Help!!! with malware I got from seriall.com

Discussion in 'Malware Help (A Specialist Will Reply)' started by OTHFan, Apr 14, 2007.

  1. OTHFan

    OTHFan Private E-2

    Ok, stupid me visited seriall.com ,and that's where I got my malware. I tried the steps on the Malware Removal Guide (to the best of my ability) becuase I'm not very good with computers to get rid of it, but it never did, so I was wondering If somebody could help me out because I'm not the greatest with computers, Thanks!
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    If you have completed all the steps in the below guide as you say you have then please attach all the requested logs and at that point one of our malware experts will review the logs and issue you some further malware removal instructions as soon as possible.

    Also can you describle what makes you think you haev malware, do you have popups, browser re-directions or antivirus that says you haev malware, IF so what are they called?



    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. OTHFan

    OTHFan Private E-2

    You I have been having pop-ups and for some reason Bitdefender closed out before ,I could save the infected file, I will have to try it again, i'm sorry to be a pain but I need some guidance on how to go about the whole process of removing it. Thank You

    But I will attach the the other programs results
     
  4. OTHFan

    OTHFan Private E-2


    Here are the attachments
     

    Attached Files:

  5. OTHFan

    OTHFan Private E-2

    I attached the HijackThis
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Even if you cannot get a BitDefender log you are still missing a couple other requested logs.

    CounterSpy
    AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
    Panda Scan - from step 6

    AND you did not install and rename HijackThis as required. Do this now and attach a new HJT log.


    Also ityou did not run Download GetRunKey from the ReadMe! Please download and use the current version in the READ ME!!! Attach a new log!
     
  7. OTHFan

    OTHFan Private E-2

    Ok Im sorry byt i'm lost, so I need to download Hijackthis, and rename it?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Read the directions in step 7 of the READ ME and follow them.;)

    You also need to do the below as mentioned in step 6 of the READ ME.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 3
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Don't forget the other two logs (CounterSpy and Panda)
     
  9. OTHFan

    OTHFan Private E-2

    I'm having trouble with the Highjack so I think I need to download winzip
     

    Attached Files:

  10. OTHFan

    OTHFan Private E-2

    Hopefully I did it right. Here Is The Highjackthis
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look like you loaded CounterSpy into WordPad instead of notepad. That does not create plain text files unless you save it as plain text. Don't worry about it....I'll convert it. What about PandaActiveScan? What order are you running things in? CounterSpy should have been one of the early scanning steps.

    Did you notice that your current HJT log now shows things the other did not?? That is why we need it installed and renamed properly! Now that you have it correct, you can see some of the Vundo and Winlogonhook infections.
     
  12. OTHFan

    OTHFan Private E-2

    I scaned the counter spy in order of it's time and I scanned it again, did you want the 2 scans. I scaned with panda and then afterr that it says


    Detected Disinfected
    Virus 0 0
    Spyware 0 0
    Hacking tools and rootkits 0 0
    Dialers 0 0
    Security Risks 0 0
    Suspicious files 0 0



    Select a device to scan...
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!
     
  14. OTHFan

    OTHFan Private E-2

    Can I leave the ComboFix run while I Go, I'm sorry I have To Leave. I will post The results (log) Later, Thanks For Your Great Help So Far
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Just unplug your cable to the internet to be safe! You're welcome!
     
  16. OTHFan

    OTHFan Private E-2

    Where do you get the logs from the ComboFix, when it's done no logs come up, I did it and it reboot my computer and all that, Microsoft did their Anti-Spyware Scan too. The Pop Ups are still here though :(
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The log should be C:\combofix.txt
     
  18. OTHFan

    OTHFan Private E-2

    This is the only log I could find related to combo Fix ,and it was an error. Is it suppose to be on the desktop the program

    1 file(s) copied.
    1 file(s) copied.

    Error: Key: software\microsoft\windows\currentversion\policies\system does not exist!

    C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1

    SteelWerX Registry Console Tool 2.0
    Written by Bobbi Flekman 2006 (C)

    Error: Key: software\microsoft\windows\currentversion\uninstall\webnexus does not exist!

    FINDSTR: Line 6779 is too long.

    SteelWerX Registry Console Tool 2.0
    Written by Bobbi Flekman 2006 (C)

    Error: Key: software\winpcap does not exist!

    Could Not Find C:\DOCUME~1\ALLUSE~1\STARTM~1\-d743~1.lnk
    Could Not Find C:\DOCUME~1\ALLUSE~1\STARTM~1\4bb6~1.lnk
    Could Not Find C:\Documents and Settings\-83f1~1.url
    'swreg' is not recognized as an internal or external command,
    operable program or batch file.
    'swreg' is not recognized as an internal or external command,
    operable program or batch file.
    'swreg' is not recognized as an internal or external command,
    operable program or batch file.
    Could Not Find C:\WINDOWS\system32\perflib_perfdata_*.dat
    1 file(s) copied.
    'swreg' is not recognized as an internal or external command,
    operable program or batch file.
     
  19. OTHFan

    OTHFan Private E-2

    I did Combo again and I finally got a log and I did the other 2
     

    Attached Files:

  20. OTHFan

    OTHFan Private E-2

    Hijackthis attachment
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Continue by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)
    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of ddabx.dll once and then click the kill button. After you have killed all of the ddabx.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    urqopmk.dll
    vcgcevvc.dll

    Next double click on explorer.exe and again click once on each instance of ddabx.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    urqopmk.dll
    vcgcevvc.dll

    Next double click on iexplore.exe and again click once on each instance of ddabx.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    urqopmk.dll
    vcgcevvc.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://wwe.com/
    O2 - BHO: (no name) - {56E14622-F3C0-4C2B-9738-633988BF959A} - C:\WINDOWS\system32\ddabx.dll
    O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - C:\WINDOWS\system32\vcgcevvc.dll
    O2 - BHO: (no name) - {6C622D52-0612-414B-A063-105A614D396F} - C:\WINDOWS\system32\urqopmk.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
    O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\hisfffbl.dll",setvm
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O20 - Winlogon Notify: ddabx - C:\WINDOWS\system32\ddabx.dll
    O20 - Winlogon Notify: urqopmk - C:\WINDOWS\SYSTEM32\urqopmk.dll
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
    O21 - SSODL: coursings - {f8d02387-789a-4c0f-a1d8-8a93f33ee4df} - C:\WINDOWS\system32\yephk.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\ddabx.dll
    C:\WINDOWS\system32\hisfffbl.dll
    C:\WINDOWS\system32\urqopmk.dll
    C:\WINDOWS\system32\vcgcevvc.dll
    C:\WINDOWS\system32\xbadd.bak1
    C:\WINDOWS\system32\xbadd.bak2
    C:\WINDOWS\system32\lbfffsih.tmp
    C:\WINDOWS\system32\xbadd.tmp
    C:\WINDOWS\system32\lbfffsih.ini
    C:\WINDOWS\system32\lbfffsih.ini2
    C:\WINDOWS\system32\xbadd.ini
    C:\WINDOWS\system32\xbadd.ini2
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\BearShare

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  22. OTHFan

    OTHFan Private E-2

    All The Steps went good, the only things I could not find were Bearshar in my programs ,and vcgcevvc.dll in Killbox. But othere then that it went great:) For some reason the logs wont attach.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you trying to attach new logs and not the same old ones!

    Also watch closely in the Manage Attachments window for messages. They are not very obvious to most people. Tell me if you see any messages.
     
  24. OTHFan

    OTHFan Private E-2

    Here They are: And I also ran Spybot and It found two things

    Smitfraud-C.Toolbar 888 ( 2 entries)
    Double CLick (1 entrie)
     

    Attached Files:

  25. OTHFan

    OTHFan Private E-2

    Deleted Post
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below should not be running when using HijackThis
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\LimeWire\LimeWire.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe

    Also from now on, please finish/terminate GetRunKey before running ShowNew so that the temp files from GetRunKey (there are a lot of them) do not show in the ShowNew log.


    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of cvqkeqro.dll once and then click the kill button. After you have killed all of the cvqkeqro.dll under winlogon click ok. (If you do not find the dll, just continue on.)


    Next double click on explorer.exe and again click once on each instance of cvqkeqro.dll and kill it. (If you do not find the dll, just continue on.)

    Next double click on iexplore.exe and again click once on each instance of cvqkeqro.dll and kill it. (If you do not find the dll, just continue on.)


    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - C:\WINDOWS\system32\cvqkeqro.dll
    O2 - BHO: (no name) - {AA7CA802-E0DB-4303-B438-AC2406A1C70B} - C:\WINDOWS\system32\ddabx.dll (file missing)

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\cvqkeqro.dll
    C:\WINDOWS\system32\iwrdhopt.dll
    C:\WINDOWS\system32\getfile.dat
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  27. OTHFan

    OTHFan Private E-2

    The Process went good again, I'm still not sure if I have any maleware still. The Computer Is working good but there is always that scare that there might be a pop-up here or there.
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Somehow you have started using a very old version of GetRunKey. Please delete ALL copies from your PC and download the current version from the READ ME and attach a new log!

    However, your other two logs are clean now so I would expect that we should be okay! But let's be sure!
     
  29. OTHFan

    OTHFan Private E-2

    I took forever to get the log for this because it would work properly saying something about some key number but it finally worked and here is the log :)
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you have one remain registry key to remove!

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  31. OTHFan

    OTHFan Private E-2

    The process went great ,and I would just luck to thank you for step-by-step help, and your endless patience with a "amateur" lol. I greatly appreciate your help. Thank You Very Much
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds