Spyware, possible Virus issue

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mac2118, Mar 1, 2008.

  1. Mac2118

    Mac2118 Private E-2

    I somehow managed to get some good stuff on my computer. Here's the symptoms:

    When ever I open My Computer, My documents, any folder, explorer.exe stops and restarts and the window I opened isn't opened. whenever I have IE open (I know.. I should have FF but for as much browsing as I do, this works fine) explorer.exe opens and closes, opens and closes (it's actually taken me bout 10 minutes to get to this point so far with having to click back in the txt field everytime)

    So far, I have ran my Symantec Antivirus and Ad-Aware. I have taken a HijackThis log and will include it at the bottom. if anyone couldhelp me out, I would really appreciate it!!!

    edit:

    I was looking over the log and noticed the rundll32.exe files. I ended the processes of those 4 instances that were running, and everything appears to be fine. I just need to get rid of the source of these problems.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. Mac2118

    Mac2118 Private E-2

    everything appears to be running better. however, when windows finishes starting up, I get errors that missing .dll's exist.

    attached are the requested files
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How in the world did you get Vista so badly infected. Have you been running this PC with UAC disabled all the time and have you been running without proper protection? It looks like all the protection software you have installed was just installed after getting your infection.


    Uninstall the below old versions of software:
    Java(TM) SE Runtime Environment 6
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {13521A14-0E2A-48FA-B1F3-17A01C4BE307} - C:\Windows\system32\hgghe.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\fcywx.dll,#1
    O4 - HKLM\..\Run: [3cf4079a] rundll32.exe "C:\Windows\system32\sjdneyxn.dll",b

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now do the below which you skipped in step 1 of the READ ME
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. Mac2118

    Mac2118 Private E-2

    things seem to be running a bit better. The dll file error at startup is gone. however, I get an error whenever I start up IE: Cannot find '::{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}'. Make sure the path or Internet address is correct.

    I did have norton AV on this computer, but since I started having these problems, I installed the symantec corporate version from where I work to see if that did any better with this problem (I did the same with Adaware also)
     

    Attached Files:

  6. Mac2118

    Mac2118 Private E-2

    here's the MGlog files. I wasn't able to edit the post.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are referring to the free version or Ad-Aware, it provides no protection at all and is not very useful in removing much of the malware in todays world. If you are referring to the paid version of Ad-Aware, it does offer protection but it is still not very useful in removing much of the malware in todays world.

    You started using MSconfig again to control startups which you must not do per step 1 in the READ ME. You need to read more about this. See the below link:

    Dealing with Startup Processes

    Put your PC into Normal Startup mode now and then continue with the below. Some items did not get properly fixed last time. Make sure you have no browsers open when you click Fix checked in HijackThis.

    You did not uninstall Viewpoint Media Player as requested. Please uninstall it now.



    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {13521A14-0E2A-48FA-B1F3-17A01C4BE307} - C:\Windows\system32\hgghe.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    Folder::
    C:\Program Files\Common Files\kkzi
    C:\Windows\kkzi
     
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{13521A14-0E2A-48FA-B1F3-17A01C4BE307}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds