help with malware and viruses

Discussion in 'Malware Help (A Specialist Will Reply)' started by neilconlisk, Nov 14, 2007.

  1. neilconlisk

    neilconlisk Private E-2

    i have been having problems with pop-ups and security toolbar, i followed the malware removal manual on MG.com and im going to attach all my log files, any help will be appreciated
     

    Attached Files:

  2. neilconlisk

    neilconlisk Private E-2

    here are some more logs
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Where is the requested log from BitDefender Online scan?

    You appear to have ignore step 3 of the READ ME. I see Avast and McAfee installed. You must uninstall one of these now.

    You also installed HijackThis exactly where we specified not to install it in step 7 of the README. Please install it properly into the folder we requested. Then continue with the below.

    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Viewpoint Media Player


    Download this file - combofix.exe
    1. Double click combofix.exe & follow the prompts.
    2. When finished, it will produce a log ( C:\combofix.txt ) for you. Attach this log to your next reply See: HOW TO: Attach Items To Your Post
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    4. the ComboFix log
     
  4. neilconlisk

    neilconlisk Private E-2

    here's the new runkey newfile and hijack this logs
     

    Attached Files:

  5. neilconlisk

    neilconlisk Private E-2

    here's the bit defender scan as a text file, sorry about that it wouldn't load as an html document and i forgot to post it before
     

    Attached Files:

  6. neilconlisk

    neilconlisk Private E-2

    here's the combofix log



    and i uninstalled viewpoint mcafee and the old java version



    thanks for the help, the combofix.exe seemed to reduce the popups, thanks. any other suggestions?
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ComboFix was in the procedure before getting the new logs. You ran things in the wrong order. Thus you will need to attach new logs from GetRunKey, ShowNew and HijackThis now.
     
  8. neilconlisk

    neilconlisk Private E-2

    i haven't been able to access the major geeks website from my laptop. im assuming more malware. I also cannot attach or copy the logfiles into an email to transfer them to a different computer.

    please help
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First please install GetRunKey and ShowNew properly. They must not be on your Desktop nor in your My Documents folder with dozens of other files. They need to be in there own folder as requested in the READ ME. Please put them in C:\MGtools You can put all the files from GetRunKey.zip and ShowNew.zip into this folder.

    Uninstall the CounterSpy trial now since we are finished with it.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    O2 - BHO: (no name) - {0665A09F-BE85-42B2-9D28-35B80C0DDA99} - (no file)
    O2 - BHO: (no name) - {1CAC234C-620B-493E-8016-197E5E03287D} - (no file)
    O2 - BHO: (no name) - {7C11EBC8-4DD2-4E98-803F-A3C42146133C} - C:\WINDOWS\system32\jkhhg.dll
    O2 - BHO: (no name) - {820A2C8D-DFC0-4A9F-B3CA-4410CA4F7C04} - C:\WINDOWS\system32\cbxwtuv.dll
    O2 - BHO: (no name) - {8FB5B012-E8CB-46cd-B6D2-ED428FAE9043} - (no file)
    O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\jtzrtjmb.dll
    O2 - BHO: (no name) - {c5378c28-8be8-4ed5-9d87-d56a5157a6da} - C:\WINDOWS\system32\bdyhhil.dll (file missing)
    O2 - BHO: 0 - {EEBA1963-91AE-418C-3CB3-478B643910FE} - C:\Program Files\Online Services\quhas537.dll (file missing)
    O2 - BHO: (no name) - {F6560C76-8962-45AD-9C02-4A5C86A19429} - C:\Program Files\Internet Explorer\mevozudemC:\DOCUME~1\NEILCO~1\LOCALS~1\Temp\CEMG555077.exe.dll (file missing)
    O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\jtzrtjmb.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [winshow] "C:\WINDOWS\winshow.exe"
    O4 - HKLM\..\Run: [plite731] C:\WINDOWS\plite731.exe
    O4 - HKLM\..\Run: [60b70284] rundll32.exe "C:\WINDOWS\system32\ipoghajc.dll",b
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
    O20 - Winlogon Notify: jtzrtjmb - C:\WINDOWS\SYSTEM32\jtzrtjmb.dll

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.
    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    If you could not run Avenger for any reason, boot into safe mode and manually delete as many of the below files and folders as the system allows you to delete and then reboot into normal mode to continue with ATF-Cleaner.
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!
     
  10. neilconlisk

    neilconlisk Private E-2

    i followed the instructions, i still cant access the major geeks website. i also cannot upload certain files, such as a specific word perfect document, to an email attachment or other places that i previously attempted to load the show new and getrunkey and HJT logfiles, i also cannot copy and paste any of the log files to e-mails. this may be due to the fact that i tried to fix some of the entries on HJT prior to getting advice. such as some of the files under BHO in the log file.

    other than that, there are less popups on the computer, it seems that those problems have been partially if not completely fixed, i haven't seen any signs of the security toolbar and the security warning pop ups.

    so yeah, i can't access certain websites or attach certain files
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the 4 follow up logs I requested at the end of my previous instructions so that I can continue to help you. You need to find a way of copying those logs to another PC if necessary and then attaching them. Or you can try to put all 4 logs into a ZIP file and attach it. Either way I need the logs to know whether the fixes worked and what state your PC is in.
     
  12. neilconlisk

    neilconlisk Private E-2

    there you go
     

    Attached Files:

  13. neilconlisk

    neilconlisk Private E-2

    and hijack this
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your logs it looks like you did not do what was requested. They even still show CounterSpy installed which was the first thing I asked you to uninstall. I recommend that you start at the beginning of message #9 and do everything again even though some items may no longer be there. Make sure you follow all steps in the order written and then attach new logs. Make sure you obtain the logs at the end of the process not during the process (ie., the HijackThis log must be obtained at the end not while you are fixing things with HijackThis). Also make sure you shutdown your browser before fixing with HijackThis and it would not hurt to shutdown any active protection from antivirus and antispyware programs while doing the fix.

    There are some new things in your logs too that will have to get fix but we need to have a little more success with the previous fix first. Also McAfee did not get completely uninstalled so we will have to correct that too.
     
  15. neilconlisk

    neilconlisk Private E-2

    the avenger log had an error i think, nothings really in the text file i will p ost it anyway
     

    Attached Files:

  16. neilconlisk

    neilconlisk Private E-2

    heres the other one,

    hope i did it all right this time
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your logs you either did not do the fixes or something went completely wrong especially since Avenger did not work at all. Please run the procedure in message # 9 again. Be careful to follow all steps exactly and in the order written. Also shut down all browsers, antivirus, and antispyware programs before running the steps. Print the procedure or save it to a Word file on your PC for reference because I want you to have all browsers closed this time.
     
  18. neilconlisk

    neilconlisk Private E-2

    i hope this is good

    more updates, now every time i do a google search links redirect me to ad pages, and there seems to be some weird stuff going on with the spell chack in word perfect, its not recognizing simple words.
     

    Attached Files:

  19. neilconlisk

    neilconlisk Private E-2

    thanks for the help and patience, this is a longer process than i expected, and its rare that i can make it to a computer that will allow me to access the majorgeeks website
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please delete the below copy of HijackThis. This is not the correct location for it to be run from.
    C:\Documents and Settings\Neil Conlisk\Desktop\hijackthis\analyzethis.exe


    McAfee did not uninstall properly. Please run this: McAfee Consumer Product Removal Tool

    Now run this: WareOut Removal and attach the requested log from FixWareOut.

    Now we need to get you on board with using the new versions of GetRunKey and ShowNew which are part of a program named MGtools. Please follow the directions in this link: Using MGtools and then attach the requested C:\MGlogs.zip file. This will contain 5 logs in a single attachment. You will no longer have to run and attach separate logs from GetRunKey, ShowNew and HijackThis.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds