Need help with Malware & Virus removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by marre, Apr 21, 2007.

  1. marre

    marre Private E-2

    I have gone through the steps in "Read & Run First". I started with the Smithfraud-C.Toolbar888. Couldn't get rid of it. In going through this process, there seems to be a multitude of Malware and Viruses....win32.Agent.aze and others.

    This process got rid of some but not all...please help. I will never let friends use my computer again!!

    Thanks!

    Marre
     

    Attached Files:

  2. marre

    marre Private E-2

    This is part 2 of the files.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Continue by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)
    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winexz32.dll once and then click the kill button. After you have killed all of the winexz32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    byxvsrr.dll

    Next double click on explorer.exe and again click once on each instance of winexz32.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    byxvsrr.dll

    Next double click on iexplore.exe and again click once on each instance of winexz32.dll and kill it. (If you do not find the dll, just continue on.)


    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    byxvsrr.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: (no name) - {0309638F-93F8-44D3-84CF-240EB1AB7F1F} - C:\WINDOWS\system32\byxvsrr.dll
    O4 - HKLM\..\Run: [saujzun.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\saujzun.dll,ecwsdq
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O20 - Winlogon Notify: byxvsrr - C:\WINDOWS\SYSTEM32\byxvsrr.dll
    O20 - Winlogon Notify: winexz32 - C:\WINDOWS\SYSTEM32\winexz32.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\byxvsrr.dll
    C:\WINDOWS\system32\saujzun.dll
    C:\WINDOWS\system32\winexz32.dll
    C:\WINDOWS\system32\ccc3.dll
    C:\WINDOWS\system32\ddabb.dll
    C:\WINDOWS\system32\bbadd.bak1
    C:\WINDOWS\system32\bbadd.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. marre

    marre Private E-2

    Thanks for your help!

    Went through all the steps. With Process Explorer - didn't have any winexz32.dll but had 2 byxvsrr.dll under winlogon.exe and 1 byxvsrr.dll under explorer.exe

    Did NOT get the PendingFile....etc when using KillBox and KillBox did reboot my computer.

    I had uninstalled IE7 or whichever the latest version is and am now going with an older version. Think it would be okay to reinstall the latest? Would rather not have it at all but some sites have to have IE (like Panda Active Scan etc)

    I notice that I am having one helluva time trying to get on the majorgeek website and navigate it....any other website - no problem. I have DSL connection but I am having a difficult time getting on this site.

    I am attaching the latest files you asked for...hope I have told you everything..oh yeah....when I was trying to do this stuff, my McAfee kept warning me about VirtuMonde or something like that and it couldn't get rid of it. But since I have gone through the steps and rebooted, it hasn't popped back up.

    The site won't let me upload HJT file again...it says I have already done it once and won't let me do it again. I tried to rename to Hijackthis2 and several other things but no go.

    Thanks!!!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    IE7 is not required to access the online scan sites. IE6 will work just fine.

    I'm not sure what you mean. What problems exactly are you having?

    That means you are trying to attach the same log as you attached last time. You need to get a NEW log and attach it.
     
  6. marre

    marre Private E-2

    Sorry, but I may have messed up....think after I ran HJT I forgot to click on save log. Just re-ran HJT and am attaching the log.

    About getting on majorgeeks....the page won't come up, it is like it is stuck and just grinding away trying to display pages - they may eventually come up after sitting there awhile. It doesn't do this with other sites; and, I have another computer, which I am on now via wireless router and pages come right up. I can navigate from page to page and they all come right up on this computer...but not the one that the virus is on.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does your other computer also have the below items installed and running:

    Embarq TotalAccess
    McAfee (all of the software)

    If you run in safe mode, can you connect to the internet. If so, do you have the same problems connecting to MGs in safe mode.


    Let's Reset Web Settings and clear your cache:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now click Start, Run and enter ipconfig /flushdns and click OK!

    Did the above steps change any symptoms?

    Now run HJT and have it fix the below lines:

    O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\wootwywi.dll (file missing)
    O2 - BHO: (no name) - {1FAED6CF-B47B-46D8-A081-DE6B8A75BE10} - C:\WINDOWS\system32\ddabb.dll (file missing)

    Attach a new HJT log.
     
  8. marre

    marre Private E-2

    Yes, my 2nd computer has these programs and alot more than the desktop.

    Safe mode makes no difference on the infected computer...actually after having done the latest steps, it still does the same thing. The geeks website comes up but only the green background is displayed....no content at all and status bar says 'Done'. This is not happening with other sites I go to with it. The geeks site will eventually come up if I let it sit....after 2 or 3 minutes. Once on the site, I can navigate to a page maybe 2 before it does it again. This doesn't happen on my laptop and never use to happen on majorgeeks site with my desktop. I actually go to the site quite often and browse.

    Attached is new HJT....I also reset System Restore this time.

    Thanks!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is unlikely that this is a malware problem! It would really be very unlikely that malware would only cause a problem like this on Majorgeeks! It could be related to some setting in your McAfee software including the firewall and SiteAdvisor. Try shutting down/disabling or uninstalling all of McAfee and see what happens.

    However even after saying the above, let's also dig a little deeper for malware!

    Now please download F-Secure's BlacklightBeta
    • Download fsbl.exe and save it to the Desktop.
    • Once saved... double click fsbl.exe to install the program.
    • Click accept agreement and Click scan
    • This application may trigger a warning from your antivirus. Let the driver load. Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.

     
  10. marre

    marre Private E-2

    First, let me thank you for sticking with me. I really appreciate it and am ready any time you are to hand over a kidney or give you a kid!

    I ran Spybot and there was still Smitfraud-C.toolbar888. So, I ran the smitfraud tool then ran Spybot again in Safe and Normal mode - doesn't show up any more.

    Thanks again for hanging in there with me!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Attach a log from Spybot! It is probably just finding a couple of benign registry keys!

    Did you try disabling or uninstalling all of the McAfee software to see what happens?
     
  12. marre

    marre Private E-2

    I tried disabling McAfee - no difference. I have McAfee on my second computer and it doesn't seem to be the problem. I'm not attaching the Spybot file as the Smitfraud seems to be gone now after running Smitfraudfix. I have run Spybot a few more times in normal and Safe mode - doesn't show up. Do I seem to be Malware free now......maybe my internet problem with majorgeeks is a cookie vs security setting issue? I have tried a bunch of different settings with the browser and McAfee....I can't seem to find the right thing.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but that does not mean that they are both setup the same. Since your system has been malware free since completing message # 7, I was just looking to see if it was a settings type issue. Also since your other PC appears to work fine, it would seem to rule out something at a higher level in your network or beyond. It does seem to mean something on this PC has been changed. Figuring out what, is the problem.

    You have to realize that just because your PC appears malware free based on the scans and logs, it does not guarantee that there is no malware. Potentially there is some new form of malware on your PC that is not known or detected. Also it's possible that the malware we removed already, changed some settings on your PC and now even with the malware removed, it could be causing issues. But on the other side it still could be something in your own software. I have seen many people that have big issues with that Earthlink Total Access software. Many have said it should have been called Totall No-Access. But I don't know it that is your problem or not. The same is true for McAfee. Some times the best thing to do, is to uninstall software like this and see what happens. Trying to stop the software usually does not work and you cannot easily stop all of it from loading and running since services are also used.
     
  14. marre

    marre Private E-2

    Thanks for all your help. I take it that the log from Blacklightbeta didn't show anything unusual....

    Thanks again! I love this site, everyone is always so helpful!!

    Marre
     
  15. marre

    marre Private E-2

    Got my issue resolved with this website. When we reset IE settings, it turned the windows firewall back on.....I use McAfee firewall, so I had 2 firewalls going. I discovered this when I uninstalled McAfee. Why it would do it with this website and not all others, I don't know.

    I reinstalled PCTools firewall and no problem!! Yeah! Thanks for everything!

    Marre
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A reset of web settings has nothing to do with any firewall. It just resets IE to be the default browse and changes a few other related settings. I'm not sure how your Window Firewall was renable, but it was not from a reset of web settings.

    And in addition, we did not even reset web settings until message number 7. You were already complaining about problems accessing Major Geeks in message # 4.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds