New Dude About To Cry!!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rottenjohnny, Apr 22, 2007.

  1. rottenjohnny

    rottenjohnny Private E-2

    Hi everyone, am new to this forum.Having a hard time removing some horrible malware. am attaching log files please help....
     

    Attached Files:

  2. rottenjohnny

    rottenjohnny Private E-2

    Also..
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    What ever you were attaching in the logfile.txt and history.txt files are not what we requested and are not needed.

    We need the logs from AVG AntiSpyware and PandaActiveScan as requested in the READ ME. Please attach them.

    Also you did not run BitDefender Online Scan as requested in step 6. You installed BitDefender 8 Antivirus. Now you are in conflict with step 3 of the READ ME. You must uninstall BitDefender 8 Antivirus now before continuing!

    Also you did not set you PC for Normal Startup (via MSconfig) as requested in step 0 of the READ ME. Select Normal Startup mode now and remain in that mode.

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)
    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of gebbaby.dll once and then click the kill button. After you have killed all of the gebbaby.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    mllmk.dll

    Next double click on explorer.exe and again click once on each instance of gebbaby.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    mllmk.dll

    Next double click on iexplore.exe and again click once on each instance of gebbaby.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    mllmk.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\gaajtqcw.dll (file missing)
    O2 - BHO: (no name) - {483CC496-D041-4545-8D9E-2D64294F97B2} - C:\WINDOWS\system32\gebbaby.dll
    O2 - BHO: (no name) - {5B9550EE-A9D0-4132-A833-17044DCD7FA1} - C:\WINDOWS\system32\mllmk.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\gfgpctnv.dll",setvm
    O20 - Winlogon Notify: gebbaby - C:\WINDOWS\SYSTEM32\gebbaby.dll
    O20 - Winlogon Notify: mllmk - C:\WINDOWS\system32\mllmk.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.2_04

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\gebbaby.dll
    C:\WINDOWS\system32\gfgpctnv.dll
    C:\WINDOWS\system32\mllmk.dll
    C:\WINDOWS\system32\bsicpwqq.dll
    C:\WINDOWS\system32\wvhbimcp.dll
    C:\WINDOWS\system32\kmllm.bak1
    C:\WINDOWS\system32\kmllm.bak2
    C:\WINDOWS\system32\qrjoljxp.tmp
    C:\WINDOWS\system32\gyytbyob.ini
    C:\WINDOWS\system32\kmllm.ini
    C:\WINDOWS\system32\nulnitrp.ini
    C:\WINDOWS\system32\vntcpgfg.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. rottenjohnny

    rottenjohnny Private E-2

    Hi chaslang, thanx for your help.Sorry for uploading wrong files, I cannot find Panda active scan or AVG files I will rerun them and attach files. I am still getting online pop ups (888.com only so far) just got a pop up from winantivirus while writing this and start up is still dragging. Here are the other files requsted.. Thanx
     

    Attached Files:

  5. rottenjohnny

    rottenjohnny Private E-2

    I have attached an AVG report that was done after Killbox and process explorer. I found the original Pandascan report after saving one i did after killbox and process exp i have attached both. sorry for doing it a bit backwards but i'm still quite new at this...
    Appreciate your help
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you undo the steps taken in step 2 of the READ ME to show hidden files and extensions? Please re-do step 2 again and do not changes this setting. If you did not change it then make sure you tell me.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Shutdown Ad-Aware's Ad-Watch.exe program before doing the below.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of gebbaby.dll once and then click the kill button.
    After you have killed all of the gebbaby.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs
    (If you do not find the dll, just continue on):
    jkhhh.dll

    Next double click on explorer.exe and again click once on each instance of gebbaby.dll and kill it.
    (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs
    (If you do not find the dll, just continue on):
    jkhhh.dll

    Next double click on iexplore.exe and again click once on each instance of gebbaby.dll and kill it.
    (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs
    (If you do not find the dll, just continue on):
    jkhhh.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\rjoehblv.dll
    O2 - BHO: (no name) - {27FE085A-F5AB-4938-9BCD-8409B4290C67} - (no file)
    O2 - BHO: (no name) - {483CC496-D041-4545-8D9E-2D64294F97B2} - C:\WINDOWS\system32\gebbaby.dll
    O2 - BHO: (no name) - {ABAB1BF7-6AAF-48D8-B55E-B7C9308D97D1} - C:\WINDOWS\system32\jkhhh.dll
    O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\pxjlojrq.dll",setvm
    O20 - Winlogon Notify: gebbaby - C:\WINDOWS\SYSTEM32\gebbaby.dll
    O20 - Winlogon Notify: jkhhh - C:\WINDOWS\system32\jkhhh.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\cujbunun.dll
    C:\WINDOWS\system32\bsicpwqq.dll
    C:\WINDOWS\system32\gebbaby.dll
    C:\WINDOWS\system32\hhhkj.bak1
    C:\WINDOWS\system32\hhhkj.bak2
    C:\WINDOWS\system32\hhhkj.ini
    C:\WINDOWS\system32\iblpqfbc.dl
    C:\WINDOWS\system32\jkhhh.dll
    C:\WINDOWS\system32\pxjlojrq.dll
    C:\WINDOWS\system32\rjoehblv.dll
    C:\WINDOWS\system32\vckqfggj.dll
    c:\windows\smdat32m.sys
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\Softwin\BitDefender8
    c:\program files\Need2Find
    c:\windows\cdmxtras

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. rottenjohnny

    rottenjohnny Private E-2

    Hi chaslang,
    I did undo step 2 to see if it would improve start up time and then forgot to reset it. Have done all tasks everything went fine. Going to see if alls well now and will let you know if there's any problems. Am attaching logs you requested...
     

    Attached Files:

  9. rottenjohnny

    rottenjohnny Private E-2

    Have been running some programs and on the net all appears to be well...
     
  10. rottenjohnny

    rottenjohnny Private E-2

    Have just noticed something called Privacy Protector popping up at startup and there's an icon for it on my desktop. I didnt download it
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have a Vundo infection! This is the main item we have been working on removing. It keeps coming back. This normally happens due to three possible reasons:
    • your infection changed inbetween the posting of your logs and the time a fix was posted for you and you running the fix. Thus the fix would not get everything
    • more surfing/downloading was performed on bad websites
    • removal instructions not being followed exactly
    Yes I see it. It is new and just showed up today ( April 24 th ). It looks like someone or something installed it since it is in Add/Remove programs. First try going to Add/Remove programs and see if it will uninstall. I will leave steps for manual removal in my instructions below just in case it does not uninstall.


    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of jkhhh.dll once and then click the kill button. After you have killed all of the jkhhh.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    eovvremi.dll

    Next double click on explorer.exe and again click once on each instance of jkhhh.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    eovvremi.dll

    Next double click on iexplore.exe and again click once on each instance of jkhhh.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    eovvremi.dll

    Now just exit Process Explorer.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\Program Files\PrivacyProtector Free\UPRP.exe
    C:\Program Files\PrivacyProtector Free\uprpcw.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\eovvremi.dll
    O2 - BHO: (no name) - {27FE085A-F5AB-4938-9BCD-8409B4290C67} - (no file)
    O2 - BHO: (no name) - {D5F9D109-F09B-4AF9-9818-30F8A7AC3E22} - C:\WINDOWS\system32\jkhhh.dll
    O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\pxjlojrq.dll",setvm
    O4 - HKLM\..\Run: [PrivacyProtector Free] "C:\Program Files\PrivacyProtector Free\UPRP.exe" /min
    O4 - HKLM\..\Run: [uprpcw] "C:\Program Files\PrivacyProtector Free\uprpcw.exe" -c
    O20 - Winlogon Notify: jkhhh - C:\WINDOWS\system32\jkhhh.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Program Files\PrivacyProtector Free\UPRP.exe
    C:\Program Files\PrivacyProtector Free\uprpcw.exe
    C:\Documents and Settings\Paul Mc Clafferty\Desktop\PrivacyProtector Free.lnk
    C:\WINDOWS\system32\afctwpdk.dll
    C:\WINDOWS\system32\eovvremi.dll
    C:\WINDOWS\system32\iblpqfbc.dll
    C:\WINDOWS\system32\hhhkj.tmp
    C:\WINDOWS\system32\jkhhh.dll
    C:\WINDOWS\system32\pxjlojrq.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.
    After reboot locate the below folder and delete if found:
    C:\Program Files\PrivacyProtector Free
    C:\Documents and Settings\Paul Mc Clafferty\Application Data\PrivacyProtector Free

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    IMPORTANT: Do not power down or reboot your PC now. You must keep it running while waiting for me to post the next steps! You can physically unplug your cable to the internet for security while waiting but you must not reboot or power down
     
  12. rottenjohnny

    rottenjohnny Private E-2

    Hi chaslang..have completed all steps. I did power down and reboot computer yesterday don't know if that affects this attempt. Anyway here are requested logs Thanx..
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are basically clean now. You just forgot to delete one folder. Delete the below:

    C:\Documents and Settings\Paul Mc Clafferty\Application Data\PrivacyProtector Free


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds