Popups and Closes Programs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by StillGreen, Mar 27, 2007.

  1. StillGreen

    StillGreen Private E-2

    Hi, first time experience with malware this bad. Usually an adware and virus scan was enough for me but this one is tough.

    When I connect to the internet, pop-ups from IE would come up advertising an anti-virus software (I use firebox to browse). Also, certain things would close on me very quickly. For example, firefox would close when I google'd "spyware" or went to websites with anti-spyware information. Also, many anti-spyware installation programs would close right after I run it. This also became a problem with HJT.

    I have followed the steps in your guide to the best of my ability. Here are some things I thought might seem important to know during the process:

    - During the first step, I removed "Windows SA" accidently while removing "Windows SR 2.0". I'm not sure if Windows SA was important.
    - For software that closed on me, I installed them through safe mode. One problem with safe mode was that explorer.exe was not running. Even after I ran it through New Task, it would keep closing. So I just used New Task to run the installations but this got me suspicious.
    - I couldn't update AVG after the installation. I can't access the internet in safe mode and in normal mode, the program would close.
    - I deleted the quarantine list from Norton Antivirus but during the BitDefender online scan, the realtime scanner through up some warnings and put some files in quarantine. I noticed it was reflected in the online scan so I mentioned it.
    - I was not able to run HijackThis. While trying to rename the file in C:\Program Files\HJT, the folder would close. I used Run... and renamed the file through the dialog box. The folder still closed when I tried again. Finally, I tried executing it directly from Run. A dialog box came up but it closed before I could read it. Now the program force-closes like the other cases.

    This is all I can remember for now. I've attached 5 of the log files (HJT couldn't run so I can't get that file).

    Please help me. Thank you.
     

    Attached Files:

  2. StillGreen

    StillGreen Private E-2

    Additional required logs
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 6"
    Java 2 Runtime Environment, SE v1.4.2_03"
    Java 2 Runtime Environment, SE v1.4.2_12"
    Java 2 SDK, SE v1.4.2_12

    Reboot and install:
    Java Runtime 6

    Now:
    1. Download this file - Combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Please download VundoFix.exe to your desktop.

    * Double-click VundoFix.exe to run it.
    * Click the Scan for Vundo button.
    * Once it's done scanning, click the Remove Vundo button.
    * You will receive a prompt asking if you want to remove the files, click YES
    * Once you click yes, your desktop will go blank as it starts removing Vundo.
    * When completed, it will prompt that it will reboot your computer, click OK.
    * Please post the contents of C:\vundofix.txt and a new HiJackThis log.

    Note: It is possible that VundoFix encountered a file it could not remove.
    In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the
    Scan for Vundo button." when VundoFix appears at reboot.

    Now attach the below logs and tell me how the above steps went.

    1. Combofix log
    2. VundoFix log
    3. new GetRunKey log
    4. new ShowNew log <--- please run the latest version.
    5. new HJT
     
  4. StillGreen

    StillGreen Private E-2

    Here are the requested files.

    Combofix would open a command prompt but close immediately. I skipped ahead to run VundoFix. After that, I was able to run Combofix. Maybe the order was important so...
     

    Attached Files:

  5. StillGreen

    StillGreen Private E-2

    The rest of the files
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download and run the following PurityScan uninstaller from on of the two below links:

    PurityScan Uninstaller Link 1

    PurityScan Uninstaller Link 2


    1. Save the Uninstaller to your desktop.
    2. Double click on the OiUninstaller.exe icon on your desktop.
    3. Click on "Run".
    4. Enter the four digit code that is displayed and click on "Uninstall".
    5. Click on "Ok" and reboot your computer.

    Please attach new logs for:
    GetRunKey log
    ShowNew log
    HJT
     
  7. StillGreen

    StillGreen Private E-2

    I ran the uninstaller. Here are the new logs.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Please delete these:
    C:\Documents and Settings\Simon\Desktop\Click to Find and Fix Errors.url
    C:\Documents and Settings\Simon\Application Data\acccore

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.accoona.com/search?q=%s
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {0BAA97DB-1ACD-45CF-8495-9D359CE2D5E0} - C:\WINDOWS\system32\xicthrtv.dll
    O2 - BHO: (no name) - {2040C9CF-9F69-4A67-F89B-09554AB073C0} - C:\WINDOWS\system32\lbzzgsc.dll (file missing) G
    O2 - BHO: (no name) - {2599EF01-CCA3-4AEA-AC58-CA24E4601BE6} - (no file)
    O2 - BHO: (no name) - {3043475E-17ED-4E11-B731-66475DAE13F7} - C:\WINDOWS\system32\ddcby.dll (file missing) G
    O2 - BHO: (no name) - {432D8C41-8586-11D8-997D-00C026232EB9} - C:\WINDOWS\bvm202.dll (file missing)
    O2 - BHO: (no name) - {57C92DC4-62ED-E73E-DA1B-0B63F13E38E9} - C:\WINDOWS\system32\ustsiel.dll (file missing) G
    O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - C:\WINDOWS\system32\mcsrcrpj.dll (file missing)
    O2 - BHO: (no name) - {96446312-2514-480B-9E19-84292CD2C225} - (no file)
    O2 - BHO: (no name) - {A4AA3EF8-B0FF-4202-9C19-BEF6628C9F8A} - (no file)
    O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\jalhmurx.dll",setvm
    O20 - Winlogon Notify: notifyc - C:\WINDOWS\system32\ccc.dll (file missing)
    O20 - Winlogon Notify: winisd32 - C:\WINDOWS\SYSTEM32\winisd32.dll

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\SYSTEM32\cmikluyy.dll
    C:\WINDOWS\SYSTEM32\dugjhytu.dll
    C:\WINDOWS\SYSTEM32\hxlljyjh.dll
    C:\WINDOWS\SYSTEM32\qxcqrxch.dll
    C:\WINDOWS\SYSTEM32\xicthrtv.dll
    C:\WINDOWS\SYSTEM32\xqvhxfl.dll
    C:\WINDOWS\SYSTEM32\judyyfwy.ini
    C:\WINDOWS\SYSTEM32\inisd32.dll

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click the box to unregister .dll's. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
  9. StillGreen

    StillGreen Private E-2

    AVG would occasionally pop-up warning me about Adware.Virtumonde. I wasn't sure what action to take and I figured it would be best not to interfere. So I chose ignore in all cases. What action should I take if this comes up again?

    I performed all the steps you mentioned.

    For Pocket Killbox, I clicked on the red-and-white Delete button twice. Once because I read the step before reading the whole line. So I chose not to reboot and checked off the unregister dll's box. Then I clicked the button for the second time and chose to reboot.

    After the reboot, I still got the same messages from AVG.

    Here are the new log files. The HJT log was generated after all the steps were done (it is not the one from using HJT's Fix).
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry for the delay. Tim has not been around much lately!

    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Now exit Killbox
    Now attach the below new logs and tell me how the above steps went.
    1. ComboFix
    2. GetRunKey
    3. ShowNew
    4. HJT

    You may have some more to cleanup but I want to get the above new scans run before continuing.
     
  11. StillGreen

    StillGreen Private E-2

    Thank you for looking at this.

    I ran all the steps without any problems.

    I did get a message from AVG when I started my computer. It's reporting a downloader.purityscan.ee. Should I have this cleaned/quarantined the next time it asks?

    Here are the requested files.
     

    Attached Files:

  12. StillGreen

    StillGreen Private E-2

    HJT file
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My next steps should delete it.

    Is the below URL something you configured?

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gunbound.ijji.com/


    And what about the below?
    O15 - Trusted Zone: http://*.gunbound.net
    O15 - Trusted Zone: http://*.nprotect.net
    O15 - Trusted Zone: http://*.softnyx.net
     
  14. StillGreen

    StillGreen Private E-2

    Yes, I set those a long time ago. I stopped using IE so those pages aren't relevant to me anymore.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So does that mean we can remove them? I'll be posting a big fix soon.
     
  16. StillGreen

    StillGreen Private E-2

    Yes you can.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Goto Add/Remove Programs and uninstall Outerinfo if found. If not found, tell me later. But continue thru all steps.

    Continue by downloading another tool we will need

    - Process Explorer

    Extract it to its own folder somewhere that you will be able to locate it later.


    Make sure you have rebooted in Normal Mode (do not open any other processes)

    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winisd32.dll once and then click the kill button. After you have killed all of the winisd32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs(If you do not find the dll, just continue on):
    jjklig.dll
    mljif.dll

    Next double click on explorer.exe and again click once on each instance of winisd32.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    jjklig.dll
    mljif.dll
    Next double click on iexplore.exe and again click once on each instance of winisd32.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    jjklig.dll
    mljif.dll

    Now just exit Process Explorer.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\Documents and Settings\Simon\Application Data\?racle\m?dtc.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gunbound.ijji.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {0BAA97DB-1ACD-45CF-8495-9D359CE2D5E0} - C:\WINDOWS\SYSTEM32\xicthrtv.dll (file missing)
    O2 - BHO: (no name) - {15C0FA43-65F5-6F23-A348-1CE33C9CFBCC} - C:\WINDOWS\system32\xzpbw.dll
    O2 - BHO: (no name) - {15FDD0E0-28C0-430C-8CE6-25BCC9BF50E2} - C:\WINDOWS\system32\ljjklig.dll
    O2 - BHO: (no name) - {49EE48A7-1E05-4591-B7CB-EFDBDA1A3AB3} - C:\WINDOWS\system32\mljif.dll
    O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\rxwckeec.dll",setvm
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Ncao] "C:\DOCUME~1\Simon\MYDOCU~1\FNTS~1\logonui.exe" -vt tzt
    O4 - HKCU\..\Run: [Oegnbp] "C:\Documents and Settings\Simon\Application Data\?racle\m?dtc.exe"
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O15 - Trusted Zone: http://*.gunbound.net
    O15 - Trusted Zone: http://*.nprotect.net
    O15 - Trusted Zone: http://*.softnyx.net
    O18 - Filter: text/plain - {D985939B-9F28-4361-8179-FD340620B792} - (no file)
    O20 - Winlogon Notify: ljjklig - C:\WINDOWS\SYSTEM32\ljjklig.dll
    O20 - Winlogon Notify: mljif - C:\WINDOWS\system32\mljif.dll
    O20 - Winlogon Notify: winisd32 - C:\WINDOWS\SYSTEM32\winisd32.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\Simon\Desktop\OiUninstaller.exe
    C:\Documents and Settings\Simon\Local Settings\Application Data\vgsoixg.dll
    C:\WINDOWS\Downloaded Program Files\bridge.dll
    C:\WINDOWS\Downloaded Program Files\BridgeX.dll
    C:\WINDOWS\SYSTEM32\wintcc.exe
    C:\WINDOWS\SYSTEM32\ljjklig.dll
    C:\WINDOWS\SYSTEM32\mljif.dll
    C:\WINDOWS\SYSTEM32\mroluugv.dll
    C:\WINDOWS\SYSTEM32\rxwckeec.dll
    C:\WINDOWS\SYSTEM32\winisd32.dll
    C:\WINDOWS\SYSTEM32\xzpbw.dll
    C:\WINDOWS\SYSTEM32\mmf.sys
    C:\WINDOWS\SYSTEM32\fijlm.bak1
    C:\WINDOWS\SYSTEM32\fijlm.bak2
    C:\WINDOWS\SYSTEM32\ceekcwxr.ini
    C:\WINDOWS\SYSTEM32\fijlm.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  18. StillGreen

    StillGreen Private E-2

    I didn't finish everything but I was wondering about a step with processexplorer.

    I didn't find jjklig.dll but I do see ljjklig.dll. Should I kill that?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that was a cut and paste typo. The file name should be ljjklig.dll
     
  20. StillGreen

    StillGreen Private E-2

    For the ProcessExplorer, none of the .dll's appeared for iexplorer.exe.

    Everything else ran smoothly and no warnings from AVG. Also, the IE popups stopped appearing. Slight slowness but most likely from all those startup programs loading up.

    Here are the requested logs.

    (The button for attaching files is missing. I am in advanced mode. I will post and see if I can attach through an edit).

    edit: Ok, got the files uploaded
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is AVG Antispyware a paid version? If not then uninstall it.

    Do you need WeatherBug loading at startup? If not, fix the line showing in your HJT log.

    Also have HJT fix the below line:
    O20 - Winlogon Notify: winisd32 - winisd32.dll (file missing)

    I still see a left over folder from PurityScan.
    • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    • Delete the below files and folders:
      • C:\ComboFix.tx
      • C:\ComboFix2.txt
      • C:\qoobox
      • C:\VundoFix.txt
      • C:\VundoFix Backups
    • Now run ComboFix again
    Now attach new logs from
    • ComboFix
    • ShowNew
    • HJT
    Is everything runnning okay?
     
  22. StillGreen

    StillGreen Private E-2

    AVG uninstalled and weatherbug taken out.

    All the other steps had no problems.

    Everything seems to be running fine :)
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  24. StillGreen

    StillGreen Private E-2

    Thank you so much for all your help.

    That prevention guide looks great!
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds