Computer acting strange and new Admin accounts popping up - please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by sandeman, Feb 28, 2007.

  1. sandeman

    sandeman Private E-2

    Hello.

    I have some roommates who go a little crazy on the P2P programs. As a result, my computer is garbled. I have accounts set up for me, my wife, and guests, but I have been lax on enforcing this. As a result, I think my computer is infected. Just yesterday, while sitting at my computer, there was a weird command line window open with a cursor that was going crazy on the screen. I shut down my computer, and restarted it, and saw that there was a new administrator named "Adminestrator" on my computer, complete with a picture and everything.

    I logged on to my account and disabled the new account, then deleted it. An hour later, it reappeared.

    This brought me to here.

    I have followed the steps as best as I could, but with the Panda Online scan, I tried for hours, but it kept hanging up on my. It did say that I had 3 rootkits. (Not sure what that means.)

    Without further ado, I am attaching what I have.

    Note: I bought this computer about 4 years ago, and it had Windows XP pro installed on it. When I installed the SP2, I was informed that I have a "bad" version of Windows XP. THere is no boot disk, and the guy who sold me the computer closed up shop a long time ago. My comp is no where Vista ready, so what can I do?

    Thanks a million, and long live us geeks!

    Sandeman
     

    Attached Files:

  2. sandeman

    sandeman Private E-2

    And here are the rest of the files that I have.

    Please help. :)

    Sandeman
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Please uninstall thru add/remove programs:
    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 4"
    J2SE Runtime Environment 5.0 Update 6"
    J2SE Runtime Environment 5.0 Update 9

    Reboot and install:
    Java Runtime 6

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32\Searchx.htm
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    O4 - HKCU\..\Run: [ttool] C:\WINDOWS\9129837.exe
    O4 - HKCU\..\Run: [JavaUpdate0.07] C:\WINDOWS\System32\bvpr.exe
    O16 - DPF: {4FCFF034-6F56-4D65-8C31-70D98C475428} (ddm_download.ddm_control) - http://bins.dynamicdesktopmedia.com/cab/ddm_control.CAB
    O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\148359.exe
    C:\WINDOWS\system32\a3d70417.exe
    C:\WINDOWS\system32\atasnt40.dll
    C:\WINDOWS\system32\gadmsysw.dll
    C:\WINDOWS\System32\bvpr.exe
    C:\WINDOWS\system32\drivers\atnt40k.sys

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click on the box to unregister .dll's. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
  4. sandeman

    sandeman Private E-2

    Okay,

    I followed the instructions given, but only really ran into one snag -

    This file was not on the list for the hijackthis list:

    O4 - HKCU\..\Run: [ttool] C:\WINDOWS\9129837.exe

    Just to be sure, I made sure to C&P it into project killbox.

    Also, I followed the instructions on the project killbox step, but I did not see the square that allowed you to delete the DLL files. I did delete the files and reboot though.

    Attached are the logs requested. Thank you for your help.

    One thing that is scary though, I went to install a windows update today. I did not finish installing it, because I saw your post here, and thought that it would be best to completely clean out the system before installing updates. :D Now, I did not finish it, but that is the ONLY thing that I attempted to install today. I am seeing a new folder in C:\Program Files titled "BONJOUR" that says that it was created today. I KNOW I did not install this. French for "Hello". Should I be worried about this? (I know, one step at a time. :) )

    Sandeman

    Thank you so much. :)
     

    Attached Files:

  5. sandeman

    sandeman Private E-2

    LOL. I think it may have to do with the Skype program I installed. :eek:

    Sandeman
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use windows explorer to delete these:
    C:\WINDOWS\system32\REN79.tmp
    C:\WINDOWS\system32\REN7A.tmp
    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry
    Let's see if that does it.
    Attach new logs for :
    ShowNew
    GetRun
    HJT
     
  7. sandeman

    sandeman Private E-2

    Okay,

    I have followed the instructions, here are the logs for consideration:

    Sandeman
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean. You may uninstall any programs we had you download.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  9. sandeman

    sandeman Private E-2

    Thank you kind and generous GEEKS!

    Funny thing, my computer seems to be running faster. LOL.

    Question for you - where do I go to get rid of all the bloatware in my startup programs? I have something like 4 different AV/Spyware killers, and they are also all loading up at startup. Another amazing annoying one is Startup Manager. Do I just uninstall through Add/Remove programs, or do I have to go in and look through registries?

    Sandeman

    Again, thanks a million!~

    Cheers, and a beer for the geeks!:major
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you read the How to protect yourself link? That should answer some of the multiple spyware guestions. And yes, remove items thru add/remove. Then run CCleaner (both cleaner and issues - making the backup when prompted).

    Please, also read this thread:
    http://www.forums.majorgeeks.com/showthread.php?t=106650
     
  11. sandeman

    sandeman Private E-2

    Yes sir. Read through the how to protect yourself link. Great reading. I hit a snag though - seems my copy of Windows is not recognized by MS. I am not surprised, as I found out the guy who sold me the computer was not exactly the honest type.

    Thank you for the link - I will work through the steps. You guys have been awesome!

    I am manually installing the patches for windows from the Software Patch site. I am probably going to ask this there, but I will give it a shot here:

    A lot of the patches require a restart. I am starting from 2004 just to be on the safe side. (I already have SP2 installed, and I do not know from then on) As I see it right now, it looks like it is going to take a week to get my computer back up to par.

    Is there an easier way?

    Thanks

    Sandeman
     
  12. sandeman

    sandeman Private E-2

    Hmm. Found something in my Add/Remove programs list.

    It is IE Host R3

    AFAIK, this is spyware/malware. How do I get rid of it? Do I just remove it from the Add/Remove programs list?

    Sandeman
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you can remove it thru the add/remove programs ....let us know if it causes problems removing.

    As to patches ...I only allow the security patches and am careful of what is trying to be installed (No IE7 or any call-home crap - but that's just me.) You can download as may as you need, then run them and deny the restart until you have install a bunch. One last thought ...make a restore point before each install ...just in case!

    Sorry I missed the IE hosts ...have HJT remove/fix this as well:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
     
  14. sandeman

    sandeman Private E-2


    I am not seeing the IE Host R3 anymore in the Add/Remove Programs. Weird, because I did not touch it.

    As for this line, I found something almost the same:

    You told me:

    and all I could find was

    It is not quite the same, am I still supposed to remove it?

    Sandeman

    Thanks for all of your help!~
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The registry patch may have removed it ...and no, don't remove the other line in HJT.
    Is everything running OK?
     
  16. sandeman

    sandeman Private E-2

    So far, so good. I have successfully patched everything up to date.. and the computer is working good so far. ;)

    I am now moving on to trying to install ZoneAlarm when I get back from the weekend. I have one program I know that may be a little hard to train ZA to accept, and I am waiting for the Devs of that program to give me some guidance.

    I want to thank you for all of your help on this. You saved me from a potential reinstall of XP. <shudder>

    Sandeman

    Geek till it MHz. Love it! :major
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome ...safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds