This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Suspicious .mph file

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Please don't run any more scans or delete anything until we get a proper diagnosis of what's on your machine.


Please do the following

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi and thank you for responding!! here are the 2 texts i got from DDS: [attachment removed] [attachment removed] GMer taking a long time scanning, so post later
Hi,

Please do the following:


Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Before I use Combofix, I'm just wondering what I should do if my computer if unable to reboot after it is finished, since Ive read somewhere that it is a possibility. And is it really needed to run combofix, because I really don't want to ruin my computer ! :wacko:
I can't guarantee that something unforeseen wont happen it's always a possibility, with many infections and tools - even antivirus applications can cause the computer to crash. Combo Fix is the only tool that has built in protection features it installs erunt backup it creates a system restore point and it installs the Recovery Console (just make certain you allow it to do so) If you follow the instructions exactly and disable all your security programs, you should be OK But it is up to you whether you wish to continue cleaning.

Hi,

Just for your consideration as to whether or not to continue cleaning, this is on your computer

http://www.sophos.com/security/analyses/vi…rojpuperru.html

which is a data harvesting Trojan.

You should probably change all your passwords for your online accounts and banking institutions and notify your Financial Institutions that your personal information may have been compromised.


Oh my gosh!

Alright ComboFix is being installed right away!
Hi!!! My ComboFix scan finally finished! [attachment removed] *crosses fingers and hopes for good news* also, i see the file C:\Qoobox\Quarantine\C\WINDOWS\system32\DP.sys.vir Is it safe to keep it there or will it be deleted once I remove ComboFix?
Hi,

Please do not touch the items in Qoobox, they are safe there and we will be cleaning that up once you are all clean.

Also you show two AntiVirus products, Avast and Norton, one needs to be uninstalled. Having more than one AV causes system slowdowns, conflicts and crashes.

Please do the following:


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:


Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Suspicious_mph_file_t108540.html

Collect::
c:\windows\system32\gfhkj.tmp

DirLook::
c:\documents and settings\Andy Yeung\Local Settings\Application Data\agrlic

RegLock::
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\Main\FeatureControl]
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.


NEXT


  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    c:\windows\{F755D7CE-5D61-4236-87EA-31C82A17C29F}.dat

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Please do the same for the following file:

c:\windows\system32\{F75690C1-16F3-4094-8F77-8A85AEDFBA44}.dat
Hello log from ComboFix: [attachment removed] and here is the result for c:\windows\{F755D7CE-5D61-4236-87EA-31C82A17C29F}.dat Scanner results Scanner results : Scanners did not find malware! Time : 2009/11/29 10:59:56 (PST) Scanner Engine Ver Sig Ver Sig Date Scan result Time a-squared 4.5.0.8 20091129080156 2009-11-29 - 8.971 AhnLab V3 2009.11.29.00 2009.11.29 2009-11-29 - 1.141 AntiVir 8.2.1.78 7.10.1.117 2009-11-27 - 0.297 Antiy 2.0.18 20091127.3320938 2009-11-27 - 0.119 Arcavir 2009 200911280020 2009-11-28 - 0.019 Authentium 5.1.1 200911271611 2009-11-27 - 1.201 AVAST! 4.7.4 091129-0 2009-11-29 - 0.002 AVG 8.5.288 270.14.87/2534 2009-11-29 - 0.595 BitDefender 7.81008.4663453 7.29205 2009-11-30 - 3.989 CA (VET) 35.1.0 7145 2009-11-26 - 13.171 ClamAV 0.95.2 10091 2009-11-28 - 0.004 Comodo 3.12 3081 2009-11-29 - 0.726 CP Secure 1.3.0.5 2009.11.28 2009-11-28 - 0.005 Dr.Web 4.44.0.9170 2009.11.29 2009-11-29 - 7.261 F-Prot 4.4.4.56 20091129 2009-11-29 - 1.276 F-Secure 7.02.73807 2009.11.29.03 2009-11-29 - 0.051 Fortinet 11.107- 11.107 2009-11-29 - 0.156 GData 19.9080/19.596 20091129 2009-11-29 - 8.191 Ikarus T3.1.01.74 2009.11.29.74615 2009-11-29 - 4.122 JiangMin 11.0.800 2009.11.27 2009-11-27 - 16.357 Kaspersky 5.5.10 2009.11.29 2009-11-29 - 0.023 KingSoft 2009.2.5.15 2009.11.29.15 2009-11-29 - 0.949 McAfee 5.3.00 5817 2009-11-29 - 3.350 Microsoft 1.5302 2009.11.29 2009-11-29 - 6.752 Norman 6.01.09 6.01.00 2009-11-27 - 4.006 nProtect 20091127.01 6396533 2009-11-27 - 3.818 Panda 9.05.01 2009.11.29 2009-11-29 - 1.789 Quick Heal 10.00 2009.11.28 2009-11-28 - 1.224 Rising 20.0 22.23.06.04 2009-11-29 - 6.853 Sophos 3.01.0 4.47 2009-11-30 - 3.120 Sunbelt 5518 5518 2009-11-18 - 2.261 Symantec 1.3.0.24 20091129.002 2009-11-29 - 0.176 The Hacker 6.5.0.2 v00081 2009-11-28 - 0.694 Trend Micro 9.000-1003 6.660.07 2009-11-29 - 0.021 VBA32 3.12.12.0 20091128.2038 2009-11-28 - 2.553 ViRobot 20091128 2009.11.28 2009-11-28 - 1.165 VirusBuster 4.5.11.10 10.114.4/2016264 2009-11-29 Here is the result for c:\windows\system32\{F75690C1-16F3-4094-8F77-8A85AEDFBA44}.dat Scanner results : Scanners did not find malware! Time : 2009/11/29 11:03:22 (PST) Scanner Engine Ver Sig Ver Sig Date Scan result Time a-squared 4.5.0.8 20091129080156 2009-11-29 - 3.969 AhnLab V3 2009.11.29.00 2009.11.29 2009-11-29 - 0.931 AntiVir 8.2.1.78 7.10.1.117 2009-11-27 - 0.409 Antiy 2.0.18 20091127.3320938 2009-11-27 - 0.118 Arcavir 2009 200911280020 2009-11-28 - 0.018 Authentium 5.1.1 200911271611 2009-11-27 - 1.198 AVAST! 4.7.4 091129-0 2009-11-29 - 0.002 AVG 8.5.288 270.14.87/2534 2009-11-29 - 0.298 BitDefender 7.81008.4663453 7.29205 2009-11-30 - 3.974 CA (VET) 35.1.0 7145 2009-11-26 - 7.114 ClamAV 0.95.2 10091 2009-11-28 - 0.004 Comodo 3.12 3081 2009-11-29 - 0.701 CP Secure 1.3.0.5 2009.11.28 2009-11-28 - 0.004 Dr.Web 4.44.0.9170 2009.11.29 2009-11-29 - 7.216 F-Prot 4.4.4.56 20091129 2009-11-29 - 1.197 F-Secure 7.02.73807 2009.11.29.03 2009-11-29 - 9.144 Fortinet 11.107- 11.107 2009-11-29 - 0.142 GData 19.9080/19.596 20091129 2009-11-29 - 5.610 Ikarus T3.1.01.74 2009.11.29.74615 2009-11-29 - 4.108 JiangMin 11.0.800 2009.11.27 2009-11-27 - 4.015 Kaspersky 5.5.10 2009.11.29 2009-11-29 - 0.024 KingSoft 2009.2.5.15 2009.11.29.15 2009-11-29 - 0.519 McAfee 5.3.00 5817 2009-11-29 - 3.304 Microsoft 1.5302 2009.11.29 2009-11-29 - 6.089 Norman 6.01.09 6.01.00 2009-11-27 - 4.006 nProtect 20091127.01 6396533 2009-11-27 - 3.617 Panda 9.05.01 2009.11.29 2009-11-29 - 1.977 Quick Heal 10.00 2009.11.28 2009-11-28 - 1.485 Rising 20.0 22.23.06.04 2009-11-29 - 0.316 Sophos 3.01.0 4.47 2009-11-30 - 3.084 Sunbelt 5518 5518 2009-11-18 - 1.682 Symantec 1.3.0.24 20091129.002 2009-11-29 - 0.247 The Hacker 6.5.0.2 v00081 2009-11-28 - 0.693 Trend Micro 9.000-1003 6.660.08 2009-11-30 - 0.021 VBA32 3.12.12.0 20091128.2038 2009-11-28 - 2.154 ViRobot 20091128 2009.11.28 2009-11-28 - 0.410 VirusBuster 4.5.11.10 10.114.4/2016264 2009-11-29 - 2.381 ■Heuristic/Suspicious ■Exact Note: This file has been scanned before. Therefore, this file's scan result will not be stored in the database. :unsure:
Hi,

please do the following:


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.




NEXT


Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI