9-1-1 Adware Problem!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by iknitta, Sep 26, 2007.

  1. iknitta

    iknitta Private E-2

    Help, I think my computer is infected with something. Here are the required attachments.
     

    Attached Files:

  2. iknitta

    iknitta Private E-2

    Here are the last three attachments. Thanks.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Yes you have multiple Vundo infections!

    Why did you attach text file copy of the READ & RUN ME??? You need to attach the log from AVG Antispyware.

    Also you need to properly installed GetRunKey. It appears that you did not extract it from the ZIP file before running it like you did with ShowNew. Please do this so that the next log is correct.

    Download this file - combofix.exe
    1. Double click combofix.exe & follow the prompts.
    2. When finished, it will produce a log ( C:\combofix.txt ) for you. Attach this log to your next reply See: HOW TO: Attach Items To Your Post
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    4. the ComboFix log
    Make sure you tell me how things are working now!
     
  4. iknitta

    iknitta Private E-2

    Thanks for the quick reply. I re-installed GetRunKey (hopefully correctly) and ran it along with ShowNew in safemode. Here are the attachments.

    Everything seems to be running fine for now..
     

    Attached Files:

  5. iknitta

    iknitta Private E-2

    These are the other attachments.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it did not work properly. You need to check to see if you are seeing one of the error messages mentioned on the download page for GetRunKey. Let me know.

    Also note, these scans are not supposed to be run in safe mode. ;)

    Who has been giving you registry patches to run???????
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O20 - Winlogon Notify: ddayw - C:\WINDOWS\
    O20 - Winlogon Notify: geede - C:\WINDOWS\

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. iknitta

    iknitta Private E-2

    Aloha! I downloaded GetRunKey again, right clicked "Start", left clicked "Explore", and unzipped it to it's own folder C:\GetRunKey. Hopefully that was correct.. Okay here's the attachments. (Programs were run in Normal Mode this time.) As for registry patches I don't recall getting any registry patches (actually I don't know what that is :confused ).
     

    Attached Files:

  9. iknitta

    iknitta Private E-2

    And the other attachment.
     

    Attached Files:

  10. iknitta

    iknitta Private E-2

    Wow, thanks for the speedy reply! I followed your instructions to the "T".
     

    Attached Files:

  11. iknitta

    iknitta Private E-2

    HJT attachment.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is still not running properly. I repeat my question, are you checking for the error messages mentioned on the download page for GetRunKey.
     
  13. iknitta

    iknitta Private E-2

    Nope, no error messages. Nothing pops up when I unzip and run the program.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A command prompt window should open and messages may appear in that window.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, Run, and enter cmd and click OK. This will open a command prompt window. In the command prompt window enter the below commands each followed by the enter key. Note there is a space after the cd and after the dir
    cd C:\GETRUNKEY
    dir > c:\flist.txt

    Now attach the c:\flist.txt file here.
     
  16. iknitta

    iknitta Private E-2

    Ooops, I meant to say that none of the error messages pop up when I unzip and run the program.

    When I run GetRunKey the Command Prompt Window appears and I get this message:

    "NOTE: Ignore any error messages about not finding registry keys! Just wait for the program to finish running!!
    C:\xtmpsysccs.txt
    C:\xtmpsyscs2.txt
    C:\xtmpsyscs3.txt
    1 file(s) copied.

    C:\xrkey00.txt

    C:\xrkey01.txt

    C:\xrkey02.txt

    C:\xrkey03.txt

    C:\xrkey04.txt

    C:\xrkey05.txt

    C:\xrkey06.txt

    C:\xrkey07.txt

    C:\xrkey08.txt

    C:\xrkey09.txt

    C:\xrkey10.txt

    C:\xrkey11.txt

    C:\xrkey12.txt"

    Then Notepad opens up with runkeys.txt.

    Please forgive my computer incompetence :eek:

    I really appreciate your time and patience.

    Iz
     
  17. iknitta

    iknitta Private E-2

    Here we go. I hope I did it right this time.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm!!!

    Click Start, Run, and enter cmd and click OK. This will open a command prompt window. In the command prompt window enter the below commands each followed by the enter key. Note there is a space after the cd and after the dir
    cd C:\GETRUNKEY
    GetRunKey.bat

    Take note of any messages different than what you posted last time (that is if any are different). When the notepad file opens, just close it.

    Now attach the new c:\runkeys.txt file here.

    By the way how are things running now??
     
  19. iknitta

    iknitta Private E-2

    Okay, there was a slight difference in the Command Prompt Window (after the program was done running):

    "...
    C:\xrkey09.txt

    C:\xrkey10.txt

    C:\xrkey11.txt

    C:\xrkey12.txt

    All finished getting Run Keys. The log is in C:\runkeys.txt

    Windows 9x and Me users should close this window now!

    C:\GetRunKey>
    "

    As for my computer it seems to be running great! Perhaps the malware is gone?

    Well... I can't attach the c:\runkeys.txt file. It says: "You have already attached this file in thread : 9-1-1 Adware Problem!".
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I believe your malware is gone too! I'm just concerned as to why GetRunKey is not running properly. I want you to try one last set of steps

    • Delete the C:\GetRunKey folder
    • Unzip the GetRunKey.zip file into the exact same folder where you already have ShowNew (this was C:\ShowNew )
    • goto the C:\ShowNew folder with Windows Explorer
    • first double click on ShowNew.bat to create a new log from it
    • then double click on GetRunKey.bat to create a new log from it.
    • attach the two new logs (newfiles.txt and runkey.txt).
    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  21. iknitta

    iknitta Private E-2

    Thanks for all the help! I really appreciate you spending the time and stress to help out a newbie like me. :)

    There's just one more thing though. Today when I left my computer idle for like 20 minutes (this happened twice) I came back and found my computer a little laggy. I pressed the "Ctrl"+"Shift"+"Alt" combo to bring up my Windows Task Manager and found "conime.exe" running. Since I have the Processlibrary.com Quick Access I checked out what this was and supposedly it is a dangerous process so I immediately ended the process through Windows Task Manager, which resulted in my computer going back to normal speed. Seeing as how this process popped up twice, both of which occured after I had left my computer idle for some time and caused my computer to be laggy, I wonder if I still have any malware left. Any thoughts?
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! Thanks for helping me find out why GetRunKey.bat was not running properly. You may not have noticed, but it ran okay this time. For some reason on your PC, it would not run properly in the original folder you had.


    Totally incorrect. conime.exe is a valid Windows process as long as it is running from the proper location which is C:\Windows\system32. If you look back at your previous HijackThis logs you will see it has been there all along ( C:\WINDOWS\system32\conime.exe ) and I have been ignoring it because it is valid. conime is short for Console Input Method Editor and has to do with other language support features. See the below links for more info:

    http://www.microsoft.com/windows/ie/ie6/downloads/recommended/ime/default.mspx
    http://www.microsoft.com/globaldev/handson/user/IME_Paper.mspx

    You can even see the file mentioned by name here: http://support.microsoft.com/kb/903204
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds