Extra help needed...

Discussion in 'Malware Help (A Specialist Will Reply)' started by Chief, Jun 10, 2007.

  1. Chief

    Chief Private E-2

    I've run all the scans from the guide and my computer is still have some slow-down problems and problems while I'm on the internet. I'm not sure what caused the initial problems or when they occurred. But now that I've installed AVG Anti-spyware I have gotten repeated alerts for malware
    Backdoor.Small.os C:\Windows\system32\perfc000.dat
    I would appreciate it you could take a look at the logs and direct me with anything further that I might do.
     

    Attached Files:

  2. Chief

    Chief Private E-2

    Here's the rest of the logs...
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You neglected to have AVGAntispyware fix the problems it found!
    Please run it again and have it fix everything.

    Use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_03
    Viewpoint Media Player

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt


    Please download and install Registrar Lite. Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to each of the following keys (one at a time) and take ownership of them (I explain how to do that further down).

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDSERVICE]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_CMDSERVICE]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\cmdService]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETWORK_MONITOR]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_NETWORK_MONITOR]

    To take ownership of the key do the following:

    * Copy & Paste the registry key from above into the Address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    * Click-on Security in the top Menu
    * Select Take Ownership
    * Repeat these steps for all of the registry keys given above before continue to the next steps below.
    * Now leave RegistrarLite running and continue
    * Now run the fixME.reg REGISTRY PATCH below in this message.
    * Tell me the results. Any error messages?
    * Now in RegistrarLite click View and then Refresh
    * Now navigate one at a time to each of the above keys we took ownership of to make sure they were deleted.
    * If any of the keys still exist, move on down to PART 2 - Setting Permissions for Everyone below!.

    Here is the Registry Patch

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    PART 2 - Setting Permissions for Everyone

    Run the below if some of the registry keys still exist after running the above steps.

    Now I want you to use Registar Lite again to navigate to each of the below keys (one at a time) by pasting them into the Address Bar and hitting return. But this time click the Security menu item and select Edit Permissions so we can change permissions to everyone ( I describe this down below the list of registry keys).

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDSERVICE]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_CMDSERVICE]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\cmdService]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETWORK_MONITOR]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_NETWORK_MONITOR]

    After click Edit Permissions , here is what I expect you to see in the Group or user names area of the form:

    Everyone
    SYSTEM

    Select Everyone by clicking on it. Now at the bottom in the Permissions box click the check box for Full Control. The click Apply and then OK to get back to the main Registrar Lite screen. Nowright click on the registry key and select Delete. The click View and Refresh. Check to see if the registry key just deleted truly deleted. If so, move on to the next to work thru the whole list. If it does not delete, I want you to boot into safe mode and repeat these exact same steps to see if we can do it from safe mode.

    Then reboot your PC!

    Now attach the logs for:
    GetRun
    Shownew
    HJT
    Avenger
     
  4. Chief

    Chief Private E-2

    I removed the programs that you listed and I also ran HijackThis. After I selected fix on HijackThis, this error message came up:
    An unexpected error has occurred at procedure: modBackup_MakeBackup(sItem=O20 - AppInit_DLLs: C:\WINDOWS\system32\perfc000.dat)
    Error #5 - Invalid procedure call or argument

    I have also been having problems trying to download Avenger from your link. Each time I try to open it, it says that this page cannot be displayed. I've tried restarting my computer and that didn't seem to work. The link also seems to be working fine on my computer upstairs. I have yet to do the rest of what you suggested.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    See if you can use windows explorer to find and delete:
    C:\WINDOWS\system32\perfc000.dat

    As to Avenger ...it shouldn't open a page...it should just give you a download box. You can download it on another computer and then copy to cd or thumb drive and install.
     
  6. Chief

    Chief Private E-2

    I used Windows explorer to try and delete C:\WINDOWS\system32\perfc000.dat but right after I tried I got an alert from AVG Anti-Spyware about it. I think I had also try to delete it several days ago but it was not successful. I also did the rest of what you instructed but to be honest I'm not sure the registry keys were deleted. I did not see them come up when I pasted them in the address bar but I didn't really know quite what I was looking for.
     
  7. Chief

    Chief Private E-2

    Here's the last log.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please post new logs for:
    GetRun
    ShowNew
    HJT

    Avenger did what it needed to do ...that was good!

    I need to see if you had success removing the reg. items.
     
  9. Chief

    Chief Private E-2

    Sorry about that I had some trouble uploading the logs last night.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Remove all of your browser toolbars and extensions.

    Find and delete:
    C:\WINDOWS\system32\perfc000.dat

    Then run Registrar Lite.

    Copy and paste the below into the Address box of registrar lit and hit the Enter key.

    HKEY_LOCAL_MACHINE\SYSTEM

    Then click the Security pull down ont the top menu and choose Take Ownership. Click OK in the next window to approve it. Now exit Registrar Lite and continue.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.

    Run the below and attach the requested log:

    Running Spy Sweeper

    Make sure you reboot after running Spy Sweeper.
    Now let's fix the other problems. Note that the O20 lines may already be gone if SpySweeper was able to completely fix them.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O20 - AppInit_DLLs: C:\WINDOWS\system32\perfc000.dat

    Reboot into normal mode and attach the logs for:
    Spy Sweeper
    GetRun
    ShowNew

    Be sure to tell me how things are running.
     
  11. Chief

    Chief Private E-2

    I ran the Spy Sweeper scan but since I don't have a subscription I couldn't remove what it found. When I selected fix in HijackThis I received an error message:

    An unexpected error has occurred at procedure: modBackup_MakeBackup(sItem=O20 - AppInit_DLLs: C:\WINDOWS\system32\perfc000.dat)
    Error #5 - Invalid procedure call or argument

    I have noticed that my computer is running quite a bit better but there are still times on startup and while on the internet where it seems to be running a little slow still.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Where you unable to take ownership of the CMDService?

    Please download DelCmdService, and save it to your Desktop.

    * Unzip the content to your Desktop (a folder named delcmdservice)
    * Double-click on the delcmdservice folder
    * Double-click on delreg.bat to launch the tool
    * When the tool has finished, please reboot your computer

    Attach a new RunKeys and HJT log.
     
  13. Chief

    Chief Private E-2

    I am unsure if I was able to take ownership of CMDService or not. Also I was unable to download DelCmdService service. A message said the site could not be found that the address might be incorrect.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use this link: delcmdservice
     
  15. Chief

    Chief Private E-2

    Heres the two new logs... I have also noticed that when I try to search on google the majority of the results that I now get are junk like ads. If you could help me with that I'd appreciate it as well.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Lets try this again ...run Registrar Lite.

    Copy and paste the below into the Address box of registrar lit and hit the Enter key.

    HKEY_LOCAL_MACHINE\SYSTEM

    Then click the Security pull down on the top menu and choose Take Ownership. Click OK in the next window to approve it. Now exit Registrar Lite and continue.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.

    194.54.90.226 ---> is this your ISP (RIPE network)?
    If not....have HJT fix these items:

    O17 - HKLM\System\CCS\Services\Tcpip\..\{4EF367E7-8B0F-4DAB-AAA3-0BCEF09E3A05}: NameServer = 194.54.90.226
    O17 - HKLM\System\CCS\Services\Tcpip\..\{83756053-71FE-4236-ABE9-9531F93A9F9F}: NameServer = 194.54.90.226
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C48E8CDB-A97B-4881-8C4D-8580737675FC}: NameServer = 194.54.90.226

    After clicking fix, exit HJT

    Attach a new log:
    GetRun
    HJT
     
  17. Chief

    Chief Private E-2

    After I selected yes to merge the fixme.reg file with the registry I got this message:

    Cannot import C:\Documents and Settings\HP_Owner\Desktop\fixme.reg: The specified file is not a registry script. You can only import binary registry files from within the registry editor.

    I did not use HijackThis to remove those items because I found 194.54.90.226 listed as my value for DNS Server under my wireless network connection details. Should I go ahead and remove them anyways or are they needed?
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you: Then click File and then Save As. Change the Save as Type to All Files?

    Has this been the problem in the past with the reg. fixe?



    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt


    Do not remove the DNS addy ...it's your isp .....I just wanted to know if it was or not.

    Attach the avenger log.
     
  19. Chief

    Chief Private E-2

    I had the fixme.reg file save as All Files like requested and it did not work. This is the first time I've had that problem. The other times I've done a reg. fix it has worked fine.
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you removed all your toolbars and plug-ins?
    Have you run CCleaner?
    If you type in Google to the address bar, do you still get the same results?
    Does it happen with other search engines ..eg: alltheweb?
     
  21. Chief

    Chief Private E-2

    I believe I have removed all the toolbars. I have none displayed in Internet Explorer. CCleaner was run at the very beginning when I followed the ReadME. Google seems to be the only search engine where I have really noticed the ads. AllTheWeb seemed to give me proper results along with MSN.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't think you are having any additional malware issues...however, attach a new GetRunKeys log.
     
  23. Chief

    Chief Private E-2

    Things do seem to be running considerably better.
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Frankly, I'm stumped as to the results with Google.....since every thing looks clean.
    Let's do the final cleanup and see if that helps:
    To Reset Web Settings:

    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    Your logs look clean. You may uninstall any programs we had you download (including CounterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    TIP: ;) Run WareOut Removal Make sure to attach the requested log.
     
    Last edited: Jun 18, 2007

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds