Follwed directions in "Read & Run Me First" need logs reviewed please.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Roger Beta, Apr 5, 2006.

  1. Roger Beta

    Roger Beta Private E-2

    I'm so pleased with this site. Its really wonderful that you guys can devote your time and knowledge to help folks like myself remove the crud from our machines. I performed the steps outlined in the "Read and Run Me First" to the best of my ability. I read it many times to make my best effort at providing you with the information you need in the format you want it. I hope I have followed your instructions correctly and I apologize in advance if I made an error. I look forward to taking the next steps to remedy what remains of my laptops' infection. I had to run the online scans in normal boot because my only connection to the internet is wireless. My RJ45 connection has a tab broken off. Because the malware continues to reconstitute itself in normal boot even after having run the cleaning steps I have not been able to complete Bitdefender scan and I'm not sure if I should try the Panda ActiveScan since you say to run Bitdefender first. Ok I tried Bitdefender once more before posting this. I "fixed" a couple things in HT scan before running bitdefender and I actually completed the scan but when I clicked "view the report" it never displayed, as if the link was bad. Hope I have not screwed things up worse than they already are.

    P.S. I read the "Protect yourself from Malware" post and have instituted the recomendations on my desktop to prevent infection. My laptop is the machine that I'm needing help with repairing. I mention the desktop because I have a question about my choice of AV and firewall. I chose the AVast Home Edition anti-virus and ZoneAlarm firewall. After install AVast informed me of a conflict with ZoneAlarm having something to do with privacy features of ZoneAlarm. Also, ZoneAlarm does not recognize AVast as my anti-virus program. Is there a better combination of AV and Firewall that I should use instead?
    Thanks, Chas.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    It would be a good idea for you to do the PandaActiveScan procedure but do it after doing the below.

    Please download Look2Me-Destroyer.exe to your desktop.
    • Close all windows before continuing.
    • Double-click Look2Me-Destroyer.exe to run it.
    • Put a check next to Run this program as a task.
    • You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
    • When Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
    • Once it's done scanning, click the Remove L2M button.
    • You will receive a Done Scanning message, click OK.
    • When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK.
    • Your computer will then shutdown.
    • Turn your computer back on.
    • Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log.
    If Look2Me-Destroyer does not reopen automatically, reboot and try again.

    If you receive a message from your firewall about this program accessing the internet please allow it.

    If you receive a runtime error '339' please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32 Directory.
    http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX


    Now after attaching the destroyer and new HJT logs, run Panda and attach the log when it finishes.
     
  3. Roger Beta

    Roger Beta Private E-2

    I have run the L2M Destroyer as instructed. I then ran HJT and have saved both log files. I fired up IE to run Panda scan and IE has an error and must close. I've rebooted a couple times and get the same error each time I try to run IE. I'm currently running the Malware removal steps again and I hope to restart and be able to run IE but I wanted to go ahead and post the two logs I have in case I am unable to restore IE to functional status. I hope you can make recomendations based on these two logs that can at least get me to a point of being able to run any additional scans that will help in destroying this infection. Thank you for your help. Chas.
     

    Attached Files:

  4. Roger Beta

    Roger Beta Private E-2

    Sucess! After running the Malware removal process yet again I was able to run IE and succesfully scan with BD and Panda both. Here are the results.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That Bitdefender log is not useful. It must be obtained exactly as indicate in step 6 for it to be helpful.

    Let's get an installed programs list from HijackThis too!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
    Did you follow the steps exactly as written in the READ & RUN ME to fix the Spybot bugs???? Make sure you did!

    Also give the below a run!

    http://www.purityscan.com/uninstall.html

    Now run the below and attach the Ewido log:

    Running Ewido Anti-Malware

    Then attach a new HJT log. You still have a load of problems. I just need to get more info before we can get them all fixed.
     
    Last edited: Apr 9, 2006
  6. Roger Beta

    Roger Beta Private E-2

    I saved the BD report a couple different ways. If this report is the one that benefits our cause, then the instructions in step 6 aren't correct. When Bitdefender completes the scan you must click on "Click here to export report" rather than "Click here to view the report". As far as Spybot goes I ran the "Immunization" and I ran the "Check for problems" and "Fix Selected Problems". All products were deselsected and I used the only thing in S&D I could find called SDHelper. I found it under "Tools", then "Resident" then I checked the box marked Resident "SDHelper". The instructions in Step4 did not mention how to go about using SDHelper just that I should, so hopefully I did use it correctly. I'll be back shortly with the other info. you requested in the last post. Thanks, Chas.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks fine to me! I quote from the READ ME:

     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is installed and enabled by default as long as no options are changed while installing. Although I have seen cases where it seemed like something (like another malware blocking tool or maybe having IE running) causes it not to be enabled.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note:
    That is still the wrong way to get the Bitdefender log. It is supposed to be an HTML file.

    But this one is at least a log not a summary. It is just a lot more time consuming to read since it is not formatted properly like the HTML file would be. It also requires more steps on your part to edit it this way. It the steps are followed you get an HTML file with a .txt file extenstion to be uploaded.
     
  10. Roger Beta

    Roger Beta Private E-2

    Your right about the Read Me. It has been updated. I have a printed copy of that entire forum dated 3-30-06 and it says:
     
  11. Roger Beta

    Roger Beta Private E-2

    I have the "Click here to export report" file saved but I did not change the "save as type" to .txt when I saved it. Do you want that? Should I run the scan again and save it as type .txt and the upload that?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Always.....I repeat Always check the online copy. Just like malware changes daily and tools have to change daily.......so does the READ ME. ;)
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Rename it to a .txt extension. HTML files cannot be uploaded as they are a security risk! Then attach the renamed file.

    Please complete what I gave you in message # 5.
     
  14. Roger Beta

    Roger Beta Private E-2

    Man I'm starting to feel like I'm high maintenance. The BDscan I uploaded previously is the "Click here to export..." version of the saved file but I did not change "Save as type" setting at the time of saving it. So I did change it just before uploading it to here. I wonder if not changing it at the time of save had an effect on the format of the report. I'll gladly run it again if it makes it easier on you. I tried running the PurityScan but it had an error "Ad log did not load" or something like that. I tried 2-3 times to no avail. Do I have porn hidden on my machine? I am booted in safe mode and ewido is running complete scan now. I apologize for not referring to the online Read me. I've just been stewing over this printed version the past few days and running it many times on end, and it did not occur to me that I should check for changes. My apologies. One final note I started ewido earlier and realized at about 49% complete that I had not run CCleaner, I stopped and canceled the scan without saving then ran the cleaner then started ewido again. I have a feeling I may have made a tragic error in not saving what I had complete. Figure I should let you know in case now I should do anything different. Thank you for your patience.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't worry about the Bitdefender log now. Also skip the PurityScan stuff. They probably realized everyone was using it to remove their crap and broke it on purpose. Just complete the stuff from message # 5 and attach the Ewido log and a new HJT log. Yes it was a bad idea to stop Ewido and not saving the log, because now I will not know what has already been fixed. Thus any instructions I give you later to delete various things may result in them not being found.
     
    Last edited: Apr 11, 2006
  16. Roger Beta

    Roger Beta Private E-2

    Here are the Ewido and HJT reports.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to install the current version of Sun Java from http://java.com/en/
    and then use Add/Remove programs to uninstall the below outdated version:
    J2SE Runtime Environment 5.0 Update 4

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\errorhandler.exe
    C:\Documents and Settings\Roger\My Documents\?racle\attrib.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R3 - Default URLSearchHook is missing
    O3 - Toolbar: Search - {7264DB02-89A8-6AA7-36BA-0695F96D0ABB} - C:\WINDOWS\wusiyxql.dll (file missing)
    O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
    O4 - HKLM\..\Run: [keyboard] C:\windows\keyboard9.exe
    O4 - HKLM\..\Run: [mousepad] C:\windows\mousepad9.exe
    O4 - HKLM\..\Run: [newname] C:\windows\newname9.exe
    O4 - HKLM\..\Run: [ms060097-52449] C:\WINDOWS\ms060097-52449.exe
    O4 - HKLM\..\Run: [errorhandler] C:\WINDOWS\errorhandler.exe
    O4 - HKLM\..\Run: [win320897-5244900] C:\WINDOWS\win320897-5244900.exe
    O4 - HKLM\..\Run: [ms0590097-5244] C:\WINDOWS\ms0590097-5244.exe
    O4 - HKLM\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.Exe -boot
    O4 - HKLM\..\Run: [wxlteglA] C:\WINDOWS\wxlteglA.exe
    O4 - HKLM\..\Run: [sys10-524490097] C:\WINDOWS\sys10-524490097.exe
    O4 - HKLM\..\Run: [sys01524490097-] C:\WINDOWS\sys01524490097-.exe
    O4 - HKLM\..\Run: [ms04490097-524] C:\WINDOWS\ms04490097-524.exe
    O4 - HKLM\..\Run: [w00251dc.dll] RUNDLL32.EXE w00251dc.dll,I2 00003ac8000251dc
    O4 - HKLM\..\Run: [win32097-52449009] C:\WINDOWS\win32097-52449009.exe
    O4 - HKLM\..\Run: [ms034490097-52] C:\WINDOWS\ms034490097-52.exe
    O4 - HKCU\..\Run: [Pcuh] "C:\WINDOWS\system32\CROSOF~1.NET\spoolsv.exe" -vt yazr
    O4 - HKCU\..\Run: [Canoucb] C:\Documents and Settings\Roger\My Documents\?racle\attrib.exe
    O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {9AC54695-69A4-46F1-BE10-10C74F9520D5} - http://cabs.elitemediagroup.net/cabs/mediaview.cab
    O20 - Winlogon Notify: NetCache - C:\WINDOWS\system32\l6l6lg3s16.dll (file missing)
    O20 - Winlogon Notify: satmmc - satmmc.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\APPLICATION DATA\NetMon <--- the whole folder
    C:\Program Files\outlook <--- the whole folder
    C:\Program Files\SurfSideKick 3 <--- the whole folder
    C:\Program Files\AdwareAlert <--- the whole folder
    C:\Documents and Settings\Roger\My Documents\?racle <--- the whole folder
    C:\WINDOWS\system32\CROSOF~1.NET <--- the whole folder
    C:\Documents and Settings\Roger\rar.exe
    C:\Documents and Settings\Roger\Local Settings\Temporary Internet Files\Ssk.log
    C:\iexplore.exe
    C:\Setup.exe
    C:\WINDOWS\system32\w00251dc.dll
    C:\WINDOWS\uniq
    C:\WINDOWS\elos.exe
    C:\WINDOWS\errorhandler.exe
    C:\WINDOWS\Um9nZXI\oA6BtrK.vbs
    C:\WINDOWS\keyboard61.dat
    C:\windows\newname9.exe <--- delete any files using the starting with the text newname and ending in .exe (like newname1.exe, newname2.exe...etc)
    C:\windows\mousepad9.EXE <--- delete any files using the starting with the text mousepad and ending in .exe (like mousepad1.exe, mousepad2.exe...etc)
    C:\windows\KEYBOARD9.EXE <--- delete any files using the starting with the text KEYBOARD and ending in .exe (like KEYBOARD1.exe, KEYBOARD2.exe...etc)
    C:\windows\GIMMYSMILEYS9.EXE <--- delete any files using the starting with the text GIMMYSMILEYS and ending in .exe (like GIMMYSMILEYS1.exe, GIMMYSMILEYS2.exe...etc)
    Also look in c:\ for any of the newnameX, mousepadX, keyboardX, GIMMYSMILEYSX files and delete them too
    C:\WINDOWS\ms034490097-52.exe
    C:\WINDOWS\ms04490097-524.exe
    C:\WINDOWS\ms0590097-5244.exe
    C:\WINDOWS\ms060097-52449.exe
    C:\WINDOWS\sys10-524490097.exe
    C:\WINDOWS\sys01524490097-.exe
    C:\WINDOWS\win32097-52449009.exe
    C:\WINDOWS\win320897-5244900.exe
    C:\WINDOWS\wxlteglA.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  18. Roger Beta

    Roger Beta Private E-2

    I killed the processes and fixed all lines mentioned in the HJT scan. I then booted into safe mode to delete items with Windows Explorer. Items listed in lines 1-6,8,11,18,20,22-27 and 29 were not present. In additon to the items you list I also deleted: setupapi.old, is-PFJNU.exe, yazzlebundle-1119.exe, and pf78ba.exe. I saw additional items I thought to be suspicious but I did not want to be overzealous in my deleting of things you did not tell me too. Something that is happening I should mention is that all of my desktop icons in normal boot remain highlighted, and when in safe mode I have no start bar nor get any response when I hit the windows key on the keyboard. Its not critical, I just thought it might be info. you could make use of. I followed the rest of your instructions and the machine seems to do pretty well. It is actually behaving quite normally except for the above mentioned quirks. I do not get jacked when browsing and as of yet no pop ups. I have about 35 processes running, cpu usage while browsing internet (3 windows) fluctuates from 0%-7% with an occasional spike up to around 20%. I still think there is stuff on here but you will know better than I. Thanks so much for the help you have already given me.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your HJT log is now clean! I'm not sure what is up with the Desktop icons all being selected. You may want to ask about that one in the Software Forum.

    When you boot in safe mode and there is not Start button, are there any Desktop icons?

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  20. Roger Beta

    Roger Beta Private E-2

    Yes there are desktop icons in safe mode. They are not selected, but there is no start bar. Of the suggested programs in the Protect Yourself from Malware which combination of Firewall and AV do you feel are the most effective together? If I were to run a repair/upgrade installation of XP would that reset my restore points?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My personal preference for a firewall is ZoneAlarm. Any of the three antivirus applications will work fine with it. Give AVG a try, I think you will like it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds