Help! Multiple problems. System in trouble.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Twistid, Jul 4, 2006.

  1. Twistid

    Twistid Corporal

    Just recently I've been having huge problems with stupid viruses spyware and adware on my computer. The ones that the multiple anti-spyware/anti-virus/anti-malware programs found was Cowabanga, Trojan Horse Winlogonhook, Titanshield, Spyquake, Virtumonde, cnsmin, and Active Spy. That's about all I remember. Of course, I only run one at a time (Webroot Spy Sweeper and Avast!) for protection and have the others installed for scanning only. I used EVERY SINGLE anti-whatever program that I have on my computer in safe mode and thought that the problem was solved (also used Add/Remove programs to uninstall the obvious such as SpyQuake and Cowabanga). So, basically I have followed the Read and Run me first. I've also tried the removing Spyquake process and the Trojan Winlogonhook process (Webroot didn't seem to remove Trojan Winlogonhook with explorer.exe off and when trying with ewido it didn't seem to detect it.). Currently I seem to have Trojan Winlogonhook and Cowabanga (which just decided to install its assy self when I started up my computer so I could run a HijackThis log). I have posted a topic earlier in the Software forum asking if Messenger Plus! was spyware but no one replied. I'm wondering if that is what is causing problems because it seemed to happen when I was trying to check my Hotmail Account while using Windows Live Messenger. I think I had it for a couple of days before that on there too which makes it a bit trivial. Now when trying to check my Hotmail account through Windows Live Messenger it seems to stop to a crawl loading the page and I haven't been able to check it since but only through Firefox or Internet Explorer (by itself). The list of installed anti-<put name here> I have installed (very many are only for scanning) is Ewido, Webroot Spy Sweeper, Avast!, eTrust PestPatrol, Windows Defender, Giant Antispyware, Sunbelt Counterspy, Bitdefender, AVG, Ad-Aware, Spybot, McAfee AVERT Stinger, Anti...worm, Trend Micro Sysclean. I will post as many logs as I can for information (right now only have 4). Right now I'm gonna try and post the Webroot Spy Sweeper log, HijackThis log, ewido log, and my ZoneAlarm Pro log.
     

    Attached Files:

  2. Twistid

    Twistid Corporal

    sorry couldn't get the log from ZoneAlarm Pro but the problematic items that seem to cause problems were (which I blocked this second time they tried to run):

    C:\WINDOWS\temp\win6A.tmp.exe (had to block access 4 times)
    C:\WINDOWS\temp\win67.tmp.exe
    C:\WINDOWS\system32\regperf.exe
     
  3. Twistid

    Twistid Corporal

    Also, when this first appeared SpyQuake installed itself in my computer and acted as if it were a virus protection program (which was obvious to me that it was not) and SpywareGuard constantly kept telling me that something was trying to change the BHO and constantly had to click "Prevent" or whatever the option was that prevented this. Also, when I did a scan with CWShredder one of the items I recall it finding was CW.MSconfig which has not reappeared after removal.
     
  4. Twistid

    Twistid Corporal

    Just did a quick scan with PestPatrol and the attached is what was found.
     

    Attached Files:

  5. Twistid

    Twistid Corporal

    By the way I apologize for the seemingly forcefulness of the title of this topic. Should have toned it down a little better, the worry of all this got to me lol.
     
  6. Twistid

    Twistid Corporal

    Just did a full system scan with PestPatrol and found the attached item. I think that the official name of the Cowabanga "game" is Yazzle.Cowabanga. Which I found when doing a google search.
     

    Attached Files:

  7. Twistid

    Twistid Corporal

    Just now when I wasn't using a browser at all Spy Sweeper reported blocking access to Here4Search.biz. Also, sometimes Avast! has shown the Script Blocker display when not using a browser (which I've only seen come up when using Internet Explorer, which I was not using at the time).
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you ran the READ & RUN ME, you should have attached the two requested logs from step 6. Please attach them.

    Also if you ran the READ ME and actually read thru all of step 0, you would see we do not recommend using Messenger Plus due to their question methods of bundling malware into their install program. Even though it can supposedly be bypassed, their methods make them untrustworthy and there program can be dificult to remove since their uninstall does not work properly and they seem to have multiple methods for installing their program. So in effect, the program itself (even without the bundled malware) behaves like malware. Their software should not be used until they change there practices.

    Once you attach the requested logs from the READ ME, we can continue. Your most obvious problem still present is winlogonhook. If you purchased Spy Sweeper, you should be calling them and asking them why they still cannot remove this malware when they have known about it for more than 4 months. If we can remove it manually (and I do more than 10 per day), why can't they do it automatically.

    You also need to follow the directions in step 3 of the READ ME. You must only have ONE antivirus application installed. You have Avast, AVG7, and Bitdefender. Uninstall ALL but one.

    You also should not be running all of these antispyware blocking tools. They are wasting tons of system resources and can cause conflicts with the ability of each to function properly. I'm assuming Spy Sweeper is your only paid program! Uninstall all free trial versions or these programs (like Pest Patrol, Ewido, GIANT AntiSpyware, SpywareGuard). Also if Spy Sweeper is truly a paid version, you should also uninstall Windows Defender.

    You must do all of the above and then attach a new HijackThis log.
     
    Last edited: Jul 4, 2006
  9. Twistid

    Twistid Corporal

    Uninstalled Messenger Live Plus!, AVG, Bitdefender, and ewido Guard (but not ewido). Multiple Anti-Spyware programs are installed but NOT run as blockers (only Spy Sweeper is being run for this). Did notice some running processes from ewido, Giant Antispyware, and Windows Defender and have deleted them from being started up when my computer starts with Codestuff Starter. Was under the impression that it's ok to have multiple Anti-spyware programs installed as long as only one is being run to block spyware (which is how I now have them running). Will run through the Read & Run me first process (thought that I had basically done so already since I had ran multiple scans with the same programs except Panda ActiveScan), I apologize. If there is still a problem with having multiple Anti-spyware programs installed but only one used for blocking Spyware then please say so. Will return with the Read & Run Me First process completed the right way.
     
  10. Twistid

    Twistid Corporal

    Sorry. Could NOT complete any online scanning. SpyQuake reared it's ugly head again when running it. Winlogonhook still couldn't be removed after 2 attempts (second after restart) with Spy Sweeper in safe mode before trying online scanning. New hijackthis log attached. Must clean system again now. Please help.
     

    Attached Files:

  11. Twistid

    Twistid Corporal

    No time to contact Spy Sweeper. Would much rather do it manually (which probably won't be difficult for me since I've messed with registry settings, and other system settings before). SpyQuake was not in Add/Remove Programs but Yazzle ActiveX and Cowabanga were. Removed them with Your Uninstaller! Also will run About Buster because having about blank problem with internet explorer.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have the active protection from SpywareGuard running. You should uninstall SpywareGuard. It is not necessary and does not come close to being as good as the protection the Spy Sweeper already provides you.

    You do not need to run about:Buster! You do not have an about:blank hijacker.

    Are the below settings something you setup?
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.funhousetrading.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9100/proxy.pac



    We need to locate some other hidden files before we can continue.


    Now run the below procedure and attach the runkeys.txt log.
    Now run the below procedure and attach the newfiles.txt log.

     
  13. Twistid

    Twistid Corporal

    K will do. Thanx :). It might've been System Restore which maybe why it kept coming back. I've already disabled (which also removes the system restore points) and am now doing a boot scan with Avast!. The first setting is one that I set. I'm not sure about the second though (maybe it's ZoneAlarm). Another reason it is probably System Restore is because Avast! found multiple problems in the System Volume Information folder which is the System Restore points location. The current Avast! scan has not returned any results so far after disabling System Restore (and it has gotten past that folder).
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is more than likely part of Google Web Accelerator.

    Are you saying you are not having any other malware issues? I still saw malware in your previous HJT log.
     
  15. Twistid

    Twistid Corporal

    Not sure if I still have malware issues or not. How do I remove the malware that was found from the HijackThis log?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
    O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
    O20 - AppInit_DLLs: javaw.dll C:\WINDOWS\system32\javaw.dll
    O21 - SSODL: furnariidae - {89e4aaba-3b21-49b3-b922-8ca35193c68e} - C:\WINDOWS\system32\zlara.dll
    NOTE: When HJT fixes the O20 AppInit_DLLs line it will popup an error message. Just ignore it, click OK, and continue.

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (if found):
    C:\WINDOWS\javaw.dll
    C:\WINDOWS\system32\javaw.dll
    C:\WINDOWS\system32\zlara.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  17. Twistid

    Twistid Corporal

    Followed instructions. Spy Sweeper still reporting Winlogonhook. Regperf.exe attempted to do something again (blocked it with firewall). New HijackThis log attached.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you follow my directions given back in message number 12 we will be able to continue to fix your other problems.


    You should also run this SpywareQuake & SpyFalcon Removal Procedure (you will see regperf.exe mentioned in the list of files to remove).
     
  19. Twistid

    Twistid Corporal

    GetRunKey and ShowNew logs attached.
     

    Attached Files:

  20. Twistid

    Twistid Corporal

    Completed SpywareQuake process. Only file found was regperf.exe for manual deletion. smitREM log attached.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winrkq32.dll once and then click the kill button. After you have killed all of the winrkq32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    awtttur.dll
    pmnll.dll

    Next double click on explorer.exe and again click once on each instance of winrkq32.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    awtttur.dll
    pmnll.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =



    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    exit


    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\WINDOWS\iun6002.exe
    C:\WINDOWS\SYSTEM32\ld100.tmp
    C:\WINDOWS\SYSTEM32\ld102.tmp
    C:\WINDOWS\SYSTEM32\llnmp.ini
    C:\WINDOWS\SYSTEM32\pmnll.dll
    C:\WINDOWS\SYSTEM32\awtttur.dll
    C:\WINDOWS\SYSTEM32\winrkq32.dll


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now attach a new HJT log and tell me how the steps went.

    Also attach a new log from ShowNew.

    Make sure you tell me how things are working now!
     
  22. Twistid

    Twistid Corporal

    New HijackThis and ShowNew log attached (noticed that you wrote the ShowNew chaslang ;)). Everything appeared to go alright and everything appears to have been deleted that was supposed to be :). So far nothing out of the ordinary happening at the moment on my computer.
     

    Attached Files:

  23. Twistid

    Twistid Corporal

    Just did a scan of the memory and Registry with Spy Sweeper again. Trojan Agent Winlogonhook found with 14 Traces. Also, while it was scanning the Script Blocker dialog for Avast! showed up (when not using Internet Explorer). Also have run the program BugOff and it says that everything was enabled except for "The ADODB.Stream object" (which is disabled), not sure if that's a problem or not but thought I should mention it.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It would be best if you did not run any scans that are not requested until we finish. Also it would be best not to install anything new while we are doing this work. What is the below file that just showed up:

    C:\Documents and Settings\Timmy\Local Settings\TEMP\c6jbce4g.zip

    I have no idea what and more importantly where Spy Sweeper found these problems. They could just be in System Restore or in one the quarantine like folder form what we have been doing. Even Killbox saves stuff deleted in a c:\!Killbox folder for backups.

    We have some minor cleanup to finish.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {398C2A6A-4289-4A6B-8E44-0684C779390C} - C:\WINDOWS\system32\pmnll.dll (file missing)
    O20 - Winlogon Notify: ddcyvut - ddcyvut.dll (file missing)
    O20 - Winlogon Notify: winrkq32 - winrkq32.dll (file missing)
    After clicking Fix, exit HJT.

    Other than that, your logs are clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point. Then you should either delete the C:\!Killbox folder or run Killbox and click File, Cleanup, Delete all Backups.

    After that, you should work thru the below link (as long as you are not having any malware problems):

    How to Protect yourself from malware!
     
  25. Twistid

    Twistid Corporal

    Have no idea what file that is that just showed up (I have not installed any new programs during this entire process. Completed all the steps and read the How to Protect yourself from malware. Everything looks like it went well. When this whole thing is done then please tell me so that I don't have to wait a while to install any new programs =o). Thanx
     
  26. Twistid

    Twistid Corporal

    System Restore has also been re enabled ;).
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

     
  28. Twistid

    Twistid Corporal

    When I went to that folder it was no longer there ???. Thanx for your great help Chaslang! :)
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds