Help...Virus Attack

Discussion in 'Malware Help (A Specialist Will Reply)' started by BenJoeM, Mar 21, 2007.

  1. BenJoeM

    BenJoeM Private E-2

    I am being attacked by viruses! It has taken me nearly 30 to 40 minutes to post this posting.

    Here are the three that Bitdefender is finding:

    Trojan.Juan.Q
    Trojan.peed.gen
    Adaware.vstoolbar.a

    Hijackthis Log Attached
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Quite often poor performance/slow PCs are mostly due to what and how many applications are being run. Your may fit into this category since you have so much running and you really need to take a good look at your own log and come up with a list of items you don't recognize. Also while doing that, decide whether there are items you recognize but don't need.

    At any rate to work on your malware problems (which you do have) you must try to do as much of the below as possible. The more you do, the better the chance that we can help you. The more logs the better. Also make sure HijackThis is installed and renamed as requested.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. BenJoeM

    BenJoeM Private E-2

    Thanks for the message, a smart idoit would have looked there first, but I was in a panic, so I am the dumb idiot.

    I have followed all the steps, and the computer seems to be running much better.

    I could not go into Safe Mode, the screen just stayed blank, so I did everything from Normal Mode, but disconnected from the network when it said I should.

    I have also saved all the log files. I have gone in and re-made sure my cookies were deleted so some of the spyware may now be gone and I could see most of the virus I was seeing are gone too.

    I am going to do more scans, but I am still struggling to get everything cleaned off, so I am going to post my logs. I did a search but couldn't find the info I needed.
     

    Attached Files:

  4. BenJoeM

    BenJoeM Private E-2

    Here are the last three

    Thanks for your help..
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    Continue by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)
    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of ddabc.dll once and then click the kill button. After you have killed all of the winhab32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    nnnljki.dll

    Next double click on explorer.exe and again click once on each instance of ddabc.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    nnnljki.dll

    Next double click on iexplore.exe and again click once on each instance of ddabc.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    nnnljki.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {6D797CF1-3D5E-4436-B891-0F12DEFBACA9} - C:\WINDOWS\system32\nnnljki.dll (file missing)
    O2 - BHO: (no name) - {9974412C-BA00-4581-ABDD-5F9D52D8C559} - (no file)
    O2 - BHO: (no name) - {C41AEDC3-F82C-46AC-91D9-BC991F1D2F05} - C:\WINDOWS\system32\ddabc.dll
    O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\qganvxec.dll",setvm
    O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O20 - Winlogon Notify: ddabc - C:\WINDOWS\system32\ddabc.dll
    O20 - Winlogon Notify: nnnljki - nnnljki.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Program Files\a.txt
    C:\462.tmp
    C:\WINDOWS\system32\ddabc.dll
    C:\WINDOWS\system32\jkhfg.dll
    C:\WINDOWS\system32\qganvxec.dll
    C:\WINDOWS\system32\nnnljki.dll
    C:\WINDOWS\system32\cbadd.bak1
    C:\WINDOWS\system32\cbadd.bak2
    C:\WINDOWS\system32\cbadd.tmp
    C:\WINDOWS\system32\cbadd.ini
    C:\WINDOWS\system32\cbadd.ini2
    C:\WINDOWS\system32\cexvnagq.ini
    C:\WINDOWS\system32\gfhkj.ini
    C:\WINDOWS\system32\jwioxqdj.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. BenJoeM

    BenJoeM Private E-2

    Ok, I am done.

    I hope this is it, it is running better. I was already ahead of you on the JSE thing. I have been browsing the other forums on this site and found that suggestion.

    I followed it step by step. The only problems I saw (or not problems) was most of the files nnnljki.dll could not be found. But one was left when I did HJT.

    Also a couple of the HJT Fixes I couldn't find either, I looked for 10 minutes to make sure but couldn't find them all, so I am hoping I got them all.

    Other than that it all ran well and I am posting my logs now. Please let me know what you think and give me any other suggestions. I have finally bogged down and deleted a ton of programs too.


    Thanks so much for your help, you have been amazing. Please let me know what more I can do.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually you were behind! You should have already done that in step 6 of the READ ME. Take a look! ;)


    Your problems spread inbetween the time you first posted and doing my fix. We have some more to do.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {D38439EC-4A7F-42b4-90C2-D810D7778FDD} - C:\WINDOWS\system32\gusvbkqf.dll

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\chg.exe
    C:\WINDOWS\system32\lbbmcjrf.exe
    C:\WINDOWS\system32\mgpydqdl.exe
    C:\WINDOWS\system32\mqwrielc.exe
    C:\WINDOWS\system32\pvapybtl.exe
    C:\WINDOWS\system32\rfastyct.exe
    C:\WINDOWS\system32\vrgtlqif.exe
    C:\WINDOWS\system32\vxxevdea.exe
    C:\WINDOWS\system32\ccytyghe.dll
    C:\WINDOWS\system32\gusvbkqf.dll
    C:\WINDOWS\system32\hxwyeroo.dll
    C:\WINDOWS\system32\qmhnelgh.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\VSAdd-in

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  8. BenJoeM

    BenJoeM Private E-2

    Ok, I went back to check and you are tight, I did miss it. I guess I assumed I had the most current. ASSUME - makes an AS$ out of U and ME

    Well, I did as instructed and here are the LOGS

    Let me know what the next step is:

    Thanks again for all your help!
     

    Attached Files:

  9. BenJoeM

    BenJoeM Private E-2

    It wont let me post the ShowNew Log, even if I change the name it says that I have already posted it.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before doing anything else, open up the newfiles.txt log and tell me what date and time you see on line 17 of the file.


    Also you did not tell me how things are currently working.
     
  11. BenJoeM

    BenJoeM Private E-2

    My system seems to running faster, I haven't had any popups either.

    As for Line 17, I am not sure what you mean. I would hate to post it right into a post, So I added a 123 to the file and it seems to upload now.

    BenJoe
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What I was getting at was that you were previously trying to upload the same old newfiles.txt log. You had not re-run ShowNew.bat. Now you did just completed re-running ShowNew.bat at Fri March 23, 2007 04:05:29 PM

    You did not need to add the 123 to it to the current log you just posted.

    In the morning when you ran GetRunKey at Fri March 23, 2007 07:46:44 AM
    You just did not run ShowNew to get a new log at that same time frame and that is why you could not attach it. It was the same old log.



    Another file showed up that needs to be deleted. Either use Pocket Killbox or delete the below manually:
    C:\WINDOWS\system32\msnxymgc.dll

    Then attach another NEW log from ShowNew.
     
  13. BenJoeM

    BenJoeM Private E-2

    Ok, I think I have done it right this time. I also have uninstalled a lot of programs, trying speed things up. The computer seems to be doing better, it still hangs every now and then.

    Tell me what you think
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You logs are basically clean except one file I had you delete (chg.exe) is not back and also some new strange looking files showed up. Do you know what the below are from/for?
    Code:
    "C:\WINDOWS\system32\"
    chg.exe       Mar 23 2007      114688  "chg.exe"
    
    "C:\WINDOWS\Temp\"
    00wcjku_.dll  Mar 23 2007           0  "00wcjku_.dll"
    00wcjku_.err  Mar 23 2007           0  "00wcjku_.err"
    00wcjku_.out  Mar 23 2007           0  "00wcjku_.out"
    00wcjku_.tmp  Mar 23 2007           0  "00wcjku_.tmp"
    00wcjk~1.cmd  Mar 23 2007         925  "00wcjku_.cmdline"
    00wcjk~1.cs   Mar 23 2007      179432  "00wcjku_.0.cs"
    
    You can have HJT fix the below lines which are not needed. This will help speed things up a little.
    O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
    O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"


    Everything else left now you will have to decide whether you need it or not. You have a ton of stuff running and I would bet you don't really need a lot of it. This quite typically of many laptops which barely run because way too many processes and device driver items get loaded. You have to be careful when you install software on your PC. Too many companies just install all kinds of junk that really is not necessary.
     
  15. BenJoeM

    BenJoeM Private E-2


    I have know Idea what the files are. I will do the rest, but should I fix those.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well the one in the C:\Windows\Temp folder should go away just by running CCleaner but I still wonder what you ran on March 23 rd that created them.

    Can you put the c:\windows\system32\chg.exe file into a ZIP file and attach it here?
     
  17. BenJoeM

    BenJoeM Private E-2


    Well, I just got to my computer after a long day on the road. I ran Ccleaner first and SpyBot, it found a bunch of stuff again so I immunized once more. Then went to System32 fold to get the file you requested. It is now gone. I wonder if cleaned with spybot or ccleaner. My computer is running very well right now, no slowdowns, no lag time. Do you want me to post another log to make sure.

    As for what I did on the 23rd, I am thought about it alot and I didn't do much with my computer that day. In the morning I did the tasks you asked me to do, then I went to work. It asked to update Sophos. I checked my email in outlook, then went to a Java Chat site for a customer support software group. Then I didn't touch my computer all day. Then around 4 pm I started to download a program that I already had on my computer but I wanted to reinstall and repair it. But then I stopped the download because I had already done it previously. Then I did your next set of tasks. That is it.

    Any ideas.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Attach a new log from ShowNew and let's see what is there now.
     
  19. BenJoeM

    BenJoeM Private E-2

    Ok here it is, I also noticed that I have Net Framework 1.1 and 2.0, can I delete 1.1 or do I need it. I had a program that required it, I still use the program but now I have 2.0 on my computer too.

    BenJoe
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  21. BenJoeM

    BenJoeM Private E-2

    Thanks so much for your help, the only other problem I am having is Outlook has been sending me emails that I know are viruses. For example I have been receiving emails from webmaster and administrator@ my server. I haven't opened the zip files attached. But I check with our IT department and they don't have web accounts for these names. Any ideas?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I doubt they are being sent to your from Outlook! They are being received by Outlook! They are probably incoming spam mail and the sender address is probably just being spoofed.
     
  23. BenJoeM

    BenJoeM Private E-2

    Ok, thanks again for all the help. I really appreciate it.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds