please take a look at my logs... malware removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by FredMadison, Sep 10, 2006.

  1. FredMadison

    FredMadison Private E-2

    hi there,

    long time lurker, first time poster!

    i read the sticky about logging everything first and THEN posting, so i've attached all my logs after following the instructions to the letter.

    someone got a little crazy downloading torrent files :mad: and now i have trojans and other nasties.

    system is a barebones that i built, WIN XP SP2, 2GB RAM, 2.8GHz Celeron, ASUS Mobo, 40GB HDD (boot drive) and 200GB secondary drive, partitioned as E:, F:, G:.

    i have plenty of computer experience (building, reg-editing, etc.) and i think i know most of what needs to be done, but i don't know everything... so that's where you guys come in! :)

    please have a look and let me know what you would do (besides not downloading torrent files! LOL)

    thanks in advance
    FM
     

    Attached Files:

  2. FredMadison

    FredMadison Private E-2

    here are the other 2 logs

    thanks!
    FM
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You had MSconfig disabling various startups when you got the log from GetRunKey. Please makes sure you are now set to Normal Startup mode (not Selective Startup).

    Did you knowingly install DeluxeCommunications? This is malware as far as I know.

    Goto Add/Remove programs and uninstall the below:
    BearShare
    DeluxeCommunications
    J2SE Runtime Environment 5.0 Update 6

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Now make sure you are in Normal Startup mode and attach new logs from GetRunKey and HijackThis.
     
  4. FredMadison

    FredMadison Private E-2

    ok, here ya go... i had already deleted Bearshare and Deluxe Communications (no i didn't install DC, it was hidden in a torrent i'm sure.)

    installed new JRE. new files attached.

    thanks!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    DO you know what the below file is for?
    O20 - AppInit_DLLs: dxclib303562752.dll

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (if found):

    C:\Documents and Settings\Administrator\Local Settings\Temp <--- delete all files in this Temp folder
    E:\Program Files\MixmanStudioDemo.exe
    C:\Program Files\Common Files\{24315E18-0AF0-1033-1226-050111020001}\Update.exe
    C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\chrome\whenu_ff.jar
    C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\components\whenu_ff.dll
    C:\Program Files\Mozilla Firefox\plugins\npclntax.dll
    E:\WINDOWS\SYSTEM\SBUtils\SBWinet.dll
    E:\WINDOWS\SYSTEM\SBUtils\SBWebCtl.dll
    c:\windows\system32\WinNB58.dll
    C:\WINDOWS\system32\bkd.exe
    C:\Program Files\BearShare <--- the whole folder
    C:\Program Files\DeluxeCommunications <--- the whole folder
    c:\program files\MyGlobalSearch <--- the whole folder
    C:\Program Files\Common Files\{24315E18-0AF0-1033-1226-050111020001} <--- the whole folder
    C:\WINDOWS\system32\crunner <--- the whole folder
    E:\WINDOWS\SYSTEM\SBUtils <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode and attach new logs from HJT and from ShowNew.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. FredMadison

    FredMadison Private E-2

    ok, done. logs attached...

    i have no idea what O20 - AppInit_DLLs: dxclib303562752.dll is for. :confused:

    a couple other things. just today, AV scan at bootup, AVG AV found Trojan Horse Dowloader.Generic2.DFK in C:\ProgramFiles\InetGet2\eltadperf.exe. I quarantined it. The file was moved to the virus vault, and I deleted the empty remaining folder. I didn't see anything about it in the Runkeys, Shownew or HJT logs.

    also, when i open a browser window in Firefox, i've now lost the bottom 25% of the window, which is just white space now. also, when i clicked on the 'Manage Attachments' button here at MG, it wouldn't do anything. maybe i deleted a file by accident? not sure if this is related, but thought i would mention it. (this does not happen in IE, which i am responding from now.)

    besides that and the new Trojan discovered, everything is running fine. No popups, etc. thanks for the help. let me know what you think.

    FM
     

    Attached Files:

  7. FredMadison

    FredMadison Private E-2

    ...from previous post

    [also, when i open a browser window in Firefox, i've now lost the bottom 25% of the window, which is just white space now. also, when i clicked on the 'Manage Attachments' button here at MG, it wouldn't do anything. maybe i deleted a file by accident? not sure if this is related, but thought i would mention it. (this does not happen in IE, which i am responding from now.)]

    for anyone else reading this post and having this problem, the bottom of the screen in Firefox (where it shows the URL address in the bottom left corner) seems to have 'jumped up' creating a 'dead zone' with no text except for a red ^ on the left hand side. left and/or right clicking in this area does nothing.

    problem fixed. i downloaded Firefox again and installed it right on top of the old one. then i clicked Tools/Extensions and saw that WhenU was installed. i uninstalled it, closed and restarted Firefox and the bottom of the screen has returned and the 'Manage Attachments' button on MG works. i don't know if this is 'THE fix' but it worked for me.

    is WhenU part of Firefox? i find that hard to believe...

    anyway, thought i would update the post before you spent any time on this issue.

    thanks.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Take a look back at the fix I gave you in message number 5. I had these lines:
    That was WhenU. It is malware and we were unhooking it from FireFox.

    Look for this file and delete if found:
    C:\windows\system32\dxclib303562752.dll

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  9. FredMadison

    FredMadison Private E-2

    yes, i understand that. but AFTER i had removed WhenU via your two lines, when i reinstalled Firefox, it said that WhenU was installed. that's what made me wonder about WhenU being included in Firefox.

    that dxclib303...exe file was not in \System32 to be deleted. i searched the drive as well, and it could not be found.

    i turned off System Restore/rebooted/then re-enabled System Restore.

    the only thing that i'm concerned about now is that Trojan that was just found today. i was able to quarantine (and delete) it as soon as i booted up today, but i makes me wonder how it got there. i'll keep an eye out...

    thanks so much for the help. really.
    FM
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know where you are getting it from. That folder did not show in your ShowNew log so it was either not there at the time of your scan or it was there for longer than 90 days (which is the date at which I cut off the scan for new files). Your PC is not properly protected until you complete the How to protect thread. You did not even have a real firewall installed.
     
  11. FredMadison

    FredMadison Private E-2

    firewall is on the router. would you suggest a local FW as well?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Didn't you read step 3 of the How to protect thread? One part of it says:
     
  13. FredMadison

    FredMadison Private E-2

    I hadn't gotten that far yet.

    Is this what they call the 'Good Major/Bad Major' routine?

    SW FW installed. Sir. :)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    LOL! Read faster! :D
     
  15. FredMadison

    FredMadison Private E-2

    thanks again for the help. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds