Malware i can't get rid off

Discussion in 'Malware Help (A Specialist Will Reply)' started by Rick_1138, Mar 24, 2007.

  1. Rick_1138

    Rick_1138 Private E-2

    Hi all,

    i am new to the forum, however was directed here from DearWandy.com.

    I have found some malware on my PC but i do not know how it has gotten there.

    i am experiencing some pc slowdown and i am getting pop ups, only while browsing however.

    i have Firefox, i have AVG anti-virus and anti-spyware, i have spybot also.

    I have cleaned my drive many times and these files cannot find anything, i have run CCleaner etc as per your anti malware instructions and i have now run Hijackthis.

    Could someone please look over my log file from Hijack and advise me if i have a problem

    i have attached the log file as per instructions but if i have done this incorrectly, please advise me as to what to do.

    I would be very grateful for any advice someone could give me.

    regards

    Rick
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi Rick and welcome to the forums


    Sadly Hijackthis only shows up a very small proportion of malware on a pc as its limited in what it scans for so to that end and to fully remove malware off your PC we will need you to complete the below:


    Our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. Rick_1138

    Rick_1138 Private E-2

    Hi,

    thanks for the rewply, i am currently carrying out all of the tests to get reports for my next post.

    However during my hunting about, i have noticed that in the process tab of the task manager there is something running called (System idle process SYSTEM) it is using about 90% CPU and is about 16kb big.

    is this possibly the main issue, or is this a normal running process?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    System Idle Process is not a real process. It is just the amount of idle time your processor has and ideally you want this to be very high. What you should be more interested in is what is using the other 10%!
     
  5. Rick_1138

    Rick_1138 Private E-2

    Okay i have gone through all of the steps given and have gotten the desired log files in the correct order.

    Please find them attached in this reply and the next one.

    I hope you can help me with this as i have been doing this for 7 hours, and i am on my 6th cup of coffee, its 4 am here as clocks just went forward, i am away to bed now.

    Many thanks for the help so far, Computing is fun isn't it? lol
     

    Attached Files:

  6. Rick_1138

    Rick_1138 Private E-2

    here is the other 3 reports (runkeys, newfiles and hijack this)

    I am still experiencing ad pop ups, after all of the advised steps.

    i have even carried out the spyaxe et al anti virus link, as this was on my old PC but it cam e up clean.

    I hope you can help me guys

    Best Regards

    Rick
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is the below file for??
    C:\Documents and Settings\Richard Rose\My Documents\InternetGameBox_setup.exe

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 3
    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\3.bin\MWSBAR.DLL,S
    O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll
    C:\Program Files\MSN Messenger\riched20.dll
    C:\WINDOWS\system32\hztfgyseff.exe
    C:\WINDOWS\system32\hztfgyseff.dat
    C:\WINDOWS\system32\hztfgyseff_nav.dat
    C:\WINDOWS\system32\hztfgyseff_navps.dat
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\MY Web Search <---- or anything similar to MyWeb.....

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. Rick_1138

    Rick_1138 Private E-2

    Hi there,

    thanks for the help so far. I have carried out the steps you mentioned and i have attached the required logs.

    However i am still getting pop ups on my browser, i hope you have some further ideas as to what is giving me this grief.

    Cheers mate

    Regards

    Rick

    p.s. this is what is on my browser when a pop up appears. This will be obvious to you but don't click on it!!!!!

    (http://www.amaena.com/securityworm8...wp_was7&lid=422&affid=pp_1473419981&j=0&ex=1&)
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't need any further ideas. It is still the same things I gave you last time. Did you forget to click Fix checked in HijackThis. Everything I asked you to fix is still there. In addition the bad files cause the problems are still there. Make sure that ALL applications are closed and that NO browser windows are open (as requested) before using HijackThis.

    Also you must make sure you answer my questions. You did not answer my question from last time!!

    Let's try again!


    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\3.bin\MWSBAR.DLL,S
    O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Did you receive a success message about adding this patch to the registry??

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\WINDOWS\system32\hztfgyseff.exe
    C:\WINDOWS\system32\hztfgyseff.dat
    C:\WINDOWS\system32\hztfgyseff_nav.dat
    C:\WINDOWS\system32\hztfgyseff_navps.dat
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot, run Windows Explorer and manually check to make sure the below files have been deleted. If you still see them, delete them:
    C:\WINDOWS\system32\hztfgyseff.exe
    C:\WINDOWS\system32\hztfgyseff.dat
    C:\WINDOWS\system32\hztfgyseff_nav.dat
    C:\WINDOWS\system32\hztfgyseff_navps.dat


    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  10. Rick_1138

    Rick_1138 Private E-2

    Hi mate,

    sorry if i seemed like i was being a bit flippant, that was not my intention.

    i thought i had carried out all of your taks, but i may have missed a step, so i have done them again and i have attached the required logs.

    To answer you questions:

    1.The file:
    C:\Documents and Settings\Richard Rose\My Documents\InternetGameBox_setup.exe

    Was a part of something a mate of mine stupidly downloaded from Myspace, i deleted it , but that must have stuck, i have removed it manually now.

    2. When i added the registry file 'fixME.reg', it was loaded succesfully and i received the message stating this.

    3. when i carried out Killbox, i did receive the 'PendingFileRenameOperations' when i clicked the reboot button.

    4. After carrying out these steps i am still experiencing malware issues, as you wanted to have a progress update at this point.

    I hope you can help me find out what is going on in my pc.

    cheers mate
     

    Attached Files:

  11. Rick_1138

    Rick_1138 Private E-2

    Hi,

    i have just had a long look through my NewFiles.txt log, (i got home at about 12:15PM and had to get up for 6.00AM!! so i was a little hazy on peering into pages of code! doh!

    I have noticed that the files:

    C:\WINDOWS\system32\hztfgyseff.exe
    C:\WINDOWS\system32\hztfgyseff.dat
    C:\WINDOWS\system32\hztfgyseff_nav.dat
    C:\WINDOWS\system32\hztfgyseff_navps.dat

    Are still in the folders apparently, however they did not show up in windows explorer.

    I am at work at the moment, but i will load the PC in safe mode and have a look for the files then.

    I found out that someone had a similar issue to me, i.e. the same web addresses during pop ups, i.e. ammea etc.

    This is where yu suggested doing the file hunt in safe mode, so i shall try this.

    I will let you know how i get on, again many thanks for all your patience and help guys.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The files should show in Windows Explorer as long as step 2 of the READ & RUN ME was done properly. And it normally should matter what boot mode you are in. However sometimes the malware itself once loaded may prevent you from seeing the files. And often times just a simple boot into safe mode will stop the malware from loading, thus deleting files is easier in safe boot mode since so much less is running including the malware itself. Long story short, use safe mode to be on the safe side, and remember the files are there and that is the reason for your problems.

    The items in your HJT log (which have nothing to do with the 4 hidden files) have no been fixed. Looks like you remembered to click Fix checked this time. ;)


    If you still run into a problem getting those file deleted. Use the below procedure.

    • Download The Avenger http://swandog46.geekstogo.com/avenger.zip by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it.
    A log file from Avenger will be produced at C:\avenger.txt, please post that log here along with a new ShowNew log.
     
    Last edited: Mar 26, 2007
  13. Rick_1138

    Rick_1138 Private E-2

    well i have deleted the files in safe mode and run Ccleaner.

    All seems well at the moment, i am not experiencing any pop-ups, (fingers crossed)

    Thanks for all the help guys, and for providing me with some better anti spyware tools.

    hope i can pass on this knowledge about the site to others .
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and good job!!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds