Following Posting Directions

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mold13, Jul 7, 2005.

  1. mold13

    mold13 Private E-2

    P4 2.2 GHZ
    XP Home
    512 MB RAM
    30 Gig HardDrive


    I can not seem to get rid of a virus (installer.exe) so I am in the process of following the directions so I can post my results after using HiJack This....

    I am up to the: Scanning and Cleaning Steps and Trend's Micro Free Online
    Virus Scan it picked up two infected System files:

    TROJ CLICKER AS Can not access
    1. C:\\Windows\System32\Config\systemprofile\LocalSettings\Temp...

    WORM RBOT.GEN Can not access
    2. C:\\Windows\System32\wuamk032.exe

    Can these be deleted? I didn't delete them, but then I couldn't complete the next step the Symantec Security Check. The system hangs here.

    Thanks in advance!
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download the following two files, create a folder on your desktop, call it TSC. Save these 2 files there!

    Sysclean Package

    Pattern.zip

    Once you have these downloaded into the folder you just created, double click the file sysclean.com

    When the system cleaner loads, click SCAN to start the scanner. After you have completed this scan above procede with the below.


    [​IMG] Download HijackThis 1.99.1

    [​IMG] Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    [​IMG] Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    [​IMG]Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    [​IMG]Run HijackThis and save your log file.

    [​IMG] Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    [​IMG]Need help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  3. mold13

    mold13 Private E-2

    I ran the Sysclean package and HiJack This as detailed. I still have two viruses (installer.exe and another which only pops up occasionally).

    I can't get the attachment to upload. It times out every time. I even tried it on a clean pc???

    Once infected computer booted the browser is hijacked:

    htt://mynbx247.info

    I am also getting an error dialogue box that simply says:

    Error: Loader couldn't initialize service!
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If you cant upload the log then copy and paste the HJT log inline and I will convert it for you.
     
  5. mold13

    mold13 Private E-2

    Thanks!

    Inline log attached!
     

    Attached Files:

    Last edited by a moderator: Jul 8, 2005
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add or Remove Programs for the following and Uninstall them if found:

    Viewpoint


    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost

    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [Anti-Virus Update Scheduler] C:\WINDOWS\system32\1.tmp
    O4 - HKLM\..\Run: [ZoneEdit] C:\WINDOWS\System32\uzfdy.exe
    O4 - HKLM\..\Run: [Microsoft Update] wuamk032.exe
    O4 - HKLM\..\Run: [Microsoft Update 32] wininit.exe
    O4 - HKLM\..\RunServices: [Microsoft Update] wuamk032.exe
    O4 - HKLM\..\RunServices: [Microsoft Update 32] wininit.exe
    O4 - HKCU\..\Run: [update.exe] C:\update.exe

    O15 - Trusted Zone: *.musicmatch.com
    O15 - Trusted Zone: *.musicmatch.com (HKLM)

    O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAccessVerisign/ie/bridge-c5.cab

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled and navigate to and DELETE the following if they should remain:

    C:\Program Files\Viewpoint ←–– Delete this whole folder if it exist!

    C:\WINDOWS\System32\uzfdy.exe

    C:\WINDOWS\System32\wuamk032.exe

    C:\WINDOWS\system32\1.tmp

    C:\update.exe

    wininit.exe ←–– Search for this file and delete when found!

    NEXT:
    Run CCleaner to clean up cookies and temp files.

    Run full scans with Ad-Aware SE & Spybot S&D and have both programs fix what they find.
    Note: Remember to get all updates before doing the scans.

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    Reboot to Normal Windows , Scan with HijackThis and attach the new log.
     
  7. mold13

    mold13 Private E-2

    Completed all steps.This time browser wasn't hijacked after normal boot! Nor did AVG pick up on the installer.exe file.

    Here is the latest log file.

    And THANK YOU for all the help.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a couple of new problems that showed up.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to Windows Process Moniter Then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Windows Process Moniter

    You may be told a reboot is needed at this point. Do not reboot. Just exit HijackThis which we will startup again in a moment to use different options.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [MSN MMISSENGER] mssmmspgr.exe
    O4 - HKLM\..\RunServices: [MSN MMISSENGER] mssmmspgr.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    c:\windows\system32\mssmmspgr.exe and also look for c:\windows\mssmmspgr.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  9. mold13

    mold13 Private E-2

    New HJT log attached.

    Other than problem below, things seems to be working smoothly!

    Ran into unrelated problem. This is a friend's computer and he never installed XP Service Pack 2. In the middle of this installation, computer froze and it didn't complete the Service Pack 2 install. It now it says system is unstabland it needs to be uninstalled. When uninstalling using Add/Remove Programs it lists all programs on the pc and says uninstalling SP2 may make them unstable?? Do I go ahead anyway?

    Sorry if this isn't the place to ask this question..
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You already had SP2 installed in message # 7 so I do not understand why you are only reporting this problem now. I see from the two longs posted, that you had SP1 in message # 5. SP2 should not have been installed at any point in time on a PC that is infected with malware. Why did you upgrade? It was not recommended in these steps for you to do that (at least not yet). Your question with SP2 uninstall belongs in the Software Forum.

    You did not post the follow up HJT log.
     
  11. mold13

    mold13 Private E-2

    Sorry about that. After cleaning up some of the issues the Automatic Windows update box began to work again and reported the SP2 Critical update needed to be installed. I realize now, I should have waited. When I posted without reporting it, I thought it would simpley be a matter of uninstalling the partial installation. I didn't realize it would detect all pc programs and say they may become unstable.

    Attached is the log file.

    Thanks for your patience!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to Mouse Hardware Sync (or that is not found look for mousehs )Then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Mouse Hardware Sync

    If that does not work, use the short name: mousehs

    You will probably be told to reboot here, so reboot.

    You should not have more than one antivirus installed. You have AVG and Bitdefender. Pick the one you want and uninstall the other.

    Post a new HJT log after doing the above and tell me how things are working.
     
  13. mold13

    mold13 Private E-2

    Uninstalled BitDefender.

    Followed instructions.

    When I executed Hijack.exe the following happened.

    1. An msdos window opens titled C:\Windows\System32.cmd.exe with a flashing cursor. Had to be manually closed

    2. A dialogue box popped up with the following error message.
    "Your current security settings prohibit running Activ X controls on this page. As a result the page may not display properly."
    Clicked ok and the browser completed opening and the URL displaysed

    c:\temp\update.html

    This browser page displays the instructions on installing the Active X Control
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well now you have a bad service back that we fixed in message # 8. Let's fix it again.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to Windows Process Moniter Then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Windows Process Moniter

    At this point reboot and then go follow the steps in the below thread. We need to get your system better protected. This includes getting a real firewall installed. Then disable the WinXP SP2 firewall which does not provide sufficient protection.

    How to Protect yourself from malware!


    Then post a new HJT log.
     
  15. mold13

    mold13 Private E-2

    Deleted Windows Process Moniter Service as instructed.

    Went to instructions on malwre page and followed all steps. Installed ZoneAlarm and ran:
    AVG free
    Spyware Blaster
    Ad-Aware SE
    CC Cleaner

    Still having windows SP2 update problem as detailed in earlier post. Posted problem on Software forum for advice. Nothing yet.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now your log is clean. I'm not sure why you are having problems with Windows update. Hopefully someone of the Software Forum can help with that. But something you may want to try. Set your system to automatically look for an install Windows Updates. Then reboot and see if that helps.
     
  17. mold13

    mold13 Private E-2

    Thank you so much for all your help!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Let me know if the autoupdate helps or if anyone in the Software Forum gives you an answer that works.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds