What a mess - hoping someone can help

Discussion in 'Malware Help (A Specialist Will Reply)' started by princess_zammy, May 23, 2007.

  1. princess_zammy

    princess_zammy Private E-2

    Hi

    Did all the "read and run me first". Only trouble I seemed to have was BitDefender failed to update definitions but I ran the scan anyhow.

    Still seem to have Messenger Service pop-ups and AntiVir picking up Tr/BHO.G - everytime I clicked on anything, my computer any shorcut etc it would bring up this up again as being detected. I have left them up - not deny access, delete or qurantine because wehn I was deny access before it would just reinvent itself someplace else. The only way I could run any of these scans was to use the "run" option and scroll to where I needed to go. It is also picking up TR/Crypt.PEC2X.Gen.

    I ran everything in Admin except for CCleaner which I also ran in user. Please forgive me if I have done anything wrong or missed something - I have been at this all day - just trying to let you know as much as possible.

    thank you in advance
     
    Last edited: Jan 6, 2008
  2. princess_zammy

    princess_zammy Private E-2

    Rest of Logs

    Please find attached the rest of the logs.

    thank you
     
    Last edited: Jan 6, 2008
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please run this Virtumonde aka Trojan Vundo Removal and do not attach the requested log from VundoFix after running it the first time. What I want you to do is to keep running VundoFix until it comes up clean. Then attach the final log from VundoFix.



    Now attach the below new logs and tell me how the above steps went.
    1. VundoFix
    2. GetRunKey
    3. ShowNew
    4. HJT
     
  4. princess_zammy

    princess_zammy Private E-2

    Virtumonde Clean - Attached Logs

    Hi Chaslang

    Thank you so much for your assistance. Requested logs attached.
     
    Last edited: Jan 6, 2008
  5. princess_zammy

    princess_zammy Private E-2

    HJT New log

    last one
     
    Last edited: Jan 6, 2008
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: HJT New log

    Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to the following key and take ownership of it (explained further down):

    HKEY_LOCAL_MACHINE\software\microsoft\mssmgr

    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the Menu
    • Select Take Ownership
    • Now leave RegistrarLite running and continue
    • Now run the REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate to HKEY_LOCAL_MACHINE\software\microsoft\mssmgr
    • Does the above mssmgr key still exist! If so, right click on it and select Delete.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixWLH.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    After completing ALL of the above instructions, continue here!

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.


    Make sure you have rebooted in Normal Mode (do not open any other processes)
    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winwea32.dll once and then click the kill button. After you have killed all of the winwea32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of winwea32.dll and kill it. (If you do not find the dll, just continue on.)

    Next double click on iexplore.exe and again click once on each instance of winwea32.dll and kill it. (If you do not find the dll, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
    O2 - BHO: (no name) - {84572CB8-5A48-49DC-A505-457D26BB44D6} - C:\WINDOWS\System32\ddcya.dll (file missing)
    O2 - BHO: (no name) - {DA0C29E1-1889-41EC-981F-19C48FFAFCD4} - C:\WINDOWS\System32\khfdcay.dll (file missing)
    O4 - HKLM\..\Run: [regmgr] C:\WINDOWS\System32\regmgr.exe
    O4 - HKLM\..\Run: [SManager] smanager.7.exe
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Startup: PowerReg Scheduler V3.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O20 - Winlogon Notify: sstqp - C:\WINDOWS\System32\sstqp.dll (file missing)
    O20 - Winlogon Notify: winwea32 - C:\WINDOWS\SYSTEM32\winwea32.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\System32\regmgr.exe
    C:\WINDOWS\System32\smanager.7.exe
    C:\WINDOWS\System32\sstqp.dll
    C:\WINDOWS\System32\winwea32.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.
    Now run Ccleaner


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  7. princess_zammy

    princess_zammy Private E-2

    New logs

    Hi again

    - Regitrar Lite and Registry Patch - no errors. After it was refreshed - key doesnt exist

    - ProcessExplorer - After clicking "Threads" got following error message:

    This version of dbghelp.dll configured does not support the miscrosoft symbol server. Please download and install the Microsoft Debugging Tools for Windows to get a version that does.

    I just clicked off that window without downloading anything and continued. Had one winwea32.dll for winlogon, none for explorer or iexplore.

    - HijackThis - Couldnt find the following 3 keys:

    - Killbox - no errors - did not get PendingFileRenameOperations

    - CCleaner - 16mb cleaned

    - GetRunKey - when it finished I got a Messenger Service Pop-up for www dot xpreg32 dot com

    Logs attached, awaiting your reply.

    Thank you again for your assistance
     
    Last edited: Jan 6, 2008
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: New logs

    Not true! It is still there and so is the winwea32.dll registry key which is related to the mssmgr key. These are both part of the WinLogonHook infection. We will fix this a different way this time.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger.

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Mozilla Firefox (1.5.0.11)

    Make sure you reboot after uninstalling the above!

    Then install the current version of FireFox from: Mozilla Firefox

    Now delete the below folder:
    C:\Documents and Settings\user\Application Data\Viewpoint

    Also delete the below files:
    C:\Program Files\Common Files\Yazzle1162OinAdmin.exe
    C:\WINDOWS\system32\pqtss.bak1
    C:\WINDOWS\system32\pqtss.bak2

    Now run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O20 - Winlogon Notify: winwea32 - winwea32.dll (file missing)

    After clicking Fix, exit HJT.

    Now let's try fixing the mssmgr registry key again but my procedure will be a little different than last time.

    Run Registrar Lite navigate to each of the following keys (one at a time) and take ownership of them (I explained how to do that further down).

    HKEY_LOCAL_MACHINE\software\microsoft\mssmgr

    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the Address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the top Menu
    • Select Take Ownership
    • Now leave RegistrarLite running and continue
    • Now run the fixWLH.reg REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate one at a time to each of the above keys we took ownership of to make sure they were deleted.
    • If any of the keys still exist, move on down to PART 2 - Setting Permissions for Everyone below!.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixWLH.reg to your desktop (yes overwrite the previous copy). Be sure the Save as type is set to all files Once you have saved it double click it and allow it to merge with the registry.

    PART 2 - Setting Permissions for Everyone
    Run the below if some of the registry keys still exist after running the above steps.

    Now I want you to use Registar Lite again to navigate to each of the below keys (one at a time) by pasting them into the Address Bar and hitting return. But this time click the Security menu item and select Edit Permissions so we can change permissions to everyone ( I describe this down below the list of registry keys).
    After click Edit Permissions , here is what I expect you to see in the Group or user names area of the form:

    Everyone
    SYSTEM

    Select Everyone by clicking on it. Now at the bottom in the Permissions box click the check box for Full Control. The click Apply and then OK to get back to the main Registrar Lite screen. Nowright click on the registry key and select Delete. The click View and Refresh. Check to see if the registry key just deleted truly deleted. If so, move on to the next to work thru the whole list. If it does not delete, I want you to boot into safe mode and repeat these exact same steps to see if we can do it from safe mode.

    Then reboot your PC!

    After reboot check to see if the mssmgr key is still gone. If not, repeate the above Registrar Lite procedure again but do it after booting into safe mode and make sure you DO NOT OPEN ANY BROWSERS. Only run the procedure and no other programs.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    If you are still getting popups, shutdown MSN Messenger and Yahoo Messenger and then tell me if you are getting popups.
     
  9. princess_zammy

    princess_zammy Private E-2

    Hmm...Couldnt do Step 2

    Hi there again...

    When I ran the disable/uninstall messenger program, I got this error:

    Advanced INF Install
    Error unregistering the OCX 16422

    I clicked ok and it then ran the unintsall and it confirmed that it had been removed although the one Messenger Service window that had previously popped up was still there.

    Uninstalled other things, rebooted etc as you asked.

    After Running HJT, then reloading Firefox (the updated version), got Messenger Service Pop Up.

    Ran fixWLH.reg with no errors. Key still there.

    Tried to do Step 2 to remove it, however it isnt like you said. Under Group or User, I have the following:

    Admin
    Creater Owner
    Power Users
    System
    Users

    So I have stopped there, awaiting your advice. Ran logs anyhow confused

    thanks in advance
     
    Last edited: Jan 6, 2008
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hmm...Couldnt do Step 2

    let's try another tool!
    1. Download RegASSASSIN.
    2. Unzip the file to your desktop. You will have a new desktop icon named RegAssassin.exe.
    3. Reboot your computer into SAFE MODE
    4. Once in SAFE MODE, double click on the RegAssassin icon to open the program.
    5. Checkmark the options "Reset Permissions" and "Delete Registry Keys and all Subkeys".
    6. In the registry key window carefully enter:
      • HKLM\software\microsoft\mssmgr
    7. Click on Delete hot button. Tell me if you get any error messages
    8. Reboot into Normal Mode.
    9. Attach a new log from GetRunKey
    Also delete the below file:
    C:\WINDOWS\system32\pqtss.ini

    Then attach a new log from ShowNew.


    Now let's manually Disable Messenger Service

    • Click Start > Run and type services.msc in the Open: line and click OK
    • In the right pane, scroll down to Messenger.
    • Double click Messenger and click the General tab.
    • Under Service Status: click the Stop button.
    • In the Startup Type: drop down box, select Disable.
    • Click Apply and OK.
    Are you still getting Messenger Service popups? If so shutdown Yahoo Messenger! Do you still get them (make sure Yahoo Messenger is not running)?​
     
  11. princess_zammy

    princess_zammy Private E-2

    Me again...

    Hi Chaslang

    Thanks for your patience....

    Well after trying to delete key in both Admin and User account in safe mode, I got following error for both:

    Error - Hive returned NULL

    Did everything else you asked, attached logs as requested.

    After disabling Messenger Service have not got another pop up - yahoo and Firefox currently running.

    Does this mean we are nearly there? :cool
     
    Last edited: Jan 6, 2008
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Me again...

    Okay let's try it another way!


    Download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt please attach that log here, along with a new GetRunKey log.
     
  13. princess_zammy

    princess_zammy Private E-2

    Hope your having a good weekend...

    Hi there

    logs attached...

    thank you again for all your time
     
    Last edited: Jan 6, 2008
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hope your having a good weekend...

    Okay it appears that Avenger was able to remove those registry keys!.


    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  15. princess_zammy

    princess_zammy Private E-2

    Thank you - Thank you

    Wow thank you!

    I really appreciate all your help - you're worth more money ;)

    Should I also uninstall:

    Yahoo toolbar - i'm usually careful with this - not sure how it got there >.<

    The other programs that you got me to install:

    Hijack This
    Process Explorer
    Registrar Lite
    Reg Assasian
    MessengerDisable and
    Killbox

    Also, someone told me its better to turn System Restore off altogether because it can cause viruses etc to reinfect...should I just leave it on after I toggle it?

    One last thing, if my virus protection picks something up, what should I do?

    thank you again in advance

    princess_zammy
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Thank you - Thank you

    Yes you can uninstall or delete them as appropriate.

    This would be a very bad idea. Having System Restore could save your butt some day.

    Yes you should leave System Restore enabled.

    Just let it it fix the problem.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds