please can someone help me :(

Discussion in 'Malware Help (A Specialist Will Reply)' started by tiffany311, Jan 28, 2007.

  1. tiffany311

    tiffany311 Private E-2

    My brother was using my internet over the weekend and I noticed that I have this System Alert warning, It says .......................
    System Alert:Malware Threats
    Your computer is infected with a back door Trojan that allows the remote attacker to perform various malicious actions. Click this baloon to download a malware removal software.......................

    What does this mean?

    I then went and checked in my Avg log and it showed

    Trojan horse Downloader.Zlobe.HNX
    C:\WINNT\System 32\ nnbbrhbd.dll
    Backup copy infected.

    Can some one please tell me what this means? I am so lost:(
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Now after attachin the above two logs, you need to continue with the below since you may have other issues too!

    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.

    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. tiffany311

    tiffany311 Private E-2

    Here is the results of my scan for your review now I am moving onto step 2.confused Thanks again I really appreciate it.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that found things as I suspected. Let's see rapport.txt number 2!
     
  5. tiffany311

    tiffany311 Private E-2

    here is report #2. but when it asked me to do registry cleaning it said that there was no registry to clean??
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't worry about it. Just continue on now to my next steps. These will take you awhile to run. Just complete all of the steps and come back and attach all of the logs.
     
  7. tiffany311

    tiffany311 Private E-2

    Hi, I was wondering where do I find a log to save with counter spy I don't see anything please help me find it so that I can save the log and proceed with the next scans thank you very much I am running windows 2000
     
  8. tiffany311

    tiffany311 Private E-2

    here is my counterspy scan, i hope i did it right:)

    Spyware Scan Details
    Start Date: 1/29/2007 8:57:28 PM
    End Date: 1/29/2007 9:15:53 PM
    Total Time: 18 mins 25 secs

    Detected spyware
    No spyware were found during this scan
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Continue on to the all the other steps! It is best if you complete all steps before coming back to post. You should be offline while doing much of the procedure.
     
  10. tiffany311

    tiffany311 Private E-2

    I don't know why but my Avg log won't post please help:cry
    I could not run runkeys.text I had a message that came up and said can't run on my computer?? as well as newfiles.txt
    anyways I am going to be doing the bit defender and panda scan:wave
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is no reason why the other steps of the READ ME (including GetRunKey and ShowNew ) should not run on your PC. If you are getting error messages, you need to observe the ones describe on the download pages for GetRunKey and ShowNew. And if any of those messages are what you are seeing, apply the appropriate fix. If those are not the messages you are receiving then you must give the exact word for word message that you are receiving.

    In addition you need to follow steps in the order written! Bitdefender and PandaActiveScan must be run BEFORE any of the following GetRunKey, ShowNew, or HJT.

    We don't need a log from your AVG antivirus program unless it is reporting something that the others are not.
     
  12. tiffany311

    tiffany311 Private E-2

    here are my other scans for your review.I will try to do the runkeys.txt and newfiles.txt:( :eek:
     

    Attached Files:

  13. tiffany311

    tiffany311 Private E-2

    I tried doing the two scans and it says that I can't because it is running somewhere else on my computer? I don't understand this please help:cry :cry
     
  14. tiffany311

    tiffany311 Private E-2

    I can't seem to run the other scan??:cry
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not following the directions on the download pages for ShowNew and GetRunKey. ALL files must be extracted from the ZIP file and you MUST run the .bat files from a Windows Explorer session as explained. Also you must check to make sure you are not getting any of the two error messages mentioned.

    Please follow the directions step by step and attach logs from both tools. The newfiles.txt log you attach is not complete because the instructions were not followed.
     
  16. tiffany311

    tiffany311 Private E-2

    I did both scans I am sorry but I have tried too many time to extract it somewhere other than my desktop. this is the best I can do. I read and reread your instructions and all I do is fail.:cry
    But here are my scans
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you got GetRunKeys extract and run properly at least. Now you need to run ShowNew and attach a new log since you also have it extracted to your Desktop.

    Then got back and do step 2 of the READ & RUN ME properly. You did not follow those directions. Make sure you follow each step for your Windows version. It looks like the only item you did not do properly was to Uncheck the option for Hiding extensions for know file types.
     
  18. tiffany311

    tiffany311 Private E-2

    I am sorry I tried and tried I give up, sorry for being a waste of time:(
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All you have to do is run ShowNew.bat just like you did GetRunKey.bat. You already have it extracted to your Desktop. Just double click on it to run it and the log will be created. Just make sure you double click on ShowNew.bat and not ShowNew.zip which is also still on your Desktop.
     
  20. tiffany311

    tiffany311 Private E-2

    I hope I did it right:)
    Please review and I will await for further instructions.:eek: rolleyes
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Now you got it! ;)

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 9
    System Alert Popup

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\CFK User.COMPUTER-5ED6C3\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    Did you choice to setup your start pages to blank.htm? If not, add the below 2 items to the HJT fix list below.
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
    O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
    O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
    O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
    O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone

    After clicking Fix, exit HJT.

    Now reboot in normal mode

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now locate the below folder and delete it if found:
    C:\Program Files\Video ActiveX Object

    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  22. tiffany311

    tiffany311 Private E-2

    Oh boy, I am just wondering why, when I booted my computer my avg has faded somewhat as there is absolutely no color to it at all?? My question is I went to see what was wrong and it says that my resident sheild is not loaded so I went into properties and tried to load it and it won't allow me to check the box that says to check it and the shield will load what can I do?
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall it, reboot (don't skip the reboot) then reinstall!

    Let me know if it is okay now. If not, tell me they complete version number you are running.

    Did you complete my last instructions? If so, I need to see the logs!
     
  24. tiffany311

    tiffany311 Private E-2

    Uninstall it, reboot (don't skip the reboot) then reinstall!

    What is it you are wanting me to uninstal? My AVG?? I am using the free Avg that has a resident shield.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes AVG is the subject!
     
  26. tiffany311

    tiffany311 Private E-2

    Ok now can you please email me a free avg download with a resident shield, thank you and I am doing those steps that you have requested:)
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  28. tiffany311

    tiffany311 Private E-2

    here are the scans you requested, also I was wondering if you can send me a link so that i can get free avg (grisoft)
     

    Attached Files:

  29. tiffany311

    tiffany311 Private E-2

    I keep getting this message that pops up it says.....................

    Messenger Service
    Message from System Alert on 2/4/2007 1:26:57 AM
    STOP! WINDOWS REQUIRES IMMEDIATE ATTENTION
    Windows has found CRITICAL SYSTEM ERRORS.
    Run Registry Repair from: http://fixwin32.com
    FAILURE TO ACT NOW MAY LEAD TO DATA LOSS AND CORRUPTION!


    then at the end there is a little box to click ok, what should I do?
    is this really serious??

    I wait to here back before doing something I might regret!
    Thanks again for your help!
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Already gave it to you in message # 27.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! it is not serious! Don't click on it.
    You did not do ALL of the steps I gave you in message # 21. At a minimum I can tell the registry patch was not done and it does not look like you fixed everything with HijackThis. Please go back and make sure you follow ALL steps and in the order given. Then attach new logs.
     
    Last edited: Feb 4, 2007
  32. tiffany311

    tiffany311 Private E-2

    I followed your instructions 2 times. I know I did what you said for me to do.:D
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry but your runkeys.txt log still indicates otherwise. Are you sure you are adding the fixME.reg registry patch to the registry exactly as specified. Are you getting a message that indicates it was successfully added? Because based on the runkeys.txt log it is not being added to the registry. Let's try again, but this time I'm going to add some additional items to it that HijackThis does not seem to be fixing either.

    First delete the below! This is not the correct place to run HijackThis from! You had it better (not what was requested but better) in earlier logs. Only run the one in C:\Program Files\analyse.exe\analyse.exe from now on!

    C:\Documents and Settings\CFK User.COMPUTER-5ED6C3\Desktop\analyse.exe\analyse.exe

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure you get a success message!!! And if you get any popups asking about adding this to the registry or from your antivirus or antispyware programs about a change being made, make sure you allow this change.

    Then attach news log from GetRunKey and HijackThis!

    Are your problems with AVG resolved now?
     
  34. tiffany311

    tiffany311 Private E-2

    Here you go:)
     

    Attached Files:

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which directions did you follow this time? Which registry patch did you add into the registry this time? The one from message number 34 as instructed or the previous one from message # 21. It looks like maybe you finally did #21 correctly (what were you doing wrong before), but you were supposed to do what is in message # 34.

    We are not going any further until you follow the instructions in message number 34 (all of the instructions in the message). You still did not delete the improperly installed version of HijackThis and you are therefore still running it wrong.
     
  36. tiffany311

    tiffany311 Private E-2

    please please please tell me I did something right! I am starting to get a bit frustrated::(
     

    Attached Files:

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well you did add in the correct registry patch now! ;) And it finally fixed what we needed to fix!

    But you are till not following all directions! You must slow down. And read all steps and follow them in the order written. I have requested multiple times that you do the below:
    And you still have not done this. It may not matter anymore now if all your problems are resolved.

    So let me ask whether you are still having any problems?
     
  38. tiffany311

    tiffany311 Private E-2

    NO I am not having no other problems! thank you very much for helping me;;)
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Now it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds