Evil Malware not going away

Discussion in 'Malware Help (A Specialist Will Reply)' started by Tim3773, Apr 27, 2007.

  1. Tim3773

    Tim3773 Private E-2

    Ive tried doin it without you guys and i came close, but no cigar. Heres everything you need to know:

    MyWay Search Assistant is in Control Panel and I can't figure out how to remove it.

    Edit snipped CS log

    And anything else you need to know I'll be more than happy to let you know, but I can tell you that I noticed something was wrong once my video clips on WinAmp were skipping and whatnot, and then the last straw that had me come here was my Counter-Strike wasn't working...a gamer needs his games.
     
    Last edited by a moderator: Apr 27, 2007
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Majorgeeks!

    Sadly not everything we need to know, we will need you to follow the below guide and attach all the logs requested.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. Tim3773

    Tim3773 Private E-2

    I'm sorry, i had a friend over when i was doing that and i forgot to go back to look ><.

    One more thing i forgot to tell you was i was NOT able to reboot in safe mode. Whenever I try i get a blue screen and an error message.

    The New Text Document is the Counterspy log. I couldnt think of anything else to call it.

    But I did read through and do everything in those instructions previous to the forums but ill try and go by the letter again.
     

    Attached Files:

  4. Tim3773

    Tim3773 Private E-2

    Heres the next 3, thanks for the help.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not rename HijackThis as requested in step 7 of the READ ME. Because you did not rename it, some of the malware you have may not show in your HJT log and we may not get the fixes correct. You must rename C:\Program Files\HJT\HijackThis.exe to C:\Program Files\HJT\analyse.exe

    Do this now before continuing on to the below steps!



    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Platform, Enterprise Edition 1.4 SDK
    Java 2 Runtime Environment, SE v1.4.2_03

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    If you need the Sun Java Development kit you can get it here: http://java.sun.com/javase/downloads/index.jsp

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also delete the below folder
    C:\Documents and Settings\Tim\Application Data\Viewpoint


    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKCU\..\Run: [bw2qRTj9g] appscax.exe
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O15 - Trusted Zone: *.musicmatch.com
    O15 - Trusted Zone: *.musicmatch.com (HKLM)
    O20 - Winlogon Notify: jkhfe - C:\WINDOWS\system32\jkhfe.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\WINDOWS\system32\jkhfe.dll
    C:\WINDOWS\system32\appscax.exe
    c:\temp\salmau.dat
    c:\program files\SearchRelevant
    C:\Program Files\SearchRelevant\SearchRelevant1.dll
    C:\Documents and Settings\crack\crack.exe
    C:\Documents and Settings\Fraps_install.exe
    C:\Program Files\BitComet\Downloads\Fraps_+_crack.rar
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.


    Now please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. Tim3773

    Tim3773 Private E-2

    I did all that and still got issues, I fixed the hjt stuff but now for whatever reason its not letting me attach files on the forums? idk wat its about but ill try reposting another one after this
     
  7. Tim3773

    Tim3773 Private E-2

    Yeah for whatever reason I cant post attachments? i dont know im computer retarded lately :(
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try again after emptying your browser cache and clicking refresh. If you cannot attach files now then explain exactly what is happening. Make sure you observe the Manage Attachments window closely for errors. They are not always very obvious.
     
  9. Tim3773

    Tim3773 Private E-2

    Attach Files
    Valid file extensions: bmp doc gif jpe jpeg jpg log pdf png psd txt zip

    thats all it says, if you want me to post the log not as an attachment i can im just gonna wait for your approval tho
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you browsing to the files and clicking Upload? What happens?

    If you attached files before, you should be able to attach them now. Make sure you are trying to attach NEW logs and not the same ones previously uploaded.
     
  11. Tim3773

    Tim3773 Private E-2

    Your not understanding me so Ill explain more thoroughly...I can not use smilies, fonts, undo buttons, nor do I even have the option to attach files. Here is exactly what it looks like:

    Additional Options
    Miscellaneous Options
    Automatically parse links in text
    Disable smilies in text
    Attach Files
    Valid file extensions: bmp doc gif jpe jpeg jpg log pdf png psd txt zip
    Thread Subscription
    Notification Type:

    Theres no scroll bar no link nothing underneath attach files except that right there
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This often happens when you need to clear your cache and refresh as previously mentioned. Try using a different browser. Use this: Mozilla FireFox
     
  13. Tim3773

    Tim3773 Private E-2

    I use Firefox...did i delete something when i did the ATF cleaner? I just downloaded Firefox before i started posting on this because i learned my lesson so its literally only a week old on my computer.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I was assuming you were using IE. If your problem is with FireFox then run IE and tell me what happens.

    Only temp files similar to CCleaner but CCleaner did not seem to be working properly or you were not running it properly based on your logs. Thus I suggested ATF Cleaner
     
  15. Tim3773

    Tim3773 Private E-2

    Ok i shouldve tried this a while ago cuz it works haha...my bad.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your HJT log, you did not fix what I asked you to fix in message # 6. Are you sure you selected everything and did you shutdown all browsers, and most important.. did you remember to click Fix Checked? Repeat the HijackThis part of step 6 and then get a new log and attach it.
     
  17. Tim3773

    Tim3773 Private E-2

    I just did it again, i thought i did it before but here goes take 2
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Now you got it! ;) How are things working now?
     
  19. Tim3773

    Tim3773 Private E-2

    still messed up
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not helpful! You must give specifics!
     
  21. Tim3773

    Tim3773 Private E-2

    Nothing that got messes up got fixxed, my movies and games and everything that got infected is still not working.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's not due to malware! You need to take a look at the things you are running at startup and you may need to reinstall some items.

    You don't even have an antivirus or firewall installed yet and they will impact performance too. But they are necessary to protect you.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here are some item that are slowing you down and that are not necessary:

    1) Four Toolbars!!!!
    • AOL Toolbar
    • Google Toolbar
    • Webshots Toolbar
    • Yahoo Toolbar
    2) Unnecessary Startups for your system to work! You can run this when and only when you really need them.
    • O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    • O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    • O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    • O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    • O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    • O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    • O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    • O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
    • O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    • O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
    • O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    • O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    • O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    • O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    • O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
    • O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
    • O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
    • O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    • O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
     
  24. Tim3773

    Tim3773 Private E-2

    I forgot how to stop startup processes...and id rather not guess and blow up my desktop.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First uninstall software that you don't need or don't use! Why do you need all of those toolbars.

    Then for other unrequired startups that I mentioned, you should first look for options within the program to tell them not to load when Windows startup. If they don't have such an option, you can use HijackThis to remove the registry key entry so that it does not startup. Those are show in my list with the O4 at the beginning of the lines.

    You can alternatively use a program like this Startup CPL to control startups. Do not use MSconfig which so many people use. It was not meant for this purpose.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds