HELP ! Zentom System Guard took over!!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ilener, Jul 30, 2011.

  1. ilener

    ilener Private E-2

    All of a sudden this message, which is still popping up every 30 seconds, came up, I closed it, suddenly the huge window opens and "Zentom System Guard Installer" begins to install malware!!!

    No Task Mngr
    No control alt delete
    Nothing.
    Turn off power immediately.
    Too late.

    I cannot open...
    task manager
    dos prompt
    regedit
    msconfig

    Avast found nothing
    Spybot found nothing

    I deleted Zentom fro QUicklaunch, and application data, but it's probably renamed itself.

    Ahhhh! :cry:cry:cry:cry:cry

    Please help!!!
    I've searched on here but found nothing. This malware has taken over my pc and I can't do anything at the moment to delete it.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.


    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post )


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.


    Then try running these instructions: Using MGtools


    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • a log from online SAS scan if you could make one
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  3. ilener

    ilener Private E-2

    I followed all of the links, all of the directions, ran all the programs except the Windows OS Cleaning Software link and some programs I needed to restart a few times before they would run.
    At this moment the Zentom seems to be gone. I have included a hijackthis log and await your reply.
    Thank you!

    I am unable to run the Windows OS Cleaning Software link from your webpage, it closes each time.


    This log file is located at C:\rkill.log.
    Please post this only if requested to by the person helping you.
    Otherwise you can close this log when you wish.

    Rkill was run on 07/30/2011 at 10:24:49.
    Operating System: Microsoft Windows XP


    Processes terminated by Rkill or while it was running:



    Rkill completed on 07/30/2011 at 10:25:20.

    This log file is located at C:\rkill.log.
    Please post this only if requested to by the person helping you.
    Otherwise you can close this log when you wish.

    Rkill was run on 07/30/2011 at 10:27:54.
    Operating System: Microsoft Windows XP


    Processes terminated by Rkill or while it was running:



    Rkill completed on 07/30/2011 at 10:28:14.

    exeHelper by Raktor
    Build 20100414
    Run at 10:28:58 on 07/30/11
    Now searching...
    Checking for numerical processes...
    Checking for sysguard processes...
    Checking for bad processes...
    Checking for bad files...
    Checking for bad registry entries...
    Resetting filetype association for .exe
    Resetting filetype association for .com
    Resetting userinit and shell values...
    Resetting policies...
    --Finished--

    Logfile of HijackThis v1.99.1

    (EDIT: Please ATTACH items to your posts!!)
     

    Attached Files:

    • HJT.txt
      File size:
      7.7 KB
      Views:
      7
    Last edited by a moderator: Jul 30, 2011
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to try another browser then or use another computer totally to transfer the tools needed over to the PC we are working on. I know you say everything seems better now but I would like to verify this by analysing the logs that you attach for me. :)

    Windows XP Malware Removal/Cleaning Procedure
     
  5. ilener

    ilener Private E-2

    Well, of course you are right!:major Its still there, just quieter. I did an Avast boot scan and its finding stuff that it doesn't like.

    Ok, so please tell me how to transfer the tools from another computer. Are you saying to just download them on a jump drive or similar and use that on my troubled computer?

    Just making sure.
    Ilene
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, use either a cd or a thumb drive to transfer the tools.
     
  7. ilener

    ilener Private E-2

    I've spent forever doing these scans and using a jump drive to get them on the pc. There is a MGTools folder in C:, I never saw anything more than a moment of a black window open and close.

    I was able to use RKill and have a log. Malwearbytes found a bunch of stuff, mbam log enclosed. Combofix worked fine. I never saw anything happen with MG Tools. Perhaps need further instructions on that.

    Here are my logs.
    thanks,
    Ilene
     

    Attached Files:

  8. ilener

    ilener Private E-2

    more logs.
    Hope I did this correctly.


    thanks Ilene
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\drivers\vvqc.sys
    c:\windows\system32\termvw32.dll
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.



    Now download and run SUPERantispyware as per the instructions and attach the log.

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  10. ilener

    ilener Private E-2

    Going down the list of things to do .. .Combofix and the script went fine. Couldn't seem to shut down Avast, so I uninstalled it, then ran Combofix and script again. Have log.

    Then, when I got to the Super AntiSpyware program, it won't run anything more than a quick black window that flashes and goes away. I tried it from the desktop, three times.

    :major After each time, a window I NEVER saw before opens up and says I'm infected and the title of this window & software is "XP ANTISPYWARE 2012".
    What the heck is that?!?! Never seen it before, and it keeps showing up each time I run the SAS program. I figured it was not valid since its not 2012 yet and I never saw it before, nor read about it on your pages.

    Running TDSKiller now.
     
  11. ilener

    ilener Private E-2

    Logs

    SAS Still won't run for more than a second with a black window.

    Here are my latest logs

    Ilener
     

    Attached Files:

  12. ilener

    ilener Private E-2

    I got MGTools to run,
    log attached.

    Ilener
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do you have your XP boot CD?
     
  14. ilener

    ilener Private E-2

    Yes, I sure do.

    There is some kind of 'fraud security" files that Spybot tried to delete, but can't because they are in use. Safe mode no longer works for me, can't open start menu or any programs.

    I feel like I'm watching a slow death :tired

    What's your suggestion?
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to use your Windows XP CD to boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    After running the fixmbr command then boot back to normal mode Windows and run MBRCheck again Then attach the log. Also explain if you are still having any malware problems.
     
    Last edited: Aug 10, 2011
  16. ilener

    ilener Private E-2

    I tried to run the Fixmbr and it warned me that it may result in having NO access to my files, which I cannot do at this moment because there are many files from my business on here and pictures that I could never retrieve again.

    So, I ran the MRBCheck once again and it found problems, fixed it. In addition I have tried for two days now to get the recovery console to run, but it refuses and just cycles back to the black window that says for me to choose whether I want to start Win XP normally or Recovery Console. No matter what I choose I am redirected there.

    Then I reinstalled my windows from the cd, under the "repair your windows" choice or whatever the exact title is. It did. Not good. In doing so it deleted my SP1, SP2, SP3. I managed to reinstall SP1. I am unable to install SP2 as it hangs in the first 1/5 of the installation after it checks files and gets your system ready. Tried it about four times, even re-downloaded it, too.

    Oh, I did run the Chkdsk /p and that went fine. I did that first before attempting Fixmbr.

    Due to the confidential files on my pc (I'm a psychologist) and other things I am afraid to open any programs on here at this time. I'm thinking about getting a newer, bigger hard drive today at Best Buy, installing windows XP on it (because I love XP and its easy to work with) and transferring my photos and business files, iTunes, and other important software data that I've created over the years on here. If I only transfer data, pics, microsoft excel files, Microsoft Word files...by making this nasty drive the drive 2, then it will not boot from it, only booting from the new hard drive. then take out the original drive and be done with it,maybe?!:confused

    Will this work?
    What do you suggest now? Its been over a week now.

    ps. I figured out where I got this p.o.s. Zentom software system murdered. I visited "baby daddy day" dot com after someone posted something funny about an experience with being told about some girl's baby daddy, so I was looking for a funny quote or line to post in reply... that is when Zentom took over my computer, hid the firefox download menu, denied access to TAsk Manager and infiltrated into every system file it could before I hit the power off button. Do Not go to this website, I sure never will again.
    :-o
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So attach a new log after running it again please? (considering you said it fixed something)
     
  18. ilener

    ilener Private E-2

    I would but I can't seem to find it, please tell me where it hides?
    :confused
     
  19. ilener

    ilener Private E-2

    Sorry, sometimes the 'blonde' gets in the way.
    Here is file.
    Still haven't gotten sp3 back on here yet.

    do you want another hijackthis log?
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The MBR still shows as "unknown" Now, that does not necessarily mean infected, however, if you are still having issues...

    Then the only way to go is to back up those important files and follow my previous instructoins in post # 15, THEN re-run MBRCheck again.
     
  21. ilener

    ilener Private E-2

    Everything seems to be running fine, will download SP3 now, hopefully my display improves.

    I want this invasive stuff off my computer, so I will "back up those important files and follow my previous instructoins in post # 15, THEN re-run MBRCheck again. "

    Most importantly, I want all of that garbage deleted. So, I'll get to work on this.
    :major
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let us know how you get on.
     
  23. ilener

    ilener Private E-2

    Finally I was able to get SP3 installed, but it was not easy.
    After trying numerous times, then failing to install using safe mode I started to end the processes running by using task manager. Some of them I knew could be turned off easily, the rest I had no clue. When I was down to about half or so, I started terminating the ones I didn't remember seeing on there before or often. Oh, the reason SP3 wouldn't install and most likely the reason I had such problems installing sp1 and sp2, was the same reason, perhaps.

    So, with SP3 installation stuck about 1/5 of the way, I was down to the shortest list I've ever had in task manager, then I closed a process called csrss.exe and instantly SP3 starting installing super, super fast and it completed. Rebooted, no problem. I have no idea why, perhaps you can tell me.

    Later when I get back home, I'll post the MBR log.
    How can you tell what processes are running that I really don't need to run? What log can I send you that would give you that info?
    :major
     
  24. ilener

    ilener Private E-2

    Not good. Something found.
    I wasn't sure what to choose at this point so please advise me.

    MWB log attached

    1- something about a disk
    2- repair
    3. exit
     

    Attached Files:

    Last edited: Aug 10, 2011
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Be very careful with ending processes you are not sure about with task manager. ;)

    Did you actually do this:

    and THEN re-run MBRCheck? If not, then that is exactly what I would like for you to do please.
     
  26. ilener

    ilener Private E-2

    ok
    I did the FIXMBR from WinXP disk
    MBR code detected
     

    Attached Files:

  27. ilener

    ilener Private E-2

    Had extra time, so ran combo Fix again
     

    Attached Files:

  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  29. ilener

    ilener Private E-2

    Well, I've been using the computer for a couple of days now and everything seems to work quite well. Its not slow, there seems to be nothing found in the SAS or Spybot, etc, so I'd like to free you up from my insane experience of being hijacked so you can help others.

    At this time, I believe I'm good to go.
    Thank you so much for showing me the way to fight these things and get them off of my pc!
    :major
    You're the best ever!:boxing
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please go to virustotal and upload the following files for analysis, and let me know the results.

    c:\windows\system32\termvw32.dll


    Could you please get this: termvw32.dll into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    log retrievable @ C:\collect.zip


    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      temlvw32.dll
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  31. ilener

    ilener Private E-2

    Damn!
    termvw32.dll
    Submission date:
    2011-08-15 17:46:35 (UTC)
    Current status:
    finished
    Result:
    17/ 43 (39.5%)

    VT Community

    not reviewed
    Safety score: -
    Compact
    Print results
    Antivirus Version Last Update Result
    AhnLab-V3 2011.08.15.00 2011.08.15 Trojan/Win32.Agent
    AntiVir 7.11.13.48 2011.08.15 TR/Agent.ojiq
    Antiy-AVL 2.0.3.7 2011.08.15 Trojan/Win32.Agent.gen
    Avast 4.8.1351.0 2011.08.15 -
    Avast5 5.0.677.0 2011.08.15 -
    AVG 10.0.0.1190 2011.08.15 Agent3.ZGJ
    BitDefender 7.2 2011.08.15 -
    CAT-QuickHeal 11.00 2011.08.13 -
    ClamAV 0.97.0.0 2011.08.15 -
    Commtouch 5.3.2.6 2011.08.15 -
    Comodo 9756 2011.08.15 Backdoor.Win32.DarkMoon.A
    DrWeb 5.0.2.03300 2011.08.15 -
    Emsisoft 5.1.0.8 2011.08.15 Trojan.Win32.Agent!IK
    eSafe 7.0.17.0 2011.08.15 -
    eTrust-Vet 36.1.8502 2011.08.15 -
    F-Prot 4.6.2.117 2011.08.15 -
    F-Secure 9.0.16440.0 2011.08.15 -
    Fortinet 4.2.257.0 2011.08.15 W32/Agent.OJIQ!tr
    GData 22 2011.08.15 -
    Ikarus T3.1.1.107.0 2011.08.15 Trojan.Win32.Agent
    Jiangmin 13.0.900 2011.08.15 -
    K7AntiVirus 9.109.5017 2011.08.15 Trojan
    Kaspersky 9.0.0.837 2011.08.15 Trojan.Win32.Agent.ojiq
    McAfee 5.400.0.1158 2011.08.15 Artemis!50C7385B09D3
    McAfee-GW-Edition 2010.1D 2011.08.15 Artemis!50C7385B09D3
    Microsoft 1.7104 2011.08.15 -
    NOD32 6380 2011.08.15 -
    Norman 6.07.10 2011.08.15 -
    nProtect 2011-08-15.01 2011.08.15 -
    Panda 10.0.3.5 2011.08.15 Generic Trojan
    PCTools 8.0.0.5 2011.08.15 -
    Prevx 3.0 2011.08.15 -
    Rising 23.71.00.03 2011.08.15 -
    Sophos 4.68.0 2011.08.15 -
    SUPERAntiSpyware 4.40.0.1006 2011.08.15 -
    Symantec 20111.2.0.82 2011.08.15 WS.Reputation.1
    TheHacker 6.7.0.1.277 2011.08.15 Trojan/Agent.ojiq
    TrendMicro 9.500.0.1008 2011.08.15 -
    TrendMicro-HouseCall 9.500.0.1008 2011.08.15 -
    VBA32 3.12.16.4 2011.08.15 Trojan.Win32.Agent.ohvi
    VIPRE 10172 2011.08.15 Trojan.Win32.Generic!BT
    ViRobot 2011.8.13.4621 2011.08.15 -
    VirusBuster 14.0.170.0 2011.08.15 -
    Additional information
    MD5 : 50c7385b09d3717e05fcc0b16a6591b4
    SHA1 : 9075a75f71d01b657387a4291c764f590a979fc3
    SHA256: 57f6ea998be432bf23586c4c0a82e970d1300ca40227936e54599e2c5db4f7a2

    Will zip the file asap and complete the rest
     
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, attach the collect.zip and also the systemlook log. We need to finish up. :)
     
  33. ilener

    ilener Private E-2

    I've searched everywhere and cannot find collect.zip, so I am posting it here.
    File name:
    termvw32.dll
    Submission date:
    2011-08-17 14:43:20 (UTC)
    Current status:
    finished
    Result:
    20/ 44 (45.5%)

    VT Community

    not reviewed
    Safety score: -
    Compact
    Print results
    Antivirus Version Last Update Result
    AhnLab-V3 2011.08.17.00 2011.08.17 Trojan/Win32.Agent
    AntiVir 7.11.13.113 2011.08.17 TR/Agent.ojiq
    Antiy-AVL 2.0.3.7 2011.08.17 Trojan/Win32.Agent.gen
    Avast 4.8.1351.0 2011.08.17 -
    Avast5 5.0.677.0 2011.08.17 -
    AVG 10.0.0.1190 2011.08.17 Agent3.ZGJ
    BitDefender 7.2 2011.08.17 Trojan.Generic.KDV.320183
    ByteHero 1.0.0.1 2011.08.17 -
    CAT-QuickHeal 11.00 2011.08.17 -
    ClamAV 0.97.0.0 2011.08.17 -
    Commtouch 5.3.2.6 2011.08.17 -
    Comodo 9776 2011.08.17 Backdoor.Win32.DarkMoon.A
    DrWeb 5.0.2.03300 2011.08.17 -
    Emsisoft 5.1.0.8 2011.08.17 Trojan.Win32.Agent!IK
    eSafe 7.0.17.0 2011.08.16 -
    eTrust-Vet 36.1.8506 2011.08.17 -
    F-Prot 4.6.2.117 2011.08.16 -
    F-Secure 9.0.16440.0 2011.08.17 Trojan.Generic.KDV.320183
    Fortinet 4.2.257.0 2011.08.17 W32/Agent.OJIQ!tr
    GData 22 2011.08.17 Trojan.Generic.KDV.320183
    Ikarus T3.1.1.107.0 2011.08.17 Trojan.Win32.Agent
    Jiangmin 13.0.900 2011.08.16 -
    K7AntiVirus 9.109.5021 2011.08.16 Trojan
    Kaspersky 9.0.0.837 2011.08.17 Trojan.Win32.Agent.ojiq
    McAfee 5.400.0.1158 2011.08.17 Artemis!50C7385B09D3
    McAfee-GW-Edition 2010.1D 2011.08.17 Artemis!50C7385B09D3
    Microsoft 1.7604 2011.08.17 -
    NOD32 6386 2011.08.17 -
    Norman 6.07.10 2011.08.16 -
    nProtect 2011-08-17.01 2011.08.17 -
    Panda 10.0.3.5 2011.08.17 Generic Trojan
    PCTools 8.0.0.5 2011.08.17 -
    Prevx 3.0 2011.08.17 -
    Rising 23.71.02.03 2011.08.17 -
    Sophos 4.68.0 2011.08.17 -
    SUPERAntiSpyware 4.40.0.1006 2011.08.17 -
    Symantec 20111.2.0.82 2011.08.17 WS.Reputation.1
    TheHacker 6.7.0.1.278 2011.08.16 Trojan/Agent.ojiq
    TrendMicro 9.500.0.1008 2011.08.17 -
    TrendMicro-HouseCall 9.500.0.1008 2011.08.17 -
    VBA32 3.12.16.4 2011.08.17 Trojan.Win32.Agent.ohvi
    VIPRE 10189 2011.08.17 Trojan.Win32.Generic!BT
    ViRobot 2011.8.17.4625 2011.08.17 -
    VirusBuster 14.0.173.0 2011.08.17 -
    Additional information
    MD5 : 50c7385b09d3717e05fcc0b16a6591b4
    SHA1 : 9075a75f71d01b657387a4291c764f590a979fc3
    SHA256: 57f6ea998be432bf23586c4c0a82e970d1300ca40227936e54599e2c5db4f7a2
    ssdeep: 3072:IcMWUimHHFDJQpBxUGy3bvAgsvo2ARg9sD312fA6nwPm6L21BQhV8Kf/:IcMWUimFdQpBd
    yUX3RsZ2vkmHihF
    File size : 218624 bytes
    First seen: 2011-08-01 00:54:59
    Last seen : 2011-08-17 14:43:20
    TrID:
    Win32 Executable Generic (58.3%)
    Win16/32 Executable Delphi generic (14.1%)
    Generic Win/DOS Executable (13.7%)
    DOS Executable Generic (13.6%)
    Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
    sigcheck:
    publisher....: Intel Corporation
    copyright....: Copyright 1999-2009, Intel Corporation
    product......: Intel(R) CPU Performance
    description..: itlperf Module
    original name: itlperf.dll
    internal name: itlperf
    file version.: 1, 0, 0, 0
    comments.....: This installation was built with Inno Setup.
    signers......: -
    signing date.: -
    verified.....: Unsigned
    PEInfo: PE structure information

    [[ basic data ]]
    entrypointaddress: 0x17958
    timedatestamp....: 0x2A425E19 (Fri Jun 19 22:22:17 1992)
    machinetype......: 0x14c (I386)

    [[ 7 section(s) ]]
    name, viradd, virsiz, rawdsiz, ntropy, md5
    CODE, 0x1000, 0x1699C, 0x16A00, 6.59, 2cbbe99a5e0ba0d985067081b6134a51
    DATA, 0x18000, 0x27E0, 0x2800, 3.26, 3260507c9d51efb3154e29bab43d10a4
    BSS, 0x1B000, 0x9B1, 0x0, 0.00, d41d8cd98f00b204e9800998ecf8427e
    .idata, 0x1C000, 0x6B6, 0x800, 4.19, 0ba2dc7a3b2d6fed614fe9154944751a
    .edata, 0x1D000, 0x4A, 0x200, 0.76, 1f12731aff1de074399e71554b8bf3bc
    .reloc, 0x1E000, 0x1110, 0x1200, 6.61, dc3b5ec06c23d2d99337d1350df05aad
    .rsrc, 0x20000, 0x1A22C, 0x1A400, 7.94, 8321d75891cd5431b418e24597991e57

    [[ 8 import(s) ]]
    kernel32.dll: GetCurrentThreadId, WideCharToMultiByte, ExitProcess, UnhandledExceptionFilter, RtlUnwind, RaiseException, GetSystemTime, FreeLibrary, HeapFree, HeapReAlloc, HeapAlloc, GetProcessHeap
    oleaut32.dll: SysFreeString, SysReAllocStringLen
    kernel32.dll: TlsSetValue, TlsGetValue, TlsFree, TlsAlloc, LocalFree, LocalAlloc
    kernel32.dll: WriteFile, VirtualQuery, Sleep, SizeofResource, SetLastError, SetFilePointer, SetEndOfFile, ReadFile, LoadResource, GlobalUnlock, GlobalLock, GetTickCount, GetSystemTime, GetProcAddress, GetLocalTime, GetLastError, GetFileSize, GetCurrentProcess, FreeLibrary, FreeConsole, CreateProcessA, CloseHandle
    advapi32.dll: RegCloseKey
    user32.dll: wvsprintfA, MessageBoxA
    kernel32.dll: LoadLibraryA, GetWindowsDirectoryA, GetVersionExA, GetTimeFormatA, GetTempPathA, GetSystemDirectoryA, GetModuleHandleA, GetModuleFileNameA, GetFileAttributesA, GetDateFormatA, GetComputerNameA, GetCommandLineA, FindResourceA, CreateFileA, CompareStringA
    advapi32.dll: RegSetValueExA, RegQueryValueExA, RegQueryInfoKeyA, RegOpenKeyExA, RegEnumValueA, RegCreateKeyExA, GetUserNameA, CreateProcessAsUserA

    [[ 1 export(s) ]]
    ServiceMain
    ExifTool:
    file metadata
    CharacterSet: Unicode
    CodeSize: 92672
    Comments: This installation was built with Inno Setup.
    CompanyName: Intel Corporation
    EntryPoint: 0x17958
    FileDescription: itlperf Module
    FileFlagsMask: 0x003f
    FileOS: Win32
    FileSize: 214 kB
    FileSubtype: 0
    FileType: Win32 DLL
    FileVersion: 1, 0, 0, 0
    FileVersionNumber: 1.0.0.0
    ImageVersion: 0.0
    InitializedDataSize: 124928
    InternalName: itlperf
    LanguageCode: Neutral
    LegalCopyright: Copyright 1999-2009, Intel Corporation
    LegalTrademarks:
    LinkerVersion: 2.25
    MIMEType: application/octet-stream
    MachineType: Intel 386 or later, and compatibles
    OSVersion: 4.0
    ObjectFileType: Executable application
    OriginalFilename: itlperf.dll
    PEType: PE32
    PrivateBuild:
    ProductName: Intel(R) CPU Performance
    ProductVersion: 1, 0, 0, 0
    ProductVersionNumber: 1.0.0.0
    SpecialBuild:
    Subsystem: Windows GUI
    SubsystemVersion: 4.0
    TimeStamp: 1992:06:20 00:22:17+02:00
    UninitializedDataSize: 0
     

    Attached Files:

  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
     
    File::
    c:\windows\002552_.tmp
    c:\windows\000001_.tmp
    c:\windows\SET13D.tmp
    c:\windows\SET131.tmp
    c:\windows\system32\termvw32.dll
    C:\Documents and Settings\LocalService\Local Settings\Application Data\fdvt87420h448sffo45xpbwi647n672cbp055gxv         
    C:\Documents and Settings\Ilene\Application Data\fdvt87420h448sffo45xpbwi647n672cbp055gxv
    C:\Documents and Settings\All Users\Application Data\fdvt87420h448sffo45xpbwi647n672cbp055gxv
    C:\Documents and Settings\All Users\Application Data\2398310668
    C:\Documents and Settings\Ilene\Templates\fdvt87420h448sffo45xpbwi647n672cbp055gxv
     
    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termssvces]
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.



    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :regfind
      termssvces*
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
    Last edited by a moderator: Aug 18, 2011
  35. ilener

    ilener Private E-2

    Thanks, I will get this done over the next few days, working alot :p starting tomorrow, but will do this.

    Can you tell me what we are doing, what we are trying to get rid of, because it looks like there's a lot more here than just this Zentom junk. Does my harddrive have all those trojans, etc, that were listed in that text?

    What's the mission here:major, because I feel lost. (we need to do ____ because ____) would be helpful.

    Sure is amazing how messed up this is and I wish I understood what your plan is.:confused
     
  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good.

    Yes, we are seeing a number of files which should not be on your machine, such as the ones listed.

    We need to remove crap from your machine in plain terms, for obvious reasons.
    To get you clean! :-D
     
  37. ilener

    ilener Private E-2

    we are seeing a number of files which should not be on your machine, such as the ones listed.

    Exactly what I wanted to know.
    Thanks so much
     
  38. ilener

    ilener Private E-2

    Need Correction

    I just tried to run Combofix with the text you gave me and it says exactly this ... 'were you trying to run a cf script? the name of the script was incorrectly spelt" ...and then it shuts down.

    Also, I need to run it on my second drive F: because I installed a new drive and moved the infected one over. So, I was thinking to run it on C: and then change the C: to F: to send you both logs. Is this correct?

    What is misspelled in the script?:confused
    KILLALL::

    File::
    c:\windows\002552_.tmp
    c:\windows\000001_.tmp
    c:\windows\SET13D.tmp
    c:\windows\SET131.tmp
    c:\windows\system32\termvw32.dll
    C:\Documents and Settings\LocalService\Local Settings\Application Data\fdvt87420h448sffo45xpbwi647n672cbp055gxv
    C:\Documents and Settings\Ilene\Application Data\fdvt87420h448sffo45xpbwi647n672cbp055gxv
    C:\Documents and Settings\All Users\Application Data\fdvt87420h448sffo45xpbwi647n672cbp055gxv
    C:\Documents and Settings\All Users\Application Data\2398310668
    C:\Documents and Settings\Ilene\Templates\fdvt87420h448sffo45xpbwi647n672cbp055gxv

    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termssvces]
     
    Last edited: Aug 21, 2011
  39. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you save it exactly as Kes indicated > CFscript.txt?
     
  40. ilener

    ilener Private E-2

    I copied and pasted it from his reply. Also posted it below my message.

    I think I figured it out. I named the txt file something else.
    Just fixed it
     
  41. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I was referring to this:
    Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe.

    Ah, I see you edited your reply. Good to know you fixed it. Carry on. :)
     
  42. ilener

    ilener Private E-2

    It looks like mgtools only ran the getlogs.bat on drive c;
    I attempted to go directly to drive F (the original infected drive) but the screen said it was looking on c.

    Should I wait and see if it runs on F or is there something I can change ?

    Thanks
     

    Attached Files:

  43. ilener

    ilener Private E-2

    more
     

    Attached Files:

  44. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Conduit Engine <--- uninstall this junk.

    Please disable Spybot's TeaTimer.

    How to disable Spybot's TeaTimer

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\Ilene Richardson\Desktop\termvw32.dll
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    Run a full system scan with both Malware Bytes and SUPERantispyware with the F drive plugged in and make sure you include it for scanning.

    Let me know the results. Attach their logs.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  45. ilener

    ilener Private E-2

    Did I forget something?
     

    Attached Files:

  46. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, you forgot to uninstall conduit engine.

    Delete this folder

    C:\Documents and Settings\Ilene Richardson\Application Data\PriceGong

    Those logs look good apart from that, tell me what malware problems remain?
     
  47. ilener

    ilener Private E-2

    I didn't know what a Conduit Engine was and didn't know Price Gong was even there, whatever that was. Its deleted now.

    Things seem to be working just fine.

    Your help in resolving this incident was remarkable and more thorough than I ever expected.

    Please tell me what you suggest to keep running or to complete daily/weekly scans with what software? I don't want to get in this position again, ever, if I can help it.

    Appreciate all you've guided me with here. ;)
     
  48. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  49. ilener

    ilener Private E-2

    Do I also uninstall Conduit Engine? I see that in the add/remove programs list.
     
  50. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds