Unknown Malware infection- popups, browser redirected.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jules7899, Aug 6, 2006.

  1. jules7899

    jules7899 Private E-2

    Hello,
    I have run though all the steps as outlined here:
    http://forums.majorgeeks.com/showthread.php?t=35407

    I am attaching 4 logs in total, will post 3 on this entry and HJT.log in my response post.


    Notes on the steps I've taken and some history:

    1- Symptoms started 7/28/06 and included slower internet connection, popups for porn and gambling, 'False-warning' popups advertising AntivirusGold, homepage reassigning, web page redirection.

    2- I was unable to run Windows Defender in Safe mode, ran it in Normal mode after performing all steps in the 'Read Me First' thread.

    3- I previously had Virtumonde and SpySherrif (symptoms began 7/28/06), followed special instructions per this web site after following the initial 'Read Me First' steps, and the majority of my symptoms subsided (no more 'False-warning' popups featuring AntiVirus Gold, less advertising popups.) I don't think I ever truly got disinfected of all the malware, though, as the internet connection is still slower than my other machine on the same cable modem and catV cable (swapped out hardware and cabling to rule out any hardware issues). SpySherrif is no longer reported on my machine.
    (Note: Because Panda reported Virtumonde, I am running the special instructions for that malware as well after running through all the initial 'read me first' steps.)

    4- BitDefender closes before it completes a full scan. I've run it 3 times now, and it doesn't ever scan to 100%. It scans to ~75% and then the page closes.
    Each time it runs, it finds the same virus:

    Found: Trojan.Dialer.PL
    in C:\Documents and Settings\jhouse\local settings\temp\b111.exe=>(NSIS o)=>lxma_solid_nsis0002

    The status shows:
    Disinfection Failed
    Deleted
    Update Failed

    5- After running Windows Defender is Normal mode, it completed a scan with nothing in quarantine and nothing deleted, but it did show under "objects scanned" C:\WINDOWS\system32\dfrg.msc).


    6- After running VundoFix.exe, I received notification "No files were found. VundoFix v5.1.6 will now close."

    Thank you for any assistance you can give!
    -Julie
     

    Attached Files:

  2. jules7899

    jules7899 Private E-2

    4th log- HJT.log.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download the current version of ShowNew and attach a new log!
     
  4. jules7899

    jules7899 Private E-2

    Here is the newest ShowNew log.
    Thank you.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You appear to be running Symantec Antivirus but I also see the below from TrendMicro:

    O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow

    You need to uninstall Trend Micro OfficeScan Client


    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winudt32.dll once and then click the kill button. After you have killed all of the winudt32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    khfgdcy].dll
    vtutq.dll

    Next double click on explorer.exe and again click once on each instance of winudt32.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    khfgdcy].dll
    vtutq.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    F2 - REG:system.ini: Shell=
    O2 - BHO: (no name) - {77299895-8FAF-418F-8FC6-0103A5BFCC98} - C:\WINDOWS\system32\vtutq.dll
    O4 - HKCU\..\Run: [Uxbmna] C:\WINDOWS\system32\CROSOF~1.NET\JVAW~1.EXE
    O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
    O16 - DPF: {ff348b6e-fd21-11d4-a3f0-00c04fa32518} -
    O20 - Winlogon Notify: vtutq - C:\WINDOWS\system32\vtutq.dll
    O20 - Winlogon Notify: winudt32 - winudt32.dll (file missing)


    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    exit


    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    C:\WINDOWS\system32\CROSOF~1.NET\JVAW~1.EXE
    C:\Program Files\TClock\tclock_install.exe
    C:\WINDOWS\system32\khfgdcy.dll
    C:\WINDOWS\system32\vtutq.dll
    C:\WINDOWS\system32\qtutv.tmp
    C:\WINDOWS\system32\qtutv.ini
    C:\WINDOWS\system32\qtutv.ini2
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot, delete the below folder if found:
    C:\Program Files\TClock

    Also delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\jhouse\Local Settings\TEMP

    Now attach a new HJT log and tell me how the steps went.
    Also attach a new log from ShowNew.
    Make sure you tell me how things are working now!
     
  6. jules7899

    jules7899 Private E-2

    I've removed TrendMicro, and followed the steps in your post.

    Here's the newest HJT and ShowNew logs.

    Notes:

    1- The only threads I had were for vtutq.dll, under both winlogon.exe and explorer.exe.

    2- I was unable to delete the temp folder from a cmd prompt:
    "Could Not Find C:\WINDOWS\temp\win*.*" (I received this message when running the command from c:\ as well as c:\docs and settings\j...

    Thanks!
    Julie
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now just havae HijackThis fix the below line:

    O2 - BHO: (no name) - {3BD0FA94-C5F3-45CD-AFD1-ECDE6485365F} - C:\WINDOWS\system32\vtutq.dll (file missing)

    Other than that, you are clean. How are things working? If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!


    Make sure you follow the link to update your Sun Java version. You just need to update. You don't need to uninstall MS Java. After updating, uninstall the below old versions of Sun Java.

    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0
     
  8. jules7899

    jules7899 Private E-2

    Hello,
    When I sat down to the PC this morning, I had a buffer overrun error (Visual C++ program), but I didn't paste my screenshot of it to get the particulars... will see if that appears again.

    I fixed the BHO per your last message, and have rebooted.

    My machine is still sluggish. When I open IE, it gives me an hourglass for 1 sec, goes away, hourglasses again for another sec, then my homepage will load properly. When I try to go to a web page, it does the same thing (feels like I'm on a 'time delay'... the machine will do what I want, but it's choppy and isn't as quick as it was 2 weeks ago.).

    I normally do a selective startup (starting in Normal Mode currently, I am not doing a selective startup during this troubleshooting). Maybe the sluggishness is just all those programs that are running in the background that usually don't?

    I get a Symantec PCAnywhere error when I boot up, so I need to uninstall that app and reinstall (for work stuff). I also get a bttray.exe error, so I need to make sure bluetooth is not starting up automatically.

    (I just did a google search on bttray.exe, and the sluggishness I mention is quite evident. I'll click on 'search' after entering my parameters, and my machine will not appear to respond for at least 1 or 2 seconds. Then, it responds, and loads the page as it should.)

    I'm attaching a new hjt log. Wondering if there is anything left on my machine that shouldn't be?

    Thanks again for your help, I've been screwing around w/ this machine for 2 weeks on my own, and you've helped more in 2 posts than what I could do by myself! You are much appreciated!

    Julie
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    MSconfig was not designed to be used for this purposed. If you never want certain software to load yu should either uninstall it or just disable it from running at startup. You should not use MSconfig to do this. A program like this Startup CPL is a better choice.

    Is Ewido a paid subscriptions or free trial?
    • If free, uninstall it to free up system resources and avoid conflicts with Windows Defender
    • If paid, uninstall Windows Defender and keep Ewido.
    Yes there is.

    The below process should be stopped and the file and folder should be deleted:

    C:\Program Files\Common Files\{14BDCE0E-07CA-1033-0123-060601170001}\Update.exe
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why do you keep downloading new copies of vundofix.exe ?
     
  11. jules7899

    jules7899 Private E-2

    I was doing that as part of troubleshooting. I downloaded a new copy each time I ran it.


    I will remove ewido (used free version last week to troubleshoot), and will also use Startup CPL.

    I deleted the folder,
    C:\Program Files\Common Files\{14BDCE0E-07CA-1033-0123-060601170001}\Update.exe

    I didn't see the process in TaskManager just now; I'd stopped it earlier today because it was taxing my cpu. Should I check somewhere else, to see if the process Update.exe is still running?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should only be running what we ask you to run now. Vundofix would not have fixed or even detected the original problems as you may now have already realized.

    Did you delete the folder or just the update.exe file. Make sure it does not come back after another reboot.

    If it does, then attach a new log from GetRunKey. There is a registry key where this is often loaded from.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In fact let's do something that I have used before to fix this.

    Please download and install Registrar Lite

    Run Registrar Lite navigate to the following keys and take ownership of them (explained further down):

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

    To take ownership of the key do the following:
    • Copy & Paste the above registry key into the address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the Menu
    • Select Take Ownership
    • Now right click on the {14BDCE0E-07CA-1033-0123-060601170001} key in the right window pane and select Delete (let me know if you receive any error messages )
    • Exit Registrar Lite
    Attach a new ShowNew log (the runkeys.txt file).

    Also check your HJT log and make sure the update.exe process no longer is seen in the process list after reboot.
     
  14. jules7899

    jules7899 Private E-2

    Hello,
    Last time I ran VundoFix was Sat PM before posting originally, was running through the Special Instructions for Vundo because my Panda scan showed I had it. You're absolutely right- that sucker didn't find one thing and I was still real buggy.

    I deleted the folder, C:\Program Files\Common Files\{14BDCE0E-07CA-1033-0123-060601170001}\Update.exe, with the executable still in it's subfolder. After reboot, the folder is not listed under my \Common Files, and the process Update.exe is not running.

    I don't show the registry key any more:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\{14BDCE0E-07CA-1033-0123-060601170001}

    HJT log does not show Update.exe in it's processes.

    I'm off to uninstall ewido. So far, since I've removed that registry key, the machine is a lot quicker accessing IE pages. It looks like some of the programs I've got are automatically check for line connections (dlg.exe and lucallbackproxy), but after googling they look like valid programs.

    What is the most current Sun Java version I should have installed? When I go to http://java.com/en/, the most current version available looks to be the Java Runtime Environment Version 5.0 Update 6. When I verify my Java version via their website, it shows "1.5.0_06" as my installed version. Am I hitting the wrong website? You'd mentioned I needed the most current version, and to get it directly from the link in the intructions "How to Protect Yourself from Malware."

    FYI: when running Registrar Lite, I received a message "Can only take ownership with the Pro version." I continued w/ the Lite version, and deleted the subkey with no errors, no messages.

    So, give it to me straight, doc, what did I have?

    Thanks again, Mr. chaslang, whomever you are! I've never relied so heavily on the kindness of strangers when it comes to fixing my machine!
    -Julie
     

    Attached Files:

  15. jules7899

    jules7899 Private E-2

    Just to let you know... I tried to uninstall the contents of my ewido folder in normal mode, and a .dll was locked. I renamed it and still couldn't delete it. I had to remove it while in safe mode. It was shellexecutehook.dll.
    After removing it in safe mode, and deleting the ewido folder, it's no longer on my machine after booting in Normal mode.

    I also checked after the reboot to see if Update.exe was present, and whether it's registry key was present, and they were both gone.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's get the current version (1.5.0_07) from Majorgeeks.

    Sun Java Runtime Environment

    You had a few infections. The main ones were Virtumonde and winlogonhook (aka conhook). You still have a file that I want you to delete in your Temp folder. It seems to have come back. Delete the below file and make sure it stays deleted:

    C:\Documents and Settings\jhouse\Local Settings\Temp\b111.exe

    You're welcome Julie! Have you finished all of the How to protect thread (other than the Sun Java update)?
     
  17. jules7899

    jules7899 Private E-2

    I have deleted the file, C:\Documents and Settings\jhouse\Local Settings\Temp\b111.exe, rebooted, and it's not reappearing.

    I'm going to work through all the steps on "how to protect yourself from malware" this evening, and will be a better 'net citizen for it!

    Thank you again, Kind Sir, from a
    Geek in the Making
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Make sure you have toggled System Restore as requested too!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds