This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

XP Antivirus malware & cannot run malwarbytes & hijack this

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The computer is ok. Looks like the problems from this morning are gone (blaster.worm). Still have the "in page" advertisements like click here you are the 100,000 visitor. Here's the MBAM log Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6187 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 3/27/2011 4:39:52 PM mbam-log-2011-03-27 (16-39-52).txt Scan type: Quick scan Objects scanned: 178806 Time elapsed: 8 minute(s), 47 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\A9YA3MI1CF (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi mikeinsurprise,

Good, we have one more scan to do but first curiousity has gotten the better of me.

We will use Virustotal Please submit this file for analysis.


copy and paste the following into the upload a file box (it may look like there are 2 file paths but it is one complete path)

C:\_OTL\MovedFiles\03262011_075959\C_WINDOWS\SYSTEM32\webcheckz.dll



scroll down a bit and click "send file", wait for the results and post them in your next reply.

Please note that sometimes the scans take a few minutes. Please ensure that the scan has completed and the results are complete .


Next

Please open OTL.

  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, click the None button near the top (it may looked greyed out)
  • In the window under Custom Scans/Fixes copy and paste the following



    C:\DOCUMENTS AND SETTINGS\MIKE UNSER\LOCAL SETTINGS\APPLICATION DATA\{AA1F7949-20DE-494A-9C69-8373D168BCBA}\*.* /s
    /md5start
    fw20.vxd.*
    /md5stop


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt. Please post this log.


Next

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. or C:\Program Files\ESET\log.txtWe will need this later.
Please post back with the ESET log.


Please post back with
  • VirusTotal results
  • OTL.txt
  • ESET log
You can post all the logs at once if you wish.

Thanks
here's the logs:

Virus Total
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name: webcheckz.dll
Submission date: 2011-03-28 00:37:54 (UTC)
Current status: queued queued analysing finished


Result: 8/ 43 (18.6%)
VT Community

not reviewed
Safety score: -
Compact Print results Antivirus Version Last Update Result
AhnLab-V3 2011.03.27.01 2011.03.27 -
AntiVir 7.11.5.87 2011.03.27 -
Antiy-AVL 2.0.3.7 2011.03.27 -
Avast 4.8.1351.0 2011.03.27 Win32:MalOb-EI
Avast5 5.0.677.0 2011.03.27 Win32:MalOb-EI
AVG 10.0.0.1190 2011.03.27 -
BitDefender 7.2 2011.03.28 Gen:Variant.Vundo.5
CAT-QuickHeal 11.00 2011.03.27 -
ClamAV 0.96.4.0 2011.03.28 -
Commtouch 5.2.11.5 2011.03.24 -
Comodo 8130 2011.03.28 -
DrWeb 5.0.2.03300 2011.03.28 -
Emsisoft 5.1.0.4 2011.03.27 Gen.Variant.Vundo!IK
eSafe 7.0.17.0 2011.03.27 -
eTrust-Vet 36.1.8236 2011.03.25 -
F-Prot 4.6.2.117 2011.03.27 -
F-Secure 9.0.16440.0 2011.03.23 Gen:Variant.Vundo.5
Fortinet 4.2.254.0 2011.03.27 -
GData 21 2011.03.28 Gen:Variant.Vundo.5
Ikarus T3.1.1.97.0 2011.03.27 Gen.Variant.Vundo
Jiangmin 13.0.900 2011.03.27 -
K7AntiVirus 9.94.4219 2011.03.26 -
Kaspersky 7.0.0.125 2011.03.28 -
McAfee 5.400.0.1158 2011.03.28 -
McAfee-GW-Edition 2010.1C 2011.03.27 -
Microsoft 1.6702 2011.03.27 -
NOD32 5990 2011.03.27 -
Norman 6.07.03 2011.03.27 -
nProtect 2011-02-10.01 2011.02.15 -
Panda 10.0.3.5 2011.03.27 -
PCTools 7.0.3.5 2011.03.26 -
Prevx 3.0 2011.03.28 Medium Risk Malware
Rising 23.50.05.05 2011.03.26 -
Sophos 4.64.0 2011.03.27 -
SUPERAntiSpyware 4.40.0.1006 2011.03.27 -
Symantec 20101.3.0.103 2011.03.28 -
TheHacker 6.7.0.1.159 2011.03.27 -
TrendMicro 9.200.0.1012 2011.03.27 -
TrendMicro-HouseCall 9.200.0.1012 2011.03.28 -
VBA32 3.12.14.3 2011.03.25 -
VIPRE 8841 2011.03.28 -
ViRobot 2011.3.26.4378 2011.03.27 -
VirusBuster 13.6.272.0 2011.03.27 -
Additional informationShow all
MD5 : c82bea0a0e327664f15e71ceb559dd24
SHA1 : 6bbe59384081c8abcdae7cb69681cc01ac92ea8a
SHA256: 0d08251c8c89de4abf0a1b30fd6e896c68ebdbe75571c786b2f5d8c5b298ae58
ssdeep: 3072:rZMb0TILwV2aovra7GzoVNm/0KUgwXYL:MvLPZra7GzoMUgwI
File size : 108544 bytes
First seen: 2011-03-28 00:37:54
Last seen : 2011-03-28 00:37:54
TrID:
Windows OCX File (68.1%)
Win32 Executable MS Visual C++ (generic) (20.7%)
Win32 Executable Generic (4.7%)
Win32 Dynamic Link Library (generic) (4.1%)
Generic Win/DOS Executable (1.1%)
sigcheck:
publisher….: Ijdhualae Vskxgafuqrg
copyright….: © Qhvypjqio Snbmzturhrl. All rights reserved.
product……: Caurjqrfw_ Ctxezes_ Zrhwagbqv Tavnxv
description..: Fdhygjgcm Fax Server COM Client Interface
original name: FXSCOM.DLL
internal name: FXSCOM.DLL
file version.: 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned

PEiD: Armadillo v1.xx - v2.xx
PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x5A1A
timedatestamp….: 0x479FC541 (Wed Jan 30 00:30:57 2008)
machinetype……: 0x14c (I386)

[[ 5 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0x7AAE, 0x7C00, 6.67, c591d351d566d566bfc106986e7fd579
.rdata, 0x9000, 0xAE2, 0xC00, 5.06, 81138579f79795a57ec0d2fa3dde6c85
.data, 0xA000, 0x13BA4, 0xB000, 4.61, 09d0190dd8a2096f06661c02d1350734
.rsrc, 0x1E000, 0x6018, 0x6200, 4.61, e83efcd5232c41677d98321e05786149
.reloc, 0x25000, 0x8E4, 0xA00, 5.50, 438cf587bdce070550ed2ca617637d84

[[ 5 import(s) ]]
KERNEL32.dll: UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetCurrentThreadId, InterlockedExchange, GetModuleHandleW, FreeLibrary, Sleep, SetUnhandledExceptionFilter, LoadLibraryW, GetProcAddress, GlobalFree, DisableThreadLibraryCalls, GetStringTypeA, LCMapStringW, LCMapStringA, GlobalAlloc, InterlockedCompareExchange, VirtualProtect, GetSystemDirectoryW, GetCommandLineA, MultiByteToWideChar, LoadLibraryA, GetOEMCP, GetACP, GetCPInfo, WriteFile, GetEnvironmentStringsW, GetStringTypeW, HeapAlloc, HeapFree, RtlUnwind, GetVersion, GetModuleHandleA, GetModuleFileNameA, GetEnvironmentVariableA, GetVersionExA, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, HeapReAlloc, ExitProcess, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStrings
USER32.dll: LoadStringW, MessageBoxW
ADVAPI32.dll: RegCreateKeyExW, RegCloseKey, RegQueryValueExW, RegSetValueExW
ole32.dll: CoCreateInstance, CLSIDFromString
RPCRT4.dll: NdrDllGetClassObject, NdrCStdStubBuffer_Release, NdrDllRegisterProxy, NdrClientCall2

Prevx Info:
http://info.prevx.com/aboutprogramtext.asp…5C071003DA175A3
ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 32768
CompanyName: Ijdhualae Vskxgafuqrg
EntryPoint: 0x5a1a
FileDescription: Fdhygjgcm Fax Server COM Client Interface
FileFlagsMask: 0x003f
FileOS: Windows NT 32-bit
FileSize: 106 kB
FileSubtype: 0
FileType: Win32 DLL
FileVersion: 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)
FileVersionNumber: 5.2.3790.1830
ImageVersion: 6.0
InitializedDataSize: 118784
InternalName: FXSCOM.DLL
LanguageCode: English (U.S.)
LegalCopyright: Qhvypjqio Snbmzturhrl. All rights reserved.
LinkerVersion: 8.0
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 4.0
ObjectFileType: Dynamic link library
OriginalFilename: FXSCOM.DLL
PEType: PE32
ProductName: Caurjqrfw Ctxezes Zrhwagbqv Tavnxv
ProductVersion: 5.2.3790.1830
ProductVersionNumber: 5.2.3790.1830
Subsystem: Windows GUI
SubsystemVersion: 4.0
TimeStamp: 2008:01:30 01:30:57+01:00
UninitializedDataSize: 0

Symantec reputation:Suspicious.Insight


VT Community

0
This file has never been reviewed by any VT Community member. Be the first one to comment on it!


OTL.txt Log

OTL logfile created on: 3/27/2011 5:41:07 PM - Run 4
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Mike Unser\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

766.00 Mb Total Physical Memory | 321.00 Mb Available Physical Memory | 42.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 62.00% Paging File free
Paging file location(s): C:\pagefile.sys 1147 1147 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.73 Gb Total Space | 65.04 Gb Free Space | 58.21% Space Free | Partition Type: NTFS

Computer Name: OFFICE | User Name: Mike Unser | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Custom Scans ==========


< C:\DOCUMENTS AND SETTINGS\MIKE UNSER\LOCAL SETTINGS\APPLICATION DATA\{AA1F7949-20DE-494A-9C69-8373D168BCBA}\*.* /s >


< MD5 for: FW20.VXD >
[2003/02/05 04:02:00 | 000,079,947 | —- | M] () MD5=FDCCFCB07A5EF1B4DA039834B07E5FE7 – C:\WINDOWS\fw20.vxd

< >

< >

< End of report >

ESET Log

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6425
# api_version=3.0.2
# EOSSerial=8117c217123277409a330497201ad220
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-03-28 02:16:25
# local_time=2011-03-27 07:16:25 (-0700, US Mountain Standard Time)
# country="United States"
# lang=9
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 66199798 66199798 0 0
# compatibility_mode=5121 16777189 100 75 8487722 14267007 0 0
# compatibility_mode=8192 67108863 100 0 22321545 22321545 0 0
# scanned=152955
# found=4
# cleaned=0
# scan_time=4745
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001070.dll a variant of Win32/Cimag.GK trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0003268.exe a variant of Win32/Kryptik.LWD trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0003269.exe a variant of Win32/Kryptik.LWD trojan (unable to clean) 00000000000000000000000000000000 I
C:\_OTL\MovedFiles\03272011_141251\C_Documents and Settings\Mike Unser\Application Data\defender.exe a variant of Win32/Kryptik.LZH trojan (unable to clean) 00000000000000000000000000000000 I
Oldman 960– P.S. Gotta go back to work tomorrow, so just a heads up I will only be able to view your responses and respond in the evenings when I get home. Thanks again!
Hi mikeinsurprise,

The ESET detections are in old System Restore Points. These will be removed when the tools are removed.

If you can give me a link to your homepage I'll see if I can see what you are seeing there. There may be something on their site as you should see the same thing on other sites if it was coming from your computer.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • mbr.dat
  • the copy of OTL that was renamed iexplore.exe
  • aswMBR.exe

Next

Click the Start button, click Run. [Vista users, go Start>"Start search"] Copy and paste the following line into the run box and click OK
Combofix /uninstall


Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

I suggest you keep MBAM. Keep it updated and use it regularly.

ESET online scan can be removed via add/remove programs.


You can install your java and Windows updates now.


Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. You pretty much have them all, depending on which version of AdAware you have you may have a resident antispyware program.


You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis


- Make sure you have reset Automatic Updates to your chosen optionClick your start button > Control Panel > System


- Keep your antivirus program updated, as well as any other security programs you have.


-More tips and programs can be found HERE


- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879


Please post back if you have any problems with these steps.
Oldman960—

Ok, went back and did the following:

From mt desktop deleted

•any notepads/logs that we created
•mbr.dat
•the copy of OTL that was renamed iexplore.exe
•aswMBR.exe

Ran ComboFix uninstall

Went to Add/Remove programs and removed ESET. Also removed numerous other programs that haven't been used since 2004 - 2006.

Went to two websites.

My Homepage

http://ww2.cox.com/myconnection/arizona/home.cox

on the right hand side there is a clicksor block and thats where the ads pop up.

Also went to

http://www.azcentral.com/
and then started getting the same security center "virus" as last time. I closed IE, updated MBAM and ran it. It found two rogues and deleted them. See attached log:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6199

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

3/28/2011 7:34:26 PM
mbam-log-2011-03-28 (19-34-26).txt

Scan type: Quick scan
Objects scanned: 180513
Time elapsed: 12 minute(s), 57 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\documents and settings\mike unser\local settings\temp\0.5179777360968735.exe (Rogue.Installer) -> Quarantined and deleted successfully.
c:\documents and settings\mike unser\local settings\temp\jar_cache738318891892120501.tmp (Rogue.Installer) -> Quarantined and deleted successfully.

I then updated JAVA and updated it. Checked for Window's updates and there were none.

Went to IE options verified that all the security was set like you requested.

Went to IE and deleted history, temp files and cookies.

Also installed Spywareblaster and reinstalled adAdware.

Computer seems to be running good at this time.

If everything looks good in the log and you don't need me to do anything I will say thank you so very much for all the help you provided. It is greatly appreciated!
Hi mikeinsurprise,

Sorry I didn't post sooner but I wanted to check those pages on a different computer to see if those ads would show up. On mine it showed a March Madness ad and a Truck Month ad. I checked them about 60 minutes after you first posted and I saw no problem. Since they now display correctly for you it's possible that the legitament link had been compromised and was corrected between the time you posted and I checked them.

One of the MBAM detections was a temporary file and the other in some old java.Here's a link to a very good temporary file cleaner, yours to keep and use regularly.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

I think you are good to go.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI