Author Topic: AxFreePorn Disconnects me  (Read 64839 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: AxFreePorn Disconnects me
« Reply #30 on: March 18, 2007, 05:06:45 PM »
Hi FF I think a batch file would be preferable to save the chance of error

Something along the lines of

Delete

Quote
@Echo off
attrib -s -r -h "C:\Program Files\QuickTime\qttask.exe"
del /q "C:\Program Files\QuickTime\qttask.exe"
Move

Quote
@Echo off
move /y "C:\Program Files\QuickTime\bak\qttask.exe" "C:\Program Files\QuickTime"

Then for the registry something along the lines of

Quote
REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
DATA here from a comboscan log =-


mauserme

  • Guest
Re: AxFreePorn Disconnects me
« Reply #31 on: March 18, 2007, 05:12:18 PM »
Just out of curiosity, I notice a delete and move approach is usually used instead of copy and overwrite.  Is there and advantage to the former over the latter?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: AxFreePorn Disconnects me
« Reply #32 on: March 18, 2007, 05:21:08 PM »
Yes this method is used because the trojan protects itself which is why the first part is an attribute change : attrib -s -r -h followed by the deletion.  It makes it a bit tidier and a tad easier to write

mauserme

  • Guest
Re: AxFreePorn Disconnects me
« Reply #33 on: March 18, 2007, 06:43:07 PM »
Well, I was thinking something like

Quote
echo off
attrib -s -r -h C:\Program Files\QuickTime\qttask.exe
copy /y C:\Program Files\QuickTime\bak\qttask.exe  C:\Program Files\QuickTime\qttask.exe

But I suppose with this you would then want to delete the bak files to prevent any problems with future Find AWF scans.  The method you posted saves a step.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: AxFreePorn Disconnects me
« Reply #34 on: March 18, 2007, 06:47:13 PM »
Correct, in a way I just like things nice and tidy, but the bak folders will still need to be deleted.  I think the number of steps will still be the same but this way you delete the bad files in one go and then move the good ones back in one go.  Personal preference really I suppose  8)

Matty

  • Guest
Re: AxFreePorn Disconnects me
« Reply #35 on: March 18, 2007, 11:18:56 PM »
I removed Norton and quarentied rvklnlg.exe in A-squared.  I have Adaware Se Personal and will give the log from that.  There is a regedit in Windows and scanned the file at virustotal and jotti and most said no virus found and 1 said no threat detected.  I looked in Windows\System32\ for the folder RACLE~1 but i cant find it - C:\WINDOWS\System32\RACLE~1\regedit.exe .  Also can you give me steps to turn off system restore and boot in safe mode and scan with those programs.  Comodo is picking up rlvknlg.exe when Im on the computer and says it could be trojan/spyware/virus activity.  The cryptographic signature of the parent application rlvknlg.exe has changed too.  This case is too suspicious it says.  I denied it.   
« Last Edit: March 18, 2007, 11:24:40 PM by Matty »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: AxFreePorn Disconnects me
« Reply #36 on: March 18, 2007, 11:26:35 PM »
I would hold of on deleting system restore, as at the end of the day a bad restore is better than none.

Reboot into safe mode.

Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

If you wish I can investigate via a comboscan log  after you have done your scans

Download ComboScan to your Desktop.
  • Close all applications and windows.
  • Double-click on comboscan.exe to run it, and follow the prompts.
  • The scan may take a minute. When the scan is complete, a text file will open - ComboScan.txt
Extra Note: When running Comboscan, some firewalls may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so. Also, it may happen that your Antivirus flags Comboscan as suspicious. Please allow the Comboscan to run and don't let your Antivirus delete it. (In this case, it may be better to temporary disable your Antivirus)

Post the Comboscan.txt from the Comboscan into your next reply.

EDIT I have just looked at your previous log and I see you have purity as well.  So possibly the initial way to go would be to use combofix

Quote
O4 - HKCU\..\Run: [Jthl] "C:\Program Files\Common Files\??crosoft.NET\w?nlogon.exe" 99001122

The choice is yours of course as to which route to go but I would recommend combofix after the safe mode scans

Download ComboFix from [COLOR="Red"]Here[/COLOR][/URL] or [color="Red"]Here[/color][/url] to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
[COLOR="Blue"]Note: Do not mouseclick combofix's window while its running. That may cause it to stall[/COLOR]
« Last Edit: March 18, 2007, 11:32:48 PM by essexboy »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: AxFreePorn Disconnects me
« Reply #37 on: March 18, 2007, 11:30:35 PM »
Download ComboScan to your Desktop.
    Does ComboScan does a full scan or just to this particular infection?[/list]
    The best things in life are free.

    Offline essexboy

    • Malware removal instructor
    • Avast Überevangelist
    • Probably Bot
    • *****
    • Posts: 40589
    • Dragons by Sasha
      • Malware fixes
    Re: AxFreePorn Disconnects me
    « Reply #38 on: March 18, 2007, 11:35:15 PM »
    Sorry tech I have just edited my previous.  But comboscan does a one week and 3 month check on created files, a registry dump of the start up files and locations, plus dumps of other registry areas.  It has no specific target and is an analysis tool

    Offline essexboy

    • Malware removal instructor
    • Avast Überevangelist
    • Probably Bot
    • *****
    • Posts: 40589
    • Dragons by Sasha
      • Malware fixes
    Re: AxFreePorn Disconnects me
    « Reply #39 on: March 18, 2007, 11:41:05 PM »
    One for matty if you use combo fix it will remove the infected files.  So you will need to replace the bak files to their correct location , so in this cas maybe just the comboscan initially

    mauserme

    • Guest
    Re: AxFreePorn Disconnects me
    « Reply #40 on: March 19, 2007, 12:01:12 AM »
    @ Tech

    Quote
    What ComboScan will do:
    create a new System Restore point in Windows XP and Vista.
    clean your Temporary Files, Downloaded Program Files, and Internet Cache
    Files, and also empty the Recycle Bin on all drives.
    check some important areas of your system and produce a report for your
    analyst to review. ComboScan automatically runs HijackThis for you, but it
    will also install and place a shortcut to HijackThis on your desktop if you
    do not already have HijackThis installed.

    @ essexboy

    ComboScan does seem like the logical next step imo.


    @ Matty

    Does rlvknlg.exe still try to connect now?

    There is a regedit in Windows and scanned the file at virustotal and jotti and most said no virus found and 1 said no threat detected.

    That should be the clean file.  Its the one hjt showed in C:\WINDOWS\System32\RACLE~1\regedit.exe that I'm suspicious of.
    « Last Edit: March 19, 2007, 12:20:10 AM by mauserme »

    Offline polonus

    • Avast Überevangelist
    • Probably Bot
    • *****
    • Posts: 33892
    • malware fighter
    Re: AxFreePorn Disconnects me
    « Reply #41 on: March 19, 2007, 12:07:28 AM »
    Hi,

    So appropriate is comboscan followed by combofix?

    polonus
    Cybersecurity is more of an attitude than anything else. Avast Evangelists.

    Use NoScript, a limited user account and a virtual machine and be safe(r)!

    Matty

    • Guest
    Re: AxFreePorn Disconnects me
    « Reply #42 on: March 19, 2007, 01:08:02 AM »
    rlvknlg.exe came up on comodo and wanted to access the internet before. I attached comboscan and adaware results.  I snooped around in some other folders and in Windows\Prefetch theres files like

    ABC123GIAYA.EXE-010CD601.pf
    ABC123SDW7A.EXE-3899B8B3.pf
    ABC123SOKSA.EXE-0AC5E66E.pf
    ABC123CN5IA.EXE-046A4C05.pf
    RLVKNLG.EXE-1C0D1DED.pf

    and a bunch of other RUNDLL32.EXE-........ and other.exe files.  Is this where they are?
    « Last Edit: March 19, 2007, 01:11:36 AM by Matty »

    mauserme

    • Guest
    Re: AxFreePorn Disconnects me
    « Reply #43 on: March 19, 2007, 03:42:15 AM »
    The prefetch files are there to help Windows load programs faster.  Ironically this sometimes includes loading malware faster.  But I don't think its possible to execute a program from a true prefetch file.

    Just to confirm, though, does everything in that folder end with a .pf extension?

    Its interesting (informative?) that the ABC123xxxxx file name changes. 


    Matty

    • Guest
    Re: AxFreePorn Disconnects me
    « Reply #44 on: March 19, 2007, 04:20:38 AM »
    All of them in there end in .pf except for Layout.ini