Help malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by gravytrader, Jun 11, 2007.

  1. gravytrader

    gravytrader Private E-2

    Hello I am having problems with a few malware programs. I have done all the steps in the READ % RUN ME FIRST thread up to the Hijackthis portion.

    I will attach the Hijackthis log.

    Thank you very much, please tell me if would would like me to attach any other logs from the previous programs I used in the READ % RUN ME FIRST thread.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Yes you must attach exactly what we asked you to attach from the READ & RUN ME:

    CounterSpy - only for Windows XP, 2K, & NT users
    AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
    Bitdefender - from step 6
    Panda Scan - from step 6
    runkeys.txt - the log from GetRunKey.bat
    newfiles.txt - the log from ShowNew.bat
    HijackThis
     
  3. gravytrader

    gravytrader Private E-2

    Ok, here are the newfiles.txt, runkeys.txt, and Activescan.txt ...
     

    Attached Files:

  4. gravytrader

    gravytrader Private E-2

    the bdscan.txt... my counterspy froze up so im running AVG now
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I can already see you have a few infections that require a special tool to be run to remove them.


    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!
     
  6. gravytrader

    gravytrader Private E-2

    Here is the log.txt from combo fix, the newfiles.txt, and the runkeys.txt

    the AVG managed to quarentine msdtc.exe and dllhost.exe, and I havnt been getting any more popups for now. my computer did kinda crash while running combo fix, I managed to get it to restart, and when it came back up the combo fix program wrote the log anyways.
     

    Attached Files:

  7. gravytrader

    gravytrader Private E-2

    and the HJT
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
    O4 - HKCU\..\Run: [Tair] "C:\DOCUME~1\WESLEY~1\MYDOCU~1\DOBE~1\msdtc.exe" -vt yazb
    O4 - HKCU\..\Run: [Amyifl] C:\WINDOWS\F?nts\dllhost.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    After clicking Fix, exit HJT.

    Now reboot in normal mode

    Now locate the below folder and delete it if found:
    C:\WINDOWS\system32\T1QaSQ

    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     
  9. gravytrader

    gravytrader Private E-2

    Alright I completed those steps. Things are looking pretty good.
     

    Attached Files:

  10. gravytrader

    gravytrader Private E-2

    anouther threat found by Symantec

    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP765\A0054982.exe

    sais it was deleted. not sure where it came my computer was idle when it got it.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You HJT log was supposed to be from Normal Boot mode. Please attach a correct log.

    No Symantec did not delete that file. That is System Restore and no scanners can remove things from System Restore. Part of our final steps (after I see a proper HJT log) will take care of System Restore.
     
  12. gravytrader

    gravytrader Private E-2

    ok srry got confused, here
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean but you did not uninstall the CounterSpy trial as requested in message # 8. It is only a trial expires after 15 days and is of no use to you after that.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. gravytrader

    gravytrader Private E-2

    Thank you very much. I really appreciate the time you guys take to help us poor victims out :p .

    You guys are GREAT.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds