All kinds of problems. please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by bkinley24, Jan 9, 2007.

  1. bkinley24

    bkinley24 Private E-2

    First of all I am new to the forum so I hope I do this right. I have followed the steps and ran all the programs and will attach all on the scan logs. The problem I am having is first my computer has slowed down, it changes the theme on its own, and i believe I have a hijacker. When itry to go to my results on google or yahoo I get directed to other web sites. All the scans you have asked me to run aren't shpwing anything, but the AVG scan shows a Trojan.DNSchanger but it will not let me quarantine it. Also I have a trial version of NoAdware that indicates I am infected with Coolwebsearch, Trojan low zone, W32.Dbit, and MateWatcher. I tried the CW shredder to get rid of the coolwebsearch but it didn't find it. I would buy NoAdware but I am not familiar with the software so I am not sure if its reliable. I also have the trial version of XoftSpySE. It indicates I have Adwareloader and a lot of things labeled Viewpoint which it says may be potentially unwanted. Again I have not downloaded the full version because I am not familair with the software. Also a Thumbs.db file has shown up on my desktop and I didnt put it there. Can someone please help me fix this mess.
     
  2. bkinley24

    bkinley24 Private E-2

    Here are the first 3
     

    Attached Files:

  3. bkinley24

    bkinley24 Private E-2

    Here are the next 3
     

    Attached Files:

  4. bkinley24

    bkinley24 Private E-2

    Here is the hijackthis log
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    I don't know where you are getting your copy of the READ & RUN ME from but you are not downloading current versions of GetRunKey and ShowNew. Where the heck did you get them from? Please download the ones given in the READ & RUN ME and attach logs from the current versions.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After attach the new logs from GetRunKey and ShowNew, run this WareOut Removal and attach the requested log in that procedure.


    Then Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O17 - HKLM\System\CCS\Services\Tcpip\..\{18E99E3A-854C-48F2-AB26-FFA45CB53317}: NameServer = 85.255.116.91,85.255.112.234
    O17 - HKLM\System\CCS\Services\Tcpip\..\{4D01112D-1736-485B-ADDE-5F8A06E72A5A}: NameServer = 85.255.116.91,85.255.112.234
    O17 - HKLM\System\CCS\Services\Tcpip\..\{60D10807-90F0-4D45-9B3C-463296AC3653}: NameServer = 85.255.116.91,85.255.112.234
    O17 - HKLM\System\CCS\Services\Tcpip\..\{A3DF040A-6D38-40A7-8969-5A1B8EC53CEB}: NameServer = 85.255.116.91,85.255.112.234
    O17 - HKLM\System\CCS\Services\Tcpip\..\{F03405BD-60AD-4C0E-8BD3-E851512644AD}: NameServer = 85.255.116.91,85.255.112.234
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.91 85.255.112.234
    O17 - HKLM\System\CS1\Services\Tcpip\..\{18E99E3A-854C-48F2-AB26-FFA45CB53317}: NameServer = 85.255.116.91,85.255.112.234
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.91 85.255.112.234
    O17 - HKLM\System\CS2\Services\Tcpip\..\{18E99E3A-854C-48F2-AB26-FFA45CB53317}: NameServer = 85.255.116.91,85.255.112.234
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.91 85.255.112.234

    After clicking Fix, exit HJT.

    Then attach a new HJT log.
     
  7. bkinley24

    bkinley24 Private E-2

    New GetRunKey and ShowNew log
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now complete the instructions in message number 6 which it looks like you already started based on your GetRunKey log.
     
  9. bkinley24

    bkinley24 Private E-2

    FixWareout report
     

    Attached Files:

  10. bkinley24

    bkinley24 Private E-2

    I fixed the lines you state with hijackthis and am posting the new log file
     

    Attached Files:

  11. bkinley24

    bkinley24 Private E-2

    Just to let you know all the problems mentioned in the original post are still occuring. The only thing I noticed is that My google searches are not hijacked. But computer is still running too slow and NoAdware and XoftSpySE are still reporting same problems.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Installing too many antispyware programs that requite realtime system resources can be just as bad as installing multiple antivirus applications. You even have left over processes and services from software that you seem to have uninstalled but they did not uninstall completely. For example, I see a few things from Symantec/Norton and also from Webroot SpySweeper. We will clean them up below. We also need to remove a bunch of other unnecessary stuff and get a few updates. Run all the steps below in the order written.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to SymWMI Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteSymWSC into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Uninstall the below old versions of software:
    AVG Anti-Spyware 7.5 <-- I assume this is the trial from the READ ME? If so, uninstall it now unless you are going to buy it.
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 8
    J2SE Runtime Environment 5.0 Update 9
    Mozilla Firefox (1.5.0.8)
    Norton WMI Update
    Sunbelt CounterSpy <-- we are finished with this now and it is only a trial
    Viewpoint Media Player

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Also since Viewpoint software does not always uninstall properly, run this ViewpointKiller to remove Viewpoint Media software.


    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} - http://aolcc.aol.com/computercheckup/qdiagcc.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll

    After clicking Fix, exit HJT.

    Now reboot in normal mode


    Now locate the below file and folder and delete it if found:
    C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
    C:\Program Files\Common Files\Symantec Shared

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\Brandon K\Local Settings\Temp

    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!


    These are not high on my recommended list and if they are just trial programs that don't fix anything they are not useful. Especially since they are not even proving that they can fix what they find. Please attach NEW logs that show what these two programs are finding now after doing all of the above.
     
  13. bkinley24

    bkinley24 Private E-2

    Before I finish everything just wanted to let you know HJT will not let me delete the SymWSC. I copy it and paste it and hit ok. A warning comes up saying it is system-critical and can not be deleted.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You ignore the instructions I gave you. It said:
    • If you receive any error messages just ignore them and continue.
     
  15. bkinley24

    bkinley24 Private E-2

    I have done everything and am deleting the files from the C:\Documents and Settings\Brandon K\Local Settings\Temp
    folder. I deleted everything labelled file. Do I also need to delete the text documents, dat files, xml documents, emf image, and IadHide5.dll. Also there are folders within the folder do I delete those as well?
     
  16. bkinley24

    bkinley24 Private E-2

    Here are the log files
     

    Attached Files:

  17. bkinley24

    bkinley24 Private E-2

    After doing everything it has sped up a little. Also my google searches are not hijacked. NoAdware is stil showing I have the following
    coolwebsearch.xpsystem HKEY_Current_USER\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Windows\Run
    SpyGraphica
    HKEY_LOCAL_MACHINE\Software\Windows
    Trojan LowZone.BB
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\InternetSettings\ZoneMap\Domains\elitemediagroup.net
    W32.Dbit
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IrMon
    Mate Watcher
    C:\workssetup

    I don't want to try fixing this myself cause I am clueless what it means
     
  18. bkinley24

    bkinley24 Private E-2

    XoftSpySE still reports the following

    Adwareloader
    software\microsoft\windowsnt\currentversion\windows\run
    3 Viewpoint
    software\microsoft\windows\currentversion\ext\stats\{03f998b2-0e00-11d3-a498-00104b6eb52e}\iexplore\type
    software\microsoft\windows\currentversion\ext\stats\{03f998b2-0e00-11d3-a498-00104b6eb52e}\iexplore\count
    software\microsoft\windows\currentversion\ext\stats\{03f998b2-0e00-11d3-a498-00104b6eb52e}\iexplore\time
     
  19. bkinley24

    bkinley24 Private E-2

    Sorry for so many posts at once but I was looking through the programs file and the only thing i don't recognize is hotllama media. Do you know what that is. Also the Thumbs.DB file is on my desktop still and I dont remember putting it there
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now Download the Registry Search Tool

    Unzip to your Desktop and double click on regsrch.vbs
    (if you have script protection in your antuvirus program, please allow this to run)

    In the dialog that opens copy and paste in the following:

    03f998b2-0e00-11d3-a498-00104b6eb52e

    Press 'OK'

    The search will run for a while then alert you when it is finished. Press 'OK' and copy the contents of the WordPad window and attach it to this thread.


    Now repeat the above search for the below! I believe the elitemedia one will be a false positive (meaning NoAdware is wrong) since it is probably an item in your Restricted Zone.
    elitemediagroup.net
    IrMon
    SpyGraphica
     
  21. bkinley24

    bkinley24 Private E-2

    I ran the registry search tool. It located all of them except the SpyGraphica. Also earlier you had told me to delete all files in the temp folder but was i supposed to also delete the folders as well? Here are the wordpad results from th registry search.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also use RegSrch to look for this: WmdmPmSN

    Questions:


    1. Do you use any infrared devices on your PC? Like a mouse, keyboard,...etc. IrMon may just be the service mentioned here by Microsoft: http://support.microsoft.com/kb/326119

    I think much of NoAdware report is wrong but we do need to check on the IrMon service. I not sure that it is bad, nor am I sure that it is good. The Elitemedia report is more than likely totally wrong. Those were registry entries put into your Restricted Zone to protect you by Spybot or similar. NoAdware is irresponsible for not checking the values of the entries. We will double check later but I bet the values are all 4 which means they are OK! ​
    2. Does this folder exist C:\workssetup If so what is in it.
     
  23. bkinley24

    bkinley24 Private E-2

    It is a laptop and has built in wireless that I believe is infrared. I will check for the c:\workssetup as soon as I get home. Also I used a trial version of a different spyware program that reported that I have GAIN not sure what that is. My computer doea seem to be performing better but the internet is still running slower than it did. It takes a lot more time to load than usual.
     
  24. bkinley24

    bkinley24 Private E-2

    c:\workssetup does exist and this is what is in it: msworkst.exe, WBDBV31I.dll, a MSWORKS folder, and a OFFICE folder. I attached the RegSearch log for WmdmPmSN
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well then that is what NoAdware is falsely detecting!

    What spyware program are you referring too? And you NEED TO STOP downloading and installing anything except what we ask you to do. Many tools out there are rogue tools and many of them are not very good and have troubles with false positives, which is exactly what NoAdware is showing you. You should uninstall this NOW! I also recommend that you uninstall XoftSpySE too.

    Then Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Are you having any actual malware problems at this time?
     
    Last edited: Jan 10, 2007
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  27. bkinley24

    bkinley24 Private E-2

    Ok i removed NoAdwarre and XoftSpy. The other spyware program I had downloaded to use was Scan Spyware, it is the one that said I have GAIN. Should I post where it reported it being located or just delete the program?
     
  28. bkinley24

    bkinley24 Private E-2

    I added the notepad file to the registry. Do I need to leave the file on the desktop or move it somewhere or what? As for now I don't notice any malware problems. Only thing is that IE takes longer to load than usual. Also, my McAfee antivirus program sucks. I want to get a new one and dont mind paying for it. I also want a reliable firewall and spyware program again I dont mind having to pay for it. Do you have any recommendations on what software to get?
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is the worst of the three. In fact it is a rogue tool that is still on the rogue list. See it here: http://www.spywarewarrior.com/rogue_anti-spyware.htm

    Uninstall it now!
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First attach new logs from HJT and ShowNew so I can see where things stand. Then work thru the below. Yes you should dump McAfee and use what we recommend in the given link at the end. Firewalls are also included.

    It is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  31. bkinley24

    bkinley24 Private E-2

    Here are the new log files. Also there is a new problem I connect to the internet for like 10 minutes or less and then it says i am disconnected but the connection indicates it is excellent
     

    Attached Files:

  32. bkinley24

    bkinley24 Private E-2

    I finished doing the rest of the steps. Is there anything else I need to do or am I clean. Also A friend of mine recommended Kaspersky Anti-virus 6, is that worth the money.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not uninstall this rogue tool: ScanSpyware v3.8.0.4 Why not?

    Your clean but delete the below folder:
    C:\Documents and Settings\Brandon K\Local Settings\Application Data\Sunbelt Software

    Kaspersky is good but I recommend try the free tools out and see how you like them. There's no need to buy anything right now. Try the free ones (never install more than one at a time) and see if you have and preferences. They are all very good and many thousands of people use them and have no problems. Most malware problems come from things the end user does anyway.

    I see no reason for your connection to be dropping. Is this still happening? Are you sure you are not having problems with your ISP? Do you have any wired connections and are they having problems too?
     
  34. bkinley24

    bkinley24 Private E-2

    I fixed the internet. I had downloaded a windows update for the the wirless component and for some reason it wouldnt work after that so I just restored it to its state before the update. I forgot to delete the ScanSpyware before the scans but have deleted it now. I'm trying out the Avast anti virus program and its seems to work fine so I think I will stick with it. I was wondering have you heard of a program called sandboxie? Also thanks for all your help
     
  35. bkinley24

    bkinley24 Private E-2

    The only thing I notice with avast is it is unable to scan the following file but I am not sure why C:\WINDOWS\System32\logagent.exe. IS there a reason this file cant be scanned
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Yes I have heard of it but have never used it. It is available here at Majorgeeks: Sandboxie
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That file is Windows Media Player Logagent. I'm not sure why Avast would not be able to scan it unless it is being used at the time. Can it scan that file in safe mode?
    Next time you try to scan in normal boot mode, make sure ALL browsers and any other unnecessary applications (especially anything that may play sounds/music ...etc) are closed.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds