Win64/Patched.A

Discussion in 'Malware Help (A Specialist Will Reply)' started by MarkDelta, Nov 13, 2012.

  1. MarkDelta

    MarkDelta Private E-2

    Hi, seen a few people post about this and this website seems to be the one of only a few that can solve it. Please help! :confused
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=11...HP_ss&mntrId=62d770ed000000000000f8d111a1dd19
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.searchonme.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;127.0.0.1:9421;<local>
    R3 - URLSearchHook: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBit2.dll
    O2 - BHO: CrossriderApp0000435 - {11111111-1111-1111-1111-110011041135} - C:\Program Files (x86)\Premiumplay Codec-C\Premiumplay Codec-C.dll
    O2 - BHO: BitTorrentBar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBit2.dll.dll
    O3 - Toolbar: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBit2.dll
    O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (file missing)

    After clicking Fix, exit HJT.

    Now shutdown all browers and your protection program and then uninstall the below software:
    BabylonObjectInstaller
    BitTorrentBar Toolbar
    Java(TM) 6 Update 30
    Java(TM) 7 Update 4
    Premiumplay Codec-C

    Now install the current version of Sun Java from: Sun Java Runtime Environment


    Now rescan with HitmanPro
    • When it finds services.exe - Virus, allow it to Replace by clicking the down arrow next to the detection and choosing Replace.
    • Leave any other detections alone (Ignore them).
    • Afterwards, click the Next button.
    • HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.
    • After reboot and when you are back in Windows, run another scan with HitmanPro and then attach the latest hitmanpro.zip log See: HOW TO: Attach Items To Your Post.
    Then reboot your PC immediately if Hitman Pro has not already done so.


    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Windows\assembly\GAC_32\Desktop.ini
    C:\Windows\assembly\GAC_64\Desktop.ini
    C:\Windows\Installer\{77302282-2932-6e17-ce80-77bb6842d49a}\@
    C:\Windows\Installer\{77302282-2932-6e17-ce80-77bb6842d49a}\U\80000000.@
    C:\Windows\Installer\{77302282-2932-6e17-ce80-77bb6842d49a}\U\80000032.@
    C:\Windows\Installer\{77302282-2932-6e17-ce80-77bb6842d49a}\U\80000064.@
    C:\Windows\Installer\{77302282-2932-6e17-ce80-77bb6842d49a}\U
    C:\Windows\Installer\{77302282-2932-6e17-ce80-77bb6842d49a}
    C:\Program Files (x86)\Premiumplay Codec-C
    C:\Users\Mark\AppData\Local\Temp\1511610099916318.tmp
    C:\Users\Mark\AppData\Local\Temp\4153031819918471.tmp
    C:\Program Files (x86)\BitTorrentBar
    C:\Program Files (x86)\Yontoo
     
    :Reg
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}]
    [-HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110011041135}]
    [-HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440044044435}]
    [-HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550055045535}]
    [-HKEY_CLASSES_ROOT\CrossriderApp0000435.BHO.1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110011041135}]
    [-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110011041135}]
    [-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110011041135}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011041135}]
    [-HKEY_CURRENT_USER\CrossriderApp0000435.BHO]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the the new log from Hitman Pro log
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. MarkDelta

    MarkDelta Private E-2

    HJT worked fine, but then I couldn't uninstall BitTorrentBar Toolbar. The Uninstall button simply did nothing, I uninstalled BitTorrent in the hope that it would either take the Toolbar with it or allow me to uninstall it myself but it didn't work. BitTorrent was uninstalled but the Toolbar is still irremovable.

    I installed Sun Java and re-scanned with Hitman Pro, it found services.exe (with the labels 'WRP' and '932') but only found it "Suspicious". Should I still remove this?

    (Now that I think about it, I might have already removed services.exe - Virus in an earlier attempt to fix this problem which ultimately failed.)

    Also, might be worth noting that it found something called "xsherlock.xem" in the folder C:\Windows\SysWOW64\ and declared it suspicious, it's not a name I recognise but it's got the label 'Service' attached to it. Don't know if that's important.

    I ran OTM which worked until it got to the Reboot stage - it crashed so I closed it and rebooted manually, I'm not sure if this has affected the log.

    Worth noting, I know AVG can get temperamental sometimes so I've ignored the warnings it's given about Trojans being attached to OTM - but I thought you should know about it, it's detected a few.

    Sorry I didn't specify what the effects of this infection were on the first message, basically I'm getting random pop-ups in chrome (I don't need to click on anything or navigate to specific sites, it just happens randomly. Adblock just turns most of them into blank white pages.) Also when I search something on google, the links only ever take me to ebay, sometimes amazon but mostly random spam pages. Only once I've clicked a link and it's gone purple, can I click it again and actually go to the page requested. On top of this, AVG is popping up every 20-30 mins saying it's detected Win64/Patched.A and there's nothing it can do about it.

    Thanks again for your help, I really do appreciate it.

    P.S. I didn't save the log the first time I ran Hitman Pro because I wasn't sure of what to do with the suspicious files. I then got to the bottom of your message and was reminded to attach the log so I scanned again and have attached that log. So the Hitman log occurred AFTER I installed OTM. Sorry if this complicates things.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you did not remove it. If you did, your PC would not boot up. ;) We will fix this another way, but first we need to run another scan to collect more info. Then will make a new fix.

    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  5. MarkDelta

    MarkDelta Private E-2

    Alrighty...
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download this >> View attachment fixlist.txt


    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows can continue with the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. MarkDelta

    MarkDelta Private E-2

    Not sure if this is worth noting, might just be my shitty cheap keyboard playing up but, I had to reboot into System Recovery Options 3 or 4 times because my keyboard kept turning off at the point where I log in and have to type my password. It was as if it kept on being disconnected.

    I checked the connections and it was fine, but it kept happening at the same exact point. It worked eventually but I thought you should know as it was a little too coincidental for me to ignore it.

    As far as things are working now, the pop-ups haven't shown up in a while and Google links seem to be fine, thanks so much!

    Since doing this last fix I haven't seen AVG flag up Win64/Patched.A, but it hasn't been long. I'll let you know by the end of the day if it detects anything.

    Thanks again for your help, I would honestly be lost without quality sites like this and awesome people like you =]
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds