Help removing malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by gosh1976, Mar 4, 2007.

  1. gosh1976

    gosh1976 Private E-2

    I need some help removing some malware. I've had problems for a week or more now and have had to regain acces to Task manager as well as fix corrurpted Winsocks and TCP/IP files.

    It seems I still have adspy/Isearch.d.2 as well as trojan.peacom.

    I tried to run bitdefender but the scan said it was going to take 5+ hours.
     

    Attached Files:

  2. gosh1976

    gosh1976 Private E-2

    here is the information from the last two counterspy scans

    the second one was done in safe mode
     

    Attached Files:

  3. gosh1976

    gosh1976 Private E-2

    sorry to bump the thread again but I wanted to ad the activescan log
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Your Windows OS and IE versions are way out of date and represent a major security risk. It is also probable a good reason for why your PC is so badly infected. As you will see below, there are a load of problems. After we fix your malware problems, you MUST get updated.

    Do you know what the below SoftToolbar folder is for? It seem suspcious?
    Code:
    C:\Program Files\
    SOFTTO~1      Feb 25 2007              "SoftToolbar"
    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_05
    Mozilla Firefox (1.5.0.10)
    Symantec Network Drivers Update
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 0 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Now run this procedure: DelCmdService - How to use

    Now let's remove a left over service from Symantec!

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Symantec Network Drivers Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteSNDSrvc into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://wwww.cq223.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://wwww.cq223.com
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,c:\WINDOWS\1015.exe
    O2 - BHO: (no name) - {33bfd51d-c077-4926-8b0d-4e03f37a8dbf} - C:\WINDOWS\System32\4926cfsb.dll (file missing)
    O2 - BHO: (no name) - {385AB8C6-FB22-4D17-8834-064E2BA0A6F0} - (no file)
    O2 - BHO: (no name) - {d0eacd37-2232-4ddf-ae2b-1b294ae19f4f} - C:\WINDOWS\System32\4ddfntos.dll
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [init] c:\WINDOWS\100.exe
    O4 - HKLM\..\Run: [ijudvv] C:\WINDOWS\System32\ftjacmh.exe r
    O4 - HKLM\..\Run: [iepgdq] C:\WINDOWS\System32\znnxzyg.exe r
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUxdm080YYUS
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/25b024166501983b1116/netzip/RdxIE601.cab
    O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.taxsimple.com/TSWeb/msrdp.cab
    O20 - Winlogon Notify: cryptimg - C:\WINDOWS\SYSTEM32\cryptimg.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\Program Files\Internet Explorer\msimg32.dll
    C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll
    C:\Program Files\MSN Messenger\msimg32.dll
    C:\Program Files\Netscape\Netscape Browser\plugins\NPMyWebS.dll
    C:\WINDOWS\043.exe
    c:\WINDOWS\100.exe
    c:\WINDOWS\1015.exe
    C:\WINDOWS\bd2.exe
    C:\WINDOWS\bd3.exe
    C:\WINDOWS\bd4.exe
    C:\WINDOWS\bd5.exe
    C:\WINDOWS\bd7.exe
    C:\WINDOWS\bd8.exe
    C:\WINDOWS\f2.exe
    C:\WINDOWS\g3.exe
    C:\WINDOWS\pp21cn.dll
    C:\WINDOWS\Downloaded Program Files\RdxIE.dll
    C:\WINDOWS\System32\4926cfsb.dll (file missing)
    C:\WINDOWS\System32\4ddfntos.dll
    C:\WINDOWS\SYSTEM32\cryptimg.dll
    C:\WINDOWS\system\dtdhousclq.exe
    C:\WINDOWS\System32\ftjacmh.exe
    C:\WINDOWS\System32\znnxzyg.exe
    C:\WINDOWS\bd3.exe
    c:\windows\inf\polall1r.inf
    c:\windows\inf\satmat.inf
    c:\windows\satmat.ini
    C:\WINDOWS\system32\019.exe
    C:\WINDOWS\system32\1250.exe
    C:\WINDOWS\system32\00007d41.DAT
    C:\WINDOWS\system32\1A7E1A98.dat
    C:\WINDOWS\system32\431172453040.dat
    C:\WINDOWS\system32\advwhes.dll
    C:\WINDOWS\system32\ad_1128.exe
    C:\WINDOWS\system32\dufs1.exe
    C:\WINDOWS\system32\Installation.exe
    C:\WINDOWS\system32\MediaSupport.exe
    C:\WINDOWS\system32\lsanp.dll
    C:\WINDOWS\system32\msmms.dll
    C:\WINDOWS\system32\MyFavor.dll
    C:\WINDOWS\system32\MyFavor32.dll
    C:\WINDOWS\system32\peer.ini
    C:\WINDOWS\system32\sywncv98.ini
    C:\WINDOWS\system32\oljdav73.dll
    C:\WINDOWS\system32\pfxzmtforum.dll
    C:\WINDOWS\system32\pfxzmtwbmail.dll
    C:\WINDOWS\system32\pfxzmtsmt.dll
    C:\WINDOWS\system32\pfxzmtsmtspm.dll
    C:\WINDOWS\system32\pfxzmticq.dll
    C:\WINDOWS\system32\pfxzmtaim.dll
    C:\WINDOWS\system32\pfxzmtgtal.dll
    C:\WINDOWS\system32\pfxzmtymsg.dll
    C:\WINDOWS\system32\sfxzmtsmtspm.dll
    C:\WINDOWS\system32\sfxzmtsmt.dll
    C:\WINDOWS\system32\sqlservech.dll
    C:\WINDOWS\system32\wmsnds32.dll
    C:\WINDOWS\system32\wnttech.dll
    C:\WINDOWS\system32\rhbcbk96.dll
    C:\WINDOWS\system32\windav73.dll
    c:\windows\system32\drivers\etc\hosts.bho
    C:\WINDOWS\system32\drivers\00007d41.SYS
    C:\WINDOWS\system32\drivers\hidproc.sys
    C:\WINDOWS\system32\drivers\lanfs.sys
    C:\WINDOWS\system32\drivers\msmms.sys
    C:\WINDOWS\system32\drivers\restore.ini
    C:\WINDOWS\Temp\windows.exe
    C:\WINDOWS\Temp\~my1.tmp
    C:\WINDOWS\Temp\~my2.tmp
    C:\WINDOWS\Temp\~my3.tmp
    C:\~deB0.tmp
    C:\~deB9.tmp
    C:\~deBA.tmp
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.
    After reboot locate the below folder and delete if found:
    c:\windows\EliteToolBar
    c:\windows\system32\FLEOK
    C:\Program Files\Common Files\wxni

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Note: The adspy/Isearch.d.2 and trojan.peacom registry items may or may not get fixed. They sometimes require special steps to remove. We shall see.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  5. gosh1976

    gosh1976 Private E-2

    Thanks for the help!

    This has been a pain in the rear so I'll definitely be looking into rectifying the unrelated issue that has kept m from running the windows update as it's not worth the headaches.

    The softtoolbar folder appeared to be an IE add-on that had been mostly cleaned and only contained graphcis (graphics with cinese characters).... It has been deleted.

    I didn't have too much trouble going through the instructions but the SNDSrvc would not delete. An error stating that it was a windows essential component poped up when I tried to delete it per the instructions. I can retry if you need the exact wording of the error.

    the adspy stuff appears to be gone but not the trojan.peacom.
     

    Attached Files:

  6. gosh1976

    gosh1976 Private E-2

    here's the other log
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My instructions did say the below: ;)
    It was deleted and it was not essential (it probably said critical).

    It appears that you did not run the fixME.reg patch!! Why not? Did you get an error message?

    Why are you running MSconfig now???? You were not running it last time and we clearly state that it must not be used in the READ ME. Put your PC into Normal Startup mode and attach new logs from HJT and GetRunKey.
     
  8. gosh1976

    gosh1976 Private E-2

    oops sorry fogot about msconfig I was ging to reboot while wating on a reply and aol etc.. get on my nerves running at start-up

    I though the fixMe.reg had worked but I looked at again and realized I missed the first line. I re-copied the text and resaved it before running it again. It siad the operation was succesfull.

    here are the new log files again
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you referring to the two instant messengers (AIM and AIM6). If you don't want them to load at startup, have HijackThis fix those two lines. Or are you referring to AOL? Do you use AOL?
     
  10. gosh1976

    gosh1976 Private E-2

    i was refering to AIM and AIM6. I'll remove them from with Hijack This and inform the computer illeterate person that uses the computer that they'll have to just click on the icon.

    or I can atleast remove one of them
     
  11. gosh1976

    gosh1976 Private E-2

    I ran counterspy again here is the log
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look in Add/Remove programs for Symantec Network Drivers Update Do you see it? Uninstall it if found. If not found, tell me.

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also delete the below folder:
    C:\Documents and Settings\user\Application Data\Viewpoint


    Now Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to each of the following keys (one at a time) and Set Permissions for Everyone(I explained how to do that further down).
    To set permissions for Everyone for each key, do the following[/color][/size][/b]
    • Copy & Paste the registry key from above (one at a time) into the Address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the top Menu
    • Select Edit Permissions so we can change permissions to everyone. Now here is what I expect you to see in the Group or user names area of the form that comes up:
    • Everyone
    • SYSTEM
    • Select Everyone by clicking on it.
    • Now at the bottom in the Permissions box click the check box for Full Control.
    • Then click Apply and then OK to get back to the main Registrar Lite screen.
    • Now right click on the registry key and select Delete.
    • Then click View and Refresh. Check to see if the registry key just deleted truly deleted.
    • If so, move on to the next to work thru the whole list. If it does not delete, I want you to boot into safe mode and repeat these exact same steps to see if we can do it from safe mode.
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {385AB8C6-FB22-4D17-8834-064E2BA0A6F0} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [init] c:\WINDOWS\100.exe
    O4 - HKLM\..\Run: [ijudvv] C:\WINDOWS\System32\ftjacmh.exe r
    O4 - HKLM\..\Run: [iepgdq] C:\WINDOWS\System32\znnxzyg.exe r
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O20 - Winlogon Notify: cryptimg - cryptimg.dll (file missing)

    After clicking Fix, exit HJT.

    Now reboot in normal mode

    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  13. gosh1976

    gosh1976 Private E-2

    edit: I started an avg scan right after I posted this and it found a file called administratora.dat says it is Trojan Horse downloader.agent.inr and it was located at C:\Documents and Settings\administrator\Local Settings\Temp\administratora.dat

    I did not see Symantec Network Drivers Update in add/remove programs.

    Everything seems fine as far as I can tell.

    only two more issues that I see right now and that is that hijack this won't delete:

    O2 - BHO: (no name) - {385AB8C6-FB22-4D17-8834-064E2BA0A6F0} - (no file)

    I even tried it in safe mode with no luck. The other issue and I have no idea if it is related to all this is that on the logon screen when I boot to safe mode User is no longer on the list only gosh and administrator.

    here are the latest logs
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The procedures and logs you have been performing were only done on the User account. Any other account could possibly have infections too.

    Run this and attach the requested log: Getting Uninstall Programs List From The Registry


    We'll come back to this. We will need to use a procedure with Registrar Lite for this too.

    Only Administrator accounts will appear in safe mode. Is User an administator priviledged account?
     
  15. gosh1976

    gosh1976 Private E-2

    User is a member of the administrator group. I should probably change that name but I'll wait to do that. Strange that gosh is a member of users and administrators at the same time (i guess) but I probably did that when I set it up.

    I'll probably end up deleting the gosh account.

    here is the requested log.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach the below new logs and tell me how the above steps went.
    1. ShowNew
     
  17. gosh1976

    gosh1976 Private E-2

    no issues with those steps
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that fixed the left over Symantec items.


    Now let's fix the BHO line from HJT.

    Run Registrar Lite navigate to the following keyand Set Permissions for Everyone(I explained how to do that further down).
    To set permissions for Everyone for each key, do the following[/color][/size][/b]
    • Copy & Paste the registry key from aboveinto the Address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the top Menu
    • Select Edit Permissions so we can change permissions to everyone. Now here is what I expect you to see in the Group or user names area of the form that comes up:
    • Everyone
    • SYSTEM
    • Select Everyone by clicking on it.
    • Now at the bottom in the Permissions box click the check box for Full Control.
    • Then click Apply and then OK to get back to the main Registrar Lite screen.
    • Now right click on the registry key and select Delete.
    • Then click View and Refresh. Check to see if the registry key just deleted truly deleted.
    • If so, you are done. If it does not delete, I want you to boot into safe mode and repeat these exact same steps to see if we can do it from safe mode.
    If the key appears to delete, attach a new log from HJT afterwards!
     
  19. gosh1976

    gosh1976 Private E-2

    everyone was not a choice in the groups and usernames box. It had a number of the groups and the users as well as creator in the box and most had full control already though the boxes were grayed out.

    It appears to have let me delete it.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good job! ;)

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  21. gosh1976

    gosh1976 Private E-2

    thanks for all the help!!!

    I need to go to sleep now, work is gonna suck tomorrow. I want to wait to reboot a few times and run AVG at least one more time before I get rid of the unneeded files I'll do that tomorrow.

    I'll read through the protecting yourself post tomorrow as well and the first order of business is resolving my "issue" with not being able to run windows update. I think I'm still running one of the very first builds post beta testing with never having run windows update once!
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. The first step in the How to protect link is going to Windows Update. Perhaps it may even work now after fixing all the malware problems you had. Give it a try and see. If not, you may have to post in the Software Forum for help on that. You may having some missing or corrupted files in your OS. Sometimes just re-registering a few DLLs even fixes it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds