I think im infected pretty badly...

Discussion in 'Malware Help (A Specialist Will Reply)' started by suthernflames316, Oct 19, 2007.

  1. suthernflames316

    suthernflames316 Private E-2

    Came home from work lastnight and saw I had about 20 popups on my desktop. Also there is a yellow triangle with an "!" popping up constantly saying: System Alert: "PSWx-vir trojan", "Trojan-Spy.win32@mx",
    "and "NetWorm-i.virus@fp". The pops keep telling to download there malware removal software. The url for the popup is www.savetheinformation.com.

    I tried following the writeup using all the different programs and online scans. None of them seemed to fix it.

    here is the logs....
     

    Attached Files:

  2. suthernflames316

    suthernflames316 Private E-2

    Whatever it is its also changing my homepage everytime i get off and on IE. Also on my desktop, there are two icons that kind of reseble the Windows defender icons, but they say "Online Security Guide" and "Live Safety Center"
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. suthernflames316

    suthernflames316 Private E-2

    sorry, here are logs for the AVG, Bitdefender, and panda.
     

    Attached Files:

  5. suthernflames316

    suthernflames316 Private E-2

    here is the getrunkey and shownew...
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach the GetRunKey and ShowNew logs. More importantly, you are not following the version of the READ & RUN ME link I posted. Please refer to the link I gave you an notice the differences. It is also much faster to run then the older READ ME.
     
  7. suthernflames316

    suthernflames316 Private E-2

    getrunkey and shownew
     

    Attached Files:

  8. suthernflames316

    suthernflames316 Private E-2

    i followed the link man...
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on the link that I gave in message # 3 of this thread please. Notice the differences. You did not need to run BitDefender or Panda. But you do need to run ComboFix (and AVG Antispyware which you already ran). You also need to run a program named MGtools.exe which will create a MGlogs.zip file to attach.
     
  10. suthernflames316

    suthernflames316 Private E-2

    ok man ill do it. thanks for helping, this crap is getting insane! im trying to do a thesis with all this shit popping up!
     
  11. suthernflames316

    suthernflames316 Private E-2

    your combofix.exe program does not work. i save the .exe file in my C: drive and ran it. it keeps saying "reg.exe has encountered a problem."
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a problem! Remember that all you need to do right now from the new link I gave you for the READ ME is the ComboFix scan (which should fix a bunch of your problems but not all) and then the MGtools.exe procedure. Then two logs will be uploaded:
    1. ComboFix
    2. C:\MGlogs.zip
    After getting these, I can give you a full cleaning procedure.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try shutting down your antivirus and also AVG Antispyware and see if it will run. If not, move on the MGtools.
     
  14. suthernflames316

    suthernflames316 Private E-2

    i shut down norton and AVG, and still got the message. I will move on to MGTools
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is the below that you have loading at startup?
    O4 - HKCU\..\Run: [OregonTrail.exe] C:\DOWNLO~1\OREGON~1.EXE /r
     
  16. suthernflames316

    suthernflames316 Private E-2

    it appears to be orgegon trail i guess. the kids used to play it, but i thought it was deleted.
     
  17. suthernflames316

    suthernflames316 Private E-2

    since i could not run the Combofix.exe, i am attatching the Glogs.zip only.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you still want this to load or not?

    MGtools seems to have not completed properly. Did you see a popup about allow TrendMicro HijackThis to install? You have to approve this or the procedure will not complete. You only go 3 of the 5 logs that should be in the MGlogs.zip file. This normally happens when you don't allow the HijackThis program (a new version embedded in MGtools) to run.
     
  19. suthernflames316

    suthernflames316 Private E-2

    no i would rather it not load at startup.

    as for the TrendMicro....i clicked agree, and it said Hijack this is already running? I dont see how, no browsers are open, and the program is not running. At least i dont think HJT is...
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Check again to make sure you do not have your previous version running. Then goto the C:\MGtools folder and double click on the GetLogs.bat file. This will rerun all of the scans quickly and produce a new MGlogs.zip file to upload. If this still does not work, I wil give you a fix based on what I have thus far and we will go from there.
     
  21. suthernflames316

    suthernflames316 Private E-2

    think i got it...
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes and no! ;) The embedded HijackThis which is already renamed to analyse.exe ran and created a log but another tool named procdll.exe did not run. Don't worry about it now. We will go with what we have. This new HJT log shows a ton of problems which your first log did not show. This is why are original instructions for HijackThis specify that it must be renamed. In your first log it was not renamed and many many things did not show.
     
  23. suthernflames316

    suthernflames316 Private E-2

    thankyou sir! ill be patiently waiting to fix this. its amazing how your computer can be running flawlessly and the next minute it horrible.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes malware can cause tremendous problems in a very short time. We have seen brand new PCs (right out of the box) connected to the internet without proper protection and they have become infected in as little as 10 seconds of connection.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 3
    Java 2 Runtime Environment, SE v1.4.2_03
    Spybot - Search & Destroy 1.4 <-- This is the old version and not the version given in the READ & RUN ME.
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME


    Now let's remove a bad service.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to DomainService
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    This service may already be stopped but make sure it is also disabled.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {2998E8DB-02B1-404B-AF90-3575F1DB4928} - C:\WINDOWS\system32\jiigljxb.dll (file missing)
    O2 - BHO: (no name) - {2DEA0FA9-D6EE-481B-888A-248536BBF6E2} - C:\WINDOWS\system32\sstqr.dll (file missing)
    O2 - BHO: (no name) - {30692B05-1943-4A27-B8EB-D0F024FD20B2} - C:\WINDOWS\system32\vturr.dll
    O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
    O2 - BHO: (no name) - {7B9411A1-E0B4-485C-94E3-66FD16DC4AA0} - C:\WINDOWS\Web\PRINTERS\urnamin.dll (file missing)
    O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - C:\WINDOWS\system32\gbillwhh.dll
    O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\yvwpgrty.dll
    O2 - BHO: (no name) - {B8822FBC-49CD-4855-BC23-B4183F62C91B} - \
    O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\yvwpgrty.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [j9261235] rundll32 C:\WINDOWS\system32\j9261235.dll sook
    O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
    O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\iivdkgmp.dll",sitypnow
    O4 - HKCU\..\Run: [OregonTrail.exe] C:\DOWNLO~1\OREGON~1.EXE /r
    O20 - Winlogon Notify: rqropoo - rqropoo.dll (file missing)
    O20 - Winlogon Notify: sstqr - C:\WINDOWS\system32\sstqr.dll (file missing)
    O20 - Winlogon Notify: urnamin - C:\WINDOWS\Web\PRINTERS\urnamin.dll (file missing)
    O20 - Winlogon Notify: yvwpgrty - C:\WINDOWS\SYSTEM32\yvwpgrty.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went (note you get the last 3 logs by running GetLogs.bat again and attaching the new MGlogs.zip file)

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  25. suthernflames316

    suthernflames316 Private E-2

    is there anything on here that is going to ruin my "work at home server connection"....that 'DomainService' for instance?
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is malware. It has nothing to do with anything legit.
     
  27. suthernflames316

    suthernflames316 Private E-2

    before i do anything else, i ran HJT and it did not show these files on the list:

    O2 - BHO: (no name) - {2998E8DB-02B1-404B-AF90-3575F1DB4928} - C:\WINDOWS\system32\jiigljxb.dll (file missing)
    O2 - BHO: (no name) - {2DEA0FA9-D6EE-481B-888A-248536BBF6E2} - C:\WINDOWS\system32\sstqr.dll (file missing)
    O2 - BHO: (no name) - {30692B05-1943-4A27-B8EB-D0F024FD20B2} - C:\WINDOWS\system32\vturr.dll
    O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
    O2 - BHO: (no name) - {7B9411A1-E0B4-485C-94E3-66FD16DC4AA0} - C:\WINDOWS\Web\PRINTERS\urnamin.dll (file missing)
    O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - C:\WINDOWS\system32\gbillwhh.dll
    O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\yvwpgrty.dll
    O2 - BHO: (no name) - {B8822FBC-49CD-4855-BC23-B4183F62C91B} - \
    O20 - Winlogon Notify: rqropoo - rqropoo.dll (file missing)
    O20 - Winlogon Notify: sstqr - C:\WINDOWS\system32\sstqr.dll (file missing)
    O20 - Winlogon Notify: urnamin - C:\WINDOWS\Web\PRINTERS\urnamin.dll (file missing)
    O20 - Winlogon Notify: yvwpgrty - C:\WINDOWS\SYSTEM32\yvwpgrty.dll
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Remember my comment about HijackThis being renamed? ;) That's why. Here is what you do? Run the renamed HijackThis. Goto the C:\MGtools folder and double click on analyse.exe. This is the renamed HijackThis.exe file.
     
  29. suthernflames316

    suthernflames316 Private E-2

    heres the finished product.....might i say this, the popups have STOPPED!!!!!!
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you get the DomainService both Stopped & Disabled? Check again because I still see it in your HJT log.
     
  31. suthernflames316

    suthernflames316 Private E-2

    yes it was already stopped when i initially open it.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Stopped and Disabled???

    Also delete the below files if they still exist?
    Code:
     
    "C:\"
    xrkey00.txt   Oct 22 2007        1687  "xrkey00.txt"
    xrkey01.txt   Oct 22 2007         478  "xrkey01.txt"
    xrkey02.txt   Oct 22 2007         228  "xrkey02.txt"
    xrkey05.txt   Oct 22 2007        3358  "xrkey05.txt"
    xrkey06.txt   Oct 22 2007         230  "xrkey06.txt"
    xrkey07.txt   Oct 22 2007         234  "xrkey07.txt"
    yvyuxlym.txt  Oct 22 2007        6202  "yvyuxlym.txt"
    
    The goto the below folder and select all the icoxx.tmp files (where xx is any number)
    and then delete them.
     
  33. suthernflames316

    suthernflames316 Private E-2

    done. sorry about the domain service, i didnt disable it. it is disabled now.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay run GetLogs.bat one more time and attach hopefully a final (and clean) set of logs (MGlogs.zip).
     
  35. suthernflames316

    suthernflames316 Private E-2

    here you go...
     

    Attached Files:

  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I thought you said you deleted all of the icoxx.tmp files? I still see them.
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ooops! That was my fault! I did not tell you where they were. They are in the below folder;

    C:\Documents and Settings\User1\Local Settings\Temp\
     
  38. suthernflames316

    suthernflames316 Private E-2

    its okay. what about the icoAA, where A are letters??
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All of them with letters or numbers. The letters are actually numbers. They are hexidecimal numbers. ;)
     
  40. suthernflames316

    suthernflames316 Private E-2

    ok im all done!
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\newfiles.txt, C:\runkeys.txt, C:\GetUnKey.txt, and C:\MGlogs.zip logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  42. suthernflames316

    suthernflames316 Private E-2

    thanks man. i appreciate your time. do i owe you anything?! your a lifesaver to this computer and my thesis haha.
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Just keep your PC clean and spread the good word. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds