Security Popups, Spyware driving me nuts! HJT log

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Tamastara, Dec 26, 2005.

  1. Tamastara

    Tamastara Private E-2

    DELL 9100
    XP HOME SP2
    P4 3.00
    1G RAM

    I keep getting popups that try to download some probably bogus spyware or antivirus software after it says I have security issues.
    I have run ADAWARE and it shows nothing, I have run Spybot and it only shows tracking cookies.
    I also ran CLEANUP! (I know I should have waited) it seemed to help at first but it came back after rebooting.
    HJT Log file attached.
    PLEASE HELP!!!!

    P.S. Is there a way of letting me know HOW/WHERE this came from so I can kill the culprit in my house? :)

    DELL 9100
    XP HOME SP2
    P4 3.00 GHZ
    1G RAM

    My apologies for last post I was in another forum and did what they asked and aparently didn't post to the right thing. Anyway I went through steps 1-6 on this forum and the new HJT is after this forums requirements.
    Ran the following in this order,
    Ccleaner, Microsoft Maleware, Ad-Aware SE, Spybot and Microsoft Antispyware.
    I have a home network and it is on both computers. The other computer however says it has a WIN32 Infection. Is it possible that worm is the culprit and can travel to other computers in the household depositing adware and spyware?
    Please Help!

    Also if possible I would be very interested in knowing what download etc. this crap came with.
    I would be ever so grateful just for the help if nothing else!!

    Happy Holidays to everyone!!
     

    Attached Files:

    Last edited by a moderator: Dec 26, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MG's!

    You have a Vundo infection. Yo must follow standard cleaning procedures in the READ & RUN ME sticky before posting HJT logs. However, try the steps in:

    Virtumonde aka Trojan Vundo Fix w/ Tool

    Your lines will be slightly different in appearance due to a change in the Vundo type.
    Yours are:

    O2 - BHO: ATLDistrib Object - {93C6313C-9DB4-4694-8BD0-E378C573A9AD} - C:\WINDOWS\system32\vtutu.dll
    O20 - Winlogon Notify: vtutu - C:\WINDOWS\system32\vtutu.dll
     
  3. Tamastara

    Tamastara Private E-2

    I did that when I posted the second post. Could you look at the .txt that you didn't view that is the one that I ran after I did steps 1-6 of the READ & RUN ME
     
  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    My apologies, I inadvertly merged your posts when I meant to merge your threads. Reply back in this thread don't not start new threads for this problem.

    @ chaslang the current log is 122605.txt in post #1.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But you did not run the online scanners in step 6 of the READ & RUN ME and you did not post the two required logs.
    But what I was also saying in my previous message is that you need to do the steps in: Virtumonde aka Trojan Vundo Fix w/ Tool

    The READ & RUN ME will not fix Virtumonde. Special steps are needed.
     
  6. Tamastara

    Tamastara Private E-2

    ok! I did what you suggested Chaslang! Attached is the NEW HJT log file!
    Again I am SO grateful for all your help!
    Is there anyway? To know what this came in? Or how it got here?
    So sorry for all the confusion, my bad! Thanks for being patient :)
     

    Attached Files:

  7. Tamastara

    Tamastara Private E-2

    Dell 2300
    XP HOME SP2
    1.8 GHZ
    256 RAM
    2nd Computer and problem originator! I get about:blank when I open IE and have found C3kwepn.exe. as well as all the security popups etc.

    Please help again? :)

    Attached is the HJT log.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your first computer is clean now but you can fix the below minor items using HJT:


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

    You never did complete ALL of the READ & RUN ME on this first PC.

    Now for you second PC you must do ALL of the READ ME. This includes all of step 6 which is the two online scanners and attach the logs from the online scanners. After running completeing ALL of the READ ME also do the below.

    Download about:Buster 6.0

    Get any updates. Then reboot into safe mode and run About:Buster twice and save the log. Then reboot into normal mode and attach the log from About:Buster and also attach a new HJT log.
     
  9. Tamastara

    Tamastara Private E-2

    OK! I did ALL of 1-6 plus ran About:Buster. Attached are the 4 log files requested.

    I still have issues that I cannot get rid of. I thank you for your patience as mine are wearing thin! I cannot tell you how much I appreciate you and your knowledge.

    :)
    I certainly hope you had a wonderful holiday season, you sure deserve it!

    Regards,
    Tama
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis logs must be from normal boot mode unless otherwise specified.

    You also must not use msconfig to control what startups load. This is covered in the link for downloading and installing HJT. Please run msconfig and select normal startup. Then do the below:

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to SmartFinder Uninstall (or if not found look for SmartFinder_Uninstall) ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    SmartFinder Uninstall

    If that does not work try entering the short name: SmartFinder_Uninstall)

    Now exit HJT and but do not reboot if it tells you it is necessary.

    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [syscr.exe] C:\WINDOWS\syscr.exe
    O4 - HKLM\..\Run: [9.tmp] C:\DOCUME~1\OWNER~1.COR\LOCALS~1\Temp\9.tmp.exe
    O4 - HKLM\..\Run: [A.tmp] C:\DOCUME~1\OWNER~1.COR\LOCALS~1\Temp\A.tmp.exe
    O4 - HKLM\..\Run: [A.tmp.exe] C:\DOCUME~1\OWNER~1.COR\LOCALS~1\Temp\A.tmp.exe
    O4 - HKLM\..\Run: [9.tmp.exe] C:\DOCUME~1\OWNER~1.COR\LOCALS~1\Temp\9.tmp.exe
    O4 - HKLM\..\Run: [apiqt.exe] C:\WINDOWS\system32\apiqt.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O23 - Service: SmartFinder Uninstall (SmartFinder_Uninstall) - Unknown owner - C:\Documents and Settings\Owner.CORY\Local Settings\Temporary Internet Files\Content.IE5\0M2XANUP\SFUninstaller[1].exe" service (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Documents and Settings\Owner.CORY\Local Settings\Temporary Internet Files\Content.IE5\0M2XANUP\SFUninstaller[1].exe
    C:\Documents and Settings\Stephanie\Local Settings\Temp\cd_clint.dll <--- actually delete all file you can in this Temp folder
    C:\Documents and Settings\Owner.CORY\Local Settings\Temp\9.tmp.exe <--- actually delete all file you can in this Temp folder
    C:\Documents and Settings\Owner.CORY\Local Settings\Temp\A.tmp.exe
    C:\WINDOWS\system32\yjjvf.dll
    C:\WINDOWS\system32\apiqt.exe
    C:\WINDOWS\syscr.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Reminder Note: Once we have determine you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds