Virus and dialer not showing up at any scan!

Discussion in 'Malware Help (A Specialist Will Reply)' started by mini_sqrat, Jan 18, 2007.

  1. mini_sqrat

    mini_sqrat Private E-2

    Hello.

    I apparently have a dialer in my computer, but my AV (NOD32, updated regularly) could not find it. In addition, some .exe files when accessed by Spybot Search & Destroy (which I use regularly) or when I tried to move them to a different folder, caused a window in my AV System Monitor (AMON) to pop up, saying that there is a virus present, although all the exe files where scanned manually right after download.
    I followed all the steps you suggested, but with the exeption of counterspy, none of the others found anything. However, the dialer still persists, and another exe was found infected after the counterspy fixing what it had found.

    I attach the NOD32 threat log, just in case it proves useful. I am sorry if I am not supposed to attach this. Additionally, I was not able to get a report from the panda scan, since it found nothing.

    Thank you so much for your time

    Marina

    PS. I also use Zone Alarm as a firewall and I regurarly use Ad-Aware SE personal
     

    Attached Files:

  2. mini_sqrat

    mini_sqrat Private E-2

    And these are the rest of the files to be attached. Thanx again
     

    Attached Files:

  3. mini_sqrat

    mini_sqrat Private E-2

    Oups, I forgot to attach the most important :-(

    Sorry
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Why do you day you have a dialer? Do you have a log that says you have a dialer?

    You problems are more than likely due to the Cracks you or someone else is downloading and installing on this PC. Delete all the crack files and uninstall all the illegal software. That may stop you problems or at least it will help to keep them from getting worse.

    Is this Windows version a none english version? I see lots of jibberish characters in the newfiles.txt log and also things like below in HJT:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = ÓõíäÝóåéò
    O4 - Global Startup: ÃñÞãïñç åêêßíçóç HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

    And also like this too:
    C:\Documents and Settings\user\ÅðéöÜíåéá åñãáóßáò\Billy\keyfinder.exe

    Do you have corrupted folder names or is the above supposed to be Local Settings? If it is Local Settings then why does the below look OK?
    C:\Documents and Settings\user\Local Settings\Temp


    You have Spybot Teatimer running which we requested that you not run during the READ ME. You need to stop it at least while cleaning your PC of the below fixes (which are not really malware) will not work.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Mozilla Firefox (1.5.0.9)

    Make sure you reboot after uninstalling the above!


    Then install the current version of FireFox from: Mozilla Firefox

    If you need the Sun Java Development kit you can get it here: http://java.sun.com/javase/downloads/index.jsp



    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Platinum 2006 Internet Security\APVXDWIN.EXE" /s
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O16 - DPF: {A996E48C-D3DC-4244-89F7-AFA33EC60679} (Settings Class) -

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\user\ÅðéöÜíåéá åñãáóßáò\Billy\keyfinder.exe
    C:\Program Files\GameHouse\FeedingFrenzy\CrAcK.ExE
    H:\Billy\keyfinder.exe

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\
    C:\Documents and Settings\user\Local Settings\Temp

    Now run Ccleaner.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Jan 20, 2007
  5. mini_sqrat

    mini_sqrat Private E-2

    Hello again and thank you deeply for your help.

    To answer your questions

    1. No log shows a dialer, however, my computer keeps connecting to the internet without being prompt. I didn't know what to assume. Thankfully I have ADSL connection, and not pstn - dial up, as preselected.

    2. My windows version is greek. I am sorry that I cannot help you with the files you mentioned, cause I cannot see the characters also. The one I do know is this:
    "C:\Documents and Settings\user\ÅðéöÜíåéá åñãáóßáò\Billy\keyfinder.exe"
    The "ÅðéöÜíåéá åñãáóßáò" stands for "Epifaneia ergasias" which means desktop.

    3. About Tea Timer, I am sorry. I use spybot for a couple of years now, but the version I recently downloaded (updated) does not show Teatimer in the menu, and I did't know how to unselect it. However, I used the task manager each time I rebooted, to stop it from running this time, as I followed the steps you suggested. Is TeaTimer the Spybot resident?

    Now, I actually did what you suggested, but unfortunately my pc still connects to the internet without being prompt. Additionally, yesterday a new AMON notification came up, which you can see in the attached nod32threatlog.

    I cannot thank you enough for your time and your help.

    Looking forward to receiving your reply

    Thanx

    Marina
     

    Attached Files:

  6. mini_sqrat

    mini_sqrat Private E-2

    And here is the nod32 threat log

    Thank you
     

    Attached Files:

  7. mini_sqrat

    mini_sqrat Private E-2

    Just some minutes ago, while I wasn't using the PC at all, an AMON window popped up again. So, I attach the updated nod32 threat log.

    If my posting this log is isn't helpful please tell me so in your reply, so that I do not waste your time needlessly.

    Thank you once again

    Marina
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What NOD is finding is only in System Restore. Toggle system restore - see step 8 of the READ & RUN ME. Delete your NOD log so that from now on you only see new reports. Your log is also showing old stuff already removed.

    Are you still having problems?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure exactly what you mean by connecting to the internet. DSL is always connected. Do you mean that browsers are popping up by themselves?

    Teatimer is still the same as it always has been. Yes Teatimer is the active protection feature of Spybot. It is still showing trying to load in your HJT log. And it and CounterSpy may have blocked some of the last changes I requested.


    Please follow the steps below.

    First uninstall the CounterSpy trial since we are finished with it now. Then delete the below two folders:
    C:\Documents and Settings\user\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    To make sure Spybot's TeaTimer is disabled do the below
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!
    Now run HJT and fix the below lines:
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    Now exit HJT. Reboot and attach a new HJT log.

    If the two O2 BHO lines do not go away, we will need to use a special procedure to remove them.
     
  10. mini_sqrat

    mini_sqrat Private E-2

    Here in Greece, having an ADSL line means you get a modem, that is connected via usb in the PC. When you want to go into the internet, you use the connection just as the dial-up (e.g. double-click at the icon), you use the connect button, and instead of dialing a number, it dials adsl, and it requires a username and a password. What I meant by connecting automatically is that it would dial adsl and go into the net, all by itself. Of course, the connect automatically box is unchecked (at the connect by phone window that appears when you try to use the browser and you are offline)

    Anyway. I disabled tea-timer (thanx for the instructions) and I followed the steps you suggested. Also, I uninstalled nod32 and zone alarm, and I installed the kaspersky internet suite 6.0.1.411 (three months trial) to scan one more time, but it found nothing.

    To be honest, I haven't had a problem today with the internet, but still I will have to wait to see how things are going. Additionally, I have not been able to write a cd for a couple of days now. Actually, every time I try to insert an unused one, it says that it is full! I am completely lost...

    I attach the new hjt log. It seems that the 02 problems are fixed now. I would also like to ask you if it is safe to toggle system restore. I am not sure that everything is ok yet. Is it safe for me to backup my files or will it be risky to move the virus with them? I am thinking of formatting my pc if things continue to go wrong.

    I know I have said it many times, but once more thank you very very much. I am grateful for your help and the time you have spent to assist me.

    Be well

    Marina
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This could happen if you have any software that is trying to connect to the internet. This is not malware. Did this only happen when you started up your PC, or did it happen as soon as you opened a browser.

    Let us know if it still happens and describe exactly when it happens!

    I seriously doubt this has anything to do with malware.

    Yes you can toggle system restore. Your log is clean. By steps down below cover doing this.

    Yes it should be safe for you to make backups. But is your CD burner how you make backups?

    You're welcome!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds