Author Topic: Archives popping up?  (Read 3806 times)

0 Members and 1 Guest are viewing this topic.

milkflowers

  • Guest
Archives popping up?
« on: February 11, 2006, 01:44:56 AM »
So I should have known better. File-sharing was never safe and I shouldn't have gone where I did, but it's happened and now I'm paying the price.

According to Avast!, Ewido, and TrendMicro's HouseCall my computer is clean, but I'm still getting a load of random archives (all .rar, some labelled as american movies, foreign movies, porn, or music files) cropping up in my c:/documents and settings/user/complete folder. I've gone in three times now and deleted them - first time there were 20, second time there were over eighty and this last time there was one hundred and eight.

Again, I ran all three scans (and used the Avast! Virus Cleaner just to be safe) and all tell me I'm clean. I ran Hijack This and had the log analyzed over at http://hijackthis.de/index.php, and everything came back as safe... so why am I still getting these archives?!

my avast! log states:
2/10/2006 4:26:59 PM   SYSTEM   776   Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\Documents and Settings\Sparrow\Local Settings\Temporary Internet Files\Content.IE5\4LNY4PBH\inst_0004[1].exe" file. 
2/10/2006 4:27:30 PM   SYSTEM   776   Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\inst_0004.exe" file. 
2/10/2006 4:28:37 PM   SYSTEM   776   Sign of "Win32:Trojan-gen. {UPX!}" has been found in "C:\Documents and Settings\Sparrow\Local Settings\Temporary Internet Files\Content.IE5\4LNY4PBH\drdata[1].avi" file. 
2/10/2006 4:28:37 PM   SYSTEM   776   Sign of "Win32:Trojan-gen. {UPX!}" has been found in "C:\Program Files\Common Files\InetGet\mc-110-12-0000140.exe" file. 
2/10/2006 4:28:37 PM   SYSTEM   776   Sign of "Win32:Trojan-gen. {UPX!}" has been found in "C:\Program Files\Common Files\InetGet\mc-110-12-0000140.exe" file. 
2/10/2006 4:29:24 PM   SYSTEM   776   Sign of "Win32:Trojano-2873 [Trj]" has been found in "C:\Documents and Settings\Sparrow\Local Settings\Temporary Internet Files\Content.IE5\Z2EG808G\MTE3NDI6ODoxNg[1].exe" file. 
2/10/2006 4:29:24 PM   SYSTEM   776   Sign of "Win32:Trojano-2873 [Trj]" has been found in "C:\MTE3NDI6ODoxNg.exe" file. 
2/10/2006 4:29:24 PM   SYSTEM   776   Sign of "Win32:Trojano-2873 [Trj]" has been found in "C:\MTE3NDI6ODoxNg.exe" file. 
2/10/2006 4:33:46 PM   Sparrow   2744   Sign of "Win32:Trojan-gen. {UPX!}" has been found in "C:\Documents and Settings\Sparrow\Local Settings\Temporary Internet Files\Content.IE5\4LNY4PBH\drdata[1].avi" file. 
2/10/2006 4:34:06 PM   Sparrow   2744   Sign of "Win32:Trojano-2873 [Trj]" has been found in "C:\Documents and Settings\Sparrow\Local Settings\Temporary Internet Files\Content.IE5\Z2EG808G\MTE3NDI6ODoxNg[1].exe" file. 
2/10/2006 4:41:00 PM   Sparrow   2744   Sign of "Win32:Trojano-2873 [Trj]" has been found in "C:\MTE3NDI6ODoxNg.exe" file. 
2/10/2006 4:43:50 PM   Sparrow   2744   Sign of "Win32:Trojan-gen. {UPX!}" has been found in "C:\Program Files\Common Files\InetGet\mc-110-12-0000140.exe" file. 
2/10/2006 5:27:20 PM   Sparrow   560   Sign of "Win32:Trojan-gen. {UPX!}" has been found in "C:\Documents and Settings\Sparrow\Local Settings\Temporary Internet Files\Content.IE5\4LNY4PBH\drdata[1].avi" file. 
2/10/2006 5:27:24 PM   Sparrow   560   Sign of "Win32:Trojan-gen. {UPX!}" has been found in "C:\Program Files\Common Files\InetGet\mc-110-12-0000137.exe" file. 
2/10/2006 5:28:07 PM   Sparrow   560   Sign of "Win32:Adware-gen. [Adw]" has been found in "C:\Documents and Settings\Sparrow\Local Settings\Temporary Internet Files\Content.IE5\QRQTQPUH\freeprodtb[2].exe" file. 
2/10/2006 5:28:13 PM   Sparrow   560   Sign of "Win32:Adware-gen. [Adw]" has been found in "C:\Documents and Settings\Sparrow\Desktop\freeprodtb.exe" file. 

I moved everything to the chest, deleted/cleaned what I could on my own/with TrendMicro, ran avast! again and got no alerts at all....

I'm attaching my HijackThis log because I don't know exactly if these posts will hold that much :\

CharleyO

  • Guest
Re: Archives popping up?
« Reply #1 on: February 11, 2006, 02:41:14 AM »
***

Welcome to the forums, milkflowers!    :)

I can see that your computer has freeprodtb.exe which, I believe, is adware/spyware.

Please read below for more info:

http://www.softwaretipsandtricks.com/dangerous_files/2927-freeprodtbexe.html

http://www.greatis.com/appdata/d/f/freeprodtb.exe_Removal.htm

Inetget.exe is a little different in that it is most likely adware/spyware/malware but it can be a good file according to this Google search:

http://www.google.com/search?q=InetGet&rls=com.microsoft:en-US&ie=UTF-8&oe=UTF-8&startIndex=&startPage=1

You attached a HJT log but I did not download it. Perhaps someone more knowledgable in analyzing HJT will soon post a reply for you.


***

milkflowers

  • Guest
Re: Archives popping up?
« Reply #2 on: February 11, 2006, 02:42:42 AM »
Thanks for the welcome, CharleyO.

I'll check out the links - thanks for the help!

doc_esb

  • Guest
Re: Archives popping up?
« Reply #3 on: February 11, 2006, 06:34:56 AM »
Hello milkfolwers.  I have reviewed your HijackThis log and have a suggested handling.
You will probably want to print out these instructions or copy them to Notepad as most of the handling will be done in Safe Mode and you will not have internet access from there.

First, open up ewido anti-malware and do the update function.  Then close ewido.

Next, download CleanUp! from here.  Save it to your desktop.  Don't run it yet.

Now, open up HijackThis again and click on "Do a system scan only".
When it finishes, put a check before the following lines:


O4 - HKLM\..\Run: [winlog] winlog.exe

O4 - HKLM\..\Run: [winsysupd] C:\windows\winsysupd7.exe

O4 - HKLM\..\RunServices: [winlog] winlog.exe


Now, close ALL windows except HijackThis and hit the "Fix checked" button.


Now let's set Windows to show all files:

To enable the viewing of Hidden files follow these steps:

   1. Close all programs so that you are at your desktop.
   2. Double-click on the "My Computer" icon.
   3. Select the "Tools" menu and click "Folder Options".
   4. After the new window appears select the "View" tab.
   5. Put a checkmark in the checkbox labeled "Display the contents of system folders".
   6. Under the Hidden files and folders section select the radio button labeled "Show hidden files and folders".
   7. Remove the checkmark from the checkbox labeled "Hide file extensions for known file types".
   8. Remove the checkmark from the checkbox labeled "Hide protected operating system files".
   9. Press the "Apply" button and then the "OK" button and shutdown My Computer.
  10. Now your computer is configured to show all hidden files.

Because XP will not always show you hidden files and folders by default,
Go to Start > Search and under "More advanced search options".
Make sure there is a check by "Search System Folders" and "Search hidden files and folders" and "Search system subfolders"


Now reboot into Safe Mode.  (If you're not sure how to do this, click this link):
http://www.bleepingcomputer.com/tutorials/tutorial61.html

Next, using Window's explorer and/or search function, navigate to and delete the files listed in bold below if they are found to exist.  Delete ONLY the part in bold.

C:\windows\winsysupd7.exe

winlog.exe



Now run ewido anti-malware:

Click on "Scanner"
Click on "Complete System Scan" and the scan will begin.
While the scan is in progress you will be prompted to clean files, click OK
Select "none" as the action. Check "Perform action with all infections".
Once the scan has completed, there will be a button located on the bottom of the screen named Save report - click it.
Save the report.txt file to your desktop.

Now close ewido anti-malware.

Warning: While the scan is in progress, DO NOT open any folders or the Windows Control Panel !!


Now run the CleanUp! program that you downloaded:
Double-click on the icon.
Hit the "CleanUp!" button.
When the report window indicates that it has finished, hit the "Close" button.  It's that simple.

Reboot into Normal Mode, run HijackThis again, and paste the new HijackThis log and the ewido log back to this thread.  (You may have to split in into two or more posts if the log is real long.)


doc_esb
« Last Edit: February 11, 2006, 06:37:18 AM by doc_esb »

galooma

  • Guest
Re: Archives popping up?
« Reply #4 on: February 11, 2006, 11:06:12 AM »
hi and welcome milkflowers,
when your`e  out the other side of this trouble it would be worth your while loading a 3rd party firewall like kerio http://www.sunbelt-software.com/Kerio.cfm and perhaps spywareblaster,http://www.javacoolsoftware.com/
these will drastically improve your chances of staying clean
good luck  :)