Virus barrage blocks all Internet access...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Nekojin, Aug 14, 2006.

  1. Nekojin

    Nekojin Private E-2

    My girlfriend's computer seems to have come down with a bad case of viruses and other malware. We suspect that her idiot brother is responsible; he's never been good with safe surfing.

    I have as many of the logs requested as I could manage. I'm unable to get any logs from online virus scanners, because all traffic is blocked on IE, and almost all traffic is blocked through Mozilla.
     

    Attached Files:

  2. Nekojin

    Nekojin Private E-2

    And the last of the files.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow the directions in step 7 of the READ & RUN ME. You must install HijackThis where requested and you MUST rename the executable as requested. After doing this, please attach a new HijackThis log.

    Did someone knowingly install and do you use CommView? If not, you should uninstall it. It is not malware but it is a potentially dangerous utility when place in the wrong hands.

    Do you now what this ijji program is that is in Add/Remove programs and also the below line is for it?

    O16 - DPF: {A2E05F45-F127-4092-B9F7-9A02C3E04C77} (HGPlugin7USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin7USA.cab


    Are Prevx and CounterSpy the free trial versions or paid versions?
     
    Last edited: Aug 14, 2006
  4. Nekojin

    Nekojin Private E-2

    Apologies for the HijackTHis blunder - I got to the part about running it, and glossed over the details. I really should have known better. :rolleyes:

    Yes, CommView was knowingly installed, but we can remove it - we don't really use it, and if it's that much of a vulnerability, it should probably be toasted.

    PrevX and CounterSpy are trial versions. PrevX won't even finish installing properly at the moment.

    ijji is the name of a game site. We've been there with both computers, and my computer is not infected. Also, we haven't visited that site in weeks, and the infection appears to have started yesterday or two days ago.

    New HJT log attached.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you don't use it, you should uninstall it. That applies to anything else you don't use. Why waste the system resources on things you don't need or use.

    Then also uninstall Prevx.


    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Windows Vista/NT Runtime Compatibility Service ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    ntrcs

    If you receive any error messages just ignore them and continue.

    Now exit HJT and reboot when it tells you it needs to.

    After reboot install this current version of Sun Java: Sun Java Runtime Environment

    Then uninstall the below old version of Sun Java:
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6


    Now download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Now attach a new log from HJT and also tell me if you are still having problems. If so, describe them.
     
    Last edited: Aug 15, 2006
  6. Nekojin

    Nekojin Private E-2

    Done. HJT log attached.

    Norton still won't load properly. Still cannot surf to any sites using Internet Explorer(She generally uses ups.com to check connectivity issues). Firefox seems to be working fine for the moment.

    Cannot update AdAware or Spybot S&D (which are already current, but it is a good test for connectivity).
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What do you mean by this statement? Is this a new problem?

    At this point I would say you should be uninstalling Norton completely. Then reboot and look at a new HJT log. Make sure there is absolutely nothing from Symantec/Norton showing. If there is, then manual steps will be needed to remove the rest of it. After you get all of Symantec removed, let's see if IE works.
     
  8. Nekojin

    Nekojin Private E-2

    Again, apologies for the omission. This was the second site I posted the problem on (the first being AdAware's support site), and I forgot to mention it here. I seem to be making all of the clueless user mistakes. =^_^=

    Removing Norton seems to have cleared up the internet blockage. I ran both of the virus scanners mentioned in the "Do this first" thread (now that I'm able), and attached are the reports.

    Judging by the reports, things are looking up, but it doesn't look like we're done yet.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by downloading - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\WINNT\system32\wgareg.exe


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot tell me how the steps went. Also double check to make sure the C:\WINNT\system32\wgareg.exe file was really deleted.

    Make sure you tell me how things are working now!

    You need to get started on the below steps ASAP since your PC is running without protection. Personally I do not recommend re-installing Norton. And you should think twice about it too after what you just saw. It was the root of your problems with IE.


    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  10. Nekojin

    Nekojin Private E-2

    Ran through the steps. The red X didn't show up, and did not prompt for a reboot. When we rebooted, there was a file called 4.tmp running in the task manager, which I remember being identified by BitDefender as malware, and which BitDefender was unable to clean.

    I went ahead and used Killbox on 4.tmp. The red X showed up, it asked to reboot after, and I rebooted the system. After reboot, I got the error message, "Cannot find the file, 'C:\WINNT\system32\4.tmp' (or one of its core components). Make sure the path and filename are correct and that all required libraries are available.

    Is this a left-over program that we missed still trying to reinstall itself, or is this a sign that we're almost done?

    With regard to Norton, she wants to continue using it for several reasons, not the least of which being that she paid for a 2-year subscription right at the beginning of all this problem (after we realized that her system was infected; it probably got infected while Norton was doing the, "You're not a subscriber, I'm not doing a damn thing," bit). Personally, I understand and agree; I don't use Norton myself.

    I noticed that one of the files that BitDefender identified and cleaned was a .jpg file in the IE Cache. What is the likelihood that this malware was delivered through someone's MySpace or OKCupid page? Her brother uses MySpace and OKCupid.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We are almost there! Attach a new HJT log. Also attach a new GetRunKey log.

    Malware can come from anywhere! It can be difficult to pin point exactly where it came from.
     
  12. Nekojin

    Nekojin Private E-2

    Scans run. I note that HJT shows both 4.tmp and wgareg.exe as, "File missing," thankfully. =^_^=

    Is it normal for Killbox to put the cleansed files into a folder called !KillBox on the C: root?
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is exactly what I expected!

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Windows Network Security Management Service ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now repeat the above stop and disable for the following services:
    Windows Genuine Advantage Registration Service


    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    nsms

    Now repeat the Delete NT Service steps for:
    wgareg

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    F2 - REG:system.ini: Shell=Explorer.exe C:\WINNT\system32\4.tmp
    F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,C:\WINNT\system32\4.tmp
    O4 - HKLM\..\Run: [Microsoft (R) Windows Network Security Management Service] C:\WINNT\system32\4.tmp

    After clicking Fix, exit HJT.
    Now reboot your PCin normal mode and post a new HJT log.
    :

    Make sure you tell me how things are working now.
     
  14. Nekojin

    Nekojin Private E-2

    Things seem to be running smoothly now. Nothing funky in the Task Manager, nothing suspicious in the HJT log. Thanks for all your help. I truly appreciate it. =^_^=
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Now back to what I previously said:
     
  16. Nekojin

    Nekojin Private E-2

    She's running Windows 2K. Is there any comparable feature that I need to disable/reenable, or is that step irrelevant to a Win2K user?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that! No! Just complete the How to protect thread.
     
  18. Nekojin

    Nekojin Private E-2

    Thanks again for all of your help. I truly do appreciate it. =^_^=
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds