Help with virus/malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by ForumEclipse, Dec 3, 2006.

  1. ForumEclipse

    ForumEclipse Private E-2

    Hi, my computer has become infected after stupidly opening a .exe file I shouldn't have...virus 101 i know. But anyway I'm infected now. I've run McAfee virus scan and it removed what it could. Whenever I start my computer it alerts me something is trying to access the internet that I think is a part of the virus, so I always block its access. Right now my main symptoms are a very laggy system.

    I've run everything through step 7 in this thread http://forums.majorgeeks.com/showthread.php?t=35407

    So here are my attached logs for CounterSpy, BitDefender, and PandaActiveScan. I'll do the next 3 in the next post.

    Thanks for any help, the other thread was already a big help.
     

    Attached Files:

  2. ForumEclipse

    ForumEclipse Private E-2

    And here are the logs for GetRunKey, ShowNew, and HijackThis!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Now run this Virtumonde aka Trojan Vundo Removal - and save the log

    Now attach new logs from:
    • both logs from SmitFraudFix (if not already attached)
    • VundoFix
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?
     
  4. ForumEclipse

    ForumEclipse Private E-2

    ok, here is the log from the first step. Now I'll move on to the second...
     

    Attached Files:

  5. ForumEclipse

    ForumEclipse Private E-2

    And here are the logs for the 2nd SmitfraudFix, GetRunKey, and ShowNew
     

    Attached Files:

  6. ForumEclipse

    ForumEclipse Private E-2

    And here are the VirtuMonde and new HijackThis! logs.

    I have noticed my computer is running more smoothly than it had been. Whenever I start it in normal mode however I still have to block the D?XPLORE.exe from accessing the internet via McAfee. Also McAfee has a virus scanner that when enabled is a constant background scanner. However I have been unable to enable this function since the infection. I click enable and nothing happens.

    Also it may be unrelated by by desktop has been switched to None, the blue screen, and my internet downloaded wallpaper is gone. Just throwing that out there as a thought.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because we have not address this issue yet. You had a lot of problems that need to be worked separately. This is a PurityScan infection and my steps below should address this along with a whole bunch more problems! You need to be more careful where you are surfing and what you are downloading.

    Let's wait until all malware is remove but you may have to do a reinstall to fix it (if you really need this).

    It is related! This happened due to your SmiFraud problems. A necessary evil of cleaning the infection. You should be able to set them back to what you want now.

    Now let's continue with your Malware Cleanup!
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Make sure you tell me how things are working now!

    After running ComboFix, some items in the below steps (like the d?xplore.exe stuff) should be gone. So if anything indicated is not seen, just continue on thru all steps.


    I see this next item in your installed program list! It appears to be very questionable! Did you install this?
    ?MILKú??????(c)BLUEGALE

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 7
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.2_03

    Now install the current version of Sun Java from: Sun Java Runtime Environment


    Continue by downloading a tools we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.
    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\?ymbols\d?xplore.exe

    After killing all the above processes, click Back. Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {8ACFECE0-0302-04F0-7E34-20D7390A64C3} - C:\WINDOWS\system32\zcmkspj.dll
    O2 - BHO: (no name) - {20A0DC74-922E-C87F-2EB1-0B204EDD569F} - C:\WINDOWS\system32\agslplc.dll
    O2 - BHO: (no name) - {309DCBD9-21E2-47A7-A498-C8DB7A36CEF1} - C:\WINDOWS\system32\awtqr.dll (file missing)
    O2 - BHO: (no name) - {8ACFECE0-0302-04F0-7E34-20D7390A64C3} - C:\WINDOWS\system32\zcmkspj.dll
    O3 - Toolbar: Safety Bar - {fbea0445-4c4a-4136-864a-c72a4a182a84} - C:\Program Files\Safety Bar\SafetyBar.dll (file missing)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WINDOWS] C:\nmkrwa.exe
    O4 - HKCU\..\Run: [Flymk] C:\WINDOWS\?ymbols\d?xplore.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O20 - Winlogon Notify: winjvd32 - winjvd32.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\-2071625813
    C:\eodatgth.exe
    C:\sqbaln.exe
    C:\nmkrwa.exe
    C:\WINDOWS\system32\jaipdwcg.exe
    C:\WINDOWS\system32\swxcacls.exe
    C:\WINDOWS\system32\wtssu.exe
    C:\WINDOWS\system32\agslplc.dll
    C:\WINDOWS\system32\drvxag.dll
    C:\WINDOWS\system32\qnsktwtq.dll
    C:\WINDOWS\system32\uefslrby.dll
    C:\WINDOWS\system32\zcmkspj.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\ipwins
    C:\Program Files\VSAdd-in
    C:\Program Files\Common Files\{34857FAB-07CA-1033-1217-051201050001}
    C:\Program Files\Common Files\{84857FAB-07CA-1033-1217-051201050001}

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. ForumEclipse

    ForumEclipse Private E-2

    That whole process seemed to go smoothly, so here the three logs.

    Also, ?MILKú??????(c)BLUEGALE is the remnant of a very old game I had long ago that I have long since deleted, but it refuses to leave my Add/Remove Program List. I have deleted everything I can find related to it, but it won't go away. It was a japanese game, thus the ?'s, and when i click it an intelligible error message comes up with ?'s and other symbols, presumably to stand for the lack of japanese characters. If you happen to know a way to remove this from my program list that would be great.

    I can already tell the difference, everything seems to be running smoothly, and the D?XPLORE.exe trying to access the internet message is no longer coming up when i start my computer.

    Thanks!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try using this: Your Uninstaller! 2006


    I need the log from ComboFix but your other logs are clean! Are you having any other problems at this time?
     
  10. ForumEclipse

    ForumEclipse Private E-2

    oh sorry heres that log

    And I think thats about it, everything seems to be working ok now :)

    And i got Your Uninstaller! 2006, unfortunatly it dosnt even show the old program, so it must just be something with Add/Remove program. i'm almost sure its nowhere on my computer, so at least its not hurting anything.

    Thanks for all the help!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Okay then uninstall Your Uninstaller which is only a trial anyway. And run the steps in the below link and attach the log.

    Getting Uninstall Programs List From The Registry
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds