Followed steps...hijack this log... emergency

Discussion in 'Malware Help (A Specialist Will Reply)' started by Hyru, Aug 17, 2006.

  1. Hyru

    Hyru Private E-2

    My ISP called me up the other day and told me my computer was spamming their server and was requesting random websites:
    rcn.com
    tlc4u.com
    plc4v.com
    gate-way.ney
    alehop.com
    mailaka.net

    my account is suspended till I have this problem fixed. I called them up and requested I be put back online and fixed the problem (not sure if i did). So, here I am to check to see if the problem is fixed or not. I followed the steps 1-7 I believe.... HOWEVER, it seems that the 1st online virus scanner was deleting many of my .exe files (firefox, MSN, World of warcraft.exe, etc). It was saying something along the lines of...

    firefox.exe: win32.xx - file infected
    firefox.exe: win32.xx - attempted to clean - failed
    firefox.exe: win32.xx - file deleted

    now, thats not word for word... but its just to give you an idea. I stopped the scanner before it reached c:\WINNT

    So, a few of my .exe's are deleted... I guess there was avirus that was damaging them?

    anyhow...
    heres the files that I could get along with my hijackthis log. Its an emergency because if the problems not fixed... Im looking at pretty much another suspension from the ISP.

    Thanks in advance for the help!
     

    Attached Files:

  2. matt.chugg

    matt.chugg MajorGeek

    You have, (Amongst other things) a smitfraud infection.

    Please follow the procedure here and post a new HJT log and a new shownew log on your return

    NOTE: You don't appear to have any service packs installed for XP, Your operating system is therfore lots of security patchs leaving your system incredibly unsecure and open to many types of infection or malicious attack.

    NOTE: The installed version of the Java runtime on your system is also out of date. Please uninstal all previous version and instal version Sun Java Runtime Environment 5.0 Update 8
     
    Last edited: Aug 17, 2006
  3. Hyru

    Hyru Private E-2

    Thanks for the help so far, appreciate it.

    Here are the new logs:
     

    Attached Files:

  4. matt.chugg

    matt.chugg MajorGeek

    Please post a shownew log.

    YOur avast AV has been 'broken' by something, please go back to the steps and run the bitdefender online scan and post the log. Active scan wouldn't have tried to delete anything that wasn't infected I still need you to run this scan completely and post the log. If your exes are infected some software may need reinstalling anyway. Things like firefox and msn are easy to reinstal if necesary.
     
    Last edited: Aug 17, 2006
  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You have many nasties, I do see an aboutblank infection so run the below also.

    Please save these instructions to a text file in Wordpad/Notepad or print them out because we will be restarting in Safe Mode and you will have no Internet Connection.
    • Download About:Buster 6.05
    • Unzip AboutBuster.zip and it will install in it's own folder.
    • Double-click on AboutBuster.exe and then click 'OK' then 'Update'
    • Click "Check For Update" and then "Download Update".
    • Click "Exit"
    • Please Do Not Use It Yet.
    Disconnect From The Internet, pull the cable!

    Now, please reboot into Safe Mode!

    • Please Double-click on AboutBuster.exe.
    • Click "OK" then "Start" and then "OK" to allow AboutBuster to scan for all bad files.
    • Click "Yes" when About Buster asks if you will allow it to shutdown explorer.exe.
    • Allow AboutBuster to scan for all malicious files.
    • Repeat the scan if it asks to do another.
    • After the scan, click "Save Log". Post the log in your next post as it is necessary to make sure all has been cleaned
    • Then Click "Exit"

    After you complete the above, reboot back to normal mode and post the log from AB, once you have attached the log procede with the below step to make a dent in your baddies. You can now reconnect to the internet to run the scan below.

    Click on the link below and run the online scan...

    Kaspersky Anti-Virus Online Scan

    • Click on "Kaspersky Online Scanner"
    • Click Accept to procede...
    • If you get a popup askiing if you want to Install Kaspersky's ActiveX Control, click Yes to install it.
    • If you get a Security Warning popup asking if you want to install and run kavwebscan_unicode.cab, click Yes to install it.
    • After all updates are downloaded, click NEXT to continue...( Note it will take awhile to download these updates based on your connection speed).
    • Click Scan Settings and select extended and make sure both boxes are checked at the bottom, Click OK to continue.
    • Now click on My Computer and let it run!
    • This scan may take a while but it is very thorough. After the scan is complete save the log as a txt file and attach it to your next post with a fresh HJT log, ShowNew, AboutBuster log and GetRunKey Log.
     
  6. Hyru

    Hyru Private E-2

    Thanks again for the help... Here are the new files after running the scan:

    Runkeys.txt seems to be completely empty...

    Also, I keep finding signs of: win32.sality.q (not sure what it is?)
     

    Attached Files:

    Last edited: Aug 17, 2006
  7. Hyru

    Hyru Private E-2

    new HJT log
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    GetRunKey and ShowNew are both empty because you are not following the directions in the download links! YOU MUST EXTRACT all the files from the ZIP file into their own folder. You cannot run the batch files directly from the ZIP file which is what you are doing. FOllow the directions and then attach the two new logs from both GetRunKey and ShowNew

    Also you need to move the HijackThis executable to the proper folder. You have it here:

    C:\Program Files\analyse.exe

    You must not do this. You must install it here:

    C:\Program Files\HJT\analyse.exe
     
  9. Hyru

    Hyru Private E-2

    sorry, could swear I had done that.... anyhow... here we are:

    :)
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still are running ShowNew.bat from the ZIP file!
     
  11. Hyru

    Hyru Private E-2

    hmm, Im 100% sure I made a folder for it and all... im looking at the folder "Show new" in the c:\

    I am, however, getting an error when trying to run it....

    c:\WINNT\System32\cmd.exe
    c:\WINNT\system32\AUTOEXEC.NT. The system file is not suitable for running MS-DOS and Microsoft Windows applications. Choose "close" to terminate the appliacation

    options: Close and ignore

    Im sure im not running it from the zip
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Read the download link information again. It clearly explains this error!


    And also double check to make sure you have extracted ALL of the files from the ZIP into the same folder as ShowNew.bat
     
  13. Hyru

    Hyru Private E-2

    still getting the same error and I made sure I unziped it to the same folder (the folder now has 6 files in it)
     
  14. matt.chugg

    matt.chugg MajorGeek

    READ THIS: Using ShowNew

    It explains the error you are getting and provides links to the fix you will need.

    Select the version correct for your OS (XP pro, XP home, or WIndows 2000), Download it and run it.

    Delete the entire folder with 6 files in it and EXTRACT shownew to a new folder. and extract runkeys to a new seperate folder.

    Run the ShowNew.bat and RunKeys.bat in these folder and post the logs.
     
  15. Hyru

    Hyru Private E-2

    Im pretty muchd oing exactly what it says to do.

    I deleted the old folder.

    I created a new folder named ShowNew and placed it on c:\

    I unzipped shownew.zip into this folder. I also downloaded the fix for WinXPHome edition and extracted those files into the same c:\Shownew folder.
    When I run ShowNew.bat Im still getting the same error.

    so, in c:\ShowNew folder we have these files:
    AUTOEXEC.NT, command.com, CONFIG.NT, grep.exe, locate.com and ShowNew.bat

    am I supposed to run any of them prior to running ShowNew.bat?
     
  16. matt.chugg

    matt.chugg MajorGeek

    When you downloaded the fix file it should have said extract to c:\windows\system32

    move the following files from c:\shownew to c:\windows\system32

    If you don't feel confident moving the files then just rerun the fix you downloaded and let it extract to the location it chooses.

    then run shownew.bat
     
  17. Hyru

    Hyru Private E-2

    made no difference at all

     
  18. Hyru

    Hyru Private E-2

    Ive tried having the files only in system32, that didnt work. I tried having them in the same folder as shownew.bat, that didnt work, i tried having them in both system32 and shownet.bat's folder, still, same error
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not have C:\windows\system32

    You need to put the files from XPFix into c:\WINNT\system32


    Where exactly are you downloading ShowNew.zip to?
    Where exactly are you extracting the files from ShowNew.zip to?
    Are you extracting ALL of the files?

    Download the ShowNewX.zip file that is attached to this message and extract it to the same folder where you have already extracted the original ShowNew.ZIP file. Then run the ShowNewX.bat file. When it finishes running, look for this file C:\tmpfiles.txt and upload it here as an attachment!
     

    Attached Files:

    Last edited: Aug 18, 2006
  20. Hyru

    Hyru Private E-2

    see, now were getting somewhere... for some reason by default it was set to windows and not WINNT...
    here we are...
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now that we have that working! Go back to the READ & RUN ME step 3 and follow those directions. You have THREE antivirus programs installed (Avast, NOD, & Symantec). Uninstall all but one and then attach a new HJT log.

    Then you really need to run the Bitdefender and Panda online scans as requested in step 6 of the READ ME. I see in your first message you said you stopped it because it was deleting "your EXE files". If it was deleting them, then they were probably infected. Take a look at the Kaspersky log. Your system is very infected. This is probably due to your use of programs like Kazaa, Limewire, WinMX....etc) to download. Many people who come here with malware problems got them via P2P downloading. So run the two online scans and then attach the logs! You need to get the infections removed from your PC and many files if not all on yout PC could be infected already and it could be spreading.\

    Many of your problems are also the result of running and non-updated Windows XP system. Yo u are way out of date with your updates and this is a major security risk.


    You also need to uninstall the below programs as was requested in step 0 of the READ ME.
    AdwareFilter
    Kazaa 2.7.1
    Kazaa Lite Resurrection 0.0.7.6 F
    Messenger Plus!
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player
    WinMX <--- not in the READ ME but as far as I know WinMX has been discontinued!

    Do you know what the below are that appear in your Uninstall Programs list
    AutoUpdate
    Launcher

    Consider uninstalling the below. Most versions of Limewire come bundled with malware. Programs like this can also be the cause of your ISP shutting you down. Allowing your PC to act like a server can get your ISP's attention real fast and in many case they may shut you down or severely restricted your speed and download & upload capacity.
    LimeWire 4.9.30
     
    Last edited: Aug 18, 2006
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After completing what I gave you in message #21 continue with this message!

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\DOCUME~1\Owner\LOCALS~1\Temp\winolbiq.exe
    C:\DOCUME~1\Owner\LOCALS~1\Temp\winckyji.exe
    C:\DOCUME~1\Owner\LOCALS~1\Temp\winvtjn.exe
    C:\DOCUME~1\Owner\LOCALS~1\Temp\winqynesb.exe
    C:\DOCUME~1\Owner\LOCALS~1\Temp\winrakffv.exe
    C:\DOCUME~1\Owner\LOCALS~1\Temp\winibkodd.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    R3 - URLSearchHook: (no name) - _{00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
    R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
    F1 - win.ini: run=C:\WINNT\..\PROGRA~1\COMMON~1\MICROS~1\MSInfo\msinfo.exe
    F3 - REG:win.ini: run=C:\WINNT\inet20010\winlogon.exe
    O2 - BHO: (no name) - {02C09E0E-961B-120F-B91E-CBE06196283B} - C:\WINNT\apprj32.dll (file missing)
    O4 - HKLM\..\Run: [ipvd.exe] C:\WINNT\system32\ipvd.exe
    O4 - HKLM\..\Run: [ipjt.exe] C:\WINNT\system32\ipjt.exe
    O4 - HKLM\..\Run: [unypeh] C:\WINNT\unypeh.exe
    O4 - HKLM\..\Run: [ujemyrqlymyr] C:\WINNT\System32\zbuxbqi.exe
    O4 - HKLM\..\Run: [wxgnml] C:\WINNT\wxgnml.exe
    O4 - HKLM\..\Run: [Imgmjhl] C:\Program Files\Ieyqcts\Uspv.exe
    O4 - HKLM\..\Run: [vxsmaaaa] C:\WINNT\System32\vxsmaaaa.exe
    O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [xp_system] C:\WINNT\inet20010\winlogon.exe
    O4 - HKCU\..\Run: [vxsmaaaa] C:\WINNT\System32\vxsmaaaa.exe
    O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
    O15 - Trusted Zone: *.05p.com (HKLM)
    O15 - Trusted Zone: *.scoobidoo.com (HKLM)
    O15 - Trusted IP range: 206.161.125.149
    O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
    O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
    O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540013} (CInstall Class) - http://adserver.sharewareonline.com/adserver/Install.cab
    O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB
    O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
    O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} (Progetto1.int_ver34) - http://advnt01.com/dialer/int_ver34.CAB
    O21 - SSODL: IEFilter - {7BD8B520-83CA-4D84-B24F-252824517E1C} - C:\WINNT\system32\IEFilter.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (Many of these may not be found since your log may have change since posting):
    C:\WINNT\inet20010 <--- the whole folder
    C:\Program Files\Ieyqcts <--- the whole folder
    C:\Program Files\Messenger Plus! 2 <--- the whole folder
    C:\WINNT\apprj32.dll
    C:\WINNT\DHU.exe
    C:\WINNT\newfrn.exe
    C:\WINNT\unypeh.exe
    C:\WINNT\wxgnml.exe
    C:\WINNT\system32\ipvd.exe
    C:\WINNT\system32\ipjt.exe
    C:\WINNT\system32\vcmgcd32.dll
    C:\WINNT\system32\wndregmon32.DLL
    C:\WINNT\System32\zbuxbqi.exe
    C:\WINNT\System32\vxsmaaaa.exe
    C:\WINNT\system32\IEFilter.dll
    Now delete all files in the below folder (Windows will block deletion of ones from the current date):
    C:\Documents and Settings\Owner\Local Settings\Temp

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  23. Hyru

    Hyru Private E-2

    ran the scans.....
    it deleted my rundll32.exe file and I cant open up add/remove programs now
     
  24. Hyru

    Hyru Private E-2

    nevermind, fixed that problem and got it working.

    Completed all steps above... heres the online scanner log as well as the new HJT log. Some files couldnt be found when looking to manually delete them... guess they were deleted from the scanner?

    Computer definitely seems to be running better :)
     

    Attached Files:

  25. Hyru

    Hyru Private E-2

    The BitDefender file was too lareg to post, so I split it into 2 different files. Just needs to be cut and pasted to continue
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My directions said to uninstall the excess antivirus programs first!! This was supposed to have been done originally while running the READ ME and then in message # 21 it was also the first thing I said to do. You seem to have only uninstalled Avast. I still see Symantec and NOD. You must decide which of these you wish to keep and uninstall the other.

    Your HJT log is clean! If you are not having any other problems, you need to get started on the below ASAP! Your OS is severely out of date and fixing that is the first step in the below.


    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
    Last edited: Aug 19, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds