Help newbie with malware problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by HumanDrone, Nov 18, 2004.

  1. HumanDrone

    HumanDrone Private E-2

    ok, so my computer is utterly slow as of late. I can barely type up this message because of the lag. Today, i was unable to play my game (SWG) and i went on the forums to get this sorted out, and a player told me i have a malware problem and i should come here looking for help. I looked at several threads and ran my comp in safe mode, basically followed the basics of protecting you're comp.. ran adaware, spybot, spy sweeper, stinger, CClean ... all of that. And form ad-aware there were several Malware's located, and i deleted them all, however i still have this problem. So i downloaded hi-jack this ... and ran it and ill leave my log file with you to see if you can figure anything out.

    any help is appreciated, thanks.
     

    Attached Files:

  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Hi,
    You should start here, this helps most people who are not infected 100 times over or who do not have a nasty trojan:
    http://forums.majorgeeks.com/showthread.php?t=35407
    Also, it always removes a lot of items and cuts down the log file size for us making our lives just a tad simpler.


    Hijack This needs to be in its own folder, or you have no backups, this is explained here:
    http://forums.majorgeeks.com/showthread.php?t=38752

    Ill look at your logfile anyhow to give you some starting tips, I already see one ugly little trojan in there :)
     
  3. PhilliePhan

    PhilliePhan Guest

    Just to quickly add to what M.A. said - You have a load of bad crap as well as a Stopguard-related infection.

    You are also running HijackThis Improperly! It needs to be in its own, safe folder - C:\Program Files\HijackThis

    You should follow M.A.'s instruction and run through the Cleanup Tutorial and do the Alernative Scans portion as well!

    Post back with the results and one of the experts here should be able to help you.

    Best luck :)
    PP
     
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Your friend was right, you have a mess on your hands.

    Hopefully you are running the tutorial, a lot of these will be removed if you did. You may end up with a bunch of lines ending in (file missing) or (no file) and those can be removed. These may be in place of lines you see me telling you to remove below if you have done the tutorial.

    At the end I have other suggestions for a happy computer :)

    ---------------------------------------------------------------------------

    Remove these:

    C:\Documents and Settings\Tyler Richardson\Application Data\tlrm.exe
    C:\Program Files\NaviSearch\bin\nls.exe
    C:\WINDOWS\system32\??plorer.exe

    R3 - URLSearchHook: (no name) - _{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)
    O2 - BHO: MultiMPPObj Class - {002EB272-2590-4693-B166-FBD5D9B6FEA6} - C:\WINDOWS\multimpp.dll
    O2 - BHO: CATLEvents Object - {02F96FB7-8AF6-439B-B7BA-2F952F9E4800} - C:\DOCUME~1\TYLERR~1\LOCALS~1\Temp\cvscm.dat
    O2 - BHO: Zedd4Proj.clsUnoOne - {08227B4B-54FE-4C4D-809F-BCA46292FC5B} - C:\WINDOWS\System32\AANTX.dll
    O2 - BHO: (no name) - {1DAC3551-E161-4F9F-8403-675509FB7317} - C:\WINDOWS\System32\bfznzuwk.dll
    O2 - BHO: MEGASEAR - {4E7BD74F-2B8D-469E-C0FF-FA7FB592BF30} - C:\WINDOWS\DOWNLO~1\megasear.dll
    O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
    O2 - BHO: (no name) - {EAD0AE98-D898-83E5-2706-3DC4D3F46292} - C:\WINDOWS\Fgscpmpv.dll
    O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
    O3 - Toolbar: Search - {698A3772-6C1F-6CD3-C127-5F5D7B4BF074} - C:\WINDOWS\Fgscpmpv.dll
    O3 - Toolbar: MEGASEAR - {4E7BD74F-2B8D-469E-C0FF-FA7FB592BF30} - C:\WINDOWS\DOWNLO~1\megasear.dll

    Next line is possibly harmless, but not needed, so delete it:
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [odlzdntlx] C:\WINDOWS\System32\mkjlynop.exe
    O15 - Trusted Zone: *.greg-search.com
    O20 - AppInit_DLLs: wb968ic29w3.tlb


    ---------------------------------------------------------------------------


    Major suggestions to get that pc running smooth. Your running a popup blocker. Get rid of it, clean up the machine and get Service Pack 2, it has popup blocking.

    Your running multiple spyware programs and getting infected. I hope you have anti-virus and suggest you either use Spybot and its tea timer feature or purchase Ad-Aware or Spysweeper or Pest Patrol because you need on demand blocking.

    Too much startup crap. Steam, Quicktime, etc do not need to be running at startup. Check programs in your lower right corner, known as the system tray and look for load at Windows options.
     
  5. HumanDrone

    HumanDrone Private E-2

    sorry.. ive never been here before, can u point me in the direction of the clean up tutorial?
     
  6. PhilliePhan

    PhilliePhan Guest

    Here it is:
    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan and Virus Removal

    Note the steps that you can and cannot complete. Please make sure that you are in Safe Mode with System Restore OFF and have the Viewing of Hidden Files ENABLED as per the instructions in the link. Make sure to do the Online Scans.

    If you have any questions, just ask - It's not as daunting as it looks ;)

    Definitely do the Alternative scans. After that, you will probably need our help removing a few toughies like the StopGuard/Virtumundo infection.

    Also, remember to move HJT to its own folder.

    Best :)
    PP
     
  7. HumanDrone

    HumanDrone Private E-2

    ok, i just went in safe mode again and did more scans and the alternates... a squared picked up 13 malwares, this is my hijackthis file now. (problem still occurs)
     

    Attached Files:

  8. PhilliePhan

    PhilliePhan Guest

    Hi HumanDrone,

    Here is my generic fix for Stopguard-related malware infections.
    Please print out these instructions so that you can operate with All Browser Windows CLOSED.

    Please make sure System Restore is OFF and the Viewing of Hidden Files is Enabled as per the tutorial.

    Now, look in Task Manager (Ctrl-Alt-Del) for the following running process and END it, if possible:
    tlrm.exe

    NEXT:
    Look in C: > WINDOWS > PREFETCH & Delete mcsvc.exe ( or any mcsvc or cvscm entries) if found. If it is easier, you can go ahead and delete all of the files in the Prefetch Folder – It’s a good idea to do this every couple of months anyway. ( Do Not Delete The Prefetch Folder Itself )

    NOW:
    Run HijackThis and Check the Boxes for the Following:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O2 - BHO: CATLEvents Object - {02F96FB7-8AF6-439B-B7BA-2F952F9E4800} - C:\DOCUME~1\TYLERR~1\LOCALS~1\Temp\cvscm.dat

    O4 - HKLM\..\Run: [*mcsvc] C:\WINDOWS\addins\mcsvc.exe

    O4 - HKLM\..\RunOnce: [*mcsvc] C:\WINDOWS\addins\mcsvc.exe rerun

    O4 - HKCU\..\Run: [Spyware Begone] C:\freescan\freescan.exe –FastScan
    -- This is listed as a Rogue - - -> http://www.spywarewarrior.com/rogue_anti-spyware.htm

    O4 - HKCU\..\Run: [Subs] C:\Documents and Settings\Tyler Richardson\Application Data\tlrm.exe ---> Looks like a Trojan. If it is something you want, leave it alone.

    O16 - DPF: {8EF27A70-DD04-11D6-B7F6-00A0C9CD5F8A} - http://www.quikshield.com/qshsetup.exe - - - -> Google provides one of the best popup blockers with its toolbar. I suggest that you use it instead of this.

    Click FIX and then while still in HijackThis, look in the lower right-hand box where it says “Other stuff,” and select CONFIG > MISC TOOLS > select DELETE A FILE ON REBOOT and where it says File Name, enter (or navigate to the file in the HijackThis pane) C:\WINDOWS\addins\mcsvc.exe and click OPEN. A message will ask you if you want to reboot now. Click YES and reboot into SAFE MODE by tapping F8.

    You may receive an error message after rebooting into Safe Mode that says Windows could not find the file you told it to delete. Just click okay and DO NOT REBOOT AGAIN.

    While in Safe Mode (making sure that you are able to view hidden files) Navigate to and DELETE the following if they still remain:
    C:\Documents and Settings\Tyler Richardson\Application Data\tlrm.exe
    C:\WINDOWS\addins\mcsvc.exe

    THEN:
    Use Windows Explorer to run a search of your computer for:
    mcsvc
    cvscm


    and DELETE the related files. (We especially want to get rid of mcsvc.ini & mcsvc.dat & mcsvc.bak AND cvscm.ini & cvscm.dat & cvscm.bak + any other related crap.) It is important that you be thorough with this search. These files seem to like to hide all over your computer and have a nasty habit of resurrecting themselves if you do not get them ALL.

    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.

    Then, as an added precaution, Go to Start > Run and type: cleanmgr. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    Reboot to Normal Windows and Attach a fresh HJT log. How are things running? Let us know of any problems that you may have encountered with the above instructions.

    AFTER you get cleaned up, you ought to take a spin to Windows Updates and get updated. Make sure your machine is clean first.

    Best luck :)
    PP
     
  9. HumanDrone

    HumanDrone Private E-2

    well i can run my game again, and that i thank you for.

    however, my comp is still a little slower than it should be... and when i was following you're instructions, i could not find any mcsvc or cvscm anywhere when searching, i did remove it from addins though. Anyways i've attached a new log file.
     

    Attached Files:

  10. PhilliePhan

    PhilliePhan Guest

    Looks like you got some of it.

    Use Add or Remove Programs to Uninstall BullsEye Network.

    Then:
    Scan with HijackThis and Check the Boxes for the following:

    O2 - BHO: CATLEvents Object - {02F96FB7-8AF6-439B-B7BA-2F952F9E4800} - C:\DOCUME~1\TYLERR~1\LOCALS~1\Temp\cvscm.dat

    O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll

    O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll


    Again, make sure All Browser Windows are Closed when you Click FIX.

    Now boot into Safe Mode and DELETE the following if they remain:

    C:\Program Files\BullsEye Network
    C:\WINDOWS\System32\msbe.dll
    C:\DOCUME~1\TYLERR~1\LOCALS~1\Temp\cvscm.dat
    C:\WINDOWS\System32\nvms.dll

    Then:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.

    Then:
    Go to Start > Run and type: cleanmgr. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin

    And Click OK.

    Reboot to Normal Windows and Scan with HijackThis and attach that log. Let us know of any problems you may have encountered with the above instructions and how your computer is running now.

    Best luck :)
    PP
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds