After run me first !!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Alpheraz, Feb 19, 2007.

  1. Alpheraz

    Alpheraz Private E-2

    Hello,

    Malware in my computer started Internet Explorer and loaded some pages. I have performed as exactly as I could the steps recommended on the Read & Run Me First guide.

    The guide directs to start the computer in safe mode, but I have tried several times unseccessfully. The system could only be restarted in normal mode.

    Running the various antivirus programs seems to have decreased the problem with Internet Explorer. However, there are still some problems: For instance, all Norton Antirus installation fail to find the file NMain.exe, although the file is there, and also, the main executable for Spybot is deleted.

    I attach the first three scan result files.

    Thank you in advance to anyone who can help me.

    Best Regards
     

    Attached Files:

  2. Alpheraz

    Alpheraz Private E-2

    I now attach some more result files
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is this (my Spanish is non-existant):

    C:\Documents and Settings\All Users\Datos de programa\keep load junk regs\each start.exe?


    Run counterspy and have it fix/remove all that it finds.

    Uninstall these thru add/remove programs:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 9

    Reboot and install:\Java Runtime 6

    Now run:
    Sophos Anti-Rootkit will scan your computer for files that have been hidden using rootkit technology.

    Many of the newer malware infections use this technology to hide themselves and to make them more difficult to remove.

    Installation
    Download Sophos Anti-Rootkit 1.1 and save to a location you will be able to find such as your desktop

    Run sarsfx.exe by double clicking on it.

    Click Accept to agree to the EULA

    Click Install (if you wish to change the default installation location do so here but remember where you install to, the default is C:\SOPHTEMP)

    Once it finishes copying files, exit the installer​
    Running the scan
    Navigate to the location that you installed the software to (Default: C:\SOPHTEMP)

    Run sargui.exe by double clicking on it.

    Ensure that all three of the options are checked

    Click Start Scan

    Once the scan is complete, close Sophos Anti-Rootkit by closing the scan window and clicking Exit in the main window

    DO NOT CLICK 'CLEAN UP CHECKED ITEMS' OR ATTEMPT TO HAVE SOPHOS ANTI-ROOTKIT FIX ANYTHING UNLESS SPECIFICALLY INSTRUCTED TO IN THE THREAD YOU ARE WORKING ON
    Finding the logsClick on Start --> Run

    Type in %TEMP%\sarscan.log and press enter

    The log file will open in the default editor (probably Notepad)

    Click File --> Save As and save the file to your desktop or other location for easy retrieval.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: Share Accelerator Toolbar - {f5c93451-2609-4723-a053-5c19516be1a8} - C:\Archivos de programa\Share_Accelerator\tbShar.dll
    O3 - Toolbar: Multi Media Spain 2 Toolbar - {b2de6c6c-f6b9-4427-96e4-3b8de900a2b6} - C:\Archivos de programa\Multi_Media_Spain_2\tbMult.dll

    After clicking Fix, exit HJT.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT

    Be sure to tell us how things are running.
     
  4. Alpheraz

    Alpheraz Private E-2

    TimW:

    Thank you very much. I will start the cleaning process recommended by you.

    Also, You asked what is
    C:\Documents and Settings\All Users\Datos de programa\keep load junk regs\each start.exe?

    It is a folder. I do not know which program created it. It contains these three files: Bib mpeg tray, Boltbatlink, Listaxisfrag, all as "System File"

    Bets Regards,
    Antonio
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is a LOP infection that need to be removed! ;)
     
  6. Alpheraz

    Alpheraz Private E-2

    Thank you chaslang,

    How should I remove that? Just deleting the folder?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, please delete the folder and then uninstall thru add/remove programs:
    Windows Live Messenger
    Windows Live Sign-in Assistant
    Windows Live Toolbar
    Windows Live Toolbar

    These are sources of the Lop infection.

    Have you done the other items as directed?
     
  8. Alpheraz

    Alpheraz Private E-2

    Regarding the Lop infection, I will do as directed,

    Now, apparently all infections have been removed. I am using another computer, but in a few hours I wll send you newer scan files.

    I have finally been able to install and run Spybot, which was previously blocked by the malware. Spybot did not find anything abnomal.

    I also have finally been able to install Norton Antivirus.

    Thank you very much
     
  9. Alpheraz

    Alpheraz Private E-2

    Hello,

    I have followed all instructions received so far. Files are attached.

    The computer does not start in safe mode, but apart from that, things look normal.

    Best Regards,
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [hldrrr] C:\WINDOWS\system32\hldrrr.exe
    O4 - HKCU\..\Run: [hldrrr] C:\WINDOWS\system32\hldrrr.exe

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\hldrrr.exe

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    I would like to see the scan report from Sophos.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT
     
  11. Alpheraz

    Alpheraz Private E-2

    Hello,

    Hijackthis did not show:

    O4 - HKLM\..\Run: [hldrrr] C:\WINDOWS\system32\hldrrr.exe
    O4 - HKCU\..\Run: [hldrrr] C:\WINDOWS\system32\hldrrr.exe

    I merged the fixME.reg

    There was no C:\WINDOWS\system32\hldrrr.exe that I could see.

    In any case, I followed the instructions for Pocket Killbox, including the Reboot.

    I did not find anywhere the scan file from the previos sophops scan. Then, I have tried to run the scan again, but there was a critical error. I attach the file now, as well as the HJT new file.

    With the following post I will attach new files for
    * GetRunKey
    * ShowNew
    Thank you,
     

    Attached Files:

  12. Alpheraz

    Alpheraz Private E-2

    New files :
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Remove all of your browser toolbars and extensions.

    Download and install Registrar Lite

    Then run Registrar Lite.

    Copy and paste the below into the Address box of registrar lit and hit the Enter key.

    HKEY_LOCAL_MACHINE\SYSTEM

    Then click the Security pull down ont the top menu and choose Take Ownership. Click OK in the next window to approve it. Now exit Registrar Lite and continue.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.

    Run the below and attach the requested log:

    Running Spy Sweeper

    Make sure you reboot after running Spy Sweeper.
    Now let's fix the other problems. Note that the O20 lines may already be gone if SpySweeper was able to completely fix them.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O8 - Extra context menu item: Compare Prices with &Dealio - C:\Archivos de programa\Dealio\res\DealioSearch.html

    Reboot into normal mode and attach the logs for:
    Spy Sweeper
    GetRun
    ShowNew

    Be sure to tell me how things are running.
     
  14. Alpheraz

    Alpheraz Private E-2

    Run the below and attach the requested log:

    Running Spy Sweeper

    The thread doesn't exist confused

    I downloaded and run spy sweeper from http://www.webroot.com/consumer/products/spysweeper/freescan.html?rc=4213&wt.srch=1&wt.mcid=mgsdr

    I attach the results screen. It says that in order to quarantine or clean you have to subscribe.

    Now let's fix the other problems. Note that the O20 lines may already be gone if SpySweeper was able to completely fix them.

    They still exist.

    Reboot into normal mode and attach the logs for:
    Spy Sweeper
    I have not found a way to export a log.

    Thank you
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry for the bad link.

    Download and Install Registrar Lite.

    Run Registrar Lite navigate to the following keys and take ownership of them (explained further

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000]
    "Service"="cmdService"
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDSERVICE]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDSERVICE\0000]
    "Service"="cmdService"
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDSERVICE]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDSERVICE\0000]
    "Service"="cmdService"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETWORK_MONITOR]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETWORK_MONITOR\0000]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NETWORK_MONITOR]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NETWORK_MONITOR\0000]


    To take ownership of the key do the following:

    * Copy & Paste one registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the regitry key.
    * Click-on Security in the Menu
    * Select Take Ownership
    * Now right click on the registry key and select delete
    * Repeat for all registry keys
    * Tell me the results. Any errors?

    Attach new logs for:
    GetRun
    ShowNew
    HJT
     
  16. Alpheraz

    Alpheraz Private E-2

    I am not sure if I have understood the instructions.
    I might have deleted something I was not suppose to.

    I can not delete (message access denied):

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000]
    "Service"="cmdService"
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDSERVICE\0000]
    "Service"="cmdService"
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDSERVICE\0000]
    "Service"="cmdService"
    within the folder I only see another folder called "Access Denied"

    new logs are attached
    GetRun
    ShowNew
    HJT[/QUOTE]
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download delcmdservice (by Marckie), and save it to your Desktop.
    • Unzip the content to your Desktop (a folder named delcmdservice)
    • Double-click on the delcmdservice folder
    • Double-click on delreg.bat to launch the tool
    • When the tool has finished, please reboot your computer
    Attach a new RunKeys and HJT log.
     
  18. Alpheraz

    Alpheraz Private E-2

    Hello,

    I attach the requested files.
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean. You may uninstall any programs we had you download.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  20. Alpheraz

    Alpheraz Private E-2

    Hello!

    Problems already solved are coming back. Main files for both Spybot and Norton Antivirus have been removed.

    Can we run more checks or repeat those checks?

    Thank you
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes ...you need to run through all the steps in the Read and Run First and attach the logs ...
     
  22. Alpheraz

    Alpheraz Private E-2

    I reply from another computer.

    I started over again. I setup MSCONGIG to safe mode, since I couldn't achieve that with the F8 key, but know the computer is unable to restart in neither safe nor normal mode. It just keeps going back to the screen with choices to select the boot mode.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  24. Alpheraz

    Alpheraz Private E-2

    I have tried with the link you sent me, but I can not even re-install XP, since it always tries to reboot in safe mode, and the computer just won't do it. I do not know how to break the loop.
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  26. Alpheraz

    Alpheraz Private E-2

    I couldn't repair the previous windows install. My computer kept attempting to boot in safe mode once and again.
    I just installed windows xp fresh. Now I am following the read & run me first instructions. I have completed spybot, which did not find anything and I am running counterspy. Up to know no files have been detected:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds