Apparently All Kinds of Malware ...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Mmeyer, Aug 3, 2008.

  1. Mmeyer

    Mmeyer Private E-2

    I ran through your pre-process, with the exception of the "combo" fix b/c I continuously received an Error 403 when I clicked the link. I am attaching the logs I have from the other three runs, below.

    I see 3 problems:

    After completing this I receive an error message when I reboot indicating:
    "Error Loading C:\windows\system32\jjqjxaqq.dll ... The specified module could not be found."

    I also receive the (seemingly) common "Automatics updates is off" of the various virtumonde infection threads I've seen. I am unsuccessful when I attempt to turn automatic updates on.

    Finally, I am unable to run FireFox at all. I click it, double click it, etc., and it appears as though it is going to start, but to no avail. I check the running processes and there is no FireFox.exe running. Microsoft IE, on the other hand, does run. In addition, to download any of the malware removal tools I had to enter safemode with networking to do so. I was unable to attach to the majorgeeks.com website in regular windows mode.

    Attached are my logs.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Which link did you have problems with? This one:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    Or the ones in the above link that tell you where to download ComboFix.exe from?
    Either way try again. There is nothing wrong with the links (at least not now).

    We are going to need to use ComboFix so it would be best if you could get it installed and get us a log from it.
     
  3. Mmeyer

    Mmeyer Private E-2

    It was the link you showed above that I was having problems with. However, this evening it looks like it's working fine. I downloaded the software and ran it. I am attaching the log.

    Let me know what I should do next.

    Thank.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2_03
    My Way Search Assistant <-- should have been uninstalled in step 1 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    O2 - BHO: (no name) - {42BFABD3-B070-4053-9485-30D7E000D3D3} - (no file)
    O2 - BHO: (no name) - {79B36EFB-ECCA-4B76-8761-AFA5BB3B6D13} - (no file)
    O2 - BHO: (no name) - {E4471D8D-2775-47EB-AAF9-2BF82C369169} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [BM1bb7f624] Rundll32.exe "C:\WINDOWS\system32\jjqjxaqq.dll",s
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll bbwtrd.dll
    O20 - Winlogon Notify: efcDvsQk - efcDvsQk.dll (file missing)

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.



    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Aug 6, 2008
  5. Mmeyer

    Mmeyer Private E-2

    Couple of things:
    1) I missed Viewpoint Media Player and deleted it as you asked. But I did not see, nor do I see now, My Way Search Assistant, and so have not deleted it.

    2) When I ran C:\MGtools\analyse.exe I did not see the following entries:
    O2 - BHO: (no name) - {42BFABD3-B070-4053-9485-30D7E000D3D3} - (no file)
    O2 - BHO: (no name) - {79B36EFB-ECCA-4B76-8761-AFA5BB3B6D13} - (no file)
    O2 - BHO: (no name) - {E4471D8D-2775-47EB-AAF9-2BF82C369169} - (no file)
    O4 - HKLM\..\Run: [BM1bb7f624] Rundll32.exe "C:\WINDOWS\system32\jjqjxaqq.dll",s
    O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll bbwtrd.dll
    O20 - Winlogon Notify: efcDvsQk - efcDvsQk.dll (file missing)
    But, for the ones that did appear I did as you suggested.

    3) I received a success message with Fixme.reg.


    Attaching
    C:\ComboFix.txt
    C:\MGlogs.zip
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'll insert a fix for My Way Search Assistant into my prveious fix. It appears that you did not properly create the CFScript.txt file for ComboFix. The files we were trying to delete were not listed nor deleted which means the script file did not have the proper information. Please create it again exactly as specified and do the whole file from ComboFix down thru to the end. Then attach new logs. Note: Copy everything IN the quote box but do not include the Quote: text that precedes it.
     
  7. Mmeyer

    Mmeyer Private E-2

    Was out of town.
    I re-ran as suggested. Logs attached.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay the fix with ComboFix is still not working properly. Perhaps McAfee is getting in the way. Let's try fixing this another way. Try to shutdown McAfee if possible. Also ignore any popups from it about malicious scripts....etc while trying to run the below fix. Make sure you allow everything to run and do not allow McAfee to block anything.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. Mmeyer

    Mmeyer Private E-2

    Things appear to be working much better than before. When I returned home i found that a few people had been using the computer and that the "joke bluescreen" virus / malware had appeared on my machine (there was a thread about this). I ran malware bytes, it found some registry entries, deleted them and things are okay. With respect to what you and I have been working on, things are running much more smoothly now.

    Attacking logs below:
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean now.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. Go to add/remove programs and uninstall HijackThis.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds