Malware trouble - Help please

Discussion in 'Malware Help (A Specialist Will Reply)' started by Nero, Jan 25, 2007.

  1. Nero

    Nero Private E-2

    Hello. I've been having malware trouble with my PC, and would appeciate some help.

    I've completed all the steps in the 'Read and Run Me First' Thread.

    I'm attaching all the logs from these steps.

    Thanks
     

    Attached Files:

  2. Nero

    Nero Private E-2

    More logs
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Are you getting an error messages while running GetRunKey and ShowNew??? They are not running properly even though you are getting logs. Neither of them seem to be completing 100 %.

    You have some left over problems from SmitFraud and Virtumonde. Let's take care of them first.

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.


    Now run this Virtumonde aka Trojan Vundo Removal

    Now attach logs from:
    • the two rapport.txt logs
    • VundoFix
    • a new GetRunKey log
    • a new ShowNew log
    • a new HJT log
    How are things working now?
     
  4. Nero

    Nero Private E-2

    Thanks a lot for your help - it's much appreciated!

    No error messages appear when running GetRunKey and ShowNew.

    Completed Step 1, and attaching log.

    Thanks.
     

    Attached Files:

  5. Nero

    Nero Private E-2

    OK, I've run Step 2 now, and also the Virtumonde Removal. I'm attaching the logs.
     

    Attached Files:

  6. Nero

    Nero Private E-2

    More logs.
     

    Attached Files:

  7. Nero

    Nero Private E-2

    Although my Norton subscription has run out, and I've replaced it using free programs recommended by this site, it still pops up and a few days ago did so with a message saying:
    "Your computer is not protected against Trojan.Peacomm"

    I'm also unable on Internet Explorer to get into my Hotmail or other email accounts, and certain other sites. I have no idea what might be causing this problem.

    Thanks again for your help.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to your logs, Norton was still installed so I cannot comment on this yet until you complete the below and I get new logs.

    Do you still have any software from Wanadoo installed and do you use it? I see references to it in your logs?

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 3
    Java 2 Runtime Environment, SE v1.4.2_03

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
    O2 - BHO: (no name) - {7C91959F-1483-4775-988D-0E7C7011546A} - C:\WINDOWS\Cursors\ocmmws.dll (file missing)
    O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\sjfeveki.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Program Files\Video ActiveX Object\isamonitor.exe
    C:\Program Files\VSAdd-in\VSAdd-in.dll
    C:\WINDOWS\system32\dgcdpbls.exe
    C:\WINDOWS\system32\eoslmobq.exe
    C:\WINDOWS\system32\gwvlndwp.dll
    C:\WINDOWS\system32\mhiybuae.exe
    C:\WINDOWS\system32\oiuamovu.exe
    C:\WINDOWS\system32\omyduhsg.exe
    C:\WINDOWS\system32\pemuysnl.exe
    C:\WINDOWS\system32\Process.exe
    C:\WINDOWS\system32\siejaenn.exe
    C:\WINDOWS\system32\tdmbrolf.exe
    C:\WINDOWS\system32\uwyjxkdw.dll
    C:\WINDOWS\system32\vldacosu.exe
    C:\WINDOWS\system32\wgwuwhpw.exe
    C:\WINDOWS\system32\xfrlfxbd.exe
    C:\WINDOWS\system32\yddlbohb.exe
    C:\WINDOWS\mickey32.dll
    C:\WINDOWS\system32\bjopnbuw.ini
    C:\WINDOWS\system32\fuuhrhex.ini
    C:\WINDOWS\system32\ihdrbftd.ini
    C:\WINDOWS\system32\konigqqj.ini
    C:\WINDOWS\system32\lgugshgo.ini
    C:\WINDOWS\system32\mrjkqicm.ini
    C:\WINDOWS\system32\mwauuqtr.ini
    C:\WINDOWS\system32\pjbalhuw.ini
    C:\WINDOWS\system32\synaxors.ini
    C:\WINDOWS\system32\wmjjtyce.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folders and delete if found:
    C:\Program Files\VSAdd-in
    C:\Program Files\Video ActiveX Object

    Now run Ccleaner!
    Also delete all files and subfolders in the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\Dominic Rogers\Local Settings\Temp\

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  9. Nero

    Nero Private E-2

    Hi.

    There was some Wanadoo software installed on my PC when I bought it, but I uninstalled it a while ago - I don't think there's anything to do with it still in the Add/Remove Programs list.

    Things are still working the same: I can't access the same websites (Hotmail etc.). All pop-ups seem to have stopped though. Norton is still coming up with the same error message - should I uninstall Norton altogether?

    Attaching logs.

    Thanks.
     
  10. Nero

    Nero Private E-2

    Logs.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! We will remove the remaining items manually!

    Let's wait and see! Do you have more info from Norton? Does it tell you any file names and paths? Have you run a full scan with it after booting in safe mode?


    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\Dominic Rogers\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In message number 7 you said
    It does not look like you actually did what you said.


    Now Download the Registry Search Tool

    Unzip to your Desktop and double click on regsrch.vbs
    (if you have script protection in your antuvirus program, please allow this to run)

    In the dialog that opens copy and paste in the following:

    wincom32

    Press 'OK'

    The search will run for a while then alert you when it is finished. Press 'OK' and save the contents of the WordPad window to a text file and then attach the file to this thread.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also please download the current version of GetRunKey (just updated today) and attach a new log from it now.
     
  14. Nero

    Nero Private E-2

    Thanks for your continued help.

    I ran a full Norton scan in safe mode: no errors found.
    The error message that pops up from the Norton icon on the taskbar gives a link about this 'Trojan.Peacomm': http://www.symantec.com/security_response/writeup.jsp?docid=2007-011917-1403-99


    I ran this, and the only message I got was one saying:
    "No instances of 'wincom32' were found." No WordPad window to save.

    Attaching GetRunKeys log.

    Thanks.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not helpful at all! Don't they tell you what they are finding and where? If not, complain to Symantec if you bought this program. Information like that is not helpful and if they are detecting something, why aren't they fixing it. Your logs do not show any signs that I can see of the infection. This does not mean that some aspect of it does not exist. It just means from the logs, I cannot see it. But based on what I see, if you do have anything left around, it is probably inactive.

    Please complete Step 8 of the READ & RUN ME. Does Symantec still give you the message after following step 8?
     
  16. Nero

    Nero Private E-2

    I think I may have misunderstood the alert. Clicking on Symantec Help Centre, I find this:

    So the computer is NOT infected, merely not protected.

    Should I still run Step 8 of Read & Run Me?

    Thanks
     
    Last edited by a moderator: Jan 29, 2007
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's different! And yes this is a problem that is occurring a lot lately. And it is why I have the newest version of GetRunKey that I had you download. Get your Symantec updates ASAP.

    Instead of doing that! Do the below which will include it!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  18. Nero

    Nero Private E-2

    OK, I've done this.

    A few problems remain; whether they are due to Malware or not, I'm not sure:

    1. I cannot access Hotmail, eBay, and a few other internet sites.

    2. On Control Panel > User Accounts, I can't change the way users log on or off. Instead I get a message saying:

    "A recently installed program has disabled the Welcome screen and Fast User Switching. To restore these features, you must uninstall the program. The following file name might help you identify the program that made the change: RtlGina2.dll"
     
    Last edited by a moderator: Jan 29, 2007
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Probably not malware but please describe what you mean by cannot access

    Not malware. Probably due to installing your NETGEAR WG111v2 wireless USB 2.0 adapter software.

    See this discussion:
    http://www.microsoft.com/communitie...&tid=0ea79537-f61f-4688-8629-b2d009f1b734&p=1
     
  20. Nero

    Nero Private E-2

    OK, I can open up hotmail's home-page, but when I type in my address and password, all I get is a page saying "Internet Explorer cannot display the webpage".

    eBay - I can browse, but cannot sign in: same message of "Internet Explorer cannot display the webpage".
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not malware! Try the below but I'm not sure it will change anything!

    Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Also see this: http://support.microsoft.com/kb/926431

    Try using FireFox and tell me it you can get in using it. You may need to discuss these problems with Microsoft and eBay!

    Make sure you do not have any settings in your antivirus or firewall that could be blocking it. Try disabling your AV and firewall as a quick test.
     
  22. Nero

    Nero Private E-2

    Right, this seems to have solved the problems.

    Thanks a million for your help! :)
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds