Clean or not?

Discussion in 'Malware Help (A Specialist Will Reply)' started by TheFishDrowner, Jan 26, 2008.

  1. TheFishDrowner

    TheFishDrowner Private E-2

    I was downloading a patch upgrade for one of my games when Mcafee told me I had a virus (probably shouldn't have just Googled the patch and should've gone to the game site). I deleted it and of course more came eventually.

    I decided to do some scans when i looked in MyDocuments and there were over 1000 .tmp files there. I can't remember what they were labeled because i eventually deleted them in safe mode after running the scans, but it started with a 'p'.
    (sorry about being vague)

    Also, Spybot found a bunch of Virtumonde which it was able to delete.

    When I opened Internet Explorer (I generally use Firefox) to do a scan a whole bunch of tabs were open with blank:about in the title. This problem ended after a couple scans.

    While the obvious symptoms of malware are gone I was hoping you guys could do a quick check for me. Thanks in advance.

    Take your time in responding as I won't check until tomorrow and maybe you can help someone tonight.

    Sorry I don't have an AVG log but I can tell you that there was nothing rated above medium and almost everything was a tracking cookie.
     

    Attached Files:

  2. TheFishDrowner

    TheFishDrowner Private E-2

    Another thing... when i turn on my computer i get a message:

    Error loading C:\WINDOWS\system32\ecivlkgf.dll
    The specified module could not be found.
     
  3. TheFishDrowner

    TheFishDrowner Private E-2

    oops I forgot a couple of logs
     

    Attached Files:

  4. TheFishDrowner

    TheFishDrowner Private E-2

    and i forgot another one
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please only attach the logs that are requested in the procedure. You should not be attach any of the files you see in the C:\MGtools folder. They are already in the C:\MGlogs.zip file.

    Please download a current copy of ComboFix from here: combofix.exe and save it to your Desktop.

    Now we need to run ComboFix but before running it, shutdown/stop all of your protection software to the best of your ability. This includes antivirus, antispyware, or any other protection shields or similar. Any of these programs could interfere with the proper operation of ComboFix
    • Now run ComboFix by double clicking the combofix.exe icon on your Desktop & follow the prompts.
    • When finished, it will produce a log ( C:\combofix.txt ) for you.
    • Notes:
      • Do not mouseclick combofix's window while it is running. That may cause it to stall.
      • ComboFix (CF) disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting
    Attach this new C:\ComboFix.txt log.


    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {9CD28369-BCB3-4E20-8D7B-F8FD4CDF9941} - C:\WINDOWS\system32\mljjh.dll
    O2 - BHO: (no name) - {A051B1FF-8D7E-418B-AABE-4FF82F4280A2} - C:\WINDOWS\system32\nnnklih.dll
    O2 - BHO: {2896c961-e5d1-5688-31e4-44cecf700d4c} - {c4d007fc-ec44-4e13-8865-1d5e169c6982} - C:\WINDOWS\system32\prkawwvi.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [cc9316a7] rundll32.exe "C:\WINDOWS\system32\ecivlkgf.dll",b
    O20 - Winlogon Notify: nnnklih - C:\WINDOWS\SYSTEM32\nnnklih.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger. And don't forget the new ComboFix log.

    Make sure you tell me how things are working now!
     
  6. TheFishDrowner

    TheFishDrowner Private E-2

    I ran analyse.exe but couldn't find these lines:

    O2 - BHO: (no name) - {9CD28369-BCB3-4E20-8D7B-F8FD4CDF9941} - C:\WINDOWS\system32\mljjh.dll
    O2 - BHO: (no name) - {A051B1FF-8D7E-418B-AABE-4FF82F4280A2} - C:\WINDOWS\system32\nnnklih.dll
    O20 - Winlogon Notify: nnnklih - C:\WINDOWS\SYSTEM32\nnnklih.dll

    Things are moving much smoother on my computer and I didn't even realize before that it was slow.

    Thanks again
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well uninstalling McAfee had a very big effect. ;) But you do need to either reinstall it or something given from my final instructions.


    Your logs are clean but you can do the below to remove some unnecessary startups including one from McAfee which is not even installed right now.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup

    After clicking Fix, exit HJT.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds