HELP!! it won't stop!

Discussion in 'Malware Help (A Specialist Will Reply)' started by SoulEdge, Jun 3, 2007.

  1. SoulEdge

    SoulEdge Private E-2

    I'm growing incredibly tired of this spyware BS. The popups are literally endless, and they're just blank white windows that flash on and disappear rapidly. I'm waiting to get a seizure from all the flashing so I can sue these nosy, privacy-invading, property destroying bastards.
     

    Attached Files:

  2. SoulEdge

    SoulEdge Private E-2

    And here are the RunKey, ShowNew and HJT logs.

    Please don't make me take it to Geek Squad :cry
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please be more careful following instructions!
    • You did not uninstall the below as requested in step 0:
      • Viewpoint Manager (Remove Only)
      • Viewpoint Media Player
    • In step 0 of the READ ME, you did not configure your system for Normal Startup mode with MSconfig.
    • In step 2 you did not following directions for enabling viewing of hidden system files and file extensions.
    • In step 6 you did not uninstall your old J2SE Runtime Environment 5.0 Update 3 Sun Java version and download the current version as requested.
    • Also you did not attach the requested log from CounterSpy (we did not ask for a Spybot log and rarely need one which is why we do not ask for one).
    Now some potentially very bad news! You are very badly infected!! Many of your Windows system files are infected and many renamed to be a DLL file instead of an EXE file. They seem to have become infected on May 26th. Any idea what you were doing on that day. I have attached a file named infected.txt that shows all of the files that are infected and/or renamed. Unless you install an antivirus program that can repair these without deleting the files, you are probably looking at a reinstall! The free AVG may not be able to fix this! However we will try some fixes below, but I just want to make this point first since it is not possible to fix all of these manually.

    Is your AVG antivirus fully up to date? If not, please update it.
    Have you run a full scan of your system with AVG after booting in safe mode. If not, please do so. Report back what (if anything) it finds and if it fixes what it finds.



    Let's start by removing a malware service.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to MS Internet Countermeasures Framework
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteICF into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Continue by downloading two tools we will need

    - Process Explorer

    Extract it to its own folder somewhere that you will be able to locate it later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    Make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of any of the below DLL files (if found) and then click the kill button.
    a3dx8.dll
    mllli.dll
    kbdare.dll

    After you have killed all instances of any of the above DLLs under winlogon click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on explorer.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    a3dx8.dll
    mllli.dll
    kbdare.dll
    After you have killed all instances of any of the above DLLs under Explorer click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on iexplore.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    a3dx8.dll
    mllli.dll
    kbdare.dll

    After you have killed all instances of any of the above DLLs under iexplore click ok.
    (If you do not find these DLLS, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: H - {040FA520-78C6-41ce-81D0-9E733ABC1A29} - C:\WINDOWS\system32\comi.dll (file missing)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {67fce553-f230-4eae-afae-71efa37d4e06} - C:\WINDOWS\system32\kbdare.dll
    O2 - BHO: (no name) - {DEBEB52F-CFA6-4647-971F-3EDB75B63AFA} - C:\WINDOWS\system32\tmp2B.tmp.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [setup] rundll32.exe "C:\WINDOWS\efcyvu.dll",realset
    O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
    O20 - AppInit_DLLs: c:\windows\system32\gebcbxu.dll
    O20 - Winlogon Notify: A3dxq - C:\WINDOWS\system32\a3dx8.dll
    O20 - Winlogon Notify: asfile - asfile.dll (file missing)
    O20 - Winlogon Notify: kbdare - C:\WINDOWS\SYSTEM32\kbdare.dll


    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     

    Attached Files:

  4. SoulEdge

    SoulEdge Private E-2

    Thanks a ton for the how-to, but I think the best way for me to go is to just reformat from here. I want to avoid doing any permanent damage to my computer, and since it's already just about blown to hell I think that's what it's come down to.

    Again, thanks a lot for the help and I'll refer back for all of my tech needs. :)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds