kaspersky scan said 9 virus's

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by coryandnancya, Aug 17, 2006.

  1. coryandnancya

    coryandnancya Private E-2

    hi there, i sure could use a little help. here's my hijack this scan and my kaspersky scan logfile of

    Edit by chaslang: Inline HJT and Kaspersky logs removed! Cleaning steps not run!


    Scan process completed.

    thx in advance!!
     
    Last edited by a moderator: Aug 18, 2006
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please read the sticky threads before posting logs. No logs are to be posted inline and you need to run standard cleaning procedures if you are having malware problems. I would just suggest that you boot into safe mode and then delete the below folder:
    C:\WINDOWS\bundles

    If that does not resolve your problems then please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:

      • [*]runkeys.txt - the log from GetRunKey.bat
        [*]newfiles.txt - the log from ShowNew.bat
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. coryandnancya

    coryandnancya Private E-2

    hi chaslang,
    thx for the help. sorry about not reading the sites info b-4 posting. i was a little frustrated!
    well i did all that you suggested and the window hasn't popped up yet.... so maybe? anyway the window was the: internet explorer has encountered a problem and will close. then i clicked the blue highlighted: more information and it was mostly this mod ntdll.dll. that showed up. or all my windows would close unexpectantly! so if it starts acting up again.... ya know what, hope ya don't mind can i send you my logs anyway?
    thx again cory 1974 in ohio
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have run ALL of the READ & RUN ME, yes you can attach ALL of the logs I requested to be sure all malware has been removed.
     
  5. coryandnancya

    coryandnancya Private E-2

    hi, here's the first three. and i did all the things listed in the read me section. and i'm still getting that annoying pop-up about internet explorer has encountered a problem and will close. the 1 module, i guess, is mshtml.dll. another time and most often it is ntdll.dll. another time was ws2_32.dll. i looked these up and they have somethin to do with developement software. i'm not doin any type of that. next post will be my panda scan and hijack.
     

    Attached Files:

    Last edited by a moderator: Aug 22, 2006
  6. coryandnancya

    coryandnancya Private E-2

    here's the other two.
    cory
     

    Attached Files:

    Last edited: Aug 22, 2006
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you attaching copies of GetRunKey.zip and ShowNew.zip with different names? We need the logs that they create ( c:\runkeys.txt and c:\newfiles.txt )
     
  8. coryandnancya

    coryandnancya Private E-2

    ok i'll try it again.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You also MUST follow the directions in step 7 of the READ ME for installing and renaming HijackThis.exe.

    You have it here:
    C:\Documents and Settings\cory\My Documents\HijackThis.exe

    That is exactly where the directions indicate not to install it and you also did not rename the executable file.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I also see you are running:VCOM Fix-It Utilities

    Doesn't it contain an antivirus, antispyware, and maybe even a firewall?


    Is your copy of ewido anti-spyware 4.0 guard a free version or paid version?

    Did you install the below and what is its purpose?

    NPDOR File Monitor Service (NFMService)

    I consider them to be spyware. I would not give them any info. I quote from their site:
     
    Last edited: Aug 22, 2006
  11. coryandnancya

    coryandnancya Private E-2

    sorry chas, here they are. i double clicked them and didn't wait long enuff. all i saw was a black screen for about 5 sec's. thx cory
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you see message # 10?

    Also the below is not the correct place to install or run ShowNew or GetRunKey from:

    C:\Documents and Settings\cory\Local Settings\Temporary Internet Files\Content.IE5\OJWRYKR4\ShowNew[1]

    DO NOT USE the TIF folder. It will work but it is a bad idea. When I tell you to clear your cache later or if you run CCleaner, they will all be gone!
     
  13. coryandnancya

    coryandnancya Private E-2

    should i do hjt again, right this time. v-com utilities does contain antivirus, syware and firewall. but i don't have the firewall on cus i have zonealarm. i ran a scan with this and avg and they found nothing.
    i installed the npdor file to make twenty bucks. they've already sent me the money but i left it on. they monitor activities to see what ya like, i guess.
    cory
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please see step 3 of the READ ME. If VCOM has an antivirus and you plan on keeping it, you must uninstall AVG. Why are you using ZoneAlarm instead of VCOM's firewall?

    Uninstall NPdor.


    YOUR PC IS IN SELECTIVE STARTUP MODE using MSconfig, which we tell you not to use in step 7 of the READ ME.
    Did you knowingly install WeatherBug and do you use it?

    You need to properly install HJT, GetRunKey and ShowNew. I only need a new log from HJT right now though (after complete the above and other steps).
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you install this PC Pitstop Optomize stuff. Did you purchase it? If not, you should uninstall it to avoid getting the reminders.
     
  16. coryandnancya

    coryandnancya Private E-2

    actually v-coms antivirus just checks for virus when opening email attachments and when you open files. you can also scan for virus, but i don't think it is the same type of program as avg. would'nt they have conflicted long b-4. i've had them both for about 5 yrs.
    i unsubscribed from npdor and it will take up to 10 days. there is no program to uninstall in the add/remove. i got rid of pc optimize. yes i use weatherbug everyday.
    i'm just used to zonealarm.but i will check out v-coms firewall. i know i can't use both!
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will not necessarily see the conflict. They are however conflicting and the are slowing your PC down. They also can make it difficult for each program to properly detect and remove malware. Decide which one you want to keep and uninstall the other. You need to do this before we continue.

    I saw it listed in the Uninstall list that appears in the ShowNew log. That does not necessarily mean it will have an uninstall. But we can easily do that ourselves. This is another reason not to use their software. Any program that requires an install and then does not have an uninstall is not reputable. They are purposely trying to force you to keep their software. This is the same as malware.

    You now have TWO HijackThis processes running:
    C:\hjt\HijackThis.exe
    C:\hjt\analyse.exe

    Delete the first file above!!!!

    The below should not be running when you are using HijackThis:
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\NOTEPAD.EXE

    Did you get out of selective startup mode?

    Have you installed GetRunKey and ShowNew properly yet? Attached new logs when you are in normal startup mode and they are installed properly.


    You did not answer my question about Ewido from message # 10!!
     
    Last edited: Aug 22, 2006
  18. coryandnancya

    coryandnancya Private E-2

    it is the free version of ewido. yes i'm in normal start-up mode. i think i installed those two properly.
    and i will uninstall one of the antivirus programs after work today.also deleted all of the hijackthis except analyse.exe. will double check later. running out of time
    later
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's better. Now while you are uninstall one of the antivirus programs also uninstall the below:

    ewido anti-spyware 4.0
    Java 2 Runtime Environment, SE v1.4.2 <--- this is an old version and you already have the new one
    Viewpoint Media Player
    WildTangent Web Driver


    After doing the above (and uninstalling one of the antivirus programs) attach a new HJT log.
     
  20. coryandnancya

    coryandnancya Private E-2

    ok chas,
    i uninstalled avg and those other four programs.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Would you like to get rid of npdor while we are fixing remaining things?
     
  22. coryandnancya

    coryandnancya Private E-2

    yes good idea. also i just got another I.E. window with kernel32.dll as the problem mod. then all windows close....
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to NPDOR File Monitor Service ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    NFMService

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [PCDRealtime] C:\WINDOWS\realtime.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Hti] C:\npdor\npdor.exe
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
    O16 - DPF: {192F9A01-8030-48CE-9BC6-B03DE3E613C6} (PeoplePC Web Installer) - http://www.peoplepc.com/ppcos/isp60/download/ppcwebi.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\npdor <--- the whole folder
    C:\Program Files2\PCPitstop <--- the whole folder if found
    C:\WINDOWS\realtime.exe
    c:\windows\system32\unPPC.exe
    c:\windows\ss3unstl.exe
    c:\windows\system32\FLEOK
    c:\program files\QuickSearch

    Additional step to delete files in the Downloaded Program Files folder :
    - Click Start, Run, and enter cmd in the box and click OK. This opens a command prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s dm.inf
    del dm.inf
    attrib -r -h -s pcpowerscan.EXE
    del pcpowerscan.EXE
    exit

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I forgot one more thing I wanted to do!

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Then attach a new log from GetRunKey.
     
  25. coryandnancya

    coryandnancya Private E-2

    i tried what you said. when i double clicked the icon on the desktop it said do you want to add this to the reg. i clicked yes and it says it cannot add this cus it is not a registry script. i can only import binary registry files from within the registry editor. and i had the save to "all files" .
    i checked those in the hjt log off. went into safemode and deleted those files/folders.that additional step was a bust. all the cmnds. i put in were not recognized or otherwise not good. reset home page and deleted all files and cookies. i deleted the nt service "NFMSERVICE in hijack.
     
    Last edited: Aug 23, 2006
  26. coryandnancya

    coryandnancya Private E-2

    new log.

    bedtime , goodnight.
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The registry patch works just fine for me! You must not be saving it properly. Also the commands from the command prompt should also work but you must enter them correctly with the proper spaces or the will not work or be recognized. So try the registry patch and the stuff to remove files in the Downloaded Program Files folder again.

    How is everything working at this point?
     
  28. coryandnancya

    coryandnancya Private E-2

    i'll try that again when i get home tonite. you just highlight the text and copy to desktop then double click, right.. i'll do the cmd prompts also. i have gotten 5 "internet explorer has encountered a problem and will close" windows in a 1/2 hour. each one is a diff. mod. once all my windows just closed... is there anyway to get one of these problem info. messages to transfer so you could look at it. it has an awful lot of info to try and type, specially since i'm a two finger typer!
    my comp. seems to be jumpin between windows alot quicker. running great cept for that i.e. problem
    later
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You highlight the text and copy it to a notepad file and then save that file to your Desktop (or anyplace you like) but you MUST change the Save As Type to All Files and make sure that you name the file with a .reg extension.

    It is very possible that these are not due to malware. It is more than likely due to corrupted or missing system files. Yes the problems may have initiated due to malware, but at this point I would say they are not due to any still remaining malware.
     
  30. coryandnancya

    coryandnancya Private E-2

    ok got fixme to enter into the registry. still cannot get those cmnds to work.
    is there a way to find what file is corrupted or missing?
     
  31. coryandnancya

    coryandnancya Private E-2

    here's the new getrunkey.
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From a command prompt window, enter the below command:

    sfc /scannow

    If this finds any system files to be missing or corrupted it will ask you for you Windows XP CD (if it needs it). So be prepared to supply your CD.

    How is everything working now?
     
  33. coryandnancya

    coryandnancya Private E-2

    hi chas,
    i did a kaspersky scan this am and just checked it. it shows 1 virus named trojan-dropper.VBS.Inor,cz! so i, we got rid of 8, since that first scan showed 9. would the ones in my old avg vault have showed up on that scan?
    well seems to be running same cept for the usual error window. the sfc /scannow completed just fine and did not ask me anything! hmmmm...
    any other id's?
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not useful to me but a log from Kaspersky could be.

    Refesh my memory. What is the exact problem? All I seem to remember is something about kernel32.dll which is not a malware problem.

    Let's work thru the below anyway!

    Go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  35. coryandnancya

    coryandnancya Private E-2

    the problem was that i kept getting the" internet explorer has encountered a problem and will close" message. or all my windows just close. the information on that I.E. message was mostly about a ntd.dll mod. (module). or another kind of .dll so maybe i have a corrupt or missing file. i ran a trojan remover program scan and the two things i noticed was one: this file in the %systemroot%/system32/appmgmts.dll was not found. two: key KPDORFM image pathh=system32/drivers/NPDORFM.sys. file was not found. have any idea about these two files.
    i did the system restore thing and am in the process of the other.
     
  36. coryandnancya

    coryandnancya Private E-2

    here's the kaspersky log.
     

    Attached Files:

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's not a big problem! Either do a Reset of Web Setting which should delete all those files in the Temp Internet Files folder or you can delete the file yourself.

    That NPDORFM.sys is part of that junk you had installed. Remember this NPDOR File Monitor Service

    Basically you got 20 bucks from them to allow them to screw up your PC.

    My same comment applies to your Trojan remover comments. A log could be more useful. appmgmts.dll is a valid file from Microsoft. It is Software installation Service

    You should not be missing this and if you are, I don't understand why sfc /scannow did not detect it. You could just download it from the below link and put it back in your system32 folder:
    http://www.dlldump.com/download-dll...es/A/appmgmts.dll/5.1.2600.2180/download.html
     
  38. coryandnancya

    coryandnancya Private E-2

    hi chas,
    pc is running great. only two I.E. popups in a couple hours and they were different .dll,s i just used a program called anti-trojan shield 2 and it found no trojans. so i don't know where that 1 trojan-dropper is or was. maybe a temp file. i used ccleaner(and unchecked the delete temp files older than 48hrs in the advanced mode section) before running it. so maybe that was where it was.
    so thx for the help
    have a good one!
    Cory
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds