following ReadFirst, reports attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by tatsall, Mar 11, 2006.

  1. tatsall

    tatsall Private E-2

    I've been following your "Read This First" directions. All scans were run in normal mode as I could not get the computer to start in safe mode. All other instructions were carefully followed.

    CWShredder found a file called "c:\windows\ALCMTR.exe". Is this a legitimate file or should I allow CWShredder to delete it?

    My Bitdefender log is attached.

    Panda ActiveScan would not load. The error message is attached.

    I recognized WinFixer in the sticky thread and ran the fixer. The log is attached.

    Before I can run HijackThis, I need to know how to disable msconfig and startup files.

    Thanks so much for providing this website and forum. You've already been a big help!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is for your sound card. Leave it alone.

    It is given to you in step 7. Please click the links given in step 7 and read them.
     
  3. tatsall

    tatsall Private E-2

    Thank you! I can't believe I read right over that. I guess I had been working at this too many hours in a row to concentrate well anymore. I apologize sincerely! Here is my HijackThis log. The other logs were attached to my first post.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see Weatherbug in your log! Did you look for it in Add/Remove programs and try to uninstall it?

    I also see possible Look 2 Me infections.

    Something else I noticed is a remnant of SpySweeper. Did you have a version install and uninstall it? Was it the paid or free trial version?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  6. tatsall

    tatsall Private E-2

    Weatherbug was uninstalled through Add/Remove Programs. I don't understand why part of it is still there.

    Look2Me infections - I will use Look2Me VX2 Removal from your Special Removal Procedures Post.

    Spysweeper - I don't remember this program, but I guess I must have. It would have been the trial version and is not listed in the Add/Remove Programs list.

    Neopets - I did download this. It only works in IE and I rarely use IE. I will remove it. After reading your other ReadMe Posts, I've decided to lock down IE anyway. I usually use Netscape, but I like having an alternative browser so I will download one of the others you recommended.

    Spybot - Once I turn my computer on in the morning it is rarely turned off again before I head for bed, so running at start up has not been an inconveniece. It catches something pretty frequently. I will consider changing this after I finish following your HowToProtect procedures.
     
  7. tatsall

    tatsall Private E-2

    L2MeFix logs are attached. report1 is the initial report and log is from after repair.

    Neopets has been removed.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like it did not work properly. Try the below tool, follow the instructions on the download page:

    Look2Me Remover

    Afterwards, attach a new HJT log and tell me how things are working.
     
  9. tatsall

    tatsall Private E-2

     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you install this?
    O4 - Startup: StayOn Pro.lnk = C:\Program Files\StayOn Pro\StayOn Pro.exe

    Did you buy it? There are many cracked (illegal) versions around containing viruses.

    Note the below is a BIG resource hog which can slow your PC down. Do you use it?
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe

    I deleted it from every PC that I have physically worked on myself.

    Okay let's continue fixing your problems manually.
    Start by downloading two tools we will need:

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of meimhluc.dll once and then click the kill button. After you have killed all of the meimhluc.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of meimhluc.dll and kill it.

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {6422e234-ee55-4f8a-b967-2199fa225633} - C:\WINDOWS\system32\wkbfifng.dll (file missing)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exe
    O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
    O20 - Winlogon Notify: meimhluc - C:\WINDOWS\SYSTEM32\meimhluc.dll
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
    O20 - Winlogon Notify: xmlrun - C:\WINDOWS\AppPatch\xmlrun.dll (file missing)

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.
    C:\WINDOWS\system32\wkbfifng.dll
    C:\WINDOWS\SYSTEM32\meimhluc.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot locate the below with Windows Explorer and delete them (these may already be gone! We are double checking to be sure.)
    C:\Program Files\Common Files\tsa <--- the whole folder
    C:\Program Files\AWS <--- the whole folder
    C:\WINDOWS\system32\wkbfifng.dll
    C:\WINDOWS\SYSTEM32\meimhluc.dll
    C:\WINDOWS\AppPatch\xmlrun.dll

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now attach a new HJT log and tell me how the steps went.
    Make sure you tell me how things are working now!
     
  11. tatsall

    tatsall Private E-2

    I removed BigFix.

    StayOnPro was purchased directly from the author's site, but when their tech support couldn't solve a problem I had with it, it was removed. I added this startup item to the list of items fixed by HijackThis when I ran it per your last set of instructions.

    Process Explorer required me to download Microsoft Debugging Tools. I followed the given link to do so and then ran the program. No meimhluc.dll files were found under winlogon or explorer.exe.

    Everything seems to be running great at the moment. My browsers are operating at normal speed. While awaiting your evaluation of my last HJT log, I'll follow your "How to Protect Yourself from malware!" instructions.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good news!

    Just one more item to repeat cleaning up. Fix the below line using HijackThis:

    O20 - Winlogon Notify: meimhluc - meimhluc.dll (file missing)


    Then look at another log (you do not need to attach a log) yourself and make sure it is gone. Just tell me the result.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    Then continue what you started in the How to protect thread.
     
    Last edited: Mar 14, 2006
  13. tatsall

    tatsall Private E-2

    meimhluc.dll has been removed with HJT. No longer in the log!

    I have completed the Disable/Enable of System Restore.

    Thank you. Thank you. Thank you!

    I will continue with the How to Protect thread.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Happy I could help! Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds