also @ TechSpot: Tea Party Republicans and 'liberal weenies' alike celebrate Texas email privacy law

Malware disabling mcafee, redirecting internet searches and other symptoms

Discussion in 'Virus and Malware Removal' started by funkduck, Aug 4, 2011.

  1. funkduck Newcomer, in training Posts: 36

    File name:
    RapportMgmtService.exe

    Submission date:
    2011-08-12 00:57:50 (UTC)

    Current status:
    finished




    Result:
    36/ 43 (83.7%)


    VT Community

    not reviewed
    Safety score: -



    Compact

    Print results




    Antivirus

    Version

    Last Update

    Result



    AhnLab-V3

    2011.08.11.01

    2011.08.11

    Win-Trojan/Patched.DD



    AntiVir

    7.11.13.26

    2011.08.11

    W32/PatchLoad.A



    Antiy-AVL

    2.0.3.7

    2011.08.11

    -



    Avast

    4.8.1351.0

    2011.08.11

    Win32:patched-WQ [Trj]



    Avast5

    5.0.677.0

    2011.08.11

    Win32:patched-WQ [Trj]



    AVG

    10.0.0.1190

    2011.08.11

    Win32/Katusha.A



    BitDefender

    7.2

    2011.08.11

    Trojan.Patched.HE



    CAT-QuickHeal

    11.00

    2011.08.11

    W32.Patchload.O



    ClamAV

    0.97.0.0

    2011.08.12

    Trojan.Patched-167



    Commtouch

    5.3.2.6

    2011.08.11

    W32/Patched.G



    Comodo

    9712

    2011.08.12

    TrojWare.Win32.Patched.HN



    DrWeb

    5.0.2.03300

    2011.08.12

    Trojan.Starter.1695



    Emsisoft

    5.1.0.8

    2011.08.12

    Trojan-Spy.Win32.Zbot!IK



    eSafe

    7.0.17.0

    2011.08.10

    -



    eTrust-Vet

    36.1.8497

    2011.08.11

    Win32/Patchload.U



    F-Prot

    4.6.2.117

    2011.08.11

    W32/Patched.G



    F-Secure

    9.0.16440.0

    2011.08.12

    Trojan.Patched.HE



    Fortinet

    4.2.257.0

    2011.08.12

    -



    GData

    22

    2011.08.11

    Trojan.Patched.HE



    Ikarus

    T3.1.1.107.0

    2011.08.12

    Trojan-Spy.Win32.Zbot



    Jiangmin

    13.0.900

    2011.08.11

    TrojanSpy.Zbot.adxr



    K7AntiVirus

    9.109.5003

    2011.08.10

    Trojan



    Kaspersky

    9.0.0.837

    2011.08.12

    Trojan.Win32.Patched.mf



    McAfee

    5.400.0.1158

    2011.08.12

    W32/Katusha



    McAfee-GW-Edition

    2010.1D

    2011.08.12

    W32/Katusha



    Microsoft

    1.7104

    2011.08.11

    Virus:Win32/Patchload.O



    NOD32

    6370

    2011.08.12

    Win32/Patched.HN



    Norman

    6.07.10

    2011.08.11

    W32/Patched.BH



    nProtect

    2011-08-11.01

    2011.08.11

    -



    Panda

    10.0.3.5

    2011.08.11

    W32/Katusha.BN



    PCTools

    8.0.0.5

    2011.08.12

    Trojan.Paccyn



    Prevx

    3.0

    2011.08.12

    -



    Rising

    23.70.03.03

    2011.08.11

    Win32.Loader.li



    Sophos

    4.67.0

    2011.08.12

    W32/Patched-AK



    SUPERAntiSpyware

    4.40.0.1006

    2011.08.12

    -



    Symantec

    20111.2.0.82

    2011.08.12

    Trojan.Paccyn!inf



    TheHacker

    6.7.0.1.276

    2011.08.11

    -



    TrendMicro

    9.500.0.1008

    2011.08.11

    PTCH_KATUSHA.W



    TrendMicro-HouseCall

    9.500.0.1008

    2011.08.12

    PTCH_KATUSHA.W



    VBA32

    3.12.16.4

    2011.08.10

    Trojan-Spy.Zbot.gen



    VIPRE

    10143

    2011.08.12

    Virus.Win32.Agent.mpq (v)



    ViRobot

    2011.8.11.4617

    2011.08.11

    Win32.Patched.BE



    VirusBuster

    14.0.164.0

    2011.08.11

    Win32.Katusha.Gen





    Additional information

    Show all



    MD5 : 1ac0335744ee811c8494443ce1bbe7f2



    SHA1 : 5cec7e24351a1baef64bb33e9a4e48a6b91fb276



    SHA256: 6f65280dd321700473211fac74356ade83941a4408a0aa066086935c7341befd
  2. Broni Malware Annihilator Posts: 40,051   +187

    Go ahead with TFC and Eset.
  3. funkduck Newcomer, in training Posts: 36

    TFC Done.
    ESET running. 56% done and 6 threats found so far.
  4. funkduck Newcomer, in training Posts: 36

    C:\Program Files\Bonjour\mDNSResponder.exe Win32/Patched.HN trojan
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe Win32/Patched.HN trojan
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe Win32/Patched.HN trojan
    C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe Win32/Patched.HN trojan
    C:\Program Files\thinkbroadband.com\tbbMeter\tbbMeter.exe Win32/Patched.HN trojan
    C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe Win32/Patched.HN trojan
    C:\Qoobox\Quarantine\C\Windows\System32\c_18145.nl_.vir probably a variant of Win32/Rootkit.KHEBOKS trojan
    C:\Windows\System32\c_18145.nl_ probably a variant of Win32/Rootkit.KHEBOKS trojan
  5. Broni Malware Annihilator Posts: 40,051   +187

    Were those files removed, or they're still there?

    Did you reinstall McAfee?
  6. funkduck Newcomer, in training Posts: 36

    Files are still there. Do I need to check "Remove files" and redo the scan ?

    McAfee is reinstalled.
     
  7. Broni Malware Annihilator Posts: 40,051   +187

    Yes.
  8. funkduck Newcomer, in training Posts: 36

    C:\Program Files\Bonjour\mDNSResponder.exe Win32/Patched.HN trojan cleaned - quarantined
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe Win32/Patched.HN trojan cleaned - quarantined
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe Win32/Patched.HN trojan cleaned - quarantined
    C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe Win32/Patched.HN trojan cleaned - quarantined
    C:\Program Files\thinkbroadband.com\tbbMeter\tbbMeter.exe Win32/Patched.HN trojan cleaned - quarantined
    C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe Win32/Patched.HN trojan error while cleaning
    C:\Qoobox\Quarantine\C\Windows\System32\c_18145.nl_.vir probably a variant of Win32/Rootkit.KHEBOKS trojan cleaned by deleting - quarantined
    C:\Windows\System32\c_18145.nl_ probably a variant of Win32/Rootkit.KHEBOKS trojan cleaned by deleting - quarantined
  9. Broni Malware Annihilator Posts: 40,051   +187

    How is computer doing?
  10. funkduck Newcomer, in training Posts: 36

    Mcafee is persistently complaining about this still.

    C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe

    And restarting as it suggests does not fix the problem.

    How do I get rid of this ?

    Attached Files:

  11. Broni Malware Annihilator Posts: 40,051   +187

    Uninstall Rapport.

    Let me know if McAfee will still complain.
  12. funkduck Newcomer, in training Posts: 36

    Uninstalled Rapport. Mcafee is not complaining anymore.
  13. Broni Malware Annihilator Posts: 40,051   +187

    Your computer is clean [IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. (Windows XP only) Run defrag at your convenience.

    11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    12. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    13. Please, let me know, how your computer is doing.
  14. funkduck Newcomer, in training Posts: 36

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Alex
    ->Temp folder emptied: 3298990 bytes
    ->Temporary Internet Files folder emptied: 17820089 bytes
    ->Java cache emptied: 0 bytes
    ->Google Chrome cache emptied: 7380045 bytes
    ->Apple Safari cache emptied: 0 bytes
    ->Flash cache emptied: 761 bytes

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 97127 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 27.00 mb


    [EMPTYFLASH]

    User: Alex
    ->Flash cache emptied: 0 bytes

    User: All Users

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: Public

    Total Flash Files Cleaned = 0.00 mb



    OTL by OldTimer - Version 3.2.26.1 log created on 08122011_224305

    Files\Folders moved on Reboot...
    C:\Users\Alex\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GLTWVSJJ\partner[1].htm moved successfully.
    C:\Users\Alex\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTPSK1RP\ads[3].htm moved successfully.
    C:\Users\Alex\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTPSK1RP\bizo_multi[1].htm moved successfully.
    C:\Users\Alex\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FTPSK1RP\partners[7].htm moved successfully.
    C:\Users\Alex\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\A64C6H1S\sh49[1].htm moved successfully.
    C:\Users\Alex\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6K9I1458\ads[2].htm moved successfully.
    C:\Users\Alex\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6K9I1458\topic168838-3[1].htm moved successfully.
    C:\Users\Alex\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
    C:\Users\Alex\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.
    C:\Windows\temp\952ba960-743a-4847-9689-d6d9a726a04e\CliSecureRT.dll moved successfully.

    Registry entries deleted on Reboot...
  15. funkduck Newcomer, in training Posts: 36

    Just deleting the tools off the desktop.

    Having problems with this one- see attachment

    Attached Files:

  16. Broni Malware Annihilator Posts: 40,051   +187

    Download BlitzBlank and save it to your desktop.
    Double click on Blitzblank.exe

    • Click OK at the warning.
    • Click the Script tab and copy/paste the following text there:
    Code:
    DeleteFile: 
    C:\Users\Alex\Desktop\28sz8j2d.exe
    

    • Click Execute Now. Your computer will need to reboot in order to replace the files.
    • When done, post the report created by Blitzblank.
      You can find it in the root of the drive, normally C:\
  17. funkduck Newcomer, in training Posts: 36

    BlitzBlank 1.0.0.32

    File/Registry Modification Engine native application
    MoveFileOnReboot: sourceFile = "\??\c:\users\alex\desktop\28sz8j2d.exe", destinationFile = "(null)", replaceWithDummy = 0
  18. funkduck Newcomer, in training Posts: 36

    Oh dear, the FN keys arent working anymore.
    You know a fix for this?
  19. Broni Malware Annihilator Posts: 40,051   +187

    In this forum, we make sure, your computer is free of malware and your computer is clean :)
    Because the access to malware forum is very limited, your best option is to create new topic about your current issue, at Windows section.
    You'll get more attention.

    Good luck!
  20. funkduck Newcomer, in training Posts: 36

    OK thankyou very very much for your time and help :)