Virus that wont go away!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by romy, Sep 27, 2007.

  1. romy

    romy Private E-2

    i have a virus tht wont delete even after i went through malware procedures..
    i can not search on google, yahoo etc.otherwise internet explorer shuts down
    proly a problem with an add on?
    whts that?

    here are my scan logs!
     

    Attached Files:

  2. romy

    romy Private E-2

    heres my counterspy report..
    my panda scan is running at the moment
    and hijack this will be in next log.
     

    Attached Files:

  3. romy

    romy Private E-2

    final one..sry
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Will be awaiting the Panda Log & HijackThis Log.
     
  5. romy

    romy Private E-2

    panda!
     

    Attached Files:

  6. romy

    romy Private E-2

    and hijack this!
     

    Attached Files:

  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please rename HijackThis.exe to "analyze.exe", once it's renamed please attach a fresh log.
     
  8. romy

    romy Private E-2

    there u goo
     

    Attached Files:

  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, please disable any antivirus and/or antispy programs you have installed so they will not block this fix.

    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed.

    Step 2:
    Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    Again, make sure ALL browser windows are closed when you click FIX.

    Step 3:
    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Step 4:
    • Now Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to DomainService
    • Then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteDomainService into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will reboot in the next step.


    Step 5:
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    Step 6: Begin here after rebooting from Step 5!
    Next Reset Web Settings & Default Security Settings

    Note for IE 6 users:
    To Reset Web Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK

    To Default Security Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Security Tab and click Default Level for Internet, Local Intranet, Trusted Sites, and Restricted Sites. For IE 7 users, simply click the "Reset all zones to default level" button.

    Note for IE 7 users:
    Select Internet Options, then the Advanced Tab and then the Reset button under Reset Internet Explorer Settings.


    Step 7:
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Step 8:
    After you have completed ALL of the above in the correct order, please attach the following logs.
    • HijackThis Log
    • ShowNew Log
    • GetRunKey Log
    • Avenger Log
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  10. romy

    romy Private E-2

    here they are.tryna get avanger..
     

    Attached Files:

  11. romy

    romy Private E-2

    avanger log!
     

    Attached Files:

  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, be sure you close ALL antivirus and antispy programs before running this fix.

    Now scan with HJT and have it fix the below entries...

    Next, run Avenger again just like you did before...
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    Once you have completed this post, reboot a few times and attach fresh logs from the below.

    • GetRunKey
    • ShowNew
    • HijackThis
    • Avenger
     
  13. romy

    romy Private E-2

    i couldnt find this
    and when i reboot my computer an error comes up "no disk" .. try again, cancel, or ok.
    the next time i will tell more info on that error..
    but here are the logs
     

    Attached Files:

  14. romy

    romy Private E-2

    heres the other scan log u requested..
     

    Attached Files:

  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    It appears you are rebooting before running my fix which is making it useless because the infection is mutating/changing names.

    You must NOT reboot after attaching new logs.
     
  16. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Let's try this again, this time REBOOT into Safe Mode and run the fix!

    First, let's kill the bad service...
    • Now Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to DomainService
    • Then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteDomainService into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Next, scan with HJT and have it fix the below entries...
    • Now, run Avenger like you have been doing...
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    Once you have completed this post, reboot a few times and attach fresh logs from the below.
    • GetRunKey
    • ShowNew
    • HijackThis
    • Avenger
     
  17. romy

    romy Private E-2

    here they are
    the no disk error still comes
    but i can search on yahoo and google now!
     

    Attached Files:

  18. romy

    romy Private E-2

    runkeys
     

    Attached Files:

  19. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    We need to run Avenger once more...
    • Now, run Avenger like you have been doing...
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    Once complete, attach the following fresh logs.

    • GetRunKey
    • ShowNew
    • HijackThis
     
    Last edited: Sep 28, 2007
  20. romy

    romy Private E-2

    it said the following script wasnt found when i copied and pasted..
    code error 0
     
  21. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Try once more, copy ALL of the text in the quote box below..

     
  22. romy

    romy Private E-2

    nope..it says "error cannot create zip file"
    and yes i didnt copy all of the files before.
     
  23. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download a fresh copy from the link below and try again. Be sure you get "Files to delete:" because this is what tells Avenger what to delete.

    http://swandog46.geekstogo.com/avenger.zip

    Be sure you extract it and run from a location such as C:\Avenger.
     
  24. romy

    romy Private E-2

    nope..same thing happened

    well after all the errors it said :first step completed successful..reboot now? "
    then an error came up sagin "location of startup file. c/windowns....
    the trohas horse program was found on ur machine and it has been shutdown..but the FILE from which it started still remains, and can be started up again, do u want the file to be removed also? " i said yes,and rebooted..
     
  25. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download Pocket KillBox and save it to your desktop.

    Locate PocketKillbox
    (Procede with this step even if they do not show in blue)

    Next, you will be entering items into Pocket KillBox. Please select the “Delete on Reboot” Option. Copy&Paste each of the file names listed below into the box one by one, making sure Delete on Reboot is Checked for each entry. Click the Red X for each entry, but DO NOT Allow your machine to be rebooted until the last item has been entered:

    • If you get an error message about Pending Operations, just reboot your computer manually.

    Once you complete this, attach the following fresh logs.

    • GetRunKey
    • ShowNew
    • HijackThis
     
  26. romy

    romy Private E-2

    here.
     

    Attached Files:

  27. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please download F-Secure's BlacklightBeta
    • Download fsbl.exe and save it to the Desktop.
    • Once saved... double click fsbl.exe to install the program.
    • Click accept agreement and Click scan
    • This application may trigger a warning from your antivirus. Let the driver load. Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.
     
  28. romy

    romy Private E-2

    there were no files found
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete the below folder using Windows Explorer:
    C:\UWA7P

    Then user the Pocket Killbox procedure BJ gave you to delete the below files:
    C:\Documents and Settings\hipkenhb.txt
    C:\Documents and Settings\nmuhupyv.txt
    C:\Documents and Settings\wdsmmtgu.txt
    C:\Documents and Settings\wdvtdpmd.txt
    C:\cecmwdfx.txt
    C:\gtmfymqi.bat
    C:\tifhkbox.bat
    C:\WINDOWS\fkabgjpt.txt
    C:\WINDOWS\vweixbxy.txt
    C:\WINDOWS\system32\ihgwxcqr.dll
    C:\WINDOWS\system32\drivers\hsfslaib.sys
    C:\WINDOWS\system32\drivers\nciktptt.sys
    C:\WINDOWS\system32\drivers\oqqjabwx.sys
    C:\WINDOWS\system32\drivers\qhnatama.sys
    C:\WINDOWS\system32\drivers\vjvauchi.sys
    C:\WINDOWS\system32\drivers\wlcpnijl.sys
     
  30. romy

    romy Private E-2

    ok done..
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell us how things are working now!
     
  32. romy

    romy Private E-2

    there was nuthin found for the fixME scan..
    and here are the other 3 scans u requested
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's not a scan! It is a registry patch. You need to follow the directions given to add this patch to the registry. You apparently did not do it since the registry key we are trying to delete is still there. Please follow the directions again and make sure you check to see if you receive a message indicating that the patch was successfully added to the registry. If you receive a success message, attach a new log from GetRunKey.


    You should also have HijackThis fix the below lines:
    F3 - REG:win.ini: load=
    F3 - REG:win.ini: run=
    O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -



    You also need to answer questions. I asked how the below:
     
  34. romy

    romy Private E-2

    sry yes i double clicked the wrong icon
    and yea everything seems to be working fine!
    here is the runkey log
     

    Attached Files:

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I wanted to allow BJ to finish this off since he was the original person working with you, but since I see you hanging around, I did not want to waste your time. Here are your next steps since you log is now clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  36. romy

    romy Private E-2

    ok thanks so much!

    also one more question..
    i have the following stuff downloaded.
    sme of it is from last time and some i just downloaded
    tellme what to delete or add?

    spybot
    spyware blaster
    comodo firewall pro
    ad adwre
    asquared-free
    comodo BO clean
    and avast antivirus
    wow to much protection?
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you read the link I gave you yet? If not, read it and then ask any questions that remain lated.

    But note this, the below do not provide true active protection, so they do not use any system resources unless scanning with Ad-Aware or Spybot:
    Ad-aware
    Spybot
    SpywareBlaster
     
  38. romy

    romy Private E-2

    yea i have but its confusing!
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what is confusing you.
    • You need one antivirus which you have (Avast)
    • You need on firewall which you have (Comodo Firewall)
    • You neee one active realtime antispyware blocking tool which you have (Comodo BO clean)
    • Spybot is mostly a scan only tool and does not use any resources unless scanning. The Immunize & SDHelper function offer protection, but this is not considered realtime protection and requires very little resources so it is in the What do we recommend list.
    • Ad-Aware SE personal (the free version) does not use any resources unless scanning and it provides zero protection of any kind. It is up to you if you want to keep it on your PC since it is only using diskspace.
    • SpywareBlaster is not a scanner nor does it provide realtime protection but it does protected you by addressing issues with active-X. It is in the What do we recommend list
    • A-squared is in given in the thread as an additional tool for work in unison with your antivirus since it is not considered a full antivrus program and does not cause problems for your antvirus. You can live without this if you feel it is slowing your PC down.
     
  40. romy

    romy Private E-2

    ok thank you so much!
    uve made my day
    i think ur work is donee:]
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just finished off what BJ started! ;) So you're welcome from him and me. :)
     
  42. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Yeah, what he says! :D
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds