posted this morning thread gone :s - logs attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by micktay44, Oct 16, 2006.

  1. micktay44

    micktay44 Private E-2

    Recently got hit big time with a lot of trojans and downlaoders and other stuff, cleaned it the best I could, but ended up messing my safe mode up, I'd followed all the steps in the read me first thing (except for the windows defender) and that got rid of loads, however whilst doing the online scans I was still being attacked by popups and auto downloader, so i searched through your forums and did some more stuff so that I could at least get into safe mode i used the vundo thing and that sorted the safe mode problem, i've tried to get rid of my smitfraud infection however it may be still there for all I know. So I restarted the whole Read me thing now that I can access safe mode.

    Ran CCleaner, got rid of all the files it suggested.

    Ran the windows malicios removal tool, it found no threats.

    Ran a fully updated SpyBot S&S it found no threats.

    CounterSpy(trial version) came up with the following items :
    TitanPoker - deleted

    The bitdefender found:
    A trojan that says it was in the quarantine of CounterSpy however counterspy shows that it's quarantine is empty :s
    It found some in the norton quarantine but that was empty too.
    It then found some winfixer trojans in the nprotect recycle bin and then crashed later on when it got to /i386, so i ran it again came up clean

    Panda scan crashed the first time so i ran it again it found some files

    I'm still getting popups and at a loss as to what to do now

    Cheers
    Mikey
     

    Attached Files:

  2. micktay44

    micktay44 Private E-2

    here are the rest of the logs
     

    Attached Files:

  3. micktay44

    micktay44 Private E-2

    And here is the HJT log :)
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    This means you did not follow the directions in step 1 of the READ ME. The Nprotect folder should have been emptied already.

    You also did not follow the directions in step 0 for setting your PC to Normal Startup with MSconfig.


    Now uninstall the below software (if they give you any trouble uninstalling, tell me later but just continue on)
    J2SE Runtime Environment 5.0 Update 6 <--- this is an old version & you already have the current version
    MediaTickets by OIN <--- this is malware
    OIN <--- this is malware
    Safety Bar <--- this is malware
    SpywareBlaster v3.2 <--- Way out of date!!!

    Now install the current version of SpyWare Blaster


    Start by downloading a tools we will need - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - {5015D116-11FF-1453-D0AE-1234E107B3ED} - C:\WINDOWS\system32\jmmerhce.dll
    O2 - BHO: (no name) - {02E0935C-9797-439A-B459-B16BD9255829} - C:\WINDOWS\system32\mlljj.dll (file missing)
    O2 - BHO: (no name) - {1AB817ED-BB41-478F-BE0D-E8ADD3DFEED4} - (no file)
    O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA} - C:\WINDOWS\system32\nurfopvv.dll
    O2 - BHO: (no name) - {5015D116-11FF-1453-D0AE-1234E107B3ED} - C:\WINDOWS\system32\jmmerhce.dll
    O2 - BHO: (no name) - {5AA24081-6732-CEB0-4EA0-05938F6E9E8C} - C:\WINDOWS\system32\ukzsozb.dll
    O2 - BHO: (no name) - {7602A7FC-9FE8-0578-9948-045049CE0E85} - C:\WINDOWS\system32\avtsnm.dll
    O2 - BHO: (no name) - {d262e70a-7841-4a85-9aa1-8d66aa593c89} - (no file)
    O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
    O3 - Toolbar: (no name) - {C004DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
    O16 - DPF: {CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_02) -

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
    C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
    C:\Program Files\Common Files\{305109E3-0708-2057-0829-03040519002c}\Activate.exe
    C:\Program Files\Common Files\{305109E3-0708-2057-0829-03040519002c}\Uninst.exe
    C:\Program Files\Common Files\{605109E3-0708-2057-0829-03040519002c}\services.dll
    C:\Program Files\Common Files\{605109E3-0708-2057-0829-03040519002c}\Update.exe
    C:\Program Files\Common Files\?dobe\?hkntfs_exe.vir
    C:\Program Files\T?sks\attrib.exe
    C:\WINDOWS\TWljaGFlbCBUYXlsb3I\nq53u3I5vF1osr5PvaK.vbs
    C:\WINDOWS\system32\crwqawdw.exe
    C:\WINDOWS\system32\wtssu.exe
    C:\WINDOWS\bikpp.dll
    C:\WINDOWS\system32\avtsnm.dll
    C:\WINDOWS\system32\crwqawdw.exe
    C:\WINDOWS\system32\ipfycq.dll
    C:\WINDOWS\system32\ixt0.dll_tobedeleted
    C:\WINDOWS\system32\jmmerhce.dll
    C:\WINDOWS\system32\nurfopvv.dll
    C:\WINDOWS\system32\ojvszqg.dll
    C:\WINDOWS\system32\ukzsozb.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folders and delete if found:
    C:\Program Files\Common Files\{305109E3-0708-2057-0829-03040519002c}
    C:\Program Files\Common Files\{605109E3-0708-2057-0829-03040519002c}
    C:\Program Files\Common Files\?dobe
    C:\Program Files\SysProtect Free
    C:\Program Files\T?sks

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Administrator.MICHAELSCOMP\Local Settings\Temp

    Now attach a the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  5. micktay44

    micktay44 Private E-2

    I cannot remove J2SE 5.0 update 6, the other programs I couldn't find I'm assuming that I've already removed them somehow. I've uninstalled and updated SpywareBlaster.

    There were two adobe folders, one seemed legitimate the other only had one file in so I deleted that folder.

    Everything seems to be working however I haven't done any heavy browsing yet.

    Cheers for the help:)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why not? Are you getting an error message or did it not show? Try using the below to uninstall it:

    Your Uninstaller! 2006


    We have a couple more things to delete!

    Delete the below with Pocket Killbox:

    C:\WINDOWS\Downloaded Program Files\UDC6_0001_D19M1908NetInstaller.exe


    Now look for the below S?mantec folder trying to pose as Symantec and delete it. You can find it by date or by contents!
    Code:
    C:\Documents and Settings\Administrator.MICHAELSCOMP\Application Data\
    SMANTE~1      10 Oct 2006              "S?mantec"
    

    This is due to the PurityScan infection you had. The previous instructions gave a bunch of these items to delete that showed in your logs as questionmarks but as you found with &dobe (which show as Adobe) they show in Windows Explorer as valid characters. They do this in an attempt to hide from you. The "?" characters are really single or multiple illegal filename characters.

    Now attach a new log from ShowNew!
     
  7. micktay44

    micktay44 Private E-2

    Hi, the java error said somthing like check that the transforms are vaild, I used you uninstaller and it seems to have removed it completely, cheers

    here is the showNew log.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and enable System Restore to create a new clean Restore Point.
    4. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds