A Variety of Malware - Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by macker6464, Oct 17, 2006.

  1. macker6464

    macker6464 Private E-2

    Hi all

    i still have problems and everything is getting mighty slow and busy with all this anti V/MW loaded!

    I have carried out all the steps possible from http://forums.majorgeeks.com/showthread.php?t=35407 in the exact order as best I could and here I am.

    There seem to be problems remaining.

    CCleaner appeared to work fine.:)
    Microsoft Windows Defender didn't work.
    Microsoft Windows Malicious Software Removal Tool didn't work.
    CounterSpy did its stuff OK in 10 hours! LOG ATTACHED - CounterSpy.txt.:)
    Bitdefender OK - LOG ATTACHED bdscan.txt:)
    PandaActiveScan would not work in Safe Mode - found things but bombed out several times and same happened in normal mode.:eek:
    GetRunKey.zip worked fine - LOG ATTACHED runkeys.txt:)

    Will post the rest in a sec.
     

    Attached Files:

  2. macker6464

    macker6464 Private E-2

    More....

    ShowNew.Zip worked fine and LOG ATTACHED newfiles.txt :)

    I also tried Webroot SpySweeper LOG ATTACHED Spy Sweeper Session Log.txt:)

    Finally here is my HiJackThis LOG ATTACHED hijackthis.log:)

    Some of the things that keep coming up are:
    3271 Chinese Keywords
    Locators Toolbar Toolbar
    Virtumonde Adware (General)

    Also I have a program called Chinese keywords I cannot uninstall (no idea where it came from) and also Koowo Lyrics suddenly arrived. Maybe from TVAnts?

    Cheers for any help kind people!
     

    Attached Files:

  3. matt.chugg

    matt.chugg MajorGeek

    Download

    - Pocket KillBox

    - Process Explorer

    Extract each to their own folder somewhere that you will be able to locate later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)


    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of ixccpfj.dll once and then click the kill button. After you have killed all of the ixccpfj.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of ixccpfj.dll and kill it. (If you do not find the dll, just continue on.)


    Now just exit Process Explorer.

    Run HijackThis. Click the 'Do a system scan only' button.


    Once the scan has completed click Config

    Click Misc Tools

    Click Open Process Manager

    Terminate the following processes by selecting them from the list and clicking Kill Process
    These may not be present but we need to check

    Click back to return to the scan results.

    Place a checkmark in the box next to the following lines:


    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot.


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)


    If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.


    REBOOT to Normal Mode.

    Let me know how things are running now

    Post a fresh HijackThis log, a fresh newfiles log and a fresh activescan log.[/QUOTE]
     
  4. macker6464

    macker6464 Private E-2

    Cheers zillions!

    That has helped a lot - can't really say thanks enough:D

    The pc seems to be running a lot better now.

    I have also ditched a few of the overlapping anti-malware progs as well now and the pc is starting to speed up.

    A defrag gave me a boost of 40% speed too in start up / shut down.

    I have attached a fresh HijackThis log hijackthis.log:)

    and
    a ShowNew newfiles.log:)

    Again Panda ActiveScan appears to be working fine but half way through it causes the pc to suddenly switch off and restart. I tried several times:confused:
    I have got a problem with the button on my pc which sometimes switches the pc on for 1 second and then it goes dead. It can take many presses to get it to turn on and stay on. It has never just switched off though except for the 6 or so times I tried Panda Active Scan. I assumed it was a dicky button and was going to move the inards to a new case/PS.

    Do you think the PC is clean now? Is there anything you can see which I can disable (even at startup) to speed the startup?

    Need to say again MANY THANKS:)
     

    Attached Files:

  5. matt.chugg

    matt.chugg MajorGeek

    The following lines are not really needed at startup as they are not necesary or can be run as needed

    you also need to fix the following line with HJT AND CONFIRM IT IS GONE, I don't think the service exists anymore but if it does we will need to manualy remove it.,

    O23 - Service: Network Security Service (NSS) (%AF夶À¨) - Unknown owner - C:\WINDOWS\wincu.exe (file missing)
     
  6. macker6464

    macker6464 Private E-2

    Sorry for the delay.
    PC still running well but still could be a bit quicker I guess.

    The HJT log shows the following still
    O23 - Service: Network Security Service (NSS) (%AF夶À¨) - Unknown owner - C:\WINDOWS\wincu.exe (file missing)

    I have tried ticking it and fixing it in HJT but it seems to appear in the log still.

    Also a few of the above lines you pointed out still show up.

    How should I stop these running?

    HJT log and newfile logs attached.

    Many thanks

    macker6464
     
  7. macker6464

    macker6464 Private E-2

    Sorry - couldn't attach the file there.

    Here they are now;)

    macker6464
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is part of an HSA hijacker problem and it cannot be so simply fixed.

    Run this about:Buster Follow the directions in the download page. Attach a new HJT log and the log from about:buster after running it.
     
  9. macker6464

    macker6464 Private E-2

    Thanks chaslang

    I have run AboutBuster and then rebooted and run it again.
    The log is attached as Ab LogFile.txt:)

    I then ran HJT and a new hijackthis.log is attached too:)

    It looks like there are some stubbornly things hanging around:mad:

    There was no option to Check for Updates in the process but the version was AboutBuster 6.05

    cheers
    macker6464
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Network Security Service (NSS)
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste%AF夶À¨ into the box that opens, and press OK. You MUST use copy and paste to do this since the characters are not things you can type.
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Make sure viewing of hidden files is enabled (per the tutorial).

    Look for the below file and delete if found
    C:\WINDOWS\wincu.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.
    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  11. macker6464

    macker6464 Private E-2

    My strange Chinese error has disappeared and the system appears to be working quite well (fingers crossed).

    Thank you you very much. You guys really know your stuff!

    I have attached logs as requested:

    GetRunKey txt - runkeys.txt :)
    ShowNew txt - newfiles.txt :)
    HJT - HiJackThis.log :)

    I will keep my eyes on the system for any funnies.

    One thing I have noticed is that it can sometimes take several seconds to start to open an Internet Explorer window. I am assuming this is due to the anti-virus AVG and the anti Spyware Spyware Doctor slowing things down a tad.
    No worries!

    Thanks again

    Macker6464
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds better, but we have one more rogue service to remove!
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Performance Manager
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste svhost into the box that opens, and press OK. You MUST use copy and paste to do this since the characters are not things you can type.
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and this time reboot when it tells you it needs to.
    After reboot look for the below files (you may not find the first one) and delete them:
    c:\Program Files\Common Files\fh.exe
    C:\WINDOWS\system32\mmllm.ini
    C:\WINDOWS\system32\mmllm.ini2
    C:\WINDOWS\system32\lylk.dat

    Also delete the below folders:
    C:\Program Files\Common Files\{3CA5C140-068A-2057-0114-03082103002c}
    C:\Program Files\Common Files\{8CA5C140-068A-2057-0114-03082103002c}



    Now attach a new HJT log and a new log from ShowNew
     
  13. macker6464

    macker6464 Private E-2

    Thanks again


    Performance Manager was stopped but disabled it as asked.
    did the svhost thing.

    C:\Program Files\Common Files\fh.exe - Didn't exist
    C:\WINDOWS\system32\mmllm.ini - Deleted this
    C:\WINDOWS\system32\mmllm.ini2 - Deleted this
    C:\WINDOWS\system32\lylk.dat - Deleted this

    HJT log attached hijackthis.log :)
    ShownewFiles log attached newfiles.txt :)

    What dya think now?

    Cheers
    Macker6464
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    7. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  15. macker6464

    macker6464 Private E-2

    Thanks again for super support :)

    My PC feels a lot cleaner.

    I have taken all the steps you recommend and have worked through your tips for keeping clean.

    A superb site which I will recommended to all!

    Cheers

    Macker6464
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds