Novice in Ireland requires some help...

Discussion in 'Malware Help (A Specialist Will Reply)' started by irishguy79, Jun 7, 2007.

  1. irishguy79

    irishguy79 Private E-2

    Hey guys,

    I am the end of my rope here. :( I have this recurring pop up issue on my PC. My fully paid for BitDefender V10 is totally useless and cannot get rid of the virus. It finds 6 new viruses and removes them everytime I restart my PC. They always come back. I used System Internals SYSAPPS to look at my LOGON registry keys. The only one that looks unusual is ApachInc. I deleted it, but it came back on startup.
    :( When I load FireFox, Internet Explorer also launches by itself!!! and starts taking me to anti-virus websites etc. I'm so frustarted now having being dealing with BitDefender support for a week now. They seem unable to help and so just keep asking for logs :( I am at the point where I want to just wipe my machine. This is giving up I know, plus it would be so inconvenient and I would need to back up all my personal stuff and probably end up backing up this virus too. Please can someone help. I'm sorry if I did not follow the proper procedure but did not want to just post logs without explaining myself first. I will follow any suggestions or instructions or advice you have. I found you guys through a search for "ApachInc" on google.
    I have downloaded Hijackthis2 and avenger as I noted that some other thread said I needed them to aid in removal of this malware/trojan/virus thing. I would be indebted to each and all of you if anyone can offer any advice to a brother across the pond. Thanks guys.

    Neil
     
  2. irishguy79

    irishguy79 Private E-2

  3. irishguy79

    irishguy79 Private E-2

    BitDefender initially said I had this..

    Trojan.LowZones.SA
    Trojan.Virtumonde.IC
    Adware.VDM
    Trojan.Clicker.Small.YB
    GenPack:Trojan.Vundo.DLV
    Generic.Malware.did!!.D9E1AFE9
    Trojan.Agent.QT

    It deleted them all...

    after a few reboots and rescans it says I have

    Trojan.LowZones.SA
    MemScan:Trojan.BHO.BM

    It just cannot stop these things from coming back..
    I think the ApachInc process is doing something each time. :cry
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  5. irishguy79

    irishguy79 Private E-2

    as requested...

    I have no faith in BitDefender btw. Everytime I deep scan it has a new named virus found..

    here are the logs post1/2
     

    Attached Files:

  6. irishguy79

    irishguy79 Private E-2

    post 2/2

    I'll post the spycounter logs shortly. need to restart first
     

    Attached Files:

  7. irishguy79

    irishguy79 Private E-2

    counterspy log from FULL scan

    thanks (panda online scan would not complete for me?)
     

    Attached Files:

    Last edited: Jun 8, 2007
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not what we requested in the READ ME. You installed BitDefender 10 Antivirus program which is a direct conflict with step 3 of the READ ME since you already have AVG installed. Uninstall this NOW. What was requested in step 6 of the READ ME was an online scanner. If you ever need to run these steps again, makes sure you follow the steps properly.

    You need to run CounterSpy again (run it in normal boot mode) and this time have it fix what it found. There is no sense in running the scans if you tell them to ignore what they find. Then please attach a new log.


    Also per the directions in step 6 of the READ ME, uninstall the below old versions of Sun Java:
    Java 2 Runtime Environment, SE v1.4.2_03

    Make sure you reboot after uninstalling the above!

    Then install the below current version of Sun Java as requested: Sun Java Runtime Environment

    Now run this Virtumonde aka Trojan Vundo Removal but run it multiple time until it comes up clean. Then attach the final log from VundoFix.


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {1CD881E5-0D7E-4CC7-9B2F-DD558C17242A} - C:\WINDOWS\system32\mlljg.dll (file missing)
    O2 - BHO: (no name) - {54CBB12C-3481-4C5D-942D-4976C0F0A406} - C:\WINDOWS\system32\jkkkifc.dll (file missing)
    O2 - BHO: (no name) - {CD3447D4-CA39-4377-8084-30E86331D74C} - C:\WINDOWS\system32\lfascfpl.dll (file missing)
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
    O20 - Winlogon Notify: jkkkifc - jkkkifc.dll (file missing)
    O20 - Winlogon Notify: mlljg - C:\WINDOWS\system32\mlljg.dll (file missing)
    O20 - Winlogon Notify: winzlo32 - winzlo32.dll (file missing)


    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT
     
    Last edited: Jun 8, 2007
  9. irishguy79

    irishguy79 Private E-2

    Hi Chaslang,

    Sorry for mis-following the directions. :eek:
    I have now removed my copy of BitDefender. I have also removed my old Java runtime environment, rebooted, and installed the latest. I then followed all of your instructions.

    Here are the logs... Thanks

    logs 1/2
     

    Attached Files:

  10. irishguy79

    irishguy79 Private E-2

    logs 2/2

    Thanks
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not quite! ;) Where is the new log from re-running CounterSpy!


    Use Windows Explorer to delete the below file:
    C:\WINDOWS\system32\drivers\cmblju^d.sys


    Do you know what the below file that appeared on Jun 4th is for?
    Code:
    "C:\WINDOWS\system32\"
    mvcerc~1.dll   4 Jun 2007          19  "mvcerc051010.dll"

    How is everything working?
     
  12. irishguy79

    irishguy79 Private E-2

    hey Chaslang, I did try to get it right :D

    here is the latest counterspy log

    Scan History Details
    Start Date: 09/06/2007 00:52:07
    End Date: 09/06/2007 02:18:50
    Total Time: 86 Min 43 Sec
    Detected security risks
    No risks were found during this scan.

    and

    I did an AVG FULL scan and all I got was 10 threats from "tracking cookies". nothing serious there.

    I deleted the C:\WINDOWS\system32\drivers\cmblju^d.sys file as instructed.

    I have no idea what the "mvcerc051010.dll" file is for. seems to be very little inside it.

    system seems good. I am almost afraid to use IE7 in case it goes mad. Im a FF user mostly.
    BD was the program that kept showing up the errors with DLLs infected with ADware in system32. should I leave it uninstalled for now. I am a registered user, but am starting to think Im better sticking with AVG.

    any other logs you require. I will use my system over the next 24hours and see if any strange popups or alerts happen? thanks chaslang.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Put a copy into a ZIP file and attach the ZIP file here.

    If you don't like BitDefender, stick with AVG. If you were happy with BD and pay to keep it updated, then uninstall AVG, reboot, and reinstall BD. It's your choice.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. irishguy79

    irishguy79 Private E-2

    here is the dll file zipped as requested...

    I did another full AVG scan and also a Counterspy scan.

    AVG found 11 threats but they were all low threat tracking cookies or .txt cookie files.

    Counterspy found 1 threat.

    Scan History Details
    Start Date: 09/06/2007 12:52:10
    End Date: 09/06/2007 14:02:07
    Total Time: 69 Min 57 Sec
    Detected security risks

    Cookie: DoubleClick Cookie (General) more information...
    Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
    Status: Ignored

    Cookies detected
    c:\documents and settings\neil\cookies\neil@doubleclick[1].txt


    I will uninstall AVG and put on BD again and if that shows nothing I may be at the point to follow your final steps.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete this file from your system32 folder.


    When you complete my final steps and follow the instructions in the How to protect yourself link, you will see step 11 which is information about cookies.
     
  16. irishguy79

    irishguy79 Private E-2

    Hey Chaslang

    Thanks for all of your help so far. much appreciated. I will follow all your steps in the "final steps" now and hopefully disable these cookies too.

    I only have one other question now. Some website buttons don't seem to work when clicked in FireFox. For example when you click the "browse" button on gmail to choose an attachment. nothing happens. No errors. just like a dumb button. Another example is this link. http://www.kaspersky.com/downloads/kws/kavwebscan.html
    When I click accept in FF nothing happens!? but when I click accept in IE7 the link works. Any ideas. Do I need to reinstall FF or anything or is this just a setting somewhere. Thats it. Other than that I think my machine seems clean and perfect now. I deleted that file as suggested from system32 also. I will just wait to see what you think of this button issue, and from there I will run all the final steps and turn back on my system restore.
    Thanks again chaslang
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you read step 11 in that link you will see that you do not need to disable cookies and if you do, you will reduce your surfing pleasure and may not be able to access various websites properly. Cookies are not problems!

    It's not a problem. Many websites only work properly with IE. Just like in step 6 of the READ ME where we say you must use IE. The link you gave for Kaspersky is the same. You must use IE.
     
  18. irishguy79

    irishguy79 Private E-2

    Thanks for all your help chaslang. I think its back to normal now. I have followed all steps. Thanks again:wave
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds