Any help would be appreciated

Discussion in 'Malware Help (A Specialist Will Reply)' started by jaysgr, Nov 13, 2007.

  1. jaysgr

    jaysgr Private E-2

    As with most, I have hit a level of frustration with the malware that has attacked my computer. I tried to do some amatuer removals about a week ago and returned with a fatal blue screen. I took it to a repair store and they were able to get me back up and running. They told me that my computer had several infections, and I might want to consider starting over again. I hope by posting this that I can avoid having to do that with your help. Thank you again in advance. Also I have followed the steps listed in the first post. I was already running AVG as my antivirus and nothing showed up when I ran a scan so I do not have a log for that.
     

    Attached Files:

  2. jaysgr

    jaysgr Private E-2

    here are the rest of the files that are needed.
     

    Attached Files:

  3. jaysgr

    jaysgr Private E-2

    and my hjthis attach...sorry if I have not posted correctly my files, I will not even try to come across as computer savy and may have been confused after reading the first post.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Is Earthlink your ISP or is AOL? Or do you use both?
     
  5. jaysgr

    jaysgr Private E-2

    I use AOL.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While I look thru the rest of your logs, please do the below.

    Download this file - combofix.exe
    1. Double click combofix.exe & follow the prompts.
    2. When finished, it will produce a log ( C:\combofix.txt ) for you. Attach this log to your next reply See: HOW TO: Attach Items To Your Post
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not run CounterSpy or AVG Antispyware and attach the log for one of them. Why not?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's continue with your malware removal. Be sure to attach the log from ComboFix and then continue on with the below.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to ieupdater21
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteMicrosoft IEUpdater21 into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 1
    SpyNoMore 2.56

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {266E7813-591B-4A84-899A-DC2AEAD9DAAA} - C:\WINDOWS\System32\ssttt.dll (file missing)
    O2 - BHO: {861a7301-9343-b159-ebc4-e7c0b86ee89a} - {a98ee68b-0c7e-4cbe-951b-34391037a168} - C:\WINDOWS\System32\unsbibvk.dll (file missing)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O4 - HKLM\..\Run: [9056f12f] rundll32.exe "C:\WINDOWS\System32\icesmypl.dll",b
    O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\cbbyxw.dll",setvm
    O4 - HKLM\..\Run: [RegistryMonitor] C:\WINDOWS\system32\gOhgkog.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Microsoft Development Debugger] C:\WINDOWS\System32\msdev.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [EarthLink Installer] " /C
    O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\vturol.dll",setvm
    O15 - Trusted Zone: *.avsystemcare.com
    O15 - Trusted Zone: *.gomyhit.com
    O15 - Trusted Zone: *.imagesrvr.com
    O15 - Trusted Zone: *.virusschlacht.com
    O15 - Trusted Zone: *.avsystemcare.com (HKLM)
    O15 - Trusted Zone: *.gomyhit.com (HKLM)
    O15 - Trusted Zone: *.imageservr.com (HKLM)
    O15 - Trusted Zone: *.imagesrvr.com (HKLM)
    O15 - Trusted Zone: *.virusschlacht.com (HKLM)
    O20 - Winlogon Notify: midpph - midpph.dll (file missing)
    O20 - Winlogon Notify: mll591 - mll591.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  9. jaysgr

    jaysgr Private E-2

    Ok here is the Combofix.txt document, and earlier when I ran the AVG program there were not errors found so there was nothing to post. I can run it again if you would like.
     

    Attached Files:

  10. jaysgr

    jaysgr Private E-2

    For some reason I am unable to remove the Spy No more program, when I try it looks as though it tries to open but then closes less then a second later. Do you still want me to continue with the steps.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but you can also try using the uninstall utility built into Ccleaner to see if it can remove it. Continue no matter what.
     
  12. jaysgr

    jaysgr Private E-2

    I followed all the steps things seemed to go very smooth. Some of the suggested delete files through HJT did not show up when I reran the program to fix. Here are the attachments
     

    Attached Files:

  13. jaysgr

    jaysgr Private E-2

    Also I tried to uninstall that spynomore program with CC and got the same issue with it closing out without installing.
     

    Attached Files:

  14. jaysgr

    jaysgr Private E-2

    I am still not sure if my logs are clean, if anyone can help to see there is still more infections on my HJT log I would appreciate it. I am still showing a gerneric9.tav trojan on my AVG scan.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you may have an incomplete install or uninstall locking things. Try using the below to fix it:

    Windows Installer CleanUp Utility

    Did that help.



    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach a new log from GetRunKey.

    How are things working?
     
  16. jaysgr

    jaysgr Private E-2

    Yes that program finally helped remove it. Here is the new getrun.txt. The computer seems to be running a lot better the only issue is that when I rebooted last night after your help, which thank you very much I appreciate it. I ran a scan and came across a matrix.dll that was hiding out in a winbudget file that I could not find even though I have all my files being marked as show all.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What scan? And attach a log that shows me exactly what was found? Was it in System Restore?
     
  18. jaysgr

    jaysgr Private E-2

    I ran the AVG scan after I rebooted my sysytem to create a new restore point last evening, and there were no more traces of any infections, when the system ran its self test this morning is when it came across a trojan in the WinBudget\win\bin\martrix.dll.vir, there is also a systems32\drivers\etc\host that shows up to be changed in the scan as well. I wont lie I keep looking for a log but cant seem to find one for this program.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you referring too AVG Antivirus or AVG Antispyware?

    I need to know the full path of the file. You said:

    WinBudget\win\bin\martrix.dll.vir

    I need to know if the above is really

    C:\Program Files\WinBudget\win\bin\martrix.dll.vir

    Or is it somewhere else? Like in a backup folder which I will be asking you to remove when we get to our final steps and we are probably ready for them so I will give them further down. I bet it was only in the ComboFix backups which is not a problem.

    There is probably nothing wrong with your host file changing. Running the new version of Spybot will cause it to change.



    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
    Last edited: Nov 13, 2007
  20. jaysgr

    jaysgr Private E-2

    I am refering to the AVG anitvirus program. Also yes the file that is said to be infected in located in the Program Files folder, but there is no showing of a Winbudget folder existing.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just complete all of my final steps and then tell me if you still have a problem.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds