A few lingering baddies I can't get rid of

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by thealu, Jul 5, 2006.

  1. thealu

    thealu Private E-2

    I am trying to salvage my nephew's computer. It was overrun with trojans and spyware etc. He was not running any sort of antivirus or other security at all (something I'm obviously going to rectify for him when this is all done). Following instructions here and running many many additional scans and rerunning nearly everything several times both in safe modes and in standard mode, I have managed to get things under control. But I need help finishing this project off as I can't seem to get it entirely infection free.

    I cannot run Bitdefender because XP has not yet been updated to XP2 (something I will obviously do before giving the computer back). I am attaching the most recent Panda scan, CounterSpy scan, and HJT log.

    I tried using the tutorial and tackling the HJT log myself, but there were several things I couldn't find any info on at all, so decided to turn things over to you good folks from here.

    Any help is appreciated. Thanks in advance.

    thealu
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please run this: Qoologic Removal Procedure and then attach a new HJT log.

    Also tell me how things are working afterwards.
     
  3. thealu

    thealu Private E-2

    I was away for a couple of days...thanks so much for your help Chaslang.

    I ran Qoologic and it came up clean.

    A few things still going on:

    1) I had CounterSpy running in the background and it alerted me with this:

    A program trying to enable itself to start up when Windows loads has been detected:

    C:/WINDOWS/System32/Userinit.exe

    I told it to block the action as I wasn't sure what it was.

    Then I ran a Counterspy Scan which came up clean.

    2) I installed AVG last week but it has not been loading when Windows starts up, so I uninstalled and reinstalled and ran a new scan and it came up with this:

    Trojan horse Generic WHC, C:/System Volume Information/_restore (B37680B2-BA0A-4E5D-BF30-83E44C588624)?RP951/AO150770.exe

    which it deleted.

    3) An A-Squared scan came up clean (except for a cookie).

    4) A new Panda scan still has the same results as the last scan. Can you help me delete these? (I ran this in regular bootup mode, NOT in safe mode)

    5) I have attached a new HJT log.

    Thanks again Chaslang. I really appreciate your help.

    thealu
     

    Attached Files:

  4. thealu

    thealu Private E-2

    I neglected to upload the Panda Scan on the last post.

    thealu
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is a required Windows process that is necessary for you to properly login to your system. It was probably not complaining about userinit.exe but rather vbkggkn.exe that is trying to load at the same time.

    No it did not delete it. That file is in System Restore which cannot be cleaned without disabling system restore which removes the restores points.

    Are your copies of Ewido and CounterSpy both free trial versions?


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,vbkggkn.exe
    O4 - HKLM\..\Run: [ETMSGN] C:\WINDOWS\System32\ETMSGN.exe
    O4 - HKLM\..\Run: [plthzfiA] C:\WINDOWS\plthzfiA.exe
    O4 - HKCU\..\Run: [Mavpijl] C:\PROGRA~1\COMMON~1\PPPATC~1\WAUBOO~1.EXE
    O20 - Winlogon Notify: WASHData - C:\WINDOWS\system32\g040lahm1d4a.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    c:\windows\didduid.ini
    C:\WINDOWS\system32\vbkggkn.exe
    C:\WINDOWS\System32\ETMSGN.exe
    C:\WINDOWS\plthzfiA.exe
    C:\Program Files\Common Files\PPPATC~1\WAUBOO~1.EXE <--- you will have to figure out the real full path name the ~1 in the names is an abbreviation for longer names.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode and post a new HJT log.

    Now run the below procedure and attach the newfiles.txt log.
    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. thealu

    thealu Private E-2

    1) I copied the text and merged it with the registry

    2) I ran HJT and fixed the files you marked

    3) In safe mode, I tried to delete the files you marked but only found a few. I DID NOT FIND THE FOLLOWING:

    C:\WINDOWS\system32\vbkggkn.exe
    C:\WINDOWS\System32\ETMSGN.exe
    C:\Program Files\Common Files\PPPATC~1\WAUBOO~1.EXE (there was no file starting with PPPATC in the Common Files folder)

    4) I deleted everything in the Prefetch folder and ran CCleaner

    5) When I rebooted into normal mode, counterspy again warned me that UserInit was up to something. I told it to block the action.

    By the way, the copies of CounterSpy and Ewido are both just the trial versions.

    I have attached the new HJT log and the newfiles.txt log.

    Thanks Chaslang.

    thealu
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we need a little more info before continuing with the cleanup.

    Please download FindQool by LonnyRJones
    • Extract the files and place the FindQool folder into root folder of your hard disk. This is usually C:\
    • Open the folder and run Qlocate.bat
    • attach the contents of the txt.log which will open when the scan is finished. You will have to attach this to a second message because only 3 logs can be attached to a single message.
    FindQool is not a removal procedure. It is a scan that helps us to locate hidden files and registry keys so we can work up a fix for the Qoologic infection.
     
  8. thealu

    thealu Private E-2

    FindQool scan results.

    thealu
     

    Attached Files:

  9. thealu

    thealu Private E-2

    Additional info:

    Right after I sent the last post and closed Firefox, the hourglass was still on the screen. I checked Task Manager and 'update.exe' was the active process. The CPU was at 42%.

    There were no apps open and AVG still won't start at bootup so that wasn't even on. Don't know what was updating.

    I thought I'd mention this in case it was useful information.

    Thanks again Chaslang.

    thealu
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This could be due to the fact that you are running an old version of FireFox and it is trying to update to the new 2.0 Beta 1 that is out. Or it could be due to a hidden application I have seen recently. Run the below additional quick scan.

    Now run the below procedure and attach the runkeys.txt log.
    After I see this report, I will give more fixes to perform.
     
  11. thealu

    thealu Private E-2

    Runkeys.txt log attached.


    thealu
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later to run it.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window,Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\Program Files\Common Files\RACLE~1\dvdplay.exe
    C:\WINDOWS\NOELOO.DAT
    C:\WINDOWS\cmdmgr.exe
    C:\WINDOWS\srsfm.dll
    C:\WINDOWS\System32\tvmxve.exe
    C:\WINDOWS\system32\vbkggkn.exe
    C:\WINDOWS\SYSTEM32\w0022149.dll
    C:\WINDOWS\SYSTEM32\w016e197.ini


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself. However BOOT INTO SAFE MODE during this reboot and do not run anything but what I request. DO NOT open any browsers!


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,vbkggkn.exe


    Now exit HJT

    Run Windows Explorer and double check to make sure the below folders are all deleted:

    C:\Program Files\Common Files\omqk <--- the whole folder
    C:\Program Files\PECarlin <--- the whole folder


    Now reboot into normal mode and after reboot double check the same HJT entries I had you fix above and if any still remain, fix them again a second time.

    Now attach a new HJT log and a new runkeys.txt log

    Also tell me how things are working!
     
  13. thealu

    thealu Private E-2

    Question - I downloaded killbox onto the desktop thinking I would extract it to a folder in the C drive. But it did not come in a zip file. It downloaded as an .exe app.

    Can I run it from the desktop? Firefox doesn't ask me where to download, it defaults to the desktop so I would go change that setting and start over if I need it in a folder. Let me know how to proceed.

    thanks Chaslang

    thealu
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes the new version that is available for download is the raw executable that can just be run. It used to be ZIP'ed and it may be ZIP'ed again. It is difficult to keep our boiler plate messages totally up to date with this. One day ZIP, one day a self extracting exe, next day needs to be installed, and then just a ready to run application.

    Yes you can run it from the Desktop but that is not a good choice. Desktop clutter and also other users can get access to your Desktop to run it in other user accounts if that become necessary. Also if you have it on your Desktop and you are not an administrator type account and then boot into safe mode to login as administrator, you again will not be able to locate the file. It is always best to locate programs like we suggest with HijackThis. That way, any user on the PC can always find it and run it. And they can even create a shortcut (yes on your Desktop if desired) to easily run the application.

    You need to change your options in FireFox to always ask you where to download to. See Tools, Options, Download and select the option that says Ask me where to save every file
     
  15. thealu

    thealu Private E-2

    Chaslang,

    I followed all of your Killbox and HJT instructions.

    While in safe mode, as soon as HJT fixed the F2 entry you specified, Counterspy alerted me that C:/WINDOWS/System32/Userinit.exe was trying to enable itself to start at start-up again.

    I then rebooted into normal mode, ran HJT again, told it to fix F2 which was still there, and as soon as it fixed it, Counterspy popped up with the same message.

    I have rerun both HJT and the Runkey program and have attached both logs.

    One more thing of note, when I ran the Delete Temp Files in Killbox, it said that it found five user profiles. But as far as I know, my nephew has only one user profile named "DON". No one else uses his computer.

    Thanks again Chaslang. I appreciate all of your help.

    thealu
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is normal! Userinit.exe is a valid and necessary Windows process. It was the vbkggkn.exe process we were trying to remove. And is still present. Please uninstall CounterSpy and disable Ewido, then run the below again and this time attach the log even if clean:

    Qoologic Removal Procedure

    The look at your HJT log and fixed that F2 line if the vbkggkn.exe file is still at the end of the line.

    Also check to see if the C:\WINDOWS\system32\vbkggkn.exe file exists. If so, delete it.

    That's what you think! ;) Run Windows Explorer and go to C:\Documents and Settings everything shown there is actually considered a user account. Account like the following are typically found Administrator, All Users, Default User, LocalService, NetworkService, and your account.
     
    Last edited: Jul 19, 2006
  17. thealu

    thealu Private E-2

    I did understand that it was vbkggkn and not Userinit that was the problem, however I wanted to give you precise information as to what Counterspy's alert was since it's hard to know what's helpful to you in the fix process.

    I uninstalled Counterspy and Ewido, reran Qoofix (log attached, though there isn't much info in it) and reran HJT. The F2 line about Userinit, vbkggkn was gone. I have attached that log for you to look at though just in case.

    Also, I did not find vbkggkn.exe in the System32 folder.

    Intersting about the user profiles! Thanks for the explanation.

    Does it look like we're done here? What a process this has been!

    AVG still does not seem to be starting up at bootup. I'm going to try uninstalling and reinstalling again (once we're done here) and hopefully this time it will work properly. As a last ditch effort before handing his computer over to me, my nephew had installed both Norton and McAffee, which I have since uninstalled, but I wonder if there are lingering aspects of those programs which are preventing AVG from working properly...

    If you believe the computer is now clean, I will go ahead and update XP, and add other spyware/antivirus software per this site's suggestions.

    I cannot thank you enough Chaslang for your patience and your help.

    thealu
     

    Attached Files:

  18. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds