Need Removal Help-Followed Defined Steps

Discussion in 'Malware Help (A Specialist Will Reply)' started by shelleydan, Feb 4, 2007.

  1. shelleydan

    shelleydan Private E-2

    I'm so glad you're out there to help! I followed all the steps outlined on your site & I still need some removal help. I'm working on my nephew's machine & he doesn't have the CD's that came with his laptop, so starting over wasn't an option.

    He has a Toshiba Satellite laptop, celeron 2.8 ghz, 192 mb ram, 60 gb hd with 20 gb free. Running Windows XP Home with all updates. The machine is running with no major problems now, but I know there are still some bad things out there. I ran a new hjt this morning since I ran all the others last weekend. I'm attaching what I can now.

    Thank you so much for your help! Shelley
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    C:\WINDOWS\System32\n?pdb.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    O4 - HKLM\..\Run: [vz8YXH4uh] C:\documents and settings\billy gene\local settings\temp\vz8YXH4uh.exe
    O4 - HKLM\..\Run: [VvQWF] C:\documents and settings\billy gene\local settings\temp\VvQWF.exe
    O4 - HKLM\..\Run: [u7Xy] C:\documents and settings\billy gene\local settings\temp\u7Xy.exe
    O4 - HKLM\..\Run: [p0yp81WI] C:\windows\system32\p0yp81WI.exe
    O4 - HKLM\..\Run: [o7yrOCUPm] C:\documents and settings\billy gene\local settings\temp\o7yrOCUPm.exe
    O4 - HKLM\..\Run: [Lo] C:\documents and settings\billy gene\local settings\temp\Lo.exe
    O4 - HKLM\..\Run: [lMm4zGyC7] C:\documents and settings\billy gene\local settings\temp\lMm4zGyC7.exe
    O4 - HKLM\..\Run: [Ijc.exe] c:\windows\system32\Ijc.exe
    O4 - HKLM\..\Run: [iGYTExK9] C:\documents and settings\billy gene\local settings\temp\iGYTExK9.exe
    O4 - HKLM\..\Run: [bobItk] C:\documents and settings\billy gene\local settings\temp\bobItk.exe
    O4 - HKLM\..\Run: [5RRYCN95CGHCGH] C:\WINDOWS\System32\Dkp0h.exe
    O4 - HKCU\..\Run: [Gmfsusga] C:\WINDOWS\system32\r?gsvr32.exe
    O4 - HKCU\..\Run: [Osus] C:\Documents and Settings\Billy Gene\Application Data\rrup.exe
    O4 - HKCU\..\Run: [Ipuhwds] C:\WINDOWS\System32\n?pdb.exe
    O4 - HKCU\..\Run: [LooqRfd4i] dswij.exe
    O15 - Trusted IP range: 206.161.125.149

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
  3. shelleydan

    shelleydan Private E-2

    Hi Tim. I'm having trouble running pocket killbox. When I click on the red & white delete button it tells me, "you have not specified any file to delete, you must specify a file path in the yellow box".

    I went to notepad & did cntl C to make sure I had the files on the clipboard & I did. I also redownloaded pocket killbox & I tried it a second time with the same results.
     
  4. shelleydan

    shelleydan Private E-2

    I found another post that described putting each file name into pocket killbox, so I did it that way. I did get the message 'PendingFileRenameOperations'. I'm attaching the new hjt log & the other two logs you wanted.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You downloaded the Panda program rather than doing the online scan. Please uninstall it though Add/Remove Programs in the control panel.

    Please do a search for these files by going to Start / search and click on advanced to select hidden files and folders. You may have to right click on Start / explore and scroll down to these. Do not do anything with these. Just tell me if they are there, right click on them and tell me what the properties of the files say.
    C:\WINDOWS\system32\r?gsvr32.exe
    C:\WINDOWS\System32\n?pdb.exe

    This one you can delete if found!
    dswij.exe

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [crmh.exe] C:\WINDOWS\system32\crmh.exe

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.


    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT

    Be sure to tell us how things are running.
     
  6. shelleydan

    shelleydan Private E-2

    I uninstalled Panda..sorry about that.

    I did not find any of the files you noted, however, something looks funny to me with the nopdb.exe (not n?pdb.exe). It was listed at the end of the files that started with N (the list was in alphabetical order, except this file was at the end of the N's - not where it belongs alphabetically. I took an MWsnap picture of the list if you want to see it.

    I still couldn't get killbox to copy my list from the clipboard, but I did them individually like I read in another post. I'm attaching the new logs.

    The boot process seems really slow to me (>5 minutes). Once it's running, it seems fine. I checked the event log & found the following, but I think it's because it's busy doing something else. From looking at the log it looks like it took 10 minutes to boot.

    The server could not bind to the transport \Device\NetBT_Tcpip_{8E96B772-ACA9-4370-BBC4-F70215132DF2} 2504

    The server could not bind to the transport \Device\NetbiosSmb because another computer on the network has the same name. The server could not start. 2505

    THANKS FOR ALL YOUR HELP!!! I would've never figured all this out!
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run this Virtumonde aka Trojan Vundo Removal

    Now attach the below logs and tell me how the above steps went.
    1. Combofix log
    2. VundoFix log
    3. new GetRunKey log
    4. new ShowNew log
    5. new HJT
     
  8. shelleydan

    shelleydan Private E-2

    I ran combofix & the log is attached. I ran vundofix & it didn't find anything & it didn't produce a log. I ran the others & will attach the files. Everything ran OK.
     
  9. shelleydan

    shelleydan Private E-2

    Additional files...
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We don't need the vundo log, but I do need the others!
     
  11. shelleydan

    shelleydan Private E-2

    Sorry, I thought I did attach them. I see what I did...I shut down the upload window while it was working.
     

    Attached Files:

  12. shelleydan

    shelleydan Private E-2

    More files. One didn't make it last time.
     
  13. shelleydan

    shelleydan Private E-2

    I'll try one at a time.
     
  14. shelleydan

    shelleydan Private E-2

    I'm having trouble getting the files there!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try again to attach all the logs rquested including ComboFix.

    Next time you have a problem attaching them, exit the Managing Attachments window and try the below (assuming you are using IE as your browser)
    1. Click Tools and select Internet Options
    2. then on the General tab, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    3. Now click Refresh
    4. Now try uploading your attachments again.
    If this still does not work tell us how large each file is!
     
  16. shelleydan

    shelleydan Private E-2

    I split the combofix file in half last night. The two files are 642,992 + 786,339. What's the limit on txt files? There's one program, FL Studio 5, that has TONS of entries in what appears to be the hidden files section.

    My nephew is into recording music. I assume this program has something to do with that?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Compress the logs into a ZIP file and attach the ZIP. If necessary, make multiple ZIP files.
     
  18. shelleydan

    shelleydan Private E-2

    Here's the combofix zipped & the hjt. With these, I think you have everything you asked for last.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\Billy Gene\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Middadle <-- this is malware

    Make sure you reboot after uninstalling the above!

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O4 - HKCU\..\Run: [Porb] "C:\WINDOWS\System32\PPPATC~1\msconfig.exe" -vt ndrv
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)

    After clicking Fix, exit HJT

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell us how things are working now!
     
  20. shelleydan

    shelleydan Private E-2

    All of these steps went fine. I did not see one of the left over sunbelt folders (below) after the uninstall.

    C:\Documents and Settings\Billy Gene\Local Settings\Application Data\Sunbelt Software
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How are you looking for it? It is still there. Use Windows Explorer. Not Windows Search. We only configure Windows Explorer to see hidden & system files in step 2 of the READ ME. Windows Search will not show hidden or system files unless it is provisioned to do so and that is provisioned separately from within the search window.


    Are you sure you had HijackThis fix the below lines? I still see them. Did you uninstall CounterSpy first as requested?
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0\bin\jusched.exe
    O4 - HKCU\..\Run: [Porb] "C:\WINDOWS\System32\PPPATC~1\msconfig.exe" -vt ndrv
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)

    Shutdown AVG Antispyware and then have HJT Fix the above lines again and attach a new HJT log.

    Also tell us if you are having any other problems.
     
  22. shelleydan

    shelleydan Private E-2

    Are we finished with the malware removal? I've noticed something else while going thru this. Just tell me if this needs to be a new post.

    When I go to start/run & type msconfig it tells me it can't find the file. But the file is where it should be & will run if I run it from explorer.

    When I click on Help & Support it tells me it can't find helpctr.exe. Again, the file is where it should be. Also, helpsvc.exe has run excessively - taking 100% of the cpu.

    I've compared the path in DOS to my machine and I don't see anything missing there. I don't know where else to look for a breakdown.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes and no! You did not finish the instructions in my last message and attach the follow up HJT log.

    And them, if you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    This is not a topic for the malware forum, but I will give you something to do. If it does not help, you will have to continue looking for help about this in the Software Forum. Goto this link: http://www.kellys-korner-xp.com/top10faqs.htm and click on the Why doesn't Help & Support work questions. Follow those instructions.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds