Harry's Malware-01

Discussion in 'Malware Help (A Specialist Will Reply)' started by HTEUFEL, Feb 11, 2007.

  1. HTEUFEL

    HTEUFEL Private E-2

    Followed Malware Removal Steps

    Ran Panda - Was Unable To Get Report - Orig Window Closed



    Attachments This Post:

    1. Counterspy.txt
    2. Bitdefender (bdscan.txt)
    3. Avg-antispyware.txt

    NEXT POST : HARRY'S MALWARE-02 WILL
    CONTAIN ATTACHMENTS: GETRUNKEY, SWOWNEW, AND HIJACKTHIS
     

    Attached Files:

  2. HTEUFEL

    HTEUFEL Private E-2

    Harry's Maware-02 (continuation)

    Harry's Malware-02


    Continuation From Harry's Malware-01

    Attachments:

    1. Runkeys.txt
    2. Newfiles.txt
    3. Hijackthis.log

    Will Appreciate Any Help Or Critique Tha I Can Get



    Thabks In Advance



    Harry
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Harry's Maware-02 (continuation)

    Welcome to Majorgeeks!

    Please remember to stay in one thread for your problem!!!! I merged your two threads together.

    You did not install Spybot Search & Destroy from the link in the READ & RUN ME. As a result you are using Spybot - Search & Destroy 1.3 which has not been used in over two years. Please uninstall this, reboot (don't skip the reboot), and install the version in the READ ME following all directions given for it including updating and running a new scan. Then continue with the below!

    Are you using any kind of Startup manager program? I see many items that had been disable from loading at startup. They appear in an MSconfig registry key but MSconfig is not controlling them. At least not anymore. Most of them are malware. Let's fix these and other bad registry keys right now!!!!


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Most if not all of the CMDSERVICE and NETWORK MONITOR items may come back. They normally require special procedures which we will do later if necessary.


    Run this Virtumonde aka Trojan Vundo Removal and attach the requested log when you come back.
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the below new logs and tell me how the above steps went.

    1. VundoFix
    2. ComboFix
    3. GetRunKey
    4. ShowNew
    5. HJT
     
    Last edited: Feb 12, 2007
  4. HTEUFEL

    HTEUFEL Private E-2

    Re: Harry's Malware

    POP UP BLOCKER PREVENTED ME FROM SEEING MANAGE ATTACHMENTS
    RUNNING IN IETAB VIA FIREFOX

    = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

    1. UNINSTALLED SPYBOT SEARCH & DESTROY and rebooted
    A). downloaded SPYBOT ( SPYBOTSD14.EXE)
    B) INSTALLED SPYBOT
    C) UPDATED SPYBOT
    D) RAN NEW SCAN IN SAFE MODE
    E) SAVED SCAN RESULTS AS SPYBOTSD.REPORT.TXT

    2. START UP MANAGER QUESTION

    I’M NOT SURE WHICH OF THE FOLLOWING MAY QUALIFY AS A START UP MANAGER:

    I’VE USED TUT – THE ULTIMATE UTILITY,REGISTRY CLEAN EXPERT,
    VCLEANER,CWSHEDDER, ASWCLNR,SYSCLEAN,CCLEANER
    TOOLBARCOP, BHODEMON 2,AVG-ANTI-ROOTKIT-BETA NORTON INTERNET SECURITY (SINCE DELETED)


    3. SAVED FIXME.REG TO DESKTOP
    A) DOUBLE CLICKED FIXME.REG TO MERGE IN REGISTRY
    … SUCCESSFUL

    4. DOWNLOADED COMBOFIX.EXE
    REALIZED AFTERWARDS THAT I SHOULD HAVE RUN VUNDOFIX FIRST
    DID I JEAPORDIZE ANYTHING?
    A) DOUBLE-CLICKED COMBOFIX
    Will upload c:\combofix.txt

    5. Downloaded VUNDOFIX.EXE … to desktop (Virtumonde aka Trojan Vundo Removal)
    A) EXECUTED VUNDOFIX rebooted log file is : VUNDOFIX.TXT


    PLANNED ATTACHMENTS:
    1. SPYBOTSD.REPORT.TXT
    2. VUNDOFIX.TXT
    3. ComboFix
    4. RUNKEYS.TXT
    5. SHOWNEW.TXT
    6. HIJACKTHIS.LOG

    FUTURE PLANS: CMDSERVICE AND NETWORK MONITOR
    = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

    NEXT MESSAGE WILL INCLUDE RUNKEYS, SHOWNEW AND HJT

    HARRY
     

    Attached Files:

  5. HTEUFEL

    HTEUFEL Private E-2

    REPLY TO CHASLANG : Harry's Malware ADDITIONAL ATTACHMENTS

    Thtee More Attachments
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Harry's Malware

    Please leave your CAPS lock key off from now on!

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: (no name) - -{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
    O2 - BHO: (no name) - -{61C07AF3-01A3-4B85-ADB2-4EFD04E1286C} - (no file)
    O18 - Protocol: advert - {7DC356B2-7366-4F19-BF7A-4875F6AABEA0} - (no file)
    O20 - Winlogon Notify: vturr - C:\WINDOWS\

    After clicking Fix, exit HJT.


    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now locate the below file and delete it if found:
    C:\WINDOWS\system32\rrutv.ini2

    Now run Ccleaner


    Now please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to each of the following keys (one at a time) and take ownership of them (I explained how to do that further down).

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDSERVICE\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDSERVICE
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NETWORK_MONITOR\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NETWORK_MONITOR

    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the Address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the top Menu
    • Select Take Ownership
    • Repeat these steps for all of the registry keys given above before continue to the next steps below.
    • Now leave RegistrarLite running and continue
    • Now run the fixME.reg REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate one at a time to each of the above keys we took ownership of to make sure they were deleted.
    • If any of the keys still exist, move on down to PART 2 - Setting Permissions for Everyone below!.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    PART 2 - Setting Permissions for Everyone
    Run the below if some of the registry keys still exist after running the above steps.

    Now I want you to use Registar Lite again to navigate to each of the below keys (one at a time) by pasting them into the Address Bar and hitting return. But this time click the Security menu item and select Edit Permissions so we can change permissions to everyone ( I describe this down below the list of registry keys).
    After click Edit Permissions , here is what I expect you to see in the Group or user names area of the form:

    Everyone
    SYSTEM

    Select Everyone by clicking on it. Now at the bottom in the Permissions box click the check box for Full Control. The click Apply and then OK to get back to the main Registrar Lite screen. Nowright click on the registry key and select Delete. The click View and Refresh. Check to see if the registry key just deleted truly deleted. If so, move on to the next to work thru the whole list. If it does not delete, I want you to boot into safe mode and repeat these exact same steps to see if we can do it from safe mode.

    Then reboot your PC!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  7. HTEUFEL

    HTEUFEL Private E-2

    reply to chaslang: Harry's Malware 02-14-07

    = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =
    thanks for your help
    1. uninstalled counterspy ,rebooted
    a) folder deletion - could not locate any counterspy/sunbelt folders
    b) deleted 2 countersypy shortcuts
    2. ran hjt fixed 9 entries as requested - appears to be successful
    3. reset web settings
    a)successful .. i wonder if i need to reset any firefox settings
    b) set home page to about blank
    4. folder deletion rrutv.ini2 successful
    5. ran ccleaner
    6. downloaded registrar lite
    a) executed registrar lite and took ownership of keys
    b)created fixme.reg and successfully patchhed registry no error messages
    c)verified that keys were not there- bypassed step2
    7. rebooted, created logs - getrunkey,shownew,hjt will attach
    a) noticed that command service and network monitor back in registry(runkey.txt)
    b) deleted fixme.reg from desktop
    8. plan to update windows, avg's and zonealarm and then run scans
    9. note that panda on line scan is failing -!! - cant get report - only half of window is showing while scanning - emailed them - got an automated response back - no help


    harry
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run the procedure with Registrar Lite again and this time follow directions more carefully. Perhaps you forgot to do the refresh! I would suggest however you start this time at step 2 (setting permissions).


    Then attach a new GetRunKey log.


    Are you running Panda Online in safe mode? If so, try it in normal boot mode.
     
  9. HTEUFEL

    HTEUFEL Private E-2

    re:harry is malware free!!!

    thanks again
    1. updated windows, avg's and zonealarm scanned avg's - scan free!!
    2. performed part2 - successful!
    3. will follow your instructions and create restore point.
    4. attaching runkeys.txt
    ps did i tell you that 10/9 is a special day ?
     

    Attached Files:

    Last edited: Feb 14, 2007
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: harry is malware free!!!

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  11. HTEUFEL

    HTEUFEL Private E-2

    Re: Harry's Malware-free-at-last

    major-geeks, chaslang you are incredible!!!

    final steps

    turning laptop over to my grandaughter

    Decided to keep the log files and programs for future reference
    combofix, vundofix, newfiles,
    flushed and created restore points


    will become thoroughly familiar with:
    "how to protect yourself from malware"


    thanks

    harry
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Harry's Malware-free-at-last

    You're welcome Harry!

    It's okay to keep them for reference purposes, but in reality if you run into new problems you really need to download the tools again. They can change frequently to keep up with the pace of malware. So the tools can become outdated quickly. In fact the tools can also run into problems themselves due to malware learning about them. For example, right now ComboFix has been pulled from being downloaded. The are certain forms a rootkits that will cause ComboFix to malfunction and do very bad things. Thus in reality you should delete this program now. Your PC did not have the particular rootkit infection that caused this problem, but to be safe you should not run the version you have anymore. Especially without direction from a malware removal expert. In fact this is a good rule of thumb for all specialty tools like ComboFix.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds