Need help, totally lost.

Discussion in 'Malware Help (A Specialist Will Reply)' started by clanger69, Nov 13, 2007.

  1. clanger69

    clanger69 Private E-2

    The other day started to get pop ups about virus on my computer. One was ultimate defender. Then 2 new icon appeared on my desktop online security guide and live safety center. Now the only way to access internet is through safe mode. I ran some scan. Can somebody help me out, please.
     

    Attached Files:

  2. clanger69

    clanger69 Private E-2

    more scans
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the other requested logs from the READ & RUN ME:

    • CounterSpy
    • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy.
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis
     
  4. clanger69

    clanger69 Private E-2

    here you go
     

    Attached Files:

  5. clanger69

    clanger69 Private E-2

    another one
     

    Attached Files:

  6. clanger69

    clanger69 Private E-2

    last one, I can;t access the internet on normal boot, only on safe mode.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While I look thru all of your logs, please get HijackThis installed properly. You have it here:

    C:\Documents and Settings\Chris\Desktop\downloads\analyse.exe

    That is exactly where we specify not to install it. You need to have it here:

    C:\Program Files\HijackThis\analyse.exe
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I also just noticed that you skipped step 3 of the READ ME. You have both AVG7 and TrendMicro installed. You must uninstall one of these immediately.
     
  9. clanger69

    clanger69 Private E-2

    I removed avg7.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Per the READ & RUN ME you must not use Spybot's Teatimer function.

    Now Disable Spybot's TeaTimer
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!
    Uninstall the CounterSpy trial program now since we are finished with it.
    Also uninstall Viewpoint Media Player which was requested in step 0 of the READ ME.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: (no name) - {1E8A7125-5462-4E11-B575-57C8BF2ADC31} - (no file)
    O2 - BHO: (no name) - {2F02D978-0FF6-80F7-60BB-0426224AB7B3} - (no file)
    O2 - BHO: (no name) - {4CB8F4B4-5F66-4D9E-BC3B-184596A58824} - C:\WINDOWS\system32\byxwwwu.dll
    O2 - BHO: (no name) - {613C74A1-CA2C-4480-9433-ABC2EBA6C76C} - C:\WINDOWS\system32\pmnnm.dll
    O2 - BHO: {e90b4e40-cbcd-596a-ba84-1e969111a80a} - {a08a1119-69e1-48ab-a695-dcbc04e4b09e} - C:\WINDOWS\system32\fnvxrkbt.dll
    O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - (no file)
    O2 - BHO: (no name) - {FDBE523C-DE3A-4D50-A2BC-D362E2E38E23} - C:\WINDOWS\system32\awvtr.dll
    O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
    O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
    O4 - HKLM\..\Run: [2414b500] rundll32.exe "C:\WINDOWS\system32\bvoipsag.dll",b
    O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
    O20 - Winlogon Notify: byxwwwu - C:\WINDOWS\SYSTEM32\byxwwwu.dll
    O20 - Winlogon Notify: vnbknsrd - vnbknsrd.dll (file missing)
    O20 - Winlogon Notify: xdongflw - xdongflw.dll (file missing)
    O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\dpjoagoo.exe (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now let's run ComboFix to clean a few other misc items.
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log ( c:\combofix.txt ) for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. Combofix
    3. GetRunKey
    4. ShowNew
    5. HJT


    Make sure you tell me how things are working now!
     
    Last edited: Nov 15, 2007
  11. clanger69

    clanger69 Private E-2

    I fixed the location.
     
  12. clanger69

    clanger69 Private E-2

    O2 - BHO: (no name) - {FDBE523C-DE3A-4D50-A2BC-D362E2E38E23} - C:\WINDOWS\system32\awvtr.dll

    I don't have this line in hijackthis. what do I do?
     
  13. clanger69

    clanger69 Private E-2

    O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
    missing this one also
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just continue thru all steps.
     
  15. clanger69

    clanger69 Private E-2

    no good
     

    Attached Files:

  16. clanger69

    clanger69 Private E-2

    another
     

    Attached Files:

  17. clanger69

    clanger69 Private E-2

    mure
     

    Attached Files:

  18. clanger69

    clanger69 Private E-2

    when my computer rebooted there was a messege that said the avenger note pad could not be found.
    I'm still having the same problems, also now I have some 7.1 security taskbar.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Shutdown your antivirus program (TrendMicro) and AVG Antispyware and then run the Avenger part of the fix again Make sure you use the Avenger fix currently in the thread. I added some items to it.

    Then attach the log from Avenger and new logs from ShowNew and HijackThis. We will still have some more to do.
     
  20. clanger69

    clanger69 Private E-2

    here you go
     

    Attached Files:

  21. clanger69

    clanger69 Private E-2

    another
     

    Attached Files:

  22. clanger69

    clanger69 Private E-2

    last one, not getting any pop up now.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {3CAF6284-EBCE-4509-BF48-444848A4C63A} - C:\WINDOWS\system32\awvts.dll (file missing)
    O2 - BHO: (no name) - {4CB8F4B4-5F66-4D9E-BC3B-184596A58824} - C:\WINDOWS\system32\byxwwwu.dll (file missing)
    O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\gfrxdtkj.dll (file missing)
    O2 - BHO: (no name) - {D64E60F9-8EE8-4B80-88A7-55811F5A47C4} - (no file)
    O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\gfrxdtkj.dll (file missing)
    O20 - Winlogon Notify: byxwwwu - byxwwwu.dll (file missing)
    O20 - Winlogon Notify: gfrxdtkj - gfrxdtkj.dll (file missing)

    After clicking Fix, exit HJT.
    After fixing the above, get a new log from HijackThis and attach it here.
     
  24. clanger69

    clanger69 Private E-2

    here it is.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you miss fixing the below line or did it just not get fixed?

    O2 - BHO: (no name) - {D64E60F9-8EE8-4B80-88A7-55811F5A47C4} - (no file)

    Try again and tell me if it gets fixed.
     
  26. clanger69

    clanger69 Private E-2

    I did a new log
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  28. clanger69

    clanger69 Private E-2

    Thanks so much for your help. I'm aing one last prblem. When I type a web address int e, sometimes I go to a different web site. Attached is my latest hijack log
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This log is the same as your last log, clean!

    You will have to be more specific!
    1. How often does it occur?
    2. Does it happen right now?
    3. Does it happen only on certain URLs?
    4. Which URLs?
    5. Does it happen everytime on the same URL?
    6. Does it also happen in safe boot mode?
    7. Does it happen if you use another browser (like FireFox)?
    Note: If I were you I would uninstall AVG AntiSpyware and Windows Defender since you are using TrendMicro's AntiSpyware program.
     
  30. clanger69

    clanger69 Private E-2

    Sorry, I was having issues with my keyboard. Thanks again for all of your help.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds