Popping websites and IE browser redirecting

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by winterlove, Dec 10, 2006.

  1. winterlove

    winterlove Private E-2

    Hi, I have already read the "READ & RUN ME FIRST" and follow all the steps to remove malwares from my computer. However, my computer is still giving me websites pop ups and the IE browser will redirect me to another page whenever I visit a new site. I suspect I got this virus when I click on a particular website link and many websites start popping up. I already tried many other antispy and antivirus applications for the past week but I am still experiencing the same problem. I am still not really sure whether it's a virus or malware problem so I really need some help here. Thanks for helping.

    Below are some of the attachments required.
     

    Attached Files:

  2. winterlove

    winterlove Private E-2

    My runkeys txt look very weird, I already read through the instructions a few times, if I did anything wrong, please let me know because I am not really good at computer.
     

    Attached Files:

    Last edited: Dec 10, 2006
  3. winterlove

    winterlove Private E-2

    I don't know why my runkeys txt is separated into 10 different files. I will still attach the rest of the runkeys txt anyway.
     

    Attached Files:

  4. winterlove

    winterlove Private E-2

    My hijackthis attachment.

    Thank you.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These files are temporary files that GetRunKey creates while building the final log. We DO NOT want these intermediate temporary files created by GetRunKey. We only want the final runkeys.txt log as requested. If this log is not being created, you must tell us. Also make sure that you are not getting any error message in the command prompt window. Some possible error message are mentioned in the download link and it also tells you how to fix the problem if you are getting those error message.

    You also need to make sure not errors are occurring while running SHowNew because it did not run properly either. It could be that your malware issues are causing these problems with ShowNew and GetRunKey failing to run properly.

    It sounds like you may have a rootkit infection. Please download Blacklight Beta
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please post contents of the BlackLight log.

    Then continue onto the below.

    Start by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\WINDOWS\system32\com\lsass.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - Default URLSearchHook is missing
    O2 - BHO: Class - {0386D421-98BD-0323-3FA8-ED1C427590DC} - C:\WINDOWS\xcrkn1.dll
    O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
    O3 - Toolbar: (no name) - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - (no file)
    O4 - HKLM\..\Run: [Configurations Loader] winrtx.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\RunServices: [Configurations Loader] winrtx.exe
    O4 - Startup: ~(2).pif = ?
    O18 - Protocol: mp3 - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - (no file)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\xcrkn1.dll
    C:\WINDOWS\system32\com\lsass.exe
    C:\WINDOWS\SYSTEM32\Com\SMSS.EXE
    C:\WINDOWS\SYSTEM32\winrtx.exe
    C:\WINDOWS\SYSTEM32\PFPLGSCN.DLL
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!


    You also need to tell me if the below items are all valid (do you recognize all of them as things you installed and use)??
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://clubbox.co.kr/xiaomao123
    O4 - HKLM\..\Run: [Ëæ±ãÁÄÁÄ] C:\Program Files\IMU\MiniChat\chatatwill_5.exe
    O4 - HKLM\..\Run: [IMU¼´Ê±Í¨Ñ¶] C:\Program Files\IMU\imu.exe
    O4 - HKLM\..\Run: [Krixvsax] C:\Program Files\Bjltu\Jypwmn.exe
    O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) - http://www.clubbox.co.kr/neo.fld/NowStarter.cab
    O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
    O16 - DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} (Tpwin Control) - http://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB
    O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/1007/aliedit.cab
    O16 - DPF: {4B48CEDD-EB09-4FD3-AA22-5BDE98EDEF90} (EZXSActiveX Control) - http://www.buykorea.org/buykorea/front/ezxssso/install/ezxsactivex.cab
    O16 - DPF: {6D3E22C5-8087-41DE-A898-6B5E44677DAA} (HDMediatPrint Control) - http://www.humandream.com/dbook/release/HDMediaPrint.cab
    O16 - DPF: {79C871A6-F9C8-44DA-B2C9-CD9438D9642C} (EZXSInstaller Control) - http://www.cybermartkorea.com/standing/front/ezxssso/install/ezxsinstaller.cab
    O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://cont.cybermartkorea.com/cabfiles/msxml4.cab
    O16 - DPF: {938527D1-CDB7-4147-998A-B20FCA5CC976} (Cdmcco Class) - http://cafeimg.hanmail.net/cab9_1/dmcc2.cab?Version=1,0,0,10
    O16 - DPF: {C296DB5F-4B01-47E1-AB57-C590BE769111} (MOPlayerWnd Class) - http://www.melon.com/cab/P3Melon.cab
    O16 - DPF: {D25EF28B-1CC5-466F-99A3-0212DEC394B5} (AnnYoung_Player) - http://www.kpoppop.com/download/WAVAA_Player.cab
    O18 - Protocol: NetCat - {9D8327E1-E57C-46DC-A50A-980A2F8DE064} - C:\Program Files\AsiaFans\AsiaFansPlug.dll (file missing)


    If you don't recognize any of them, tell me which ones.
     
    Last edited: Dec 12, 2006
  6. winterlove

    winterlove Private E-2

    when I first run ShowNew and GetRunKey I received the error message something like "The system file is not suitable for running MS-DOS and Microsoft Window applications" so I downloaded "XPHomeFix" and unzip it. After that I run the ShowNew, I only got 1 newfiles.txt (with no more error message), and for running GetRunKey, I got xmodul.txt, xmscfg.txt, and many xrkey.txt (also no error message but I didn't get a final runkeys.txt log)

    Here's the BlackLight log attachment.
     

    Attached Files:

  7. winterlove

    winterlove Private E-2

    I can't seem to remove the following process from the process list, no matter how many times I click on the "kill process".

    C:\WINDOWS\system32\com\lsass.exe
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just continue on with the rest of the steps! Make sure you re-read or redownload the steps. I added another file to the list of things to delete with Pocket Killbox.


    Also make sure you answer my question about that list I gave you at the end of the procedure!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where did you extract the files from XPHomeFix too? Did you extract them to the C:\windows\system32 folder? If not, that is where they have to go.

    I don't know where you extracted GetRunKey to but I will assume you did something like you did with ShowNew. Thus the below is based on this assumption.

    • Click Start, Run and enter cmd and click OK. This will open a command prompt window.
    • Enter the below command at the command prompt
      • cd "C:\Downloads\getrunkey extracted\"
      • GetRunKey.bat
    • Tell me what error messages if any you see in this window.
     
    Last edited: Dec 12, 2006
  10. winterlove

    winterlove Private E-2

    I did all the steps.
    When fixing with HijackThis, I got an error message "Unexpected error occured, Error #52 (Bad file name or number) in Sub GetLongPath (?.exe)"

    Deleting files with Pocket Killbox done.

    Attached HJT log.

    Ok, I got the runkey.txt by following your instructions (Should be the right one I hope)

    After conducting all the steps, my IE browser is still popping up websites and redirecting me to another website.

    I am only using this:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://clubbox.co.kr/xiaomao123

    For the rest below, I am not using them at all, don't remember installing them actually:

    O4 - HKLM\..\Run: [Ëæ±ãÁÄÁÄ] C:\Program Files\IMU\MiniChat\chatatwill_5.exe
    O4 - HKLM\..\Run: [IMU¼´Ê±Í¨Ñ¶] C:\Program Files\IMU\imu.exe
    O4 - HKLM\..\Run: [Krixvsax] C:\Program Files\Bjltu\Jypwmn.exe
    O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) - http://www.clubbox.co.kr/neo.fld/NowStarter.cab
    O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
    O16 - DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} (Tpwin Control) - http://www.crezio.com/test/leeyunho/...n/AlwaysOn.CAB
    O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/1007/aliedit.cab
    O16 - DPF: {4B48CEDD-EB09-4FD3-AA22-5BDE98EDEF90} (EZXSActiveX Control) - http://www.buykorea.org/buykorea/fro...zxsactivex.cab
    O16 - DPF: {6D3E22C5-8087-41DE-A898-6B5E44677DAA} (HDMediatPrint Control) - http://www.humandream.com/dbook/rele...MediaPrint.cab
    O16 - DPF: {79C871A6-F9C8-44DA-B2C9-CD9438D9642C} (EZXSInstaller Control) - http://www.cybermartkorea.com/standi...sinstaller.cab
    O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://cont.cybermartkorea.com/cabfiles/msxml4.cab
    O16 - DPF: {938527D1-CDB7-4147-998A-B20FCA5CC976} (Cdmcco Class) - http://cafeimg.hanmail.net/cab9_1/dm...rsion=1,0,0,10
    O16 - DPF: {C296DB5F-4B01-47E1-AB57-C590BE769111} (MOPlayerWnd Class) - http://www.melon.com/cab/P3Melon.cab
    O16 - DPF: {D25EF28B-1CC5-466F-99A3-0212DEC394B5} (AnnYoung_Player) - http://www.kpoppop.com/download/WAVAA_Player.cab
    O18 - Protocol: NetCat - {9D8327E1-E57C-46DC-A50A-980A2F8DE064} - C:\Program Files\AsiaFans\AsiaFansPlug.dll (file missing)
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now you have both ShowNew and GetRunKey logs correct. What were you doing wrong? Was it because you did not put the files for XPHomeFix into the correct folder? Or were you not running the .bat files from an Windows Explorer session. Whatever it was, they are good now.

    It looks like you may have a Gromozon Rootkit infection. You also may not have this infection. You appear to have a least one sign of it in your logs (the StrongestOptimizer program that is installed), so let's go under the assumption that you have it and run a fix for it. This can be quite nasty and difficult to remove. Let's give the below tool a run and hope that it can fix the problems.

    Gromozon Rootkit Removal Tool

    Let me know what it reports!

    Then use HijackThis to fix all of these lines.

    You should move all of those RMV, WMA, WMV, MP3, & MP4 files out of your root folder (that is C:\ ) and store them some place appropriately named for what they are. This is not a good location to save them and makes a great way for malware to hide itself.


    Now Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10

    Now install the current version of Sun Java from: Sun Java Runtime Environment


    Attach a new HJT log now. Also attach a new log from ShowNew.
     
    Last edited: Dec 12, 2006
  12. winterlove

    winterlove Private E-2

    Actually I am sure that the pop ups went off for a while after running Gromozon Rootkit Removal Tool for the first time (I tried visiting different web pages and it was all good) but after I download Sun Java, run HJT and Shownew logs, the pop ups came back again……..weird

    For the running of ShowNew, I guess I did not put the files for XPHomeFix into the correct folder at first. When I re-extract everything, it works.

    When I was running Gromozon Rootkit Removal Tool , there was a message “Trojan. Gromozon rootkit component was not found on system”, but I continue the scan anyway. Then, while it was scanning, the scanning logs shows “Gromozon rootkit component not detected- searching for other component.” Then the program hangs my computer at the “scanning the windows directory” part (so it didn’t finish the whole scanning process), I had to restart my computer. I rescan again and this time it finished the scanning process and it’s says “Trojan.Gromozon does not exist - your system is clean.”

    I also moved all the Mp3/RMV files to the documents folder.

    I also use HijackThis to fix all of those lines.

    New Sun Java installed.

    Actually my kaspersky antivirus keeps on warning me about something like “not found: Trojan program Trojan.Win32.VB.avf File: C:\WINDOWS\system32\com\smss.exe//FSG” and I can’t delete this detection too. (just for your information)

    Attached HJT logs and Shownew logs
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the current log it created: C:\gromozon_removal.log


    Goto Add/Remove Programs and uninstall StrongestOptimizer

    If it will not uninstall or if you do not find it, make sure you tell me.

    We were cleaning stuff out of that folder a while back. See if you can delete the whole C:\WINDOWS\system32\com folder. Boot into safe mode to delete it if necessary. If you cannot delete the folder, write down all the file names you see in this folder and feed them into Pocket Killbox to delete like we did in message number

    Example names to give to Killbox:
    C:\WINDOWS\system32\com\smss.exe
    C:\WINDOWS\system32\com\lsass.exe

    After deleting all the files (if they all delete) with Killbox. Can you now delete the folder?

    • If not, run Pocket Killbox and click Options and select Remove Directories.
    • Then paste in the C:\WINDOWS\system32\com folder check Delete on Reboot and End Explorer Shell While Killing File
    • Click the red-and-white X ( Delete File ) button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue

    If Killbox does not reboot just reboot your PC yourself.

    After reboot is the C:\WINDOWS\system32\com folder gone?
     
  14. winterlove

    winterlove Private E-2

    I just realised something. Actually, once I got on the computer, before I do anything else, I switched off counterspy and kasper antivirus (because I think I switch off the counterspy and antivirus program the other time when I was scanning with gromozon_removal, so I decided to switch off my antivirus program again and true enough, the pop ups never came up, everything was fine until I opened my C:\ folder, the pop ups start to appear).

    I can find StrongestOptimizer but I cannot remove it from the program list. It will bring me to another website when I click on the uninstall tab. Then, at the empty website there’s another uninstall button, when I click on it nothing happen and StrongestOptimizer still cannot be removed. When I tried uninstalling at safe mode (without any internet connection), it brings me to the webpage address (vod.21cnyl….) where the pop ups came from. So I suspect this StrongestOptimizer could actually be the problem causing the pop ups, I am not sure though.

    Used Pocket Killbox to delete items from C:\WINDOWS\system32\com folder, also tried deleting in safe mode, even tried deleting the whole directory on reboot, everything went fine, but the folder is still there, argh......


    Here's the gromozon_removal.log and thanks for all the help up till now, hopefully the malware can be removed soon....
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Download GMER and extract it to the C:\program files\GMER folder.
    • Run the Gmer.exe program by double-clicking the executable file (gmer.exe) in Windows Explorer.
      You may be prompted to scan immediately if GMER detects rootkit activity.
      • If you are prompted to scan your system click "yes" to begin the scan.
      • If you are not prompted, Click the "Rootkit" tab, then click "Scan".
    At the end of the scan, click "Copy" to copy the scan results to the clipboard. Then paste the results in a notepad file and save them to a file like GMER.txt. Then attach the file here.

    Also try running the below to uninstall StrongestOptimizer

    Your Uninstaller! 2006

    Did that work?
     
  16. winterlove

    winterlove Private E-2

    I already scanned computer with GMER and the GMER.txt is attached below.

    Also finished running Your Uninstaller! 2006, StrongestOptimizer is successfully deleted.

    I guess the pop ups are now slower in action (most are being blocked off by the pop-ups blocker), though they are still trying to pop up when I visit some websites. I can still see the pop ups website address going on in the IE status bar.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    1. Please download The Avenger by Swandog46 to your Desktop.
    • Click on Avenger.zip to open the file
    • Extract avenger.exe to your desktop
    2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
    Code:
     Files to delete:
    C:\WINDOWS\system32\com\smss.exe
    C:\WINDOWS\system32\com\lsass.exe
    
     
    Folders to delete:
    C:\WINDOWS\system32\com
    Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

    3. Now, start The Avenger program by clicking on its icon on your desktop.
    • Under "Script file to execute" choose "Input Script Manually".
    • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
    • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
    • Click Done
    • Now click on the Green Light to begin execution of the script
    • Answer "Yes" twice when prompted.
    4. The Avenger will automatically do the following:
    • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
    • On reboot, it will briefly open a black command window on your desktop, this is normal.
    • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
    • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
    5. Please attach the c:\avenger.txt too your next reply!


    Now run Gmer again and attach a new log from it too.
     
  18. winterlove

    winterlove Private E-2

    Did all the steps.

    Attached avenger.txt and Gmer log.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's strange! Avenger deleted the files and the folder but yet it is back now in the GMER log. I wonder when it came back. Another file on your system must be respawning this. It could even be a valid system file that is infected. I would like you to repeat the same process with Avvenger and GMER but this time start by physically unplugging your cable to the internet and keep it unplugged while running Avenger and GMER. After completing that process, reconnect your cable and attach the new logs.

    If you don't see the C:\WINDOWS\system32\com\lsass.exe or C:\WINDOWS\system32\com\smss.exe mentioned in the GMER log. Then now after reconnecting your cable, check (run Windows Explorer) to see if you can actually see these files and folder.


    Also now Please download ProcessExplorer
    • Unzip it to its own folder somewhere you can locate it.
    • Make sure that ONE and only one Internet Explore browser session is open.
    • Now run procexp.exe by double clicking on it.
    • Let's configure some options first:
      • Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked.
      • Now click on iexplore.exe.
      • Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    • Now click on File and then Save As. And save the process list. Call this one iexplore.txt
    • Post it back here as an attachment.
    Now repeat the above procedure but select explorer.exe instead of iexplore.exe and save a new log call this one explorer.txt

    Attach the iexplore.txt and explore.txt logs!
     
  20. winterlove

    winterlove Private E-2

    I still see C:\WINDOWS\system32\com\lsass.exe mentioned in the GMER log, then when I run windows explorer, C:\WINDOWS\system32\com folder is still there, and inside the folder there's still the lsass.exe and smss.exe files.

    Finished running procexp.exe with one IE browser opened

    Attached all the relevant files.
     

    Attached Files:

    Last edited: Dec 15, 2006
  21. winterlove

    winterlove Private E-2

    Attched explorer.txt
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I found a few more files in your logs related to this and I'm also including some others in the list to delete just in case the do exist. Follow the steps below with a new set of files for Avenger to remove. Shutdown ALL unnecessary process before doing the below.

    1. Run Process Explorer and look to see if the two below process are running. If so, right click on them and select Kill Process. Make sure you look at the path info and only kill the ones in C:\WINDOWS\system32\com\

    C:\WINDOWS\system32\com\smss.exe
    C:\WINDOWS\system32\com\lsass.exe

    2. Copy all the text contained in the quote box below to your Clipboard by highlighting it and pressing (Ctrl+C):
    Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

    3. Now, start The Avenger program by clicking on its icon on your desktop.
    • Under "Script file to execute" choose "Input Script Manually".
    • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
    • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
    • Click Done
    • Now click on the Green Light to begin execution of the script
    • Answer "Yes" twice when prompted.
    4. The Avenger will automatically do the following:
    • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
    • On reboot, it will briefly open a black command window on your desktop, this is normal.
    • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
    • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
    5. Please attach the c:\avenger.txt too your next reply!

    Now run Gmer again and attach a new log from it too.

    Now Download & extract the current version of ShowNew (just updated): Using ShowNew

    Now attach new logs from HJT & ShowNew.
     
    Last edited: Dec 16, 2006
  23. winterlove

    winterlove Private E-2

    Did all the steps, everything went on fine.

    Attached all the required files.
     

    Attached Files:

  24. winterlove

    winterlove Private E-2

    I think the computer is working on fine now. No pop ups and redirecting of IE browser up till now. Thanks a lot for your help.

    Attached HJT log.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks a lot bette!

    Okay let's fix some items that I inadvertantly had you remove while trying to fix this nasty infection.

    Move the below files from the C:\!Killbox folder back to the C:\WINDOWS\System32\com folder
    comexp.msc
    comrereg.exe
    comempty.dat
    mtsadmin.tlb
    comrepl.exe
    comadmin.dll


    After you do this, attach a new log from ShowNew so that I can be sure they all were moved okay before I give you final cleanup steps!
     
  26. winterlove

    winterlove Private E-2

    Files moved to the C:\WINDOWS\System32\com folder.

    Shownew log attached
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good job! If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  28. winterlove

    winterlove Private E-2

    Sorry for troubling you again.

    I don't know how the pop ups came back again. My computer was working fine yesterday, but today the pop ups came back again. I quickly use system restore to restore my computer to yesterday date and so far the pop ups didn't appear. I am just a little worried that the malware is still lurking around so I am attaching my recent HJT log again for you to take a look(if you need any other logs just let me know).

    I believe the pop ups came back could be due to 2 reasons. The first reason, I redownloaded and install the recent Sun Java (because I think I put the wrong settings when counterspy prompt me whether to block one of the process and I suppose it's from the Java process, so the one I installed was not working properly. I reinstalled it, then when the counterspy and kasperantivirus prompt me about those processes/actions on my internet settings I just allowed it, then I restart my computer, the pop ups start to appear). The second reason, I plugged in my ipod after restarting my computer (could it be possible my ipod drivers got infected somehow? because I got this infection when my ipod was still connected to my computer)

    Then I check the counterspy active protection list and I think it's trying to block something like this process again "Startup: ~(2).pif = ?"
     

    Attached Files:

    Last edited: Dec 18, 2006
  29. winterlove

    winterlove Private E-2

    Kaspersky antivirus is warning me about this
    Process C:\Program Files\Internet Explorer\iexplore.exe (PID: 3336): attempt to perform suspicious actions was blocked.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is nothing in your HJT log of concern. The only item there that I still wonder about was there last time. What is this:
    O16 - DPF: {A8C3B40D-5384-44AD-ACC4-504B4D8A85F5} (BoBo P2P???????/??/???? V2) - http://www.17bobo.com/Software/BoBo_ActiveX_V2.ocx



    Installing Sun Java itself would not cause you to get infected. It is a clean application. Whether something else was able to sneak in while installing and configuring......well anything is possible because you seem to have something lurking in the background.

    I don't really know for sure but yes it is possible that you have something on your iPod that could be infecting your PC.

    Yes this is one of the items related to the infection and was in your previous HJT log and it was one of the items I was having you fix and also I was trying to delete the file.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I had wondered whether Internet Explorer and or Windows Explorer (explorer.exe) had something attached to them. That is why I had you get those logs with Process Explorer.

    Have you tried having Kaspersky do a scan on C:\Program Files\Internet Explorer\iexplore.exe and also on c:\windows\explorer.exe ? If not please do so. Are your definitions up to date? See: Kaspersky Anti-Virus Update

    Also run those two files thru the below online scanner (just click the Browse button and navigate to the files on your PC to scan them).

    http://virusscan.jotti.org/

    Copy and paste the output of the scans into your next message. It does not create logs for you, so you will have to use copy & paste.


    Did I ask you how you connect to the internet (cable, DSL, dial-up) and whether you have a router? Please answer again anyway. If you do not have a router and you use cable or DSL, you really need a router. There are just too many problems out there and the added layer of protect provide by a hardware firewall in a router is really useful.


    Does the below file actually exist on your PC?
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
     
  32. winterlove

    winterlove Private E-2

    O16 - DPF: {A8C3B40D-5384-44AD-ACC4-504B4D8A85F5} (BoBo P2P???????/??/???? V2) - http://www.17bobo.com/Software/BoBo_ActiveX_V2.ocx
    For this item from the HJT log, I don’t think I ever installed that, I am not using it too, maybe I should just delete it.

    Scan with Kaspersky on those 2 files, no threats detected.

    Scan the 2 files with http://virusscan.jotti.org/, no virus detected.

    Scanner results
    AntiVir Found nothing
    ArcaVir Found nothing
    Avast Found nothing
    AVG Antivirus Found nothing
    BitDefender Found nothing
    ClamAV Found nothing
    Dr.Web Found nothing
    F-Prot Antivirus Found nothing
    F-Secure Anti-Virus Found nothing
    Fortinet Found nothing
    Kaspersky Anti-Virus Found nothing
    NOD32 Found nothing
    Norman Virus Control Found nothing
    VirusBuster Found nothing
    VBA32 Found nothing

    I think I am suppose to look at the “Scanner results” right? Or the “Statistics” section (this site is a bit confusing)?

    I am connecting by cable broadband. Yes, I am using an “Ethernet Broadband Router”, I am not too sure whether the hardware firewall is on though (most probably it’s on) because the settings are configured by my brother, I will have to ask him again.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes have HJT fix that line!

    Only the scanner results! As long as they came up clean then all is good.

    Make sure it has a firewall and make sure it is enabled.


    Download the current version of GetRunKey. Then attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
     
  34. winterlove

    winterlove Private E-2

    Attached Files:

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't see any problems in any of your logs! Perhaps what Kaspersky was calling suspicious was nothing more than just a home page or some other kind of setting change that you were making.
     
  36. winterlove

    winterlove Private E-2

    I came back just to say "Thank you".
    I think the reoccurance of the pop ups is due to my ipod, maybe it just got affected somehow, anyway I have restored my ipod settings, and my computer system seems to be working fine now. Thanks for your help.
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds