Bugs - suspect WinFixer

Discussion in 'Malware Help (A Specialist Will Reply)' started by mrb, Jan 13, 2006.

  1. mrb

    mrb Private E-2

    I have been getting popups - usually the first pop up is winfixer. My computer is running slower than normal. When I reboot into safe mode, I have no icons, no start menu, no taskbar - black screen with safe mode in four corners - I can access my task manager by ctrl-alt-del.

    I have run all tools mentioned in Read Me section, ran BitDefender, and ran Panda (saved logs). BitDefender found nothing, Panda found 3 spyware items, 1 virus item.

    I'm a bit of a rookie, but would really appreciate help getting rid of this perplexing bug. Any help would be welcome. Thank you.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the instructions in step 7 of the READ ME properly. You version of HJT has not been used in a few years.
    You must install the new version properly and attach a new log from it.
     
  3. mrb

    mrb Private E-2

    WinZip won't unzip the file - McAfee finds a virus when I try to extract the files. This was using the first Major Geeks TX source for download.

    Virus detection message: The file C:\Documents and Settings\James\Local Settings\Temp\wz6963\HijackThis.exe was infected by the W32/Generic.worm!p2p virus and has been deleted to complete the Clean process.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because you have not updated McAfee in more than a year. Get McAfee updated or uninstall it. It is tool old to use the way it is. McAfee is wrong!
     
  5. mrb

    mrb Private E-2

    Okay -McAfee uninstalled (don't look at me - it came with the computer) :)
    HiJack This downloaded, HJT log attached.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are the below valid?
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.usefulware.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.usefulware.com

    You have a Virtumonde infection we need to fix. We have a generic procedure for doingt fixing this. I will give you the link and the HJT lines of interest you will need to use in completing the procedure. Also since you alread did the READ ME you can start the Virtumonde fix at step 3.

    Here is the link: Virtumonde aka Trojan Vundo Fix w/ Tool

    Here are the line you will need. Note the procedure shows an O2 line from HJT with O2 - BHO: MSEvents Object Your infection is a different form and has O2 - BHO: ATLDistrib Object instead!

    O2 - BHO: ATLDistrib Object - {93C6313C-9DB4-4694-8BD0-E378C573A9AD} - C:\WINDOWS\system32\ssqpm.dll
    O20 - Winlogon Notify: ssqpm - C:\WINDOWS\system32\ssqpm.dll

    After completing the Virtumonde fix, post a new HJT log.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also an important caution! Since you remove your antivirus (a required step because it was too old to be useful) you must get one installed ASAP. Also you need to get a firewall installed ASAP. The one in WinXP SP2 does not provide sufficient protection.

    That said: you need to do steps 2 & 3 in the below link immediately. We can do the rest of it later when finished with all other cleanup.

    How to Protect yourself from malware!
     
  8. mrb

    mrb Private E-2

    Loaded antivirus program and firewall, as advised. Booted up into safe mode - amazing, all of my icons were visible for the first time. Tried to run Vundo fix - after both codes are input, press enter and get message "Killing process" and then something about "-" not being recognized, HJT program opened. I cancelled, booted to normal mode, ran HJT log and waiting for instructions - what was done wrong? Code entered with spaces in correct areas - second code with last name reversed and ending in ".*"

    Please advise
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not have cancelled you should have just continued. Were you doing it in safe mode.

    You can either try again or wait until a work up a different procedure for you( in about 15 minutes).
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's use my older manual approach to fixing Virtumonde. Start by downloading two tools we will need:

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of ssqpm.dll once and then click the kill button. After you have killed all of the ssqpm.dll under winlogon click ok. (If you do not find the dll, just continue on.)


    Next double click on explorer.exe and again click once on each instance of ssqpm.dll and kill it.

    Now repeat the above in the explorer.exe process for ssqpm.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.usefulware.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.usefulware.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: ATLDistrib Object - {93C6313C-9DB4-4694-8BD0-E378C573A9AD} - C:\WINDOWS\system32\ssqpm.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O20 - Winlogon Notify: ssqpm - C:\WINDOWS\system32\ssqpm.dll

    Copy the bold text below to notepad. Save it as fixVundo.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
     
  11. mrb

    mrb Private E-2

    I have to go out of town - will work on this on Sunday afternoon. I was in safe mode when I tried the fix - I thought I was doing it wrong - the language on the fix report led me to believe - that's why I rebooted to normal and ran HJT again. I tried to reboot to safe mode again tonight and froze at the login screen each time. Couldn't get in and had to hard reboot. I had enough time to run ad aware tonight again - found more issues. Should I run READ ME tools again on Sunday before I try the above fix?

    Thanks again for your help - I have an online class that started this week and I'm trying to resolve this before I have to spend a lot of time online (on homework, of all things).

    See you on Sunday...
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No do not do the READ ME again. In fact do not run anything else on your own. Only do what I gave in my last message and do it as soon as you can. Try not to use the PC (if possible) before doing the last steps I gave you.
     
  13. mrb

    mrb Private E-2

    Okay - I have not used my computer since my last post and immediately worked on your instructions when I started my computer this afternoon.

    I have not received a pop up (yet) since I followed your instructions. My new HJT log is attaced.
     

    Attached Files:

  14. mrb

    mrb Private E-2

    My computer seems to be running much faster and I haven't received any popups. But, I'm curious - I have not been able to log in to hotmail.com nor has my husband been able to log into his employer's network... Is there something else going on that might affect these processes?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well it appears that your problems with Virtumonde are fixed. I'm not sure what is causing your problems with hotmail or for your husband's work network.

    Is it still a problem? Try another browser like Mozilla FireFox and let me know if that works.

    Also locate the below file and delete it:
    C:\WINDOWS\SYSTEM32\gebcd.dll
     
  16. mrb

    mrb Private E-2

    I'm not locating this file manually.

    Will download Firefox and try the two websites again.
     
  17. mrb

    mrb Private E-2

    Firefox fixed my hotmail prob - but not husband's work network, which leads me to believe their server is down.

    Thank you SO MUCH for your help. You rock.
    One last question - do you recommend Firefox over IE?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your answer is in step 7 of the link below.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!


    And just for the heck of it, give the below a run and see if it changes anything with using IE:

    Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
     
  19. mrb

    mrb Private E-2

    I ran Hoster - still having Hotmail problem - when I enter my user name and p/w, the following message is displayed "The Microsoft Passport Network is unavailable from this site for one of the following reasons: This site may be experiencing a problem., The site may not be a member of the Passport Network. You can: You can sign in or sign up at other sites on the Passport Network or try again later at this site."

    I will disable system restore and read about further protection - I'm sure you don't want to see me here again. :)

    Thank you again!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if any of the steps in the below help with hotmail:

    http://support.microsoft.com/default.aspx?scid=kb;en-us;307294


    It could be also as simple as the fact they you may be blocking a cookie from hotmail that needs to be placed on your PC. Do you see Privacy Report icon with a red circle and white minus sign in it? Double click on it and see what is in it.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may want to even give the below a try!

    Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
     
  22. mrb

    mrb Private E-2

    Oh - yes, several blocked cookies for hotmail.msn.com. I feel stupid.
    There are eight sites for hotmail that indicates cookies are blocked, however, when I clicked on tools/internetoptions/privacy/sites - I have hotmail in the always allow category. I clicked on the privacy report/summary and see an option to always allow cookies from MSN - should I do this?
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! And you probably need to allow passport.net
    I believe that is what hotmail uses.
     
  24. mrb

    mrb Private E-2

    After trying everything you have recommended, I am still unable to sign in at hotmail.com. I have read the troubleshooting guide at the link provided and am not finding anything specific to my experience. I tried logging in through passport.net and was able to access my e-mail by this method.
     
  25. mrb

    mrb Private E-2

    Oddly enough, when I try to access my husband's employer network, I receive a "page not found" message, however, when I log in to my employer network by remote connection, I am able to access this webpage by my employer's isp.
     
  26. mrb

    mrb Private E-2

    Correction - "page not displayed"
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm confused. I thought logging into hotmail brought you to passport.net?

    What are you Internet Options Privacy settings indicating? Are any of the hotmail or passport URLs blocked? Trying clicking the Advanced button and select Override automatic cookie handling. Then make sure your Accept both first and third part cookies. Does that help? If not, perhaps you are blocking cookies elsewhere. Like in a firewall, antispyware, or antivirus application.
     
  28. mrb

    mrb Private E-2

    I confuse myself.

    I clicked "always allow" in the privacy report/summary area and that has fixed my hotmail prob. But now I'm hung up on my husband's work website...
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It could be a similar problem but you said you could not connect with Firefox. Sounds like the site is down or you are blocking the URL with your firewall or similar.

    You must have changed something on your PC to cause these problems. I doubt the malware you got cause these problems.
     
  30. mrb

    mrb Private E-2

    Hmmm - I am pretty sure the site is up as I can access it from a remote location. I've worked with my firewall to try to get it to allow the site, and I double checked cookies, etc. No go. I don't know where to go from here, so I'm going to make my husband figure this one out with his IT dept. They have to be good for something, right? :)

    Once more - thank you so much for your help!
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I don't normally like doing this but it could be required for you husbands location. Try adding their URL to your Trusted Zone of IE (and maybe your firewall too) and see if that works.
     
  32. mrb

    mrb Private E-2

    No - it still didn't work. I double checked again that the site was still working through remote connection and it does. I'm giving up - but thanks again for all of your help and patience. It can't be easy with non-pc savvy users like myself. I am grateful!!!
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and good luck. Let us know when you get it fixed what it was.
     
  34. mrb

    mrb Private E-2

    What do you know - I fixed it and I don't even know how or why! I played around with my settings on privacy and cookies - when I didn't get results with adding it to my trusted sites, I immediately deleted those additions - don't want problems. Well, whatever ended up working apparently needed a re-boot to take effect. I re-booted as a last ditch "wonder if this works" effort. :)

    Wish I knew exactly what change I made actually allowed the site to work. But, thanks again for the guidance along the way!!!
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It could be that one of the security changes made just did not take effect properly until after a reboot.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds