help

Discussion in 'Malware Help (A Specialist Will Reply)' started by mose32, Jul 30, 2006.

  1. mose32

    mose32 Private E-2

    I am running xp with sp2. I have done my best to follow all of the steps in the "READ AND RUN ME FIRST..." thread. I have attached the logs from BitDefender, Panda, and HJT. In the course of running many of the scans I recieved messages from AnitVir Guard telling me about several variations of trojan horses...I clicked ok to deny access for all to them. What next??
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please install HijackThis as requested in step 7 of the READ ME. It is a very bad idea to install anything like this:

    C:\SPYWARE_TOOLS\analyse.exe

    How would you know what it is this way and how would anyone else look at your log know? Using C:\Program File\HijackThis\analyse.exe or C:\Program File\HJT\analyse.exe is much more obvious and is the correct place to run programs from anyway.

    Look for Acceleration Software Anti-Virus or eAcceleration in Add/Remove programs and uninstall it if found.

    Now Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.seektheglobe.com/sp2.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.seektheglobe.com/sp2.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.seektheglobe.com/sp2.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.seektheglobe.com/sp2.php
    R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    R3 - URLSearchHook: (no name) - {0026AD90-C86F-4269-97F3-DAB4897C6D06} - (no file)
    R3 - URLSearchHook: (no name) - {9368D063-44BE-49B9-BD14-BB9663FD38FC} - (no file)
    O4 - HKLM\..\Run: [WebScan] C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe -k
    O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
    O4 - HKLM\..\Run: [System service79] C:\WINDOWS\etb\pokapoka79.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O15 - Trusted Zone: http://www.launch.com

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Acceleration Software <--- the whole folder
    C:\WINDOWS\etb <--- the whole folder
    c:\program files\MedCh <--- the whole folder or file
    c:\program files\winex <--- the whole folder or file
    c:\windows\NDNuninstall4_80.exe
    C:\WINDOWS\NDNuninstall5_40.exe
    C:\WINDOWS\NDNuninstall5_48.exe
    C:\WINDOWS\NDNuninstall5_64.exe
    C:\WINDOWS\NDNuninstall6_10.exe
    C:\WINDOWS\NDNuninstall6_22.exe
    C:\WINDOWS\NDNuninstall6_98.exe
    C:\WINDOWS\NDNuninstall7_22.exe
    C:\WINDOWS\system32\drivers\etc\hosts.bho
    C:\WINDOWS\SYSTEM32\InstaFinder_inst245.exe
    C:\WINDOWS\system32\im64.dll
    C:\WINDOWS\SYSTEM32\xmltok.dll
    C:\Documents and Settings\Kyle Moser\Favorites\-Autos-
    C:\Program Files\Common Files\SearchUpgrader\client.cfg
    C:\Program Files\Common Files\SearchUpgrader\system.cfg
    C:\Program Files\Netscape\Communicator\Program\Plugins\NPMySrch.dll
    c:\windows\inf\dm.inf
    c:\windows\ss3unstl.exe


    Additional step to delete files in the Downloaded Program Files folder :
    - Click Start, Run, and enter cmd in the box and click OK. This opens a command prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s f3initialsetup1.0.0.5.inf
    del f3initialsetup1.0.0.5.inf
    exit

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Jul 30, 2006
  3. mose32

    mose32 Private E-2

    First of all, Thanks for your help chaslang!

    Sorry about the folder confusion earlier. I followed the steps that you posted, but I did not find the first two folders that you instructed me to delete after booting in to safe mode. (I made sure that all hidden files were showing.) I have attached the latest HJT log.

    The Avira AntiVir program that I am running has not indicated any other trojans (I am still scanning), but my computer is still pretty sluggish. This may be a result of 4 years of clutter that I should try to clean up.

    Any suggestions? Is this a good time to disable/re-enable system restore?
     

    Attached Files:

  4. mose32

    mose32 Private E-2

    I spoke too soon...AntiVir just picked up TR/Dldr.Keenval.3
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    More than like it is due to what you are running, how much free disk space you have, how much RAM you have, the speed of your PC, how badly fragmented your hard disk is etc.

    You need to update to the current Sun Java version and uninstall all old versions.
    See: Sun Java Runtime Environment


    Your HJT log is free from malware. You can however have HJT fix the below items which are a waste of system resources and are not necessary:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    You should also reconsider whether you really need the below:
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe

    Using a browser like FireFox with built-in popup protection removes the need for a popup blocker which I don't see the need for at all.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where did it find it? Is it just in System Restore which we have not flushed yet?
     
  7. mose32

    mose32 Private E-2

    I am attaching a scan log of my C drive. (I also have an F drive, which I probably should have told you about before.) It appears as though many of the warnings refer to restore locations, but not all. It also appears as if there are some temporary internet explorer files from version 5 even though I have version 6.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Empty your AntiVir quarantine folder then per step 1 of the READ ME, disable system restore, reboot, and then enable system restore. Now run a new scan with Antivir and attach the new log.
     
  9. mose32

    mose32 Private E-2

    Good news! (I think)...AnitVir only picked up one file with the signature of the W32/Spreder.

    Nevertheless, here is my log.

    Thanks for all the help! This is quickly becoming my favorite site, ever.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Do you know what the below file is? Did you download it? Do you need it? If not, delete it if still found but it looks like Antivir already may have move it to the quarantine.

    C:\Documents and Settings\Kyle Moser\My Documents\Other\Funny Stuff\Funny Stuff\whipworker.exe


    If you are not having any other malware problems, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds