Something malicious is lurking here...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Sioko, Jan 19, 2007.

  1. Sioko

    Sioko Private E-2

    A while back I was surfing around and landed on a korean page and I was looking for certain pics (not nasty ones!) so I clicked around trying to find the page they were on and apparently clicked on some "install weird stuff" button and it crashed my browser (yes, I've learned my lesson) so I reloaded it and it was insanely slow! I then did disk cleanup and it was better but I'm still slow. Then I was on myspace and got a friend request and when I checked out that persons page (I've learned a lesson here too) and then my SBC Online Protection told me JS/Petch had tried to infect me and then my 2wire reset itself. I ran my Spy-bot (found nothing) and SBC's spyware scan (just realmedia tracking cookie) and virus scan(clean) and the HJT and there I saw some entries I didn't recognise. I usually check periodically so I noticed the differences one of them being that *INTERNATIONAL one... Please help me get back to normal. I know some of the scans ya'll had me run found stuff... I appreciate your help!
     
    Last edited: Jan 20, 2007
  2. Sioko

    Sioko Private E-2

    I seem to have lost the panda scan log file... would you know what it is usually called by default so I can run a search for it??? Sorry...


    Found it!
     
    Last edited: Jan 20, 2007
  3. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox

    "C:\!KillBox\"
    crypt32.dll Mar 31 2003 557568 "crypt32.dll" <<--- This is a legitimate Microsoft Windows process. Restore this file to the System32 folder

    Copy the contents of the below quote box to Notepad; Save As FixReg.reg to your Desktop; make sure File Type: is set to All Files (*.*).
    Close Notepad.

    Locate FixReg.reg on your Desktop. Double-click on it and answer 'Yes' when asked if you want to merge with the registry.

    Now Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click Delete Selected Temp Files
    Then after it deletes the files click the Exit (Save Settings) button.

    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue..

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    REBOOT to Normal Mode.

    Post the following logs:
    1. ShowNew
    2. GetRunKey
    3. HijackThis
     
  4. Sioko

    Sioko Private E-2

    I tried restoring crypt32.dll but it said crypt32.dll was already there at 583kb and the file I was trying to replace it with was only 544kb so I left it alone... let me know if you want me to copy it over...
     

    Attached Files:

  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    crypt32.dll was most likely replaced by Windows File Protection when you deleted it originally.

    Your logs look pretty good. How is you system running?
     
  6. Sioko

    Sioko Private E-2

    Yeah, my browser isn't crashing, but my computer takes quite a while to boot up now. I think it's counterspy... and this sunjava thing is all over my running processes... is it nessecary or was it just for those online scans? These two things are really taking alot of my comps attention.... can I uninstall them?

    How do I do it? I see the counterspy uninstall but not the sunjava, will sunjava just follow counterspy? It's really heavy on my processor...
     
  7. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    If you visit pages that use Java then Sun Java is necessary. Most pages today make use of Java scripts.

    You can Uninstall CounterSpy. Java shouldn't be taking up all that much in system resources.

    If you are not having any other malware problems, it is time to do our final steps:
    • If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    • If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    • If we used SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    • If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    • If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    • If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    • You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    • If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    • After doing the above, you should work thru the below link:
     
  8. Sioko

    Sioko Private E-2

    All better now. thank you. I would say I feel alright about where my comp sits now ^_^ I appreciate your help greatly!

    Have a great day!
     
  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds