did all the steps need hjt log checked

Discussion in 'Malware Help (A Specialist Will Reply)' started by theguardian, Feb 24, 2006.

  1. theguardian

    theguardian Private E-2

    i am getting a program that keeps trying to install and my program spysweeper keeps blocking an attempt to iframetraff.biz. i also get a small pop up window that says if you want to access click yes and then they bring me a lot of popups. thank you
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is your version of Spy Sweeper the paid subscription version?
    Is it up to date with definitions?
    Have you run a full system scan recently? It would be good if you did and could attach a log from the scan?

    Is the below really a screen capture program you installed? I ask because there is also a keylooging trojan out there that uses the capture.exe file name too.

    O4 - HKLM\..\Run: [CaptureBat] C:\Program Files\Quick Screen Capture\Capture.exe

    Do you know what the below is? IS drive E a hard disk?

    O4 - HKLM\..\Run: [Tango] E:\Release\..\Setup.exe

    Like capture there are good and bad things using the name Tango.
     
    Last edited: Feb 24, 2006
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by emptying your Symantec\Norton AntiVirus\Quarantine folder.

    Now let's begin the fixes. Start by downloading two tools we will need:

    - Process Explorer 9.2

    - Pocket KillBox

    Extract them to there own folder somewhere that you will be able to locate them later. You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray. Since I'm going to have you disconnect from the internet, you need to save these directions locally to your hard disk in a file to use for the later reference and to make it easier to copy and paste in file names later on into killbox.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    - Look for the below processes and right click on each one and kill them
    C:\WINDOWS\TEMP\win34.tmp.exe
    C:\WINDOWS\TEMP\win447.tmp.exe
    C:\WINDOWS\TEMP\mdnhopmd.exe
    C:\WINDOWS\TEMP\ilcgopmd.exe

    - Now in also in the top process section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winaqc32.dll once and then click the kill button. After you have killed all of the winaqc32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of winaqc32.dll and kill it.

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - Default URLSearchHook is missing
    O20 - Winlogon Notify: winaqc32 - C:\WINDOWS\SYSTEM32\winaqc32.dll

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    [quote

    REGEDIT4
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
    winaqc32]
    [/quote]
    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.

    C:\Documents and Settings\The Guardian\Local Settings\Temporary Internet Files\Content.IE5\BX4GM9M6\rdgMX2405[1].exe
    C:\Documents and Settings\The Guardian\Local Settings\Temporary Internet Files\Content.IE5\XPQ912CD\rdgMX2405[7].exe
    C:\WINDOWS\Temp\adanipmd.exe
    C:\WINDOWS\Temp\anifiomd.exe
    C:\WINDOWS\Temp\djjaipmd.exe
    C:\WINDOWS\Temp\facojnmd.exe
    C:\WINDOWS\Temp\fadjfpmd.exe
    C:\WINDOWS\Temp\gklhmomd.exe
    C:\WINDOWS\Temp\idlemomd.exe
    C:\WINDOWS\Temp\kpinmpmd.exe
    C:\WINDOWS\Temp\odakbomd.exe
    C:\WINDOWS\Temp\ohdifomd.exe
    C:\WINDOWS\Temp\pofpbpmd.exe
    C:\WINDOWS\TEMP\win34.tmp.exe
    C:\WINDOWS\TEMP\win447.tmp.exe
    C:\WINDOWS\TEMP\mdnhopmd.exe
    C:\WINDOWS\TEMP\ilcgopmd.exe

    C:\WINDOWS\SYSTEM32\winaqc32.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot post a new HJT log and tell me how the steps went.
     
  4. theguardian

    theguardian Private E-2

    ok i did all the stuff u asked me to do and i am now attaching a copy of the spysweeper log and i am also including a log of hjt.
     

    Attached Files:

  5. theguardian

    theguardian Private E-2

    Is the below really a screen capture program you installed? I ask because there is also a keylooging trojan out there that uses the capture.exe file name too.

    O4 - HKLM\..\Run: [CaptureBat] C:\Program Files\Quick Screen Capture\Capture.exe

    Do you know what the below is? IS drive E a hard disk?

    O4 - HKLM\..\Run: [Tango] E:\Release\..\Setup.exe

    Like capture there are good and bad things using the name Tango.


    the quick screen capture i installed but i only have one hard disk. the tango one is not something of mine. the drive e:\ is the cd rom drive.

    thank you
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Just have HJT fix the below line:

    O4 - HKLM\..\Run: [Tango] E:\Release\..\Setup.exe


    Then let me know how things are working now.
     
  7. theguardian

    theguardian Private E-2

    ok i have posted my latest hjt log. i dont seem to be getting any popups or the install proggy or anything like that. from what i can tell looks like everything i gone. but i will let u take a look at the log.

    thank you very much for all your help.
    The Guardian
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! It's strange that the below was not in your previous log. I wonder why it appeared now!

    O20 - Winlogon Notify: winaqc32 - winaqc32.dll (file missing)

    Please have HJT fix this O20 line and attach a new log.
     
  9. theguardian

    theguardian Private E-2

    ok i deleted the file on hjt and posted the log file. i also installed a registered copy of spy emergency and it found a few infections. dialers and a copy of other things but it got rid of them.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just fix the left over line from uninstalling Spy Sweeper:

    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    Personally I would not have chosen to use Spy Emergency. At one time they were on the Rogue/Suspect Anti-Spyware Products & Web Sites list. They are no longer considered a rogue but I personally would not waste my money on it. Spy Sweeper is much better and well worth the money.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds