I need assistance please

Discussion in 'Malware Help (A Specialist Will Reply)' started by kartim, Feb 3, 2007.

  1. kartim

    kartim Private E-2

    I have a malware problem with pop ups,etc. I hope I did the Read and Run thing correctly. i've attached the results.
     

    Attached Files:

  2. kartim

    kartim Private E-2

    other attachments
     
    Last edited: Feb 3, 2007
  3. kartim

    kartim Private E-2

    my bsscan log is too large, I'll need to zip it.
     

    Attached Files:

    Last edited: Feb 3, 2007
  4. kartim

    kartim Private E-2

    other files
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have multiple antivirus programs running you must uninstall ALL but one as instructed in step 3 of the READ ME. You have AVG and Authentium's Command AV installed. Pick one and uninstall the other. Do this now before continuing!

    You have a load of problems most of which are due to you use of two many P2P programs and most of these where infected with bundles of malware. Take a quicklook at your CounterSpy log and you will see what I mean. You need to stop using these programs.

    You also need to manually clean up the we2iqjkr.Shak Family email profile in Thunderbird. See your PandaActiveScan log which indicates a bunch of malware in your Inbox.

    Panda indicates the below as being infected as Antivirus Golden. The below is the valid file name for the real AVG Antivirus program? Did you donwload and save this. Is it an illegal version from P2P downloading? It could be infected.
    C:\Downloads\avg_setup.exe

    Now you need to run this procedure: WareOut Removal attach the requested log after running it.

    Now run this procedure Virtumonde aka Trojan Vundo Removal and also attach the requested log after running it.

    After complete the above instructions move on to my next message!
     
    Last edited: Feb 3, 2007
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After doing what I posted in message # 5 continue with these instructions!

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_03
    Mozilla Firefox (1.5.0.9)

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Also Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Sunbelt Software
    C:\majorgeek\CounterSpy

    Now continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {9BD9D143-BEBD-4D34-A207-D99FE3EF773C} - C:\WINDOWS\system32\gebyx.dll
    O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\wnokergg.dll",setvm
    O4 - HKCU\..\Run: [ctpmon] ctpmon.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{28F466DC-E4E9-481F-A484-EA381897CCCC}: NameServer = 85.255.116.62,85.255.112.233
    O17 - HKLM\System\CCS\Services\Tcpip\..\{67A31D6D-0C02-4A72-9238-DB4EAB16CF23}: NameServer = 85.255.116.62,85.255.112.233
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.62 85.255.112.233
    O17 - HKLM\System\CS1\Services\Tcpip\..\{28F466DC-E4E9-481F-A484-EA381897CCCC}: NameServer = 85.255.116.62,85.255.112.233
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.62 85.255.112.233
    O20 - Winlogon Notify: gebyx - C:\WINDOWS\system32\gebyx.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Program Files\Common Files\{D86F2953-0897-1033-0726-040310170001}\Update.exe
    C:\WINDOWS\system32\ctpmon.exe
    C:\WINDOWS\system32\urroxtl.dll
    C:\WINDOWS\system32\wnokergg.dll
    C:\WINDOWS\baby.dll
    C:\WINDOWS\gift.dll
    C:\WINDOWS\system32\yhwnpbwu.dll
    C:\WINDOWS\system32\xybeg.tmp
    C:\WINDOWS\system32\ggrekonw.ini
    C:\WINDOWS\system32\lnexqkxe.ini
    C:\WINDOWS\system32\xybeg.ini
    C:\WINDOWS\system32\xybeg.ini2
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\Common Files\{D86F2953-0897-1033-0726-040310170001}

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  7. kartim

    kartim Private E-2

    I didn't know I had more than AVG on my computer. I'm pretty sure AVG is the only one I have now.

    I got rid of the P2P sharing programs (I hope) and the babysitter who was downloading everything. LOL

    Thunderbird problem should be fixed.

    AVG thing, I didn't know about and I deleted it.

    Wareout log is attached.

    Vundo log attached.

    Moving on to next set of procedures.
     

    Attached Files:

  8. kartim

    kartim Private E-2

    I decided to use IE so I haven't reinstalled Firefox.

    So far so good with everything. Let me know if I did something screwy or didn't do something correctly. Thank you so much for all of your help.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have some of the infection!


    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\csjsksgb.dll
    C:\WINDOWS\system32\kndqrbpv.dll
    C:\WINDOWS\system32\spvlhhpx.dll
    C:\WINDOWS\system32\vnyarqty.dll
    C:\WINDOWS\system32\ybktqhff.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.
    1. ShowNew


    Make sure you tell me how things are working now!
     
  10. kartim

    kartim Private E-2

    I think I got them all now. Thank you.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nope! Not yet and you did not do first step of my directions with Pocket Killbox to delete backups! Try again!! Make sure you delete backups first! And make sure you follow the directions exactly. Are you copying and pasting in the list of files or are you pasting them in on at a time?

    As a backup, after running Killbox and rebooting, check for the below files youself and delete them if still found:

    C:\WINDOWS\system32\csjsksgb.dll
    C:\WINDOWS\system32\kndqrbpv.dll
    C:\WINDOWS\system32\spvlhhpx.dll
    C:\WINDOWS\system32\vnyarqty.dll
    C:\WINDOWS\system32\ybktqhff.dll

    Then attach a new log from ShowNew but only if you believe you successfully delete all 5 files.
     
  12. kartim

    kartim Private E-2

    Alright, I'm pretty sure you're done with me. I got screwed up with what I did because of watching the Superbowl at the same time of trying to fix my computer. I pressed the EXIT key instead of the delete file button. rolleyes

    Using the "find" feature of notepad, I couldn't locate the five files. Hopefully now all I need to do is do the restore, restart procedure...

    Thank you again.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like you got them now, but you also had Pocket Killbox delete itself. Why? Anything in "C:\!KillBox\" is a backup from what Killbox has deleted and right now you have killbox.exe in that folder. It does not matter now since we are done with it, but I was just wondering why.

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  14. kartim

    kartim Private E-2

    I'm not sure how I had it delete itself, it's still on my system. I moved the exe to the folder so I would know where it was. Steps 1-8 are complete and now on to Step 9.

    You're awesome, thank you for taking the time to help me out.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You cannot save anything in the !Killbox folder since my first steps in using Pocket Killbox are to do the below:
    And this will delete everything in the !Killbox folder which is only a place for the program to store backups of what it deletes.

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds