Stuck in the middle of READ & RUN ME FIRST

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by TangoEcho, Sep 29, 2007.

  1. TangoEcho

    TangoEcho Private E-2

    I am blessed with the dreaded Virtumonde that Adaware nor Counterspy seem to be able to trash off my system. I began following the directions in Read and Run at about 6 am at 7 pm I am now stuck. It takes 52 minutes to scan my system in normal mode and about 4 hours in safe mode. rolleyes

    Because I use Firefox and it is set at default I no longer have an icon nor can I locate the exe to run Bitdefender or Panda. I've re-downloaded IE 6 (no I don't want 7, don't want it at all but choices are limited with FF), and STILL no exe.

    Even worse when I ran Counterspy in Safe mode it only picked up Winagent32 (?) which supposedly had already been cleaned off my system. Why didn't the Virtumonde show up? It was there when I switched to safe mode. Additionally, when in safe mode there is no View-> Spyware scan -> etc. for me to copy to show you all for help purposes.

    I am really trying to follow all of the instructions as requested but I am truly stuck. I can start the process over but it seems useless without IE to complete the BitDef and Panda part.

    And no VundoFix didn't work either. Ran multiple times and the minute I re-start and come back here POP UP City.

    Last but not least if the pop ups can use IE why can't I?:confused

    Win XP Pro SP1; Pent 4 3.00 GHz; 1gig RAM

    Thanks for listening to my sad tale and in advance for any help
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I'm not sure why you cannot not run IE. Are you just saying you don't know how to find it? It is here: C:\Program Files\Internet Explorer\iexplore.exe

    You can just create a shortcut to it on your Desktop. You should also be able to just click Start, Run, and enter iexplore and click OK. And this should run it. Have you tried this?
     
  3. TangoEcho

    TangoEcho Private E-2

    :eek:
    Whoot! Thanks now that IE is running I can pick up where I left off.
    I went to the folder and the exe is totally absent. I assume (?) that setting FF to default disabled it?

    Any thoughts on the other questions? I want to do this right and already things are not happening as expected in the instructions.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it isn't. It would not be running if it were missing. You probably are thinking this because you cannot see file extensions which would mean you did not do step 2 of the READ ME.


    Which questions? Why Vundo was not found by VundoFix??
     
  5. TangoEcho

    TangoEcho Private E-2

    My apologies but, not only did I do Step 2 (which was unnecessary because I always have the system set this way, but I checked to be sure), I downloaded, and installed ALL of the products the instructions recommended. I Booted in safe mode first without network and ran CCleaner, SpyBot, and then CounterSpy. I then attempted to re-start per instructions in safemode with network support and was unable to get the menu option to start with network support. I had to use msconfig to even get it booted in safemode. While I appreciate your pointing me to start -> run -> Iexplore exe. It was NOT present in the folder until I re-installed IE6 for the 3rd time. Finally, I get an IE page and when I try to use it to find Bitdefender it closes the page. Repeated attempts have been unsuccessful. I have restored IE to original defaults to no avail. I have spent 14 Hours today trying to get rid of Virtomunde and follow the 9 pages of required instructions, and I am still stuck on step 6 because the IE will not work properly. What should I do next?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the below instructions instead of what is in the READ ME.

    Download this file - combofix.exe
    1. Double click combofix.exe & follow the prompts.
    2. When finished, it will produce a log ( C:\combofix.txt ) for you. Attach this log to your next reply See: HOW TO: Attach Items To Your Post
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Then follow the instructions in this link: Using MGtools

    After doing the above attach the log from Combix and the MGlogs.zip file mentioned in the Using MGtools link.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    NOTE: You should never uninstall IE from your system. It is an integral part of your OS and is required on thousands of websites including Microsoft. Without it, you cannot get all updates for your OS and you will not be able to access many websites properly (example: BitDefender and Panda but there are many many more).
     
  8. TangoEcho

    TangoEcho Private E-2

    :D My mistake - I did not mean that I had uninstalled IE. Poor choice of wording, I just re-ran the setup to get the exe back:eek: I shall attempt to be more clear in the future.

    Attachments as requested. I must say I am certainly glad you can read em cause I only half know what some of the stuff means.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm looking at your logs now but I have to ask why you are running your PC with inadequate protection. You have no antivirus, no real firewall (the Windows firewall is not adequate) and no antispyware realtime blocking tool.
     
  10. TangoEcho

    TangoEcho Private E-2

    :eek: I am currently looking at the Macafee that comes with my semi - new Comcast Broadband. Includes anit v and a Firewall. I haven't seen enough about it yet to decide. However, it is free with my Comcast. I most recently had AVG and before that Avast neither of which I really liked. I've a very small set of internet sites that I visit and the majority of my internet time is spent playing the MMORG Runescape or playing on Neopets. I rarely go to sites other that this one, a few news sites and my online banking. In the past 3 years I've been infected only 3 -4 times and ad-aware or spybot always fixed it. Since I almost never open links in emails or download attachments I've been fairly safe. I was running ZoneAlarm but it got so annoying demanding attention that I ditched it.

    I have already the other things on your "Protect" list and use them regularly.
    Virtumonde showed up after dling a game from RealArcade. There goes that membership :p

    What do you think of Macafee and BTW do you ever sleep?:D
     
  11. TangoEcho

    TangoEcho Private E-2

    Oh I forgot there is also a built in Firewall in my Router :D
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not recommended since it will slow your PC down a tremendously. Free is nice but not at the cost of what it will do to your performance. AVG and Avast (which you imply that you did not like) are much less resource hungry and actually are probably more effective than McAfee. There are also free firewalls listed in the link you referred to.

    No! ;)

    While I work up the rest of your fix you can get started on the below.

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below folders which may be left behind by the uninstall:
    C:\Documents and Settings\Debora L. Nichols\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Looks like you missed a couple things from the READ ME too. :)

    • Uninstall Viewpoint Media Player (Remove Only) as requested in step 0.
    • Also you did not use our link for Spybot. You are running Spybot - Search & Destroy 1.2 which has not been used in over 3 years. Uninstall it and install the version given in the link in the READ ME which is this one: SpyBot-Search & Destroy
    • This is not part of the READ ME but you also have an almost 3 year out of date version of SpywareBlaster installed. You have SpywareBlaster v3.4. Uninstall this and install the current version from here: SpyWare Blaster
    I will be posting the rest of your fix soon! I had to answer a few phone calls! People just never leave me alone. ;)
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good but you still need a software firewall.
     
  14. TangoEcho

    TangoEcho Private E-2

    Reviewed list and am Downloading Following

    Comodo Personal Firewall DnLoaded
    Dnloaded AntiVir Personal
    Comodo BOClean is Downloading

    BitDefender is scanning - Finally!

    Should I install the others before going on with Panda?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It can take a long time to run and it will be more important to complete my following steps quickly.

    Panda also takes a long time to run and no do not install anything else unless I request it. Just follow the steps I have given in my previous messages and then do the below.



    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    O2 - BHO: 0 - {27535A6E-FDD5-4B13-DBAE-24530C32998A} - C:\Program Files\Accessories\qufa.dll (file missing)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [yzno] C:\WINDOWS\System32\yzno.exe
    O4 - HKLM\..\Run: [{D3-3F-F0-0B-ZN}] c:\windows\system32\dwdsrngt.exe CHD003
    O4 - HKLM\..\Run: [mebelu] C:\Program Files\Mplayer\mebelu22011.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Policies\Explorer\Run: [yzno] C:\WINDOWS\System32\yzno.exe
    O4 - Startup: PowerReg Scheduler.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O15 - Trusted Zone: http://www.neededware.com
    O16 - DPF: NDWCab - http://www.neededware.com/ndw4.cab
    O20 - Winlogon Notify: fccabab - fccabab.dll (file missing)

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  16. TangoEcho

    TangoEcho Private E-2

    Still working on first fix post. I went thru step 0 twice and still missed the Media
    file. I just recently updated Spybot - or at least I thought I did. I used the internal check for Updates. :(

    Old Oldies but goodies removed. Now I just feel naked :(
     
  17. TangoEcho

    TangoEcho Private E-2

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    O4 - HKLM\..\Policies\Explorer\Run: [yzno] C:\WINDOWS\System32\yzno.exe

    Neither present on re-boot after removing Counterspy.
    Also, is using a blank page as home page a "bad" thing?
     
  18. TangoEcho

    TangoEcho Private E-2

    Completed all tasks but am confused. I do not see a log file for HJT. Perhaps I am overlooking it?

    Attaching Avenger Log

    Other logs still have the 8:55 time stamps and are not updated. Do you still want them. I am can't see where I have missed a step so I'm not sure what is wrong.
     
  19. TangoEcho

    TangoEcho Private E-2

    Drat! Sorry - trying again
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That only looks for updates to the detections and since the detections for the old version were not being updated you were way out of date. The programs themselves needed to be updated. :)

    No! You can set that backup later if you want to use it to load your browser faster. We normally remove them because there are many many infections that set peoples home pages to this and they do not want it. It is just easier for us to remove them while cleaning and then everyone can reset their desired start pages once their PC is clean. ;)
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You just need to rerun GetLogs.bat which is in the C:\MGtools folder and it will create ALL new logs. Then please reupload the C:\MGlogs.zip file again since the contents will be all new logs.
     
  22. TangoEcho

    TangoEcho Private E-2

    Doh! headdesk
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you rerun MGtools.exe or did you just run GetLogs.bat?

    Also how are things working?
     
  24. TangoEcho

    TangoEcho Private E-2

    I re-ran MgTools

    The scary thing is that after reading the files and studying the thread on how to read HJT Logs I am beginning to understand it more and more. Yikes!

    So far since last re-boot after uninstall of CounterSpy no more poppiuppies!
    Thank you Thank you if you ever get to Tennessee I owe you dinner:cool

    I have waiting to install on my desktop one of each of the recommended tools from the Protect from Malware thread and am hoping that this doesn't happen again.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Never been to Tennessee yet! :)

    Okay since you did not reinstall Spybot and SpywareBlaster as requested in message # 12. You should do that right now then move on to the below (the link at the end is a repeat but be sure to complete all steps ).

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  26. TangoEcho

    TangoEcho Private E-2

    Meh, I was following the instructions in post #15

    "Panda also takes a long time to run and no do not install anything else unless I request it."

    Giggle
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Key words - I request it which I did in message # 12. :D:D
     
  28. TangoEcho

    TangoEcho Private E-2

    Thank you so much for all of your help! Slowly working my way down the Protect list. Just have to install each of them in turn.

    It was nice to see that I already had all of my Active X controls set correctly :D

    Your the Tops!
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  30. TangoEcho

    TangoEcho Private E-2

    All Squeaky Clean! And yup I completed step 8 per your command:D

    Surprisingly it did not take that long for the system to re-start with all the new protections. That makes me happy:yum
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good job!

    Adding any protection software does have an impact especially if you install things like internet security suites. But what we recommend in the How to line is not as resource consuming even though it does have an effect on PC performance. The alternative of getting infected frequently is not an attractive one especially since some infections can cause signficant damage and/or steal personal information.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds