Did all the read me stuff, Please check

Discussion in 'Malware Help (A Specialist Will Reply)' started by andrenal, Jan 25, 2006.

  1. andrenal

    andrenal Private E-2

    Will you please check these file results to see if I should proceed with something else. I did the read me stuff.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. andrenal

    andrenal Private E-2

    NO it is computer #2 for me. Different thread required. Thanks though really waiting on info for other thread. Guess you are real busy with this nasty Mal-Ware stuff.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normally we are a lot busy than this. Things are slow lately. Search engines must have resequenced pages again.

    Do you see either of the below in Add/Remove programs? If so, uninstall while I look at the other info.
    MediaGateway
    Zango

    Do you have the real log from Bitdefender that shows where the problems were found. The log posted is of no use.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to follow step 7 of the READ ME to get HJT correctly installed. You have it here:
    C:\Documents and Settings\Julie Wickhorst\Desktop\HijackThis.exe

    Also that step indicated HJT logs must be from normal boot mode. Yours was from safe mode. Please attach a log from normal boot mode.

    Do you use Viewpoint Manager? If not, uninstall it as indicated in step 0 of the READ ME.
     
  6. andrenal

    andrenal Private E-2

    Try these

    Hope these are better, sorry bout that.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Try these

    HJT is better but Bitdefender is still not useful. Don't worry about it now but if you follow the directions for making a log in step 6, it would be okay and include what and where it is finding the problems. What about the stuff in my other messages (the uninstalls)?


    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\n?svc32.exe
    C:\Program Files\rops\huos.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: (no name) - {43C036EF-8F5E-FDD1-0195-F44A30FBA898} - C:\WINDOWS\System32\nbhmhx.dll
    O2 - BHO: (no name) - {43C036EF-8F5E-FDD1-0195-F44A30FBA898} - C:\WINDOWS\System32\nbhmhx.dll
    O2 - BHO: (no name) - {5226780F-9BB0-B76F-E81E-B9EE8981BDC7} - C:\WINDOWS\System32\lweazn.dll (file missing)
    O2 - BHO: (no name) - {8CFA2EC7-C07B-E3A6-7751-E85B525C609F} - C:\WINDOWS\System32\kklfmzmn.dll (file missing)
    O2 - BHO: (no name) - {D82299F9-7715-5999-1746-5C50D1243ECA} - C:\WINDOWS\System32\tju.dll (file missing)
    O4 - HKLM\..\Run: [System Support] system32.exe
    O4 - HKLM\..\Run: [Services] C:\Documents and Settings\Julie Wickhorst\socks.exe
    O4 - HKLM\..\Run: [Outlook Mail Services] express.exe
    O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
    O4 - HKLM\..\RunServices: [Outlook Mail Services] express.exe
    O4 - HKCU\..\Run: [Ecldpx] C:\WINDOWS\System32\n?svc32.exe
    O4 - HKCU\..\Run: [Thna] "C:\Program Files\rops\huos.exe" -vt ndrv
    O15 - Trusted Zone: *.musicmatch.com
    O15 - Trusted Zone: *.musicmatch.com (HKLM)
    O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540013} - http://adserver.sharewareonline.com/adserver/Install.cab
    O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} - http://install.wildtangent.com/ActiveLauncher/ActiveLauncher.cab
    O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\rops <--- the whole folder
    C:\Documents and Settings\Julie Wickhorst\socks.exe
    C:\WINDOWS\System32\nbhmhx.dll
    C:\WINDOWS\System32\nbhmhx.dll
    C:\WINDOWS\System32\lweazn.dll
    C:\WINDOWS\System32\kklfmzmn.dll
    C:\WINDOWS\System32\tju.dll
    C:\WINDOWS\System32\system32.exe
    C:\WINDOWS\System32\express.exe
    C:\WINDOWS\System32\D0CE0C16B1
    C:\WINDOWS\System32\n?svc32.exe <--- This is not nvsvc32.exe. The question mark could show as any character. Sort the folder in alphabetical order. The one you want will not be in alphabetical order. If not sure, don't do anything. Just tell me what you see (include the size of each file.)

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. andrenal

    andrenal Private E-2

    Okay, did not find any of the files you said to delete in Windows Explorer, except rops folder.

    On reboot from safe mode there is a message cannot find file D0CE0C16B1.
     

    Attached Files:

  9. andrenal

    andrenal Private E-2

    Oh and a long time ago I removed Zango but don't remember the Media one.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because you did not fix some of the lines I requested that you fix in my previous message. Namely these two:


    O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
    O4 - HKLM\..\RunServices: [Outlook Mail Services] express.exe


    You still have not uninstalled the below. Do you use it? If so, you would be the first.
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

    How are things running?
     
  11. andrenal

    andrenal Private E-2

    Better. I'm sure I disabled the outlook one but.....I'll go back over the steps.

    THanks again
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just fix the two lines because they are still present. Then uninstall Viewpoint Manager.

    The get a new HJT log and attach it so we can make sure everything is fixed.
     
  13. andrenal

    andrenal Private E-2

    Consider it finished

    Returned the computer yesturday. Thank you so much for all your help.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Consider it finished

    You're welcome! But you should have completed the steps below if all problems have been fixed:

    Go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  15. andrenal

    andrenal Private E-2

    System Restore

    Oh yes of course I did the System Restore! So how do you get to recognize things in Hijackthis? Just lots of years of dealing with malware or is there a resource of known lines to delete?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: System Restore

    Read the other thread you posted the same question in.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds