Can't get rid of Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by cwilson287, Aug 31, 2006.

  1. cwilson287

    cwilson287 Private E-2

    I have tried all the scans except the Bitdefender, the link said that the file was not found. So I do not have the report for that scan. When everything first started Norton was telling me that I had a virus "win32boot.exe" and Norton could not fix it. I found the removal instructions from Trend Micro and went through all the steps and the computer is still acting like it did when it was infected with that virus. Can you please give me a hand with how to fix my problem.
     

    Attached Files:

  2. cwilson287

    cwilson287 Private E-2

    Here is my Hijack this! report.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You have quite a few problems.

    First you have some problems remaining from a SmitFraud infection. Let's work on it first.

    PLEASE READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING. Ask any questions that you may have before starting.

    Please print out or copy these instructions to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. Again, if there's anything that you don't understand, ask your question(s) before moving on with the fixes.

    Reboot your computer into Safe Mode per the safe directions in the READ & RUN ME.

    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.

    Please attach this log along in your next reply.

    After you complete the above, move on to my next message.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First install the current version of Sun Java from: Sun Java Runtime Environment

    Then uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 3



    Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to the following key and take ownership of it (explained further down):

    HKEY_LOCAL_MACHINE\software\microsoft\mssmgr

    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the Menu
    • Select Take Ownership
    • Now leave RegistrarLite running and continue
    • Now run the REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate to HKEY_LOCAL_MACHINE\software\microsoft\mssmgr
    • Does the above mssmgr key still exist! If so, right click on it and select Delete.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    After completing ALL of the above instructions, continue here!

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of awvtr.dll once and then click the kill button. After you have killed all of the awvtr.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    winvcw32.dll

    Next double click on explorer.exe and again click once on each instance of awvtr.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    winvcw32.dll

    Now just exit Process Explorer.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\Sys32Boot.exe
    C:\WINDOWS\wms64drv.exe
    C:\WINDOWS\system32\mswintcp.exe
    C:\DOCUME~1\Josh\MYDOCU~1\WNSXS~1\msdtc.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {959A6F64-ADDC-FF0E-FC38-8AEA699E2196} - C:\WINDOWS\system32\hitz.dll
    O2 - BHO: (no name) - {959A6F64-ADDC-FF0E-FC38-8AEA699E2196} - C:\WINDOWS\system32\hitz.dll
    O2 - BHO: (no name) - {B7C2B1C4-57D4-4E98-8831-8C6EC5251D7C} - C:\WINDOWS\system32\awvtr.dll
    O4 - HKLM\..\Run: [Windows shit] mswintcp.exe
    O4 - HKLM\..\Run: [Windows Automatic Updater] explore.exe
    O4 - HKLM\..\RunServices: [Windows shit] mswintcp.exe
    O4 - HKLM\..\RunServices: [Windows Automatic Updater] explore.exe
    O4 - HKCU\..\Run: [Saaw] "C:\DOCUME~1\Josh\MYDOCU~1\WNSXS~1\msdtc.exe" -vt yax
    O4 - HKCU\..\Run: [364c90dc.exe] C:\Documents and Settings\Josh\Local Settings\Application Data\364c90dc.exe
    O15 - Trusted Zone: http://locator.cdn.imageservr.com
    O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
    O20 - AppInit_DLLs: msdtc.dll C:\WINDOWS\system32\msdtc.dll
    O20 - Winlogon Notify: awvtr - C:\WINDOWS\system32\awvtr.dll
    O20 - Winlogon Notify: winvcw32 - winvcw32.dll (file missing)
    O23 - Service: win32crc - Unknown owner - C:\WINDOWS\Sys32Boot.exe
    O23 - Service: Win32DrivRem - Unknown owner - C:\WINDOWS\wms64drv.exe

    After clicking Fix, exit HJT.


    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    exit

    If you get an error message while doing the above command prompt step, just ignore it and continue!

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.
    C:\Documents and Settings\Josh\Local Settings\Application Data\364c90dc.exe
    C:\Documents and Settings\Josh\Favorites\Antivirus Test Online.url
    C:\Documents and Settings\Josh\MYDOCU~1\WNSXS~1\msdtc.exe
    C:\WINDOWS\Downloaded Program Files\gdnUS2339.exe
    C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N91M1807NetInstaller.exe
    C:\WINDOWS\Sys32Boot.exe
    C:\WINDOWS\wms64drv.exe
    C:\WINDOWS\YAXUninst.exe
    C:\WINDOWS\system32\explore.exe
    C:\WINDOWS\system32\beqqnqsd.exe
    C:\WINDOWS\system32\blcbaphw.exe
    C:\WINDOWS\system32\mswintcp.exe
    C:\WINDOWS\system32\huiiokyh.exe
    C:\WINDOWS\system32\pqmyncms.exe
    C:\WINDOWS\system32\rdyvehtr.exe
    C:\WINDOWS\system32\rgyuclgf.exe
    C:\WINDOWS\system32\tvygcrgd.exe
    C:\WINDOWS\system32\wnstssv.exe
    C:\WINDOWS\system32\xyrycrhx.exe
    C:\WINDOWS\system32\awvtr.dll
    C:\WINDOWS\system32\hitz.dll
    C:\WINDOWS\system32\hrjnsfmw.dll
    C:\WINDOWS\system32\msdtc.dll
    C:\WINDOWS\system32\rtvwa.ini
    C:\WINDOWS\system32\rtvwa.ini2

    If Killbox does not reboot or if you get a Pending Operations type error message just click OK to continue and then just reboot your PC yourself.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\
    C:\Documents and Settings\Josh\Local Settings\Temp\

    Now attach a new HJT log and tell me how the steps went.

    Also attach a new log from ShowNew and a new log from GetRunKey.

    Make sure you tell me how things are working now!
     
  5. cwilson287

    cwilson287 Private E-2

    I have completed all of the steps you advised me on and it seems that it has cleaned the system. I have attached the files that you requested after I had completed everything.

    There was nothing weird that happened while I was going through the steps, I did not get any error messages after the registry updates and the key for mssmgr was gone after the registry update. Overall, I want to thank you for a very easy to follow and easy to complete guide to help get this computer back up and running.

    Please let me know if you find anything else that I may need to do by the files that I have attached.

    Thanks again for all your help.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    You forgot to attach the log from SmitFraudFix! Please attach it now.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Please use Pocket Killbox to delete the below files:
    C:\WINDOWS\system32\nfdlriui.dll
    C:\WINDOWS\Downloaded Program Files\UDC6_0001_D19M1908NetInstaller.exe
    C:\WINDOWS\Downloaded Program Files\UDC6_0001_D19M1908NetInstaller.inf

    Then after reboot run Pocket Killbox and select File, Cleanup, Delete All Backups!

    Now download the new version of ShowNew and use it to attach a new log!
     
  7. cwilson287

    cwilson287 Private E-2

    I have completed the steps that you mentioned to complete. I am sorry that I forgot to attach the text file that you mentioned.

    Please let me know if I need to do anything else.

    Thanks again for your help.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete the below folders:
    C:\!KillBox
    C:\Program Files\Common Files\W?nSxS

    Then you will be clean!

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds