-2

    hi chaslang i had already tried about 85% of what was in your post but i have now tried it all and updated the stuff i had which is a pain because it wont autodownload
    anyway after taking the 4 or so hrs to run it all back to back it came up with 14 data miner cookies and 3 alexa registry entries which was detected by the updated adaware absolutely no other virus was found on my system as i have run all of these things in the last 5 weeks and yes superhidden folders were on view and services were stopped
    but on reboot the blocked connection attempts to wefed.biz are still there
    the site you gave me for info was ok but the computer associates website gives a lot more detail
    incidentally if i didnt have this domain or site manually blocked i wouldnt even know it was there on my computer it appears to redirect all security updates through the site
    any way where do i post the hijack this log for inspection iv already confirmed the nameserver is my isp which is cableinet
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You follow the guidelines a gave you below for posting a HijackThis log and attach it to your message in this thread.
     
  6. kernow

    kernow Private E-2

    here is the hijack this logfile hope you c something in that i have missed
    p.s.
    i have win xp booting from d drive with windows1 as sysroot to stop default entry syware
    c: drive boots win98
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your OS and IE versions are seriously out of date. You must get updated to at least WinXP SP1a. Some of your problems may be occuring due to the fact that you are so out of date.

    Problems:
    1) You must only run one software firewall. You need to choose which one you want and uninstall the other
    2) You mus only run one full blown virus application. Pick which one you want to keep and uninstall the other.
    3) Messenger Plus! 3 contains malware - including LOP. Uninstall it!
    4) You MUST NOT have any browsers running anytime you use HijackThis unless we specifically ask for it to be run that way. You had D:\Program Files\Internet Explorer\iexplore.exe running. Shut down your browser run the scan and save the log. Then come back and post. This is even more important when Fixing items with HJT.
    5) You are missing a required windows file. See the below line in you log:
    O23 - Service: Application Layer Gateway Service - Unknown - D:\WINDOWS1\System32\alg.exe (file missing)
    You need to locate this file on either your XP CD or look for it in your c:\i386 or D:\windows1\i386 directory and copy it back to your system32 folder.
    6) Have HJT fix the below line from MSN toolbar. The file is missing anyway:
    O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)

    After doing all the above post a new log and tell me how things are working.
     
  8. kernow

    kernow Private E-2

    one of my main problems is auto downloading security updates which is fine for anti vir programs but how do you save the windows updates to disk then execute them if i disable the block to wefed.biz then a remote call that lsa.shell is shutting down then my computer shuts down via ntauthority so running is ok but certain downloads crash my system
    but any way i fdisked and reformatted an old harddisk i had and installed win 98 then updated to 98se and installed norton firewall but being in a silly mood i connected it to the network to upload avg, spybot, hijack this and adaware from this comp so on startup when i blocked wefed.biz it was already on that comp too as was pong.ug66.biz both showing in the firewall though none of the other sites related to bagz showed up (i default blocked all the sites related to it) so whatever it is migrates through networks, anyway the connection attempt to wefed.biz only happens if i log on to win98 via client for ms networks if i cancel the logon and let windows boot in to the default user it does not try to connect until i start Iexplore as soon as rnaapp is started then wefed and pong shows in the firewall when i ran a search for rnaapp it showed a file called ".~~C" at this point i had not connected to the internet and a rnaapp.hlp file 19.6kb which only said "this file is not meant for browsing" the .~~C file could not be opened or scanned as it was reported as didnt exist, babylonia worm checks showed nothing
    at this point i installed the modem for direct connection but when i tried to connect the modem dialled and connected but iexplorer refused to display any web page so i permitted the wefed.biz access and the first thing i was hit with was cookies from "atdmt.com" one named as the computer name colin@atdmt.com the first cookies i blocked through firewall but 5 came through anyway pong.ugg66.biz was still blocked but no farther attempts were made to connect to that site
    after this my computer connected to msn.com and acted normally letting me in to all sites and auto updates worked fine there has been no remote shutdowns and it has not slowed down but connection to wefed.biz is definitely still there
    so is it possible that wefed.biz is goverment spyware or am i just sounding silly at this point or is it connected to atdmt.com
    anyway here is the hijack this file from that comp i am going to reformat the drive again and install win98 with no connection to the network this time and see what happens if reformatting is the only cure until some anti vir company releases definitions for it just dont like losing all comp data this way
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You current HJT log is clean. The only problem is that again, you need to get the required MS Updates.

    You should also take a look at this. It has a wefed.biz reference in it.
    http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=40571

    Also this:
    http://securityresponse.symantec.com/avcenter/venc/data/w32.bagz.d@mm.html

    You need to run all the steps of the READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal . Possible the online virus scanners or Alternative Scan section will help.
     
  10. kernow

    kernow Private E-2

    i have read all the posts for removal of bagz and manually checked the registry for them i also know that wefed.biz is based in canada and the ipp address for it is 205.209.184.222 the webpage for pong.biz is forbidden and i reckon the ug66 is a subdomain of pong .biz that is based in sweden pong.biz has an ip address of 193.0.253.26 (i have done a little research in to it)also know that bagz stops web access by modifying the hosts file but my host file and lmhost file is empty iv even tried selecting all to make sure it isnt modified with white fonts against the white background and like i said if i enable wefed.biz or permit it access on all ports then i can autodownload there are several posts that are showing symtoms of what is happening to my network how about trying to block wefed.biz on some firewalls to see if it just my computer or if it is a larger problem after all new viruses and spyware have to be discovered somehow
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you mean by this?

    The viruses are already discovered as far as I can tell. You just don't seem to be finding the cause of the infection on your network. You need to be looking on all computers and user accounts. You just said you fdisk and formatted an old hard disk and got the problem again when connected to the network. That would indicate you have infected computers in you network or what ever you normally do (like email accounts etc) are giving you the problem right back again. Before connecting to the network to you have all you protection in place including the firewall.

    Have you run these:
    avast! Virus Cleaner Tool
    McAfee AVERT Stinger
    a-squared (a²) Free edition
    RAVantivirus Online scan
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds