my malware scanning and removal progress

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by RenegadeT, Sep 25, 2007.

  1. RenegadeT

    RenegadeT Private E-2

    IBM ThinkPad T42
    Win XP (Build 2600.xpsp_sp2_gdr.070227-2254: Service Pack 2)

    PROBLEMS:
    1. Unable to access wireless network functions
    2. Windows Firewall was turned off and can not be turned on
    3. Symantec Antivirus logs shows a lot of files skipped
    4. In general the computer is taking a long time to boot up and shutdown

    So I'm following the READ & RUN ME FIRST Before Asking for Support thread on my old PC while cleaning the laptop. Notes below, and I guess I attach logs later.

    oops, I got confused and ran them trying to install and configure. Moving on...rolleyes

    Crap, I can't login as admin. I try all my passwords including simply <ENTER>, and there's one in particular that it consistantly 'hangs up' on, like 30 seconds before it denies me, all the others are pretty instant rejection. So I'm performing the scans under the one and only User account I have set up.

    I don't see this SDHelper function, I'm pretty sure when I installed this, I left it checked. Per the READ & RUN ME thread, I disabled the Teatimer function and FixedSpyBot's Ignore Products Bug. Spybot S&D Help doesnt seem to work either, so I had to skip the SDHelper step.
    It did find a bunch of Firewall and Antivirus blockers, this is looking promising :cool

    Trying to install, I get...
    ERROR- Windows Installer
    The system administrator has set policies to prevent this installation. OK


    on to AVG Anti-Spyware....
    Well, I guess I don't have any infections, but it found 2 Medium Risk Threats (TrackingCookie.Paypal and Adware.Coupons). I "Apply all actions", go to "Reports", and it tells me "No Reports Availiable" and the "Save Report As" box is grayed-out. I double checked that the Reports Settings are set to "Auto gen report after every scan", I don't know why I'm not seeing a report.


    I have a cable modem. It looks like I will have to post this now from the PC, unplug my network cable and connect it to the laptop.
    Good timing, its about time to go to bed, I won't be able to finish this tonight. Any comments, etc appreciated, I'll check back tommorow and continue the scan/removal process.
    :wave
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks

    Then you need to rerun then at again at the point they were supposed to be run (towards the end of the procedure) which was after all the other scans except HijackThis. Do this after you run the online scans as instructed in the READ ME..


    Just attach all the logs when you complete the procedure. If AVG Antispyware had nothing to report then you don't need to attach it.
     
  3. RenegadeT

    RenegadeT Private E-2

    Attempted to Uninstall IBM 32-bit Runtime Environment for Java 2, v1.4.1 with CCleaner, got a Windows Installer Error.
    Attempted to Uninstall IBM 32-bit Runtime Environment for Java 2, v1.4.1 with Windows/Control Panel/Add or Remove Programs, got a Run a DLL as an App Error when clicking the Add or Remove Programs icon.

    Plugged in network cable, no internet.
    REBOOT into Safe Mode with Networking (I'm pretty sure that's where I was), still no internet.
    REBOOT into Normal mode, and Spybot S&D starts up. When I did S&D yesterday, there were 2 file it couldn’t delete, and it scheduled a scan for next startup. Found the same 2 files, couldn’t remove. And still no internet.
    SHUTDOWN is hung up, manually power off the laptop.
    RESET cable modem (unplug for 10 seconds), boot in Safe Mode with Networking.
    IE (Homepage is weather channel.com, it looks like a text-only version)-->MajorGeeks.com

    The I Agree button and arrow don't kickoff BitDefender.

    No go here, maybe try in Normal Mode...

    IE is very slow, I get a Generic Host Process for Win 32 Services Error window.

    Same deal, it looks like the BitDefender "I Agree" and Panda ActiveScan "Scan Your PC Now" buttons are disabled or something :cry

    GetRunKey and ShowNew logs attached...well...the MANAGE ATTACHMENTS BUTTON is MIA, grrr. Let me transfer to the other computer and try from there.
     
  4. RenegadeT

    RenegadeT Private E-2

    Here's the GetRunKey and ShowNew logs. Do you think somethings wrong with my IE on the laptop, causing the BitDefender and PandaActiveScan buttons not to work, and eliminate the Manage Attachments button?
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on only those two logs, I'm not seeing any malware. Please attach a HijackThis log after following the instructions in step 7 of the READ ME. I doubt it will show anything of concern but I want to check anyway.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ooops! I take that back! Now I do see a few things in your newfiles.txt log which makes getting a HijackThis log even more important. Be sure to install and rename it properly.
     
  7. RenegadeT

    RenegadeT Private E-2

    I really appreciate your time and effort, here's the HJT log :cool
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    IBM 32-bit Runtime Environment for Java 2, v1.4.1
    Mozilla Firefox (2.0.0.5)

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4058/ftp.coupons.com/r3302/Coupons.cab
    O20 - Winlogon Notify: atiataxx - atiataxx.dll (file missing)

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  9. RenegadeT

    RenegadeT Private E-2

    I'm having difficulty removing the IBM Java.

    First of all, when I use the Windows Control Panel /Add or Remove Programs, it gives me the following error...
    [​IMG]

    So I try to uninstall with CCleaner, and I get this...
    [​IMG]

    No problem deleting Mozilla Firefox from CCleaner, I'm surprised though, arent we supposed to be using an alternate to IE?

    One more thing, it seems like every session, I get this random error...
    [​IMG]

    Sorry for the big ugly Alt/PrtScreen-->Outlook-->PDF-->JPEG pics. I'm going to bed. Will it be OK to proceed with the HJT and Avenger while running IBM Java? Thanks.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that! Part of my fix did not get pasted in. After the line which gave you a new Java to install, there should have been the below which is the current version of FireFox which you were not using.

    Install the current version of FireFox from: Mozilla Firefox

    Not sure what this is related to but errors like this are not normally malware related. They are more typically related to problems with your Windows OS. Do you have your Windows XP SP2 CD?
     
  11. RenegadeT

    RenegadeT Private E-2

    OK..will do

    I don't think my ThinkPad ever came with Win XP CDs. If it did, I can't find them.

    Should I start another thread in a different forum for that random GENERIC error? I can't un-install IBM Java. Should I go ahead and run HJT and Avenger as your post #8? I suppose I''l try.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First complete the rest of my fix from msg # 8 and then see if you can uninstall the old Java version using the below tool:

    Your Uninstaller! 2006
     
  13. RenegadeT

    RenegadeT Private E-2

    Latest Firefox...Installed

    DONE

    DONE

    DONE

    ATTACHED. It was still slow to boot up. I'll try the Uninstaller mentioned in Post#12, and will see how the computer is working.

    I haven't cleared System Restore yet.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is more than likely just due to software you are running. Symantec could be one of the biggest problems. However just to be on the safe side, let's check for rootkits.

    Now please download F-Secure's BlacklightBeta
    • Download fsbl.exe and save it to the Desktop.
    • Once saved... double click fsbl.exe to install the program.
    • Click accept agreement and Click scan
    • This application may trigger a warning from your antivirus. Let the driver load. Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.


    And you should not do this until I tell you to. ;)
     
  15. RenegadeT

    RenegadeT Private E-2

    Still having trouble removing IBM Java. I installed Your_Uninstaller, it gave errors when Uninstalling the IBM Java, but then said successful. But it is still there, I can see it from the CCleaner Uninstall window, and can run IBM Java from the Start Menu. It is no longer visible in the Your_Uninstaller window. I rebooted the computer a few times. All my work was done in Normal Boot Mode (ie not Safe Mode)

    Here's the windows I got when trying to uninstall IBM Java via Your_Uninstaller.
    First was the msiexec.exe - Application Error seen in Post#8, then these...
    [​IMG]
     
  16. RenegadeT

    RenegadeT Private E-2

    Nothing found, no warnings from Symantec, log attached.

    There was a Hacktool.Rootkit and a host of other viruses a few months ago. Re-installing Symantec and using the online help, we were able to get rid of everything, or so we thought.

    I don't need to keep Symantec. As a matter of fact, after finding this webpage, I was going to remove Symantec and try one of the "lighter" freewares. I just need to get the computer right first.

    As of now, I still can't access the Wireless network, Windows Firewall, Add/Remove Programs, Windows Security Center. Symantec Live Update also doesn't appear to be installing the latest definitions; even though I downloaded the latest, it is still showing 9/11/2007 Rev 16.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  18. RenegadeT

    RenegadeT Private E-2

    ...and there are 2 files that appeared on my desktop around the time when the computer went haywire.... javacore.20070907.001108.3356.txt and javacore.20070906.234234.5684.txt
    Both are 0 bytes in size, maybe that's why I can't attach them here.
     
  19. RenegadeT

    RenegadeT Private E-2

    I'm pretty sure I did everthing as you typed it. I'm not sure which program you're asking about here.

    Both the Windows Installer and http://windowsupdate.microsoft.com/ hang up when connected. Something's up with IE too. Like the manage attachments button is MIA in this forum, I had to use Firefox to attach the logs. I also can't use the lil smileys interface, I have to type them manually :(
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can just deleted those files.

    At one time did you have another firewall (other that Windows) installed? Like maybe Comodo Firewall? I'm wondering about this file: C:\WINDOWS\system32\drivers\CO_Mon.sys which appeared on July 30th. Can you put this file into a ZIP file and attach it here.
     
  21. RenegadeT

    RenegadeT Private E-2

    Nope, I never heard of Comodo til i got here. July 30th...that's around when the Hacktool.Rootkit and other viruses were finally "gone".

    And the drivers folder...hmmm, frequently the sound driver needs to be cycled thru a disable/enable in order to get real sound, instead of default beeps.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Were you able to get the new version of Sun Java installed?

    While I still don't know exactly what the co_mon.sys file is for, it does not appear to be a problem based on scanning it with 30 antivirus programs.
     
  23. RenegadeT

    RenegadeT Private E-2

    I didnt try to install the Sun Java since the IBM Java is still there. Should I go ahead try?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! It could help resolve some of the issues you have with Manage Attachments and other buttons including issue with running BitDefender and Panda. As stated in step 6 of the READ ME, you need to have a current version of Sun Java. You very old version will cause many problems with newer web pages and also is prone to Vundo infections while just being installed (that is it does not have to even be run).
     
  25. RenegadeT

    RenegadeT Private E-2

    OK, I downloaded the latest Sun Java to my desktop. It won't let me install it though. There are no errors, I get the hourglass when I dbl click it, or try to OPEN the .exe file from Explorer. The hourglass disappears after 20 seconds.

    I wanted to try it in Safe Mode as 'administrator', but something bizzare is going on with the login. I am not positive of my password, but I think I know which one I used. The incorrect ones, including <blank> deny me right away, but the one I think is right, it takes about 30 seconds to get the same window
     
  26. RenegadeT

    RenegadeT Private E-2

    Now I moved the Sun Java (jre-6u2-windows-i586-p.exe) to a folder on the C:drive, and it at least looks like it wants to install. I get the msiexec.exe - Application Error and Windows Installer error windows seen in Post#9
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I really belive that all of your remaining issues are problems within your Windows installation and not malware. You could be looking at needing a reinstall. You also really need to know what your Adminstrator account password is and you must never leave any account without a password since that is like opening the door of your car with the keys in the ignition and and leaving it unattended.

    Try the below and tell me what happens.

    Click Start, Run, and enter cmd and click OK. This will open a command prompt window.
    In the command prompt window enter the below command and tell me what happens:

    sfc /scannow
     
  28. RenegadeT

    RenegadeT Private E-2

    I get a Windows File Protection window
    It ran for about 10 minutes as the status bar moved to completion, and then it went away. That's all that happened.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When? Do you mean when you ran sfc and then sfc ran anyway?
     
  30. RenegadeT

    RenegadeT Private E-2

    Hmm, I guess it didn't go as planned?
    In the cmd.exe window, I typed sfc /scannow. Nothing else happened in the cmd.exe window, I instantly get an open prompt. At the exact same time I get that window. I can't alt/PrtScreen it for some reason.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to post a full list of all of your problems (which seem to be a lot) in the Software Forum. You don't have malware problems. You have problem within your Windows OS that needs to be repaired or reinstalled. Both of these are going to be rather difficult to do without a CD. If you don't have a Windows CD, do you have a recovery CD that came with your PC. You are going to need one of these CDs.

    One thing you may want to try just to see if it works is to create a new user account and check how things work when you log into the new account (assuming you can even create one - this may also fail to work).

    Also check to see if the C:\Windows\System32\rundll32.exe file exists.
     
  32. RenegadeT

    RenegadeT Private E-2

    Well I did have Malware, so all this wasn't a wasted effort. I'm not sure waht CDs I have either, all I found was MS Office CDs. I will head over to the software forum for further assistance. Thanks again for all the help.

    Yep still there, the date is pretty old, 8/4/2004
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    That date is normal! ;) I just wanted to make sure the file is there since many issues could occur if missing.


    Make sure you check out the below link:

    How to Protect yourself from malware!
     
  34. RenegadeT

    RenegadeT Private E-2

    Alright, I havent posted up in the Software Forum yet. Somehow, I got Windows Update working, and it installed 3 updates. My laptop seemes a lot better, but I still couldnt open the Control Panel/Security Center. I Un-installed Symantec and installed AVG. Then I re-installed my digi-cam software Koadk EasyShare. After the required reboot, I was getting the same errors as before; something was disabling Windows Firewall and also AVG...sometimes, the Firewall is now on and AVG is running.

    Anyways, I was able re-ran the compete list READ & RUN ME FIRST thread, could you take one another look at the logs? CounterSpy wouldnt run, so I used AVG instead (it had nothing to report)

    Everything seemed to run as described, except SHOWNEW. It gave me an error window (quoted below). I hit CANCEL a few times, then when I hit IGNORE, it finally ran.
     

    Attached Files:

  35. RenegadeT

    RenegadeT Private E-2

    GETRUNKEY and SHOWNEW logs
     

    Attached Files:

  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the download pages for both ShowNew and GetRunKey. This is one of the decribed possible errore messages that could occur due to problems within your Windows operating system. It also explained how to fixed it. Neither GetRunKey or ShowNew ran properly due to this error. You need to fix the error and then attach new logs.

    Did you look at your BitDefender log? It is loading with stuff from your Norton Quarantine which we asked you to empty in step 1 of the READ ME.
     
  37. RenegadeT

    RenegadeT Private E-2

    I'm so sorry, I definitley missed that link. Fixed the 16-Bit Error in the registry, re-ran GetRunKey and ShowNew, logs attached.

    Now, I'm positive I followed the link to clear my Symantec Quarantine before the first set of logs I did. I noticed all the Quarantine items when I ran BitDefender. I'm a little confused though; I uninstalled Symantec before this second round of logs. Can I just delete everything related to Symantec by hitting DELETE in WinExplorer?

    Thanks again, I really appreciate someone who knows their stuff looking at this, rather than me making an even bigger mess rolleyes
     

    Attached Files:

  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may have uninstall it; but Symantec often does not uninstall properly or completely so don't blame yourself. ;) Just check to see if the below folder exists. If it does then delete it:

    C:\Documents and Settings\All Users\Application Data\Symantec


    Also delete the below file:
    C:\WINDOWS\Temp\eG2

    Since you have gotten a few updates on your PC and some stuff appears to be running better, it may be worth a quick try to see if you can uninstall the below now:
    IBM 32-bit Runtime Environment for Java 2, v1.4.1


    You logs are fine other than what is mentioned above.
     
  39. RenegadeT

    RenegadeT Private E-2

    DONE
    I searched my hardrive for "Symantec" and found 3 hits
    #1-Folder C:\IBMTOOLS\APPS\NORTONAV\NAV\EXTERNAL\SYMANTEC
    Not much in this folder, but if I surf up to NORTONAN, there are some exe files in there.

    hits #2&3 are in C:\WINDOWS\Downloaded Program Files.
    Type=ActiveX Control, Status=Installed
    #2-Symantec AntiVirus scanner
    #3-Symantec RuFSI Utlity Class
    ...I think I'll right click/REMOVE these 2?


    DONE

    sweet...this didn't show up in Windows Add-Remove Programs, but CCleaner found it and seemed to uninstall it without a hiccup. We'll see how everything looks after a few reboots :cool

    Good to hear..and see my computer working better :)
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Files in this folder do not truly show in Windows Explorer. What you see does not represent what is really there. These are not really problems anyway but you may be able to get rid of at least part of this by having HijackThis fix the below lines which are really what you are seeing in the Downloaded Program Files folder.


    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab


    I'm happy to hear things are working better.
     
  41. RenegadeT

    RenegadeT Private E-2

    DONE

    Shall I toggle System Restore, per Step 8 of the READ & RUN ME thread?

    I still have DLL errors, Windows Firewall not booting up automatically and Kodak EasyShare software issues. I'll head over to the Softwear forum. Thanks for the help here. I've learned a great deal about my computer. :clap
     
  42. RenegadeT

    RenegadeT Private E-2

    What is supposed to happen with this? Its still acting the same.
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'll give you the normal speech given when we finish the malware removal process. ;) The link you have already seen is included.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    sfc = System File Checker. You can read about it here: http://support.microsoft.com/kb/310747

    Basically it is looking to see if certain protected system files are damaged or missing or are the wrong versions and attempts to fix the problem by using backup copies on your PC. Or if necessary it will ask for your Windows CD if it could not find any files it needs on your PC.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds