1. elitewombat

    elitewombat Private E-2

    Followed Readme.

    Counterspy failed to open and just caused computer to hang, same with AVG.

    Logs as follow.
     

    Attached Files:

  2. elitewombat

    elitewombat Private E-2

    Thank you for help given.

    Note: New version of Java failed to install and this is a friends computer so I have no idea what they did to get into this mess.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are badly infected. I would suggest that you call your bank and credit card companies and alert them that you may have your accounts compromised.

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Please search for and delete these:
    C:\Program Files\Viewpoint
    C:\WINDOWS\system32\Explorer.exe
    C:\Documents and Settings\Owner\Application Data\Viewpoint

    Use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0
    Viewpoint Manager (Remove Only)"
    Viewpoint Media Player

    Reboot and install:
    Java Runtime 6

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: Shell Doc Object and Control Helper Class - {00009E9F-DDD7-AA59-AA7D-AA4B7D6BE000} - C:\WINDOWS\system32\shdocvs.dll
    O2 - BHO: Shell Event Object Class - {00534B55-3155-CA4F-B41D-0E922121D03C} - C:\WINDOWS\system32\cscentfy.dll
    O2 - BHO: (no name) - {d9a0f09e-2a55-495d-a4fb-c222a72b4ccf} - C:\WINDOWS\system32\d3dda2.dll
    O4 - HKLM\..\Run: [IESet] IExplorer.dll .dbt
    O4 - HKLM\..\RunServices: [IESet] IExplorer.dll .dbt
    O4 - HKCU\..\Run: [IESet] IExplorer.dll .dbt
    O20 - AppInit_DLLs: c:\windows\system32\awtqnmm.dll
    O20 - Winlogon Notify: d3dda2 - C:\WINDOWS\SYSTEM32\d3dda2.dll

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\d3dda2.dll
    C:\WINDOWS\system32\svchtoost.exe
    C:\WINDOWS\system32\Explorer.exe
    C:\WINDOWS\system32\comcbx2.dll
    C:\WINDOWS\system32\comcs32c.dll
    C:\WINDOWS\system32\commnet8.dll
    C:\WINDOWS\system32\cscentfy.dll
    C:\WINDOWS\system32\fontqxet.dll
    C:\WINDOWS\system32\hnetviw.dll
    C:\WINDOWS\system32\dsuiexq.dll
    C:\WINDOWS\system32\msratnit.dll
    C:\WINDOWS\system32\rasqervy.dll
    C:\WINDOWS\system32\sdfinacs.dll
    C:\WINDOWS\system32\shdocvs.dll
    C:\WINDOWS\system32\srvswc2.dll
    C:\WINDOWS\system32\srvswc3.dll
    C:\WINDOWS\system32\tmp5.tmp.dll
    C:\WINDOWS\system32\winivfop.dll
    C:\WINDOWS\system32\wuasirvy.dll
    C:\WINDOWS\system32\kiscbxw.dat
    C:\WINDOWS\system32\kiscbxz.dat

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click the box to unregister .dll's. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach new logs for:

    * GetRunKey
    * ShowNew - please download the current version first!
    * HJT
     
  4. elitewombat

    elitewombat Private E-2

    The regkey failed at preventing the Iexplorer and others from reappearing.

    I also noticed that Pocket Killbox just move all files to a folder. Should this folder be deleted right away?
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do not delete the backup copy of deleted files in Pocket Kill Box....yet.

    Please run CCleaner and have it remove all the temp files.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {d9a0f09e-2a55-495d-a4fb-c222a72b4ccf} - C:\WINDOWS\system32\d3dda2.dll (file missing)
    O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\fcbaaw.dll",setvm
    O4 - HKLM\..\Run: [IESet] IExplorer.dll .dbt
    O4 - HKLM\..\RunServices: [IESet] IExplorer.dll .dbt
    O4 - HKCU\..\Run: [IESet] IExplorer.dll .dbt
    O20 - Winlogon Notify: d3dda2 - d3dda2.dll (file missing)

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\Owner\Application Data\wklnhst.dat
    C:\WINDOWS\system32\defrasw.dll
    C:\WINDOWS\fcbaaw.dll

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click the box to unregister .dll's. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT
     
  6. elitewombat

    elitewombat Private E-2

    Once again the IExplorer.dll.dtb files came back after using the regkey and Hijackthis to remove them.

    I looked in the Windows folder and found these files that i do not recognize:

    bdoscandel.exe
    ciaunwdm.exe
    GTRemove.exe
    NOTEDAD.EXE

    I had googled the NOTEDAD.EXE before hand and noticed that it was associated with the IExplorer.dll.dtb files.

    Hope this info helps!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [IESet] IExplorer.dll .dbt
    O4 - HKLM\..\RunServices: [IESet] IExplorer.dll .dbt
    O4 - HKCU\..\Run: [IESet] IExplorer.dll .dbt
    O4 - HKUS\S-1-5-18\..\Run: [IESet] IExplorer.dll .dbt (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [IESet] IExplorer.dll .dbt (User 'Default user')
    O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure you tell us whether you get a message confirming that the above fixME.reg patch was successfully added to the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\avgwlntf.dll
    C:\WINDOWS\system32\IExplorer.dll .dbt
    C:\WINDOWS\system32\IExplorer.dll.dbt
    C:\WINDOWS\NOTEDAD.EXE
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  8. elitewombat

    elitewombat Private E-2

    Sorry for the late reply been busy with school. Here are the logs.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds