Good Grief, What A CF!!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Kenny65, Jan 13, 2005.

  1. Kenny65

    Kenny65 Private E-2

    Hi Everyone,
    You've helped me in the past. I sure need it now... Long story short, I've got major Trojan trouble. I've been trying to clean this up for several hours, now. I did everything in Major 'Tude's "READTHISFIRST" string. A number of Trojans were deleted through those steps. I remain infected though. I know of 2 backup files for Hijackthis, that are infected. I can't manually delete them. The several programs suggested couldn't delete them either. I just rebooted from safe mode. Ran Ad Aware SE, & crossed my fingers. It STILL came up w/9 Registry hits.
    Please help me.
    Kenny.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. Kenny65

    Kenny65 Private E-2

    Hi Chaslang,
    Thanks for coming to my aid. You've helped me once before. That was nothing compared to this, though. Jeeze, what a mess it was. I've spent several, LONG hours on this current headache.
    I had an older version of Hijackthis, yesterday. I was running it directly from the zip file, in my briefcase (WinXP). The READTHISBEFOREPOSTINGHJTLOGS Thread says don't do this. It also says backups might not be created. Lastnight, I had 2 infected files remaining (out of 10). They were both backup files for HJT. I tried all the utilities in the READTHISBEFOREBOTHERINGUS Thread. They couldn't delete these 2 files. I couldn't even find them manually, either.
    So, I ran Ad-Aware SE upon booting up today. I was expecting the usual 9 Registry hits. They weren't there (?!). I then nuked my HJT.zip file, & downloaded a new one. I downloaded directly to a newly made C:\Programs\File. I still get a prompt I don't understand. It says I should save it directly to its own folder... I thought I just did.
    My first annoying, humble Query is, then. How do you properly download & establish HJT?
    I later ran Win Task Manager, before starting IE. I stopped a few questionable looking .exe files, before opening IE. Perhaps an illusion, but I'll take it. Yesterday gave me a headache.
    Thanks again. Kenny.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The folder should be c:\Program Files\HJT not c:\Program\File
    The c:\Program Files folder always exists on all Windows based PCs. All need to do is create the new subfolder called HJT

    You can download the HijackThis.zip file to anywhere you like. (A place where you save downloads is a good idea.) But then you need to unzip the hijackthis.exe file from the ZIP file using a program like WinZip and you tell it to unzip to the c:\Program Files\HJT folder you created (you can even create new folders on the fly while unzipping using WinZip). Then you run the hijackthis.exe file from that folder. (You can make a short cut to it anywhere you like, but just make sure you run the executable from the proper location by looking at your log after you perform a scan.)
     
  5. Kenny65

    Kenny65 Private E-2

    Good Morning Chaslang,
    Happy Weekend :). Here are the logs. Log#1 was done after running Ad-Aware SE. Log#2 was done before running A-A SE.
    I think somehow HJT is now starting when I bootup the system. I saved it the way you said to.
    Those 2 HJT backup files that are infected. They're a problem, no? Should I not disable the HJT backup option?
    Thanks again for your help. You guys are great here!!!
    Kenny.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure I follow your question but you should never be disabling the backup function in HijackThis. Antivirus programs will sometimes assume (falsely) that the HJT backup files are infected. They are not. It's just that they have information in them that was related to malware that has been fixed. This happens quite often in when adware/malware scanners create "vaults", "quarantine", or backup folders.

    I also do not see any indication that HJT is running at Startup. Are you sure about that?

    I see two antivirus applications installed and running Avast and Symantec. You must only run one. Pick one and uninstall the other.
     
    Last edited: Jan 15, 2005
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default.home
    O4 - HKCU\..\Run: [ntoror] C:\WINDOWS\ntoror.exe
    O4 - HKCU\..\Run: [MSMsgSvc] C:\WINDOWS\System\MSMSGSVC.exe
    O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v4/vet_install_popup.pl?1&4&04.00.07.02&unknown&unknown&http://www.remington.com/firearms/3d/1100


    This next item is not needed but it's up to you. It automatically checks for software upgrades AND new products, services and special offerings from Logitech.
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Desktop Messenger\8876480\Program\LDMConf.exe


    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\ntoror.exe
    C:\WINDOWS\System\MSMSGSVC.exe

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  8. Kenny65

    Kenny65 Private E-2

    Ahh... Hi Again Chas',
    I haven't been able to reply to you. Hell, I haven't been able to do much of anything. Except to curse the punk-assed kid who wrote this freakin' virus! I'd love to get my hands on him.
    I've Win XP, home ed. I did what you suggested in your last e-mail. As I said before. I've already followed the instructions in the DOTHISBEFOREBOTHERINGUS Thread. Everything was fine for a few days. The scans came up clear. All I could find infected, were those 2 backup files for HJT. The ones I can't even find MANUALLY. All of a sudden, BAM. A-A SE came up w/several new registry intruders. I started going through the clearing processes listed here. Then I noticed on a Norton Systemworks Sensor. Crap, 100% of my cache is being used, 100% of the time!!?!
    The past couple of days, I haven't been able to type a reply here. Nor have I been able to log into my hotmail acct. The log on screen won't load. The screen remains blank, although stating "Done." There's curious URL type writing across the very top of the screen for this page, too. I go to common vendor pages (BestBuy, etc.), & things just don't work. I click a link on a page, & nothing happens.
    I'm severely pissed-off by all of this. @this point, I'm hoping I can manage to install a new DVD Burner I just got. I've many pix stored on this PC, from many trips I've taken. Some are irreplaceable, including a once-in-a-lifetime trip from last Summer. Then I guess I'll have to nuke the whole damn thing, buy a new HD & memory, & start all over again.
    Kenny.
    P.S.: Thanks again for your help, Chas'.
    P.P.S.: Did I mention I'd like to severely injure the rat **ck who wrote this thing?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What were the results of running the steps in my previous message and why didn't you post the follow up HJT log.
     
  10. Kenny65

    Kenny65 Private E-2

    Hi Chaslang,
    I did delete the 4 files you'd listed. I also tried, but was unable, to delete the 2 files w/Win Exp. After nuking the 4 files, I saw no change. When I do full system scans w/Ad-Aware, or Avast!! I come up empty (no infection). I know it's there, though. I know because:

    A) IE is totally "Screwed."
    B) Norton Systemworks shows me that my cache is 100% full/used, 100% of the time...

    I'm a Nurse by profession, Chaslang. I enjoy technology. I actually spec'd & built, my current PC. It Tain't my biz, though. I'm well over my Head, here. I'm going to reboot in Safe Mode, do some scans, & post the results.

    A) If you can help get rid of this **it, great!
    B) If you can't. Please advise me. My (Memory) Cache is full 100% pretty much @bootup. If I have to "NUKE" everything... Do I have to buy a new Hard Drive & Memory? From my ignorent perspective, the Viri are present in the RAM, correct? Also, unless I want to buy a program to totally over-write my HD. It's possible that old code could infect me, anew.

    As Always, Chaslang, I thank you greatly, for your help. I'll now reboot, & post the results.

    Thank You, Babe :).

    Kenny.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still need to see a follow up HJT log Kenny!
     
  12. Kenny65

    Kenny65 Private E-2

    OK, Here it is.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How much memory do you have in this PC and what is your Processor Type (Intel, AMD) and speed?

    Why do you need this:
    O4 - Global Startup: Norton System Doctor.LNK = C:\Program Files\Norton SystemWorks\Norton Utilities\SYSDOC32.EXE

    Your system seems to have some stuff from Norton/Symantec but not other stuff they make (like antivirus). How did you end up with only some of their stuff? Is it all due to just installing system works?

    Do you use these:
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
     
  14. Kenny65

    Kenny65 Private E-2

    Hi Chas',
    I've a P4 @2.4GB, W/256MB of 2700_DDR RAM.

    I'd had a minor Virus problem, some months back. I thought I'd accidentally deleted a needed file for Norton Systemworks (things weren't working). So, I deleted/re-installed the SW programs. I'd nuked Norton Systemworks, but not the Firewall. When I subsequently contacted Norton's support ctr , somewhere in India... Some Guy named Rajnish, told me I must remove all Norton Apps together, & re-install again As One. He said that was why LiveUpdate wasn't working.
    Rajnish was wrong... I did what he said. Liveupdate still doesn't work. I tried switching to another AV Program, but NAV is still detected by the newer programs. I'm unable to delete NAV. That's why my Norton files are confusing.

    Do I need QuickTime, & ViewManager? I don't know. I defer to your better judgement. I originally loaded QuickTime to download/view "Snippets," from Bike Sites. I thought it was an application. One that is only used when called for. Was I wrong about that?

    I thought ViewManager to be a part of the OS (i.e.: Task Manager). So, I'd be afraid to have messd w/it. The OS wouldn't have let me, anyway. Again, I ask your opinion.

    I'm guessing that you actually enjoy this stuff. I guess that I might, too (were I not a Nurse). But "I.T.," isn't my Biz. To me, this is just a big hassle, & a waste of my time.
    If I should just install my new DVD Burner, & back-up my irreplaceable Pix. Please tell me now. If I should tough it out, OK. You could say that too.

    Thank You as always. Kenny.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Get into Add/Remove Programs and uninstall anything you find related to Norton or Symantec (let me know if you find anything that way). If not we may have to fix manuallly.

    You can run QuickTime without having their qttask.exe program load. It just wastes resources sticking an Icon in your tray. It's not need.

    Viewpoint Manager is not require or used by about 99.99% of the people who have. Like you they don't even no what it is or where it came from. It is garbage AOL stuck on your PC without even asking. Another resource waster. Uninstall it using Add/Remove Programs. It has nothing to do with TaskManager.

    Let's not call it quits yet! Let's try to cure this baby.
     
  16. Kenny65

    Kenny65 Private E-2

    Hi Chas',
    Who's quitting? I just don't want to lose my pix.

    You say to nuke Norton? I like my Norton Utilities. Do you think one of the Norton files is infected?

    I already hate AOL. They're a crooked company. ViewManager is as good as gone.

    I'd tried running MicroTrend's online AV scan from Safe Mode. I did it before IE gave up the ghost. It again found the 2 infected backup files from HJT. A prompt said I couldn't delete the files because they were currently in use. Hmmmm..... I wonder if I tried that through Firefox. Would they STILL be occupado?? Yeah, that's worth a shot.

    To be continued...
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not saying Norton is infected. I more concerned that something is messed up with the installation that is causing problems.

    If you are talking about the HJT backup files again, they are not infected. They just have traces of the things you have fixed. What was the full path to the files that Trend found. Did you have HJT shutdown when you scanned? I don't believe you can use FireFox on the online scanner sites.
     
  18. Kenny65

    Kenny65 Private E-2

    Hi Chas',
    "Happy Friday," to you!! After E-Mailing you last Night. I managed to get Micro-Trend's online scan, to "Nuke," the 2 HJT files I'd mentioned. You were right. You cannot get that App. to run in Safe Mode W/Networking (W/FireFox, anyway). I had to do a full boot up, & then run it. The Java screen wouldn't let me see the full file name. It looked right, though.

    My happiness was short-lived, of course. Something is still wrong. My RAM remains far too taxed... W/WIN_TaskManager. I've tried stopping certain processes. So far, my memory remains over-extended.

    Unlike when I began (several yrs. ago, w/an illegal PC). I'm now 100% legal. I can nuke, & reload anything. All I really need to save is my Pix_N_Films. I've a brand new DVD Burner just waiting to be installed.

    You know a whole lot more than me, regarding maliscious Code. The Pix, & Films I've saved. They're all that matters to me. The rest is easilly reproduceable.

    Again, I'm not quitting. All I need though, are my Pix/Films. Why beat your Head against a Wall? Espescially when it's not necessary?

    So, here's Tonight's query to you, Chas'.
    Can I install,& copy my "PixNVids" to my DVD Burner now? OR, should I wait until I've ridden myself of this current infection?

    Like I've said. I'll "Nuke" ANY FILE I need to. I've all the Originals!!!

    What Say You Now, me Lady?!?!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Go ahead and install it. See if you can get everything backed up! Then we are free to try other things if we want that could be more dangerous. I'm not sure what yet, but we can probably think of some! ;)
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also download this Generic Find It Tool - NT/2000/XP

    Extract all the files from the Generic Tool into its own folder.
    Then run find.bat. Post the log it creates back here as an attachment.
    You need to wait long enough for it to complete. The log will appear when done.
     
  21. Kenny65

    Kenny65 Private E-2

    Hi Chas',
    OK, I think I did it right. I don't know if it was a part of it or not. Avast! prompted me w/a virus warning while this program was scanning. It was a Trojan in a system dll. Flushing out the Birdies? Here's the log.
    Kenny.
    P.S.: I was in bed all weekend, sickNworthless. So, I didn't put the DVD Burner in yet.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The output from find.bat did not show anything. What is the name and path to the system file taht Avast prompted you about? Never provide incomplete information. Always provide exact specific full filenames, error messages, etc. They are important infomation. Remember I cannot see what is happening. I only know what you tell me.

    Do you still have both Norton and Avast antivirus applications installed? If so, uninstall everything on your system related to Norton/Symantec? And then reboot. Then post a new HJT log.
     
  23. Kenny65

    Kenny65 Private E-2

    Hi Chas',
    Everything seems to be working fine, now. I just don't use IE anymore. The apps I use seem to run as quickly as before. I like my Norton utilities. Unless you tell me it's a mistake. I think I'll just let it be for now.
    This was the second time you've helped me out. I remain grateful.
    Thanks.
    Kenny.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you like Norton, keep it. I was just trying to solve your current problem. You may find that you will need to use IE for some websites. Especially Microsoft.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds