Another Removing Malware Post

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Guerilla Belly, Jun 3, 2007.

  1. Guerilla Belly

    Guerilla Belly Private E-2

    Well i've had this for quite some time now a month or so and it's starting to tick me off... The pop-ups that mostly come up are Winfixer and Zedo...
    I'm completely confused and frustrated right now with it and so any help is very much appreciated, thank you
     

    Attached Files:

  2. Guerilla Belly

    Guerilla Belly Private E-2

    Alright here are the other three mentioned in the sticky
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please rename HijackThis.exe to analyse.exe as requested in the READ ME. Until you do this and attach a new log, we cannot see some of the malware items you may have since they are the ones that hide and are the reason for those instructions on renaming the program file.

    Attach a new HJT log after renaming it!

    Also you are not using the current versions of GetRunKey and ShowNew. Download the proper versions from the links in the READ ME and use them to get new logs and attach these new logs.
     
  4. Guerilla Belly

    Guerilla Belly Private E-2

    Alright so I've corrected the following statment below, thank you for taking the time Chaslang to help me out... Now I've put everything in order if there's still something wrong smack me with another post to let me know, alright?

    I redownloaded all three of those things just to be safe by the way

    So here they are. Thanks again
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still did not rename HijackThis.exe to analyse.exe as requested in the READ ME. As stated this is critical for many new infections. You log may not show things we need to see until you do this. However I will get you started and maybe we will get lucky.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 3
    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Continue by downloading two tools we will need

    - Process Explorer

    Extract it to its own folder somewhere that you will be able to locate it later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    Make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of any of the below DLL files (if found) and then click the kill button.
    d3dntl.dll
    After you have killed all instances of any of the above DLLs under winlogon click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on explorer.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    d3dntl.dll

    After you have killed all instances of any of the above DLLs under Explorer click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on iexplore.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    d3dntl.dll

    After you have killed all instances of any of the above DLLs under iexplore click ok.
    (If you do not find these DLLS, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
    O2 - BHO: (no name) - {7badb64e-18cc-4641-b894-ecc32ab26c6e} - C:\WINDOWS\system32\d3dntl.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {DEBEB52F-CFA6-4647-971F-3EDB75B63AFA} - C:\WINDOWS\system32\tmp137.tmp.dll
    O4 - HKLM\..\Run: [setup] rundll32.exe "C:\WINDOWS\vtttro.dll",realset
    O20 - Winlogon Notify: d3dntl - C:\WINDOWS\SYSTEM32\d3dntl.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Jun 5, 2007
  6. Guerilla Belly

    Guerilla Belly Private E-2

    Thank You very but, I'm don't have access to my computer until tomoorrow in which i will immediately do the things you listed... But to my understanding all I had to do for renameing was the unziped folder to analyse.exe but keep the log file was to stay the same... but I'll post another one tomorrow with analyse.exe instead of hyjack.log okay?

    here's a quote that says to just close the Notepad window and then just post on the forums:

    it is crucial that you rename hijackthis.exe to analyse.exe (as requested above) before using it or Vundo will hide itself from HJT.
    Run HijackThis and select Do a system scan and save a log file. When the scan is finished, a notepad window will pop up with the log file in it. The hijackthis.log file is already saved in the HijackThis installation folder. You can just close the notepad window now.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not talking about changing the log file name. We don't care what the log file name is. I'm referring to what was stated in step 7 of the READ ME. You did not rename the executable program. Look at your log and you will see this:

    C:\Program Files\HijackThis\HijackThis.exe

    It needs to be this:

    C:\Program Files\HijackThis\analyse.exe
     
  8. Guerilla Belly

    Guerilla Belly Private E-2

    Okay I'm finnaly back on my computer... Now i see what you mean. I think that that part of the read me should be redone to make it a little more understandable, or maybe I'm just an idiot.
     

    Attached Files:

  9. Guerilla Belly

    Guerilla Belly Private E-2

    okay so no problems doing the things you told me to do I finished and here are the logs... oh ATF Cleaners menus were a bit screwy like I couldn't click on main but it was default so it's good, but nothing will appear when you try clicking on them, maybe something to let the creater know, or maybe it's just me.

    The Post below this one (#8) is the HjackThis logs with the Exe renamed to analyse not the new HJT logs for after the cleaning process
     

    Attached Files:

  10. Guerilla Belly

    Guerilla Belly Private E-2

    And here is the new HyjackThis Log... Thank you!:)
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's very clear if you click on the link as instructed. The link immediately says:
    It can be much clearer than that. If you don' t click on the link which also in the main body of the says the below in very bold print:
    Not clicking the link is something only you can correct.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It works just fine. You are misinterpreting the behavior. If you click on Main when you are already on Main (which means IE), there is nothing to do so nothing changes. If you click on FireFox, Opera or Information, you can then click Main to get back to the main settings for IE.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a few more files to delete. Locate the below with Windows Explorer and delete them:
    C:\WINDOWS\ututtv.ini
    C:\WINDOWS\vttutu.dll
    C:\WINDOWS\vttutu.dll
    C:\WINDOWS\system32\tmp32D.tmp.dll


    Other than that, you are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. Guerilla Belly

    Guerilla Belly Private E-2

    Alright, thank you for spending your time helping me out! I haven't had any pop-ups since doing the cleaning and I hope I never see them again so I'll read the prevention read me. Thanks again!

    Am I supose to keep this on the desktop or can I delete it once it has merged with the registry?

    First, do I just send them to the recycling bin and then empty it? And I only have one vttutu.dll maybe you double posted it?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See step 7 of my previous message.


    Yes delete them and then empty the Recycle bin. And yes that was a double post of the same file.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds