Steps followed, still have problems.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sassafras, Aug 16, 2007.

  1. Sassafras

    Sassafras Private E-2

    Hello. It's been a long time (years) since I need y'all's help. I hope you can help me again. This is aggravating!

    I followed steps 1-7 in trying to clean things out and in getting logs for y'all to look at. I'm still having virus and spyware problems.

    Spybot:

    Wind Updates, 1 entry, fixed.

    Drive Cleaner 2006, 2 entries, couldn't fix. (A window of some sort keeps popping up for it.)

    MyWay.MySearch, 1 entry, fixed.


    AVG Anti-Spyware found nothing.


    I couldn't get a log for either Spybot or AVG. I hope that won't be too much of a problem.


    BitDefender found what looks like a lot (in MyDownloads, Local Settings/Temp, System Volume Information\_restore, Vundo Fix Backups, and WINDOWS\system 32). I will attach the log for it.


    Panda found 2 viruses (disinfected 2), 6 Spyware, and 1 Hacking Tool and rootkit. I wll attach the log for it.


    I ran Vundo Fix before and after doing all the required steps (because Virtumonde had shown up in a routine scan).


    In addition to the logs for BitDefender and Panda, I will be attaching logs for GetRunKey, ShowNew and HijackThis!.


    I hope I'm giving y'all all the information you need. I really need your help.
     

    Attached Files:

  2. Sassafras

    Sassafras Private E-2

    Now here are the logs for ShowNew and HijackThis.
     

    Attached Files:

  3. Sassafras

    Sassafras Private E-2

    Oh, and in case you're wondering (and I guess the logs might show it?), windows keep opening at random. Not a lot at one time, at least. But it's still pretty annoying. I don't know what they're all about. One said something about Jack9 (a gambling site?), one keeps saying something about someone on MySpace liking me or something, one pops up immediately after that one (after I click the x) about a celebrity on MySpace or some such. Then there's the one about an error (has to be false; it's coming from some online site) and then it offers some "virus protection".

    Those are the main windows I've noticed.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to rename HijackThis.exe as requested in the READ ME or some aspects of the infection you have will not even show. You also need to disable Spybot's Teatimer which was also specified in the READ ME.

    Now Disable Spybot's TeaTimer
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!

    After doing the above, continue on to the below.


    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log ( C:\combofix.txt ) for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    4. the ComboFix log
    Make sure you tell me how things are working now!
     
  5. Sassafras

    Sassafras Private E-2

    I thought I had renamed HijackThis analyse.exe. I know it's called that now somewhere. lol I renamed it analyse.exe again (in the file where I have to click to run it) and then renamed the log file to analyse.exe.log. Hopefully I did it right.

    The windows that keep popping up, in case that's important, are popping up in IE, even though I'm using Firefox.

    Also, when I ran BitDefender, the results for each virus or spyware said that a "disinfection failed", was "deleted" and that the "update failed".


    And now here are the logs. I really hope this right. I did my best and thought they were. :confused


    I tried attaching the logs for GetRunKey and ShowNew, but it gave me an error message saying that I've already added them to this thread. Am I supposed to run them again or something?

    Also, ComboFix had two text files. I didn't know which one you wanted, so I attached both.
     

    Attached Files:

  6. Sassafras

    Sassafras Private E-2

    Oh, I forgot to mention that I tried to remove WeatherBug using Add/Remove programs (I saw that suggested here somewhere), and it did remove it there, but it's still on my computer and functioning. I then tried removing it using WeatherBug itself, but I couldn't find a way of uninstalling it.

    Is it really important that I get rid of it (I've had it for years)? And if so, how do I go about doing that?


    I apologize for my ignorance and if this isn't the right place for that inquiry.
     
  7. Sassafras

    Sassafras Private E-2

    I hope I'm not speaking too soon, but no windows have popped up since my last posting. Still, I hope y'all will check out my logs and let me know for sure that things are okay and if I should do anything more.


    Thanks! :)
     
  8. Sassafras

    Sassafras Private E-2

    *sigh* A window just popped up for system doctor, whatever that is. How annoying. They're back. :(
     
  9. Sassafras

    Sassafras Private E-2

    I apologize for so many messages in a row. I hope that doesn't make things confusing.

    I ran GetRunKey and ShowNew again. Here are the logs.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    WeatherBug is not a major malware issue. It is however adware and that is why the scanners pick it up. You can always reinstall it later if you decide you really need it. Just remember that it is adware and most scanners will always detect it as a potential problem due to it being adware and also due to the fact that it installs on thousands of PC without consent from the users.

    You don't need to rename the log file. Only the EXE file as we requested.


    Yes that is what new logs meant.


    Continue by downloading a tool we will need

    - Process Explorer

    Extract it to its own folder somewhere that you will be able to locate it later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    Make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of any of the below DLL files (if found) and then click the kill button.
    wvuusrr.dll
    sstts.dll
    After you have killed all instances of any of the above DLLs under winlogon click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on explorer.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    wvuusrr.dll
    sstts.dll

    After you have killed all instances of any of the above DLLs under Explorer click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on iexplore.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    wvuusrr.dll
    sstts.dll

    After you have killed all instances of any of the above DLLs under iexplore click ok.
    (If you do not find these DLLS, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - (no file)
    O2 - BHO: (no name) - {1AE5DBAF-82B5-4B98-A4ED-2743895BD7B3} - C:\WINDOWS\system32\vtutq.dll (file missing)
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
    O2 - BHO: (no name) - {C84D8A0A-E708-42B6-90CA-9C30956A87C6} - C:\WINDOWS\system32\wvuusrr.dll
    O2 - BHO: (no name) - {CB279C33-C2AC-4296-BF11-4D51B54666C7} - C:\WINDOWS\system32\vturs.dll (file missing)
    O2 - BHO: (no name) - {CD001D9B-79E5-4934-9B23-F2151702DBCA} - C:\WINDOWS\system32\sstts.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
    O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
    O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} (Java Plug-in 1.4.2_03) -
    O20 - Winlogon Notify: sstts - C:\WINDOWS\system32\sstts.dll
    O20 - Winlogon Notify: wvuusrr - C:\WINDOWS\SYSTEM32\wvuusrr.dll
    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    I will be on vacation for a week starting this afternoon, so someone else should be around to help you complete this.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  11. Sassafras

    Sassafras Private E-2

    Whew. This stuff makes me nervous. lol I'm going to do all that you suggested now (crossing my fingers that I do it right) and get those logs to you or whoever can help me next.

    I appreciate it.
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I will be helping you from this point, once you complete chaslangs previous post attach your new logs and we will go from there.

    Good Luck!:)
     
  13. Sassafras

    Sassafras Private E-2

    I think there's a problem now. Well, a new one.

    I downloaded Process Explorer, ran it. Found and killed wvuusrr.dll and sstts.dll in all but iexplorer.exe, which I saw nowhere on the list. (I went over it at least four times.)

    Exited Process Explorer and ran HijackThis (system scan only). Found all but one of the things I was supposed to fix. (The one I couldn't find was 02 - BHO: (no name) - {CD001D9B-79E5-4934-9B23-F2151702DBCA} - C:\WINDOWS\system32\sstts.dll ).

    I went ahead and fixed all the ones I did find.


    I then downloaded The Avenger, ran it, check "input script manually", etc. Clicked "done", traffic light, restarted my computer.


    When my desktop came up, I got a message box that said:

    C:\WINDOWS\system32\cmd.exe

    Then a smaller one on top of that one that said:

    Windows - No Disk

    Exception Processing Message

    c0000013 Parameters 75b6bf9c 75b6bf9c 4 75b6bf9c 75b6bf9c


    I clicked retry, which didn't work. Clicked Continue, which didn't work. And then clicked Cancel.


    I did also see The Avenger log pop up, but I don't know what it said.


    I haven't run Ccleaner yet. Should I do that now or does something else need to be fixed first?
     
    Last edited: Aug 17, 2007
  14. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Just continue on, we will remove what is leftover.
     
  15. Sassafras

    Sassafras Private E-2

    Here are the logs for Avenger, GetRunKey and ShowNew.
     

    Attached Files:

  16. Sassafras

    Sassafras Private E-2

    And here's HijackThis.
     

    Attached Files:

  17. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    O2 - BHO: (no name) - {44218730-94E0-4b24-BBF0-C3D8B2BCE2C3} - C:\WINDOWS\system32\wlomroek.dll (file missing)
    O2 - BHO: (no name) - {59B76E2E-7F55-4971-A525-C4BACD108C70} - C:\WINDOWS\system32\sstts.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)

    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)

    Again, make sure ALL browser windows are closed when you click FIX.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Once you complete this post, reboot and attach a final HJT log. How are things running?
     
  18. Sassafras

    Sassafras Private E-2

    I haven't had any pop-ups since some time yesterday. Looks like things are on their way to getting better.


    Well, I was about to attach my latest HJT log, but there's no "Manage Attachments" button here anymore.
     
  19. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Close your browser, run ATF-Cleaner and then try again. Be sure you click the button http://forums.majorgeeks.com/images/buttons/reply.gif and post instead of clicking quick reply.
     
  20. Sassafras

    Sassafras Private E-2

    Oh, good. It's back. :)

    So, here's the HJT log.
     

    Attached Files:

  21. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we used SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger, the log (avenger.txt) and C:\avenger.
    8. If we had you download any registry patches like fixme.reg, fixme1.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
    Last edited: Aug 20, 2007
  22. Sassafras

    Sassafras Private E-2

    While looking for all the ComboFix stuff to delete, I came across 158 files (in the C:\WINDOWS folder) called $NtUninstall, each with a different 6-digit number and then another $ at the end. What are these?

    I also came across 123 notepad logs, each starting with KB, then a 6-digit number and then .log. What are these? Should I get rid of these logs and/or the $NtUninstall folders?


    Everything that needed to be deleted (Avenger, etc.) has been deleted. I will now go on to step 8 of Read and Run Me.
     
  23. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    These are legit, they are part of Windows Updates.

    These are also legit, they are also part of Windows Updates.
     
  24. Sassafras

    Sassafras Private E-2

    That's good to know. It made me nervous when I saw so many. I didn't know what had gotten into my computer this time.


    Step 8 completed. I turned off System Restore, rebooted and then turned System Restore back on.


    Anything else before going on to step 10?
     
  25. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    That should be it!
     
  26. Sassafras

    Sassafras Private E-2

    Thank you and Chas so much for your help!!

    :)
     
  27. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your Welcome!

    Surf Safely!:)
     
  28. Sassafras

    Sassafras Private E-2

    AVG just did a scheduled scan and said I had two viruses. I wasn't expecting that. :(

    I wrote down what it said:

    C:\avenger\backup.zip:\avenger\wlomroek.dll

    Trojan horse BHO.APH

    Infected, Embedded Object, Deleted


    C:\avenger\backup.zip:\avenger\wvuusrr.dll

    Trojan horse Generic6.OJT

    Infected, Embedded Object, Deleted


    C:\avenger\backup.zip

    Moved to vault, Archive

    (Clicked on "Details" and it said "Trojan horse BHO.APH".)


    C:\ProgramFiles\Hijack This\backups\backup-20070817-014106-534.dll

    Deleted

    (Clicked on "Details" and it said "Trojan horse Generic6.OJT".)


    Am I going to have to go through all those steps again?! Ugh.
     
  29. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Did you follow post #22?

    These detections are backups from what we have cleaned.

    Delete the folders below and you will be fine!

    C:\avenger
    C:\ProgramFiles\Hijack This
     
  30. Sassafras

    Sassafras Private E-2

    Post 22?


    I deleted all I could find of all you told me to delete. I'll look again though and see if I missed anything.


    Okay, I saw a couple that I missed and deleted them. Should I now re-run AVG?
     
  31. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Delete the two folder I mentioned in post 30.

    Post 22
     
  32. Sassafras

    Sassafras Private E-2

    Done. :)

    Should I re-run AVG?
     
  33. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You can if you like, but it should come back clean if you deleted those folders.
     
  34. Sassafras

    Sassafras Private E-2

    lol Okay, thanks.

    :)
     
  35. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your Welcome!:major
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds