can't get rid of problem please help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by steeltek, Sep 10, 2006.

  1. steeltek

    steeltek Private E-2

    Ok, I have done everything in the read me first section.

    I first had toolbar188, I think that I have removed that, I also have something that puts icons on my desktop that are labeled "SECURITY TROUBLESHOOTING" & "ONLINE SECURITY GUIDE". I have run the new version of SMITREM, and FIXQUAKE. I thought that this took care of the problem, but there was still some popups, and then the icons came back along with a new homepage "uptodateprotection.com".

    I am attaching my logs that I have.
     

    Attached Files:

  2. steeltek

    steeltek Private E-2

    Here are some more of my logs
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's start by working on an infection in the Smitfraud family.

    Now Download SmitfraudFix (by S!Ri) to your Desktop.

    Extract all the files to your Destop. A folder named
    SmitfraudFix will be created on your Desktop.

    Open the
    SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter
    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach that log in your next reply.

    Note:process.exe ( which is used my SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. The below is a link to what process.exe is.

    http://www.beyondlogic.org/consulting/proc...processutil.htm


    IMPORTANT: Do NOT run any other options until you are asked to do so!
     
  4. steeltek

    steeltek Private E-2

    ok done that, but don't know if it matters or not, i went to the sight for the exe informations and got this error code:

    404dnserror.com

    The page you are looking for is probably blocked by adware/spyware on your pc. Remove it with SystemDoctor software. Click here.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't pay any attention to that message. It is from the malware you have on your PC. DO NOT click that link for SystemDoctor.

    PLEASE READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING. Ask any questions that you may have before starting.

    Please print out or copy these instructions to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. Again, if there's anything that you don't understand, ask your question(s) before moving on with the fixes.

    Reboot your computer into Safe Mode per the safe directions in the READ & RUN ME.

    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach this log along in your next reply.

    After doing the above and attach the new rapport.txt log, also attach a new log from the below:
    - HJT log
    - GetRunKey
    - ShowNew
     
  6. steeltek

    steeltek Private E-2

    do i do the hjt and other scans in safe mode also?
     
  7. steeltek

    steeltek Private E-2

    ok, i done the scans in safe mode and here they are.
     

    Attached Files:

  8. steeltek

    steeltek Private E-2

    and HJT.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry I was not specific about that. In the future, always assume logs are wanted from normal boot mode because typically safe mode logs do not provide adequate information. Don''t worry about getting new logs right now. First I want to see if we can fix a few problems just by uninstalling them. While doing the uninstall of some malware items, I will also have you uninstall your outdated Sun Java and FireFox versions and replace them with new versions.

    So first goto Add/Remove programsand uninstall the below software:
    Command
    Java 2 Runtime Environment, SE v1.4.2
    Java 2 Runtime Environment, SE v1.4.2_03
    MediaTickets by OIN
    Mozilla Firefox (1.5.0.3)
    Safety Bar
    ToolBar888
    Viewpoint Media Player

    Whether they uninstall or they fail to uninstall, just continue. But if you receive any error messages, let me know.

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Now move on to my next message.
     
    Last edited: Sep 13, 2006
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After completing what I gave in message number 9, continue with the below steps!

    Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to the following key and take ownership of it (explained further down):

    HKEY_LOCAL_MACHINE\software\microsoft\mssmgr

    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the
      registry key.
    • Click-on Security in the Menu
    • Select Take Ownership
    • Now leave RegistrarLite running and continue
    • Now run the REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate to HKEY_LOCAL_MACHINE\software\microsoft\mssmgr
    • Does the above mssmgr key still exist! If so, right click on it and select Delete.
    Here is the Registry
    Patch

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all
    files" Once you have saved it double click it and allow it to merge with the registry.

    After completing ALL of the above instructions, continue here!

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while
    offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to
    the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your
    System tray.


    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on
    the Threads tab at the top.

    Once you see this screen click on each instance of winpsa32.dll once and then click the kill button. After you have killed all of
    the winpsa32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    ddcyy.dll
    ddcyyya.dll

    Next double click on explorer.exe and again click once on each instance of winpsa32.dll and kill it. (If you do not
    find the dll, just continue on
    .)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    ddcyy.dll
    ddcyyya.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are
    reading in right now (some of these may no longer be found if the uninstalls above worked):

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
    R3 - URLSearchHook: (no name) - {C84EEEA0-2E38-7DC1-14FC-07E2ED747795} - C:\WINNT\system32\fwhvwnif.dll
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: (no name) - {88653025-CAC2-43B5-8626-72CDE62D81FB} - C:\WINNT\system32\ddcyy.dll
    O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINNT\system32\ixt1.dll (file missing)
    O2 - BHO: (no name) - {C84EEEA0-2E38-7DC1-14FC-07E2ED747795} - C:\WINNT\system32\fwhvwnif.dll
    O2 - BHO: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
    O2 - BHO: (no name) - {D3B3C51E-8D11-4667-85B9-0930F519BED7} - C:\WINNT\system32\ddcyyya.dll
    O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
    O4 - HKCU\..\Run: [zqri] C:\Program Files\InetGet2\stub_109_4_0_4_0.exe
    O4 - HKCU\..\Run: [Ltho] "C:\WINNT\MBOLS~1\mshta.exe" -vt yazb
    O4 - HKCU\..\Run: [Tfsj] C:\WINNT\system32\s?mbols\msiexec.exe
    O20 - Winlogon Notify: ddcyy - C:\WINNT\system32\ddcyy.dll
    O20 - Winlogon Notify: ddcyyya - C:\WINNT\SYSTEM32\ddcyyya.dll
    O20 - Winlogon Notify: winpsa32 - C:\WINNT\SYSTEM32\winpsa32.dll
    O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINNT\IA\command.exe
    O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe

    After clicking Fix, exit HJT.


    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web
      Settings". Now go back to the General tab and set your home page address to something useful like
      www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete
      Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings,
      Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home
      page address to something useful like www.majorgeeks.com. Click
      Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click
      OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer
    Settings!


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all
    files" Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command
    prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    exit

    If you get an error message while doing the above command prompt step, just ignore it and continue!

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do
    not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after
      highlighting, right-click and choose copy):

    C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
    C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
    C:\Program Files\Common Files\{9802C890-09C3-1033-0723-030410010001}\Update.exe
    C:\WINNT\iemk32.exe
    C:\WINNT\system32\cool.exe
    C:\WINNT\eSellerateEngine.dll
    C:\WINNT\fayei.dll
    C:\WINNT\IA\command.exe
    C:\WINNT\system32\atmtd.dll
    C:\WINNT\system32\ddcyvwv.dll
    C:\WINNT\system32\ddcyy.dll
    C:\WINNT\system32\ddcyyya.dll
    C:\WINNT\system32\fwhvwnif.dll
    C:\WINNT\system32\nnnlmlk.dll
    C:\WINNT\system32\winpsa32.dll
    C:\WINNT\system32\yycdd.tmp
    C:\WINNT\system32\yycdd.ini
    C:\WINNT\system32\yycdd.ini2
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a
    PendingFileRenameOperations prompt, just click OK to continue (But please let me know
    if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folders and delete them if found:
    C:\WINNT\IA
    C:\Program Files\Common Files\{9802C890-09C3-1033-0723-030410010001}
    C:\Program Files\InetGet2
    C:\Program Files\Network Monitor
    C:\Program Files\ToolBar888

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files
    from the current day
    ).
    C:\WINNT\temp
    C:\Documents and Settings\Owner\Local Settings\Temp

    Now attach a new HJT log and tell me how the steps went.

    Also attach a new logs from ShowNew and GetRunKey.

    Make sure you tell me how things are working now!
     
  11. steeltek

    steeltek Private E-2

    Ok, done everything, but I could not remove command at add/remove progams, i kept getting an error with norton, then I allowed it, and it sent me to a web site to unistall it, didn't know what to do, so I closed web site and went on.

    Followed the rest of the instructions you gave me and here are the logs you requested, also command is still in the add/remove programs list
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run the steps again to delete the below registry key:

    HKEY_LOCAL_MACHINE\software\microsoft\mssmgr

    Make sure you double check as requested in RegistrarLite to see if it is deleted and if not, then use RegistrarLite to delete it.

    Try using the below tool to uninstall "Command"

    Your Uninstaller! 2006


    Attach a new GetRunKey log and tell me if you were able to uninstall Command.
     
  13. steeltek

    steeltek Private E-2

    Ok, done it again, and rechecked, it seems to be gone. I also removed command with the new program, but command still is showing up on the HJT logs, tried to fix, but won't go away, and I couldn't find winnt\ia\command.exe.

    I also couldn't deleted for c:\documents and settings\owner\local settings\temp\perflib_perfdata_b64.dat
    c:\documents and settings\owner\local settings\temp\perflib_perfdata_dac.dat
    c:\documents and settings\owner\local settings\temp\perflib_perfdata_db4.dat

    Here are the logs, plus my computer is still running slow, and I can't seem to get Norton running anymore, well it still does it system scan when scheduled, but it won't protect the computer for viruses, I can't turn that option on. Any ideas? Also what can I delete that is not necessary to the computer?

    Many thanks,
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Command Service ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    cmdService

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.


    Be careful what you ask for! ;) Because I will tell you that Yahoo Companion and Google Toolbar are not necessary to the computer. Personally I would uninstall them but you may like them.

    You can have HJT fix the below line too since it is not required to be loaded at startup in order to have QuickTime work:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    Now reboot your PC and attach a new HJT log. How are things working now?
     
  15. steeltek

    steeltek Private E-2

    ok it seems to be working better, but still slow on start up.

    How do I go about removing google and yahoo tool bars so they don't show back up?

    also here is the log from HJT.

    What about the perflib_perfdata_b64.dat and others like it, anything to worry about?

    How do I make norton work fine or should I use another program?

    thanks again
     

    Attached Files:

  16. steeltek

    steeltek Private E-2

    also i would like to remove norton and put in avast, i read in another post that some removed theirs, but it did not go completely away, can't remember what post though.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you don't want them then you should go to Add/Remove programs and just uninstall them.



    No! They are normal system files.


     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds