Began with Adware.Ezula and downloader, now bigger trojan/malware problems

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by araak, Nov 16, 2007.

  1. araak

    araak Private E-2

    I was searching for information on a program and hit a link which began installing things then quickly flashed my pc to blue screen then restarted. Upon restart it did the same thing (blue, restart) again and the next time it restarted I was bombarded with Norton messages stating it had had removed the Downloader virus from various locations such as Temporary Internet Files\Content.IE5\HACIBMYQ\pochki20071106[1]. These locations obviously change continually with different letter and number combinations. Norton would consistently find the Adware.Ezula virus as well although, quarantine, repair and remove apparently did nothing. Pop ups were pretty consistent upon changing any page while using IE. After trying every different adware, spyware, registry fixer, etc nothing had changed. Two days ago I began receiving false Windows notifications from the tray and on the desktop as well as from the windows security center which all seem to be bogus. Some examples of the phony system performance warnings were psw.x-vir trojan, w32.myzor.fk@yf, networm-i.virus@fp, trogan-spy.win32@mx, installed Security Toolbar 7.1 and the Malware threat black door trojan.

    Yesterday I found this forum and was working from the READ & RUN ME FIRST forum. I seemed to be making progress as I ran CounterSpy. After closing CounterSpy and restarting, my pc would no longer run in safe mode and upon a normal boot went to a blue XP screen that ran a spyware search I have never seen before (seemed to be running directly from Windows XP). After that my computer is running incredibly slow (something I hadn't noticed before). Internet Explorer no longer works correctly. At this point there are no longer any pop-ups or viruses presenting themselves, but without the Internet this all seems to have been futile. I am currently writing from my laptop. My computer is Dell XPS 210 running XP with Norton Internet Security 2006. Any assistance anybody can offer would be greatly appreciated. Thanks in advance for you kind people who put your computer savvy to helping opposed to creating viruses.

    Also, I was unable to execute the SDhelper within CounterSpy.

    UPDATE: After terminating CounterSpy and restarting via My Computer>Manage (to get log) IE started working again but now closes after less than a minute everytime. It gives the "Internet Explorer has encountered a problem and needs to close" message. Also, one time it said the problem occured while running the fdiljubb.dll add-on. This is weird and frustrating... I am still trying to run the panda scan have done all others. Upon startup I am told LoadLibrary(c:\documents and settings\all users\application data\pqxelsva.dll) failed - the specific module could not be found, says the same thing with file zahalafk.dll - hope all of this is not irreparable. Thanks again.
     

    Attached Files:

  2. araak

    araak Private E-2

    ShowNew.txt
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I'll give you some steps to get you started but this will not be a complete fix since I also needed the HijackThis log requested in the READ ME. If you have no Internet access you will have to download the tools and files mentioned onto another PC and transfer them to the problems PC somehow.

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 6
    Sunbelt CounterSpy <-- We are finished with the trial program now
    SearchAssist <-- should have been uninstalled in step 0 of the READ ME

    Now delete the below file
    C:\1363.tmp


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!
     
  4. araak

    araak Private E-2

    Hi, thank you so much for your help. It seems to have made a world of difference and the logs are below. There are no longer any error messages upon startup and IE is running entirely normal. I ran new GetRunKey and ShowNew to have the updated txt files. I hope that's what your expectation was.Thanks again, can't tell you how much I appreciate it!
     

    Attached Files:

  5. araak

    araak Private E-2

    Hijackthis.log - thanks so much, once again.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - http://downloads.ewido.net/ewidoOnlineScan.cab

    After clicking Fix, exit HJT.

    Your logs are clean other than the above non-malware things I had you fix with HJT.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  7. araak

    araak Private E-2

    Awesome. Everything is running well again and just wanted to say again how much I appreciate. You're the best!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds