Malware help

Discussion in 'Malware Help (A Specialist Will Reply)' started by SAPMickey, Jan 29, 2007.

  1. SAPMickey

    SAPMickey Private E-2

    My wife virated us by clicking on, and running an attachment called Everlasting Love. She thought she recognized the sender as a trusted source and she feels terrible. :cry

    Our problems started with slow computer, then the blue screen of death with the following messages:

    driver_unloaded_without_cancelling_pending_operations
    page_fault_in_nonpaged_area
    irql_not_less_or_equal

    I also get an error message about sltckhdg.t and a Socket Notification Sink.

    There were a bunch of files with nonsensical names dumped on my desktop that i deleted.

    when shutting down windows, explorer.exe won't respond and i have to manually close it.

    I have follwed the Read & Run Me First. I am still concerned because subsequent scans still show errors.

    I attach the logs and appreciate any help.
     

    Attached Files:

  2. SAPMickey

    SAPMickey Private E-2

    More logs.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!


    You did not follow the instructions about not using MSconfig. See step 0 of the READ ME. Get in Normal Startup mode and attach a new log from HJT.

    Please download the current version of GetRunKey which was just updated yesterday. Attach a new log from it. After that, we will be able to get started.
     
  4. SAPMickey

    SAPMickey Private E-2

    How's this?

    thanks so much
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Better! Take a look at the end of it and you will see why I wanted you to run it. Notice the Trojan.Peacomm stuff.


    Also attach the new HJT log I requested. You may have missed that comment since I could have been editing my message while you were already reading it.


    Then uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\Mikel Buckmaster\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software
     
  6. SAPMickey

    SAPMickey Private E-2

    This is incredible. i can't believe you guys do this for free!!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Neither can we! ;)

    Hang on while a work up the first stage of fixes! Yes it will take a few stages due to what Trojan.Peacomm hooks into your registry.


    In the meantime, please download and install the following. We are going to need it later! Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\WINDOWS\SYSTEM32\game1.exe
    C:\WINDOWS\SYSTEM32\game2.exe
    C:\WINDOWS\SYSTEM32\game3.exe
    C:\WINDOWS\SYSTEM32\game4.exe
    C:\\WINDOWS\\system32\\taskdir.exe
    C:\\WINDOWS\\system32\\taskdir.dll
    C:\WINDOWS\SYSTEM32\zlbw.dll
    C:\WINDOWS\SYSTEM32\wincom32.ini
    C:\WINDOWS\SYSTEM32\wincom32.exe
    C:\WINDOWS\SYSTEM32\wincom32.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.
    After reboot locate the below folder and delete if found:
    C:\80b9f0f3bf5557ae9c

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Mikel Buckmaster\Local Settings\Temp

    Now goto Add/Remove programs and uninstall the below:
    My Way Search Assistant

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!
     
  9. SAPMickey

    SAPMickey Private E-2

    It will not let me delete IadHide5.dll 25kb, 2/11/2004

    I stopped at this point.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's probably because backweb is running somewhere. Just skip it for now and continue.

    It is probably due to the below Kodak junk!
    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe


    Why are you running this PC with NO PROTECTION?
     
  11. SAPMickey

    SAPMickey Private E-2

    How do i get rid of the Kodak junk?

    I was running BSafe for filter/virus. I had to uninstall it because the filter wouldn't let me run IE from safe mode.

    What's the best av software? Are you familiar with bsafe?
     

    Attached Files:

  12. SAPMickey

    SAPMickey Private E-2

    also, i couldn't find this in the list of programs.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is still in the registry! Run the below tool so I can figure out exactly what is there and I will give you a fix.

    Run this Getting Uninstall Programs List From The Registry and attach the log.

    Does Bsafe really contain an Antivirus, a realtime antispyware/,malware blocking tool, and a firewall? Were you running the Filer or the full Security Suite?

    Their security suite is really just McAfee!


    If it prevents you from running IE in safe mode, then you need to ask them for a fix. It should not do this and at a minimum should not be necessary to uninstall inorder to run IE in safe mode.
     
  14. SAPMickey

    SAPMickey Private E-2

    never mind
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click refresh and read again!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's continue to fix the issues from Trojan.Peacomm

    Run Registrar Lite navigate to each of the following keys (one at a time) and take ownership of them (I explained how to do that further down).

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINCOM32\0000\Control
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINCOM32\0000\LogConf
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINCOM32\0000
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINCOM32

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINCOM32\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINCOM32

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINCOM32\0000\LogConf
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINCOM32\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINCOM32

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_WINCOM32\0000\Control
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_WINCOM32\0000\LogConf
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_WINCOM32\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_WINCOM32


    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the Address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the top Menu
    • Select Take Ownership
    • Repeat these steps for all of the registry keys given above before continue to the next steps below.
    • Now leave RegistrarLite running and continue
    • Now run the fixME.reg REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate one at a time to each of the above keys we took ownership of to make sure they were deleted.
    • If any of the keys still exist, move on down to PART 2 - Setting Permissions for Everyone below!.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    PART 2 - Setting Permissions for Everyone
    Run the below if some of the registry keys still exist after running the above steps.

    Now I want you to use Registar Lite again to navigate to each of the below keys (one at a time) by pasting them into the Address Bar and hitting return. But this time click the Security menu item and select Edit Permissions so we can change permissions to everyone ( I describe this down below the list of registry keys).
    After click Edit Permissions , here is what I expect you to see in the Group or user names area of the form:

    Everyone
    SYSTEM

    Select Everyone by clicking on it. Now at the bottom in the Permissions box click the check box for Full Control. The click Apply and then OK to get back to the main Registrar Lite screen. Nowright click on the registry key and select Delete. The click View and Refresh. Check to see if the registry key just deleted truly deleted. If so, move on to the next to work thru the whole list. If it does not delete, I want you to boot into safe mode and repeat these exact same steps to see if we can do it from safe mode.

    Then reboot your PC!

    Now run GetRunKey again and attach a new log!
     
  17. SAPMickey

    SAPMickey Private E-2

    Attached Files:

  18. SAPMickey

    SAPMickey Private E-2

    nope

    here you go
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay looks like we got all of Trojan.Peacomm! How are things working?

    Let's get rid of the My Way Search Assistant.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Attach a new log from ShowNew.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also answer my question about Bsafe from message # 13.
     
  21. SAPMickey

    SAPMickey Private E-2

    Things are going fine. i ran spy bot and it found Tibs.vq
     

    Attached Files:

  22. SAPMickey

    SAPMickey Private E-2



    Well, their website says:

    "you can fully protect those you care about from porn, identity theft, spyware, and computer viruses by downloading the Bsafe Online filter and All-in-One Security Suite"

    i'm pretty sure i was using the full suite.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I suggest you reinstall it and then attach the below two logs:

    ShowNew
    HijackThis

    From this we should be able to tell!
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Attach a log from Spybot if this still shows up!


    Since I believe you are really basically clean now, it is time to do our final steps (That is if you are not having any other malware problems):

    If we used Pocket Killbox during your cleanup, do the below
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  25. SAPMickey

    SAPMickey Private E-2

    it couldn't fix 2 of them.
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Back in message number 8 I had you delete C:\WINDOWS\SYSTEM32\zlbw.dll This is relate to what Spybot is reporting as Tibs.vq. It is also know as Trojan.Abwiz.E

    You can use registrar Lite to delete the below registry keys if found. You may need to use the Ownership or Permissions trick again.

    HKEY_USERS\.DEFAULT\ColorTable19
    HKEY_USERS\.DEFAULT\ColorTable20
    HKEY_USERS\S-1-5-18\ColorTable19
    HKEY_USERS\S-1-5-18\ColorTable20

    Spybot did not report the below two, but look for them too since they are typical locations this trojan also uses.
    HKEY_CURRENT_USER\ColorTable19
    HKEY_CURRENT_USER\ColorTable20
     
  27. SAPMickey

    SAPMickey Private E-2

    Ok...I have reinstalled Bsafe.

    When i was closing, I had to manually shut down something called _____PTAWIA. i also got a Socket Notification Sink error. confused

    I have not completed the last two posts you told me to do, as I was concentrating on getting Bsafe reinstalled.

    What should I do?
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a malware problem! I would bet it is related to the Kodak software you are running at startup.
     
  29. SAPMickey

    SAPMickey Private E-2

    How do i keep it from loading at startup?

    Should i go back and do the two steps in the previous two posts?
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use HJT to fix the below two lines:
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

    Do the messages in the following order 26, 23 & 24.
     
  31. SAPMickey

    SAPMickey Private E-2

    I couldn't find any of these. I ran registrar lite and copied each line into the address. it took me to the root directory, but didn't locate the specifid files.
     
  32. SAPMickey

    SAPMickey Private E-2


    new logs attached
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All you seem to have from Bsafe is a popup blocker! You need an antivirus, antispyware blocker, and a real firewall. My final steps give a link (see below) which include steps and links for all of these.

    Please click Start,Run, and enter notepad C:\WINDOWS\SYSTEM32\ver.ini and click OK. Copy and paste the information that is shown in the notepad window that opens with the contents of ver.ini back here.

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  34. SAPMickey

    SAPMickey Private E-2

    here are the contents:

    [global]
    LgbMP.ocx = 2.2.0.8
    xcon.dll= 1.2.0.9
    QHTM.dll= 1.177
    lgbBidder.ocx= 1.2.2.7
    ijl15.dll = 1.5.4.36
    sdl.dll = 1.2.6.0
     
  35. SAPMickey

    SAPMickey Private E-2

    How do i tell if i'm running Service Pack 2?
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The ver.ini file is OK!


    You are running Win XP SP2. See the beginning of your HJT log. Also you can right click on My Computer and select Properties and you will see this info and more.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds