HiJackThis log - Please Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Nybes, Oct 2, 2006.

  1. Nybes

    Nybes Private E-2

    My PC is getting torn apart by a selection of viruses, trojans, and diallers.

    I really am desperate. I'm three weeks away from submitting my thesis, and if I can't get my machine back in working order within a couple of days, I'm basically ****ed.

    I've gone through the 'Read & Run me first' procedures, with little luck. Running Spybot gave me a blue screen of death. CCleaner didn't help, and I am unable to maintain an internet connection for long enough to use PandaScan.

    I'm posting my HijackThis log here in hope of a quick response. If anyone can see any glaring issues in the log, and offer me some advice, it will be greatly appreciated.

    I will reformat if there's no other option, however this will mean losing a weeks work and specialist software that I won't be able to reinstall until it's too late.

    Any advice or suggestions are welcome.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You need to do a better and more complete job of following the directions in the READ & RUN ME. Even if you cannot run Bitdefender and Panda ( and I don't see any reason why), this still does not explain why you have not attached the logs from GetRunKey and ShowNew as requested. And also you did not rename HijackThis.exe as requested which as stated is very important.

    Please attach the GetRunKey, ShowNew, and a new HJT logs (after and renaming HJT as requested).
     
  3. Nybes

    Nybes Private E-2

    Thanks for your response.

    I'll admit to not following the READ & RUN ME procedure as thoroughly as I might. Due to time constraints, I skipped any step that caused my PC to crash after only one attempt.

    I will persevere next time. I won't be able to take a full day off to run scans again until the end of the month (I've borrowed a friend's laptop for the meantime).

    I will post the three logs requested, together with a brief outline of symptoms, around or about the 25th of October. When I do this, would it be best to start a new thread, or continue with this one?


    Again, thanks for providing this service offering support to woebegone PC users.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It would be best to locate this thread and continue! Why do you need to wait so long to get those logs. GetRunKey and ShowNew only take about 10 secs each to run on even a slow PC. Or are you saying you skipped other parts of the READ ME which do take a longer time to run?
     
  5. Nybes

    Nybes Private E-2

    Here are a list of the symptoms I'm experiencing, and a breakdown of the steps in the READ AND RUN ME.


    -Every 2-3 hours, whether online or offline, a dialler named "coolweb" appears in my Network Connections, along with a Task Manager process "cool.exe". The process can be stopped, and the dialler deleted, but both re-appear shortly afterwards. I've tried running a program called CoolWebShredder to get rid of this, it was unsuccessful.

    -When online, periodically the connection fails, and a dialler named "user********" (where ******** is a chain of random numbers) appears in my Network Connections and attempts to dial. If I try to access the dialler Propeties, I get an error message. The dialler can only be deleted after manually unplugging the modem and rebooting.

    -When not online, I periodically have a "Work Offline" dialog pop up, as if something has tried and failed to access the internet. This occurs approx every 30 minutes.

    -I've found a trojan Svchost.exe in my Program files/Common files/ directory. I can stop the process in Task Manager, and delete it, but it reappears after 6-12 hours.

    -When online, I continually have Internet Explorer windows pop up (although Firefox is my default browser). There are two varieties of these pop-ups. The first appear without warning, and are usually ads for online casino sites or 'delete you porn browsing history' programs. The second variety are accompanied by a flashing exclamation point that appears in the notifactions taskbar. These first pop up a system security warning from the taskbar, then open a IE window with an ad for one of several dodgey spyware removal programs.

    -When logged in as administrator, I'm met with an empty desktop. If I attempt to lauch Explorer through the task manager, the desktop appears for about five seconds, then disappears again. This prevents me from running scans etc on the administrator account.

    -When running registry and system scans, I occasionly get a BSoD stating that a irrecoverable error has occured in the Winlogon module. This only seems to occur when running scans.



    Breakdown of the steps in READ AND RUN ME

    0: Preliminary House Cleaning & Setup
    -completed sucessfully

    1: Secondary House Cleaning
    -completed successfully other than being unable to run CCleaner on Administrator account.

    2: Enable viewing of hidden files, system files and file extensions
    -done

    3: Do not use Multiple Antivirus Applications or Software Firewalls
    -n/a

    4: Downloading Tools
    -getrunkey - done
    -shownew - done
    -spybot - unable to stay online long enough to download
    -Microsoft Windows Defender/ XP SP2 - unable to stay online long enough to download
    -CounterSpy - unable to stay online long enough to download
    -Hijack This! – done

    5: Cleaning Malware
    -only able to run CCleaner, and even then, not on Administrator account.

    6A: Online Virus And Trojan Scanning
    -unable to stay online long enough to run Bitdefender and Pandascan

    6B: Scanning for Additional Info
    -done

    7: HijackThis log posting
    -done

    I've attached the three logs requested.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm going to post two messages! This is the first! Complete this procedure completely including attaching the requested log before doing the second procedure.

    Okay you have a lot of problems. To name a few of the major ones, you have Smitfraud, multiple Virtumonde infections, and Winlogonhook. Let's get started.

    And another MAJOR PROBLEM is that you are running this PC with no antivirus, no antispyware, and no firewall. WHY????

    Did you configure the below two R1 line Proxy settings for some reason?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5400
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;<local>;*windowsupdate.com;download.microsoft.com;*windowsupdate.microsoft.com;codecs.microsoft.com;activex.microsoft.com;
    liveupdate.symantecliveupdate.com;liveupdate.symantec.com;service1.symantec.com;*.nai.com;*.networkassociates.com;*.trademe.co.nz


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 8
    Java 2 Runtime Environment, SE v1.4.1_02
    Safety Bar

    Now install the current version of Sun Java from: Sun
    Java Runtime Environment



    Then install the current version of FireFox from: Mozilla Firefox

    Now let's work on Smitfraud and some other malware. We will get to Virtumonde and Winlogon hook a little later.


    Download SmitfraudFix (by S!Ri) to your Desktop.

    Extract all the files to your Destop. A folder named
    SmitfraudFix will be created on your Desktop.

    Open the
    SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter
    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach that log in your next reply.

    Note:process.exe ( which is used my SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. The below is a link to what process.exe is.

    http://www.beyondlogic.org/consulting/proc...processutil.htm


    IMPORTANT: Do NOT run any other options until you are asked to do so!
     
    Last edited: Oct 7, 2006
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is my second message. Make sure you have follow the first procedure before doing the below.

    PLEASE READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING. Ask any questions that you may have before starting.

    Please print out or copy these instructions to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. Again, if there's anything that you don't understand, ask your question(s) before moving on with the fixes.

    Reboot your computer into Safe Mode per the safe directions in the READ & RUN ME.

    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.

    Now reboot into normal mode and attach this new rapport.txt log here.

    Now also attach new logs from ShowNew, GetRunKey, and HJT!
     
  8. Nybes

    Nybes Private E-2

    No excuses for having no antivirus or firewall, just stupidity on my part. I'll rectify this as soon as possible. Money is an issue for me, if you could recommend me some reputable free software that would be much appreciated.

    The two R1 line Proxy settings were not knowingly configured. Should they be altered? If so, how would I go about doing that?


    Uninstall old versions of software:
    -Done

    Install current versions of Sun Java and FireFox:
    -Done

    Download and run SmitfraudFix - Search
    -Done. Log is attached.

    Run SmitfraudFix - Clean - in safe mode
    -My desktop didn't appear when logged in on safe mode. Ran smitfraudfix.cmd from Task Manager. Clean ran successfully, however Disk Cleanup froze. Ended the Cleanmgr process and restarted Cleanmgr from Task manager, this time it ran sucessfully. Log is attached.


    New logs from ShowNew, GetRunKey, and HJT! to follow in next message.
     

    Attached Files:

  9. Nybes

    Nybes Private E-2

    New logs.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of pmkhe.dll once and then click the kill button. After you have killed all of the pmkhe.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs(If you do not find the dll, just continue on):
    winzdn32.dll
    wvuutss.dll

    Next double click on explorer.exe and again click once on each instance of pmkhe.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    winzdn32.dll
    wvuutss.dll

    Now just exit Process Explorer.

    No goto Add/Remove Programs and uninstall: ToolBar888


    Now please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\svchost.exe
    C:\Program Files\Common Files\{5CDB5EE2-0A1F-1033-0716-030224200040}\Update.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5400
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;<local>;*windowsupdate.com;download.microsoft.com;*windowsupdate.microsoft.com;codecs.microsoft.com;activex.microsoft.com;liveupdate.symantecliveupdate.com;liveupdate.symantec.com;service1.symantec.com;*.nai.com;*.networkassociates.com;*.trademe.co.nz
    O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\File Sharing Revolution\Plugins\RazaWebHook.dll
    O2 - BHO: (no name) - {278B661A-14A8-D8B0-6AF4-03088B866149} - C:\WINDOWS\System32\unaoakg.dll
    O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINDOWS\System32\ixt0.dll (file missing)
    O2 - BHO: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{3CDB5EE2-0A1F-1033-0716-030224200040}\MyToolBar.dll
    O2 - BHO: (no name) - {D3B3C51E-8D11-4667-85B9-0930F519BED7} - C:\WINDOWS\System32\wvuutss.dll
    O2 - BHO: (no name) - {F359DB79-0C10-44F4-8FB4-D7ABCED1CF9F} - C:\WINDOWS\System32\pmkhe.dll
    O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{3CDB5EE2-0A1F-1033-0716-030224200040}\MyToolBar.dll
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
    O20 - Winlogon Notify: pmkhe - C:\WINDOWS\System32\pmkhe.dll
    O20 - Winlogon Notify: winzdn32 - C:\WINDOWS\SYSTEM32\winzdn32.dll
    O20 - Winlogon Notify: wvuutss - C:\WINDOWS\SYSTEM32\wvuutss.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Program Files\Common Files\{5CDB5EE2-0A1F-1033-0716-030224200040}\Update.exe
    C:\Program Files\Common Files\svchost.exe
    C:\WINDOWS\svchost.exe
    C:\WINDOWS\system32\cool.exe
    C:\WINDOWS\system32\efcyywv.dll
    C:\WINDOWS\system32\pmkhe.dll
    C:\WINDOWS\system32\tuvwttr.dll
    C:\WINDOWS\system32\unaoakg.dll
    C:\WINDOWS\system32\winzdn32.dll
    C:\WINDOWS\system32\wvuutss.dll
    C:\WINDOWS\system32\ehkmp.tmp
    C:\WINDOWS\system32\ehkmp.ini
    C:\WINDOWS\system32\ehkmp.ini2
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete it if found:
    C:\Program Files\Common Files\{3CDB5EE2-0A1F-1033-0716-030224200040}
    C:\Program Files\Common Files\{5CDB5EE2-0A1F-1033-0716-030224200040}

    Now attach a the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  11. Nybes

    Nybes Private E-2

    Download Process Explorer and Pocket KillBox
    -Done


    Reboot in Normal Mode and run Process Explorer. Kill instances of pmkhe.dll, winzdn32.dll and wvuutss.dll from winlogon and explorer.
    -Done


    Uninstall ToolBar888
    -Done


    HijackThis - Killing processes.
    C:\WINDOWS\svchost.exe
    -Did not appear!
    C:\Program Files\Common Files\{5CDB5EE2-0A1F-1033-0716-030224200040}\Update.exe
    -Killed


    Run HJT Scan and Fix

    The following lines were not found! All others selected and fixed.

    O2 - BHO: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{3CDB5EE2-0A1F-1033-0716-030224200040}\MyToolBar.dll
    O2 - BHO: (no name) - {F359DB79-0C10-44F4-8FB4-D7ABCED1CF9F} - C:\WINDOWS\System32\pmkhe.dll
    O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{3CDB5EE2-0A1F-1033-0716-030224200040}\MyToolBar.dll


    Merge fixme.reg with registry.
    -Done


    Pocket Killbox:
    Delete Temp Files.
    -Done
    Delete Files on Reboot.
    -Done


    Locate 2 folders and delete:
    -Done


    New logs are attached.

    System has been running smoothly for approx half an hour now with no sign of pop-ups or diallers. Recently, these would appear within five minutes of reboot. Looking good so far!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and enable System Restore to create a new clean Restore Point.
    4. After doing the above, you should work thru the below link:
     
  13. Nybes

    Nybes Private E-2

    OS is now up to date, with anti-virus and firewall installed.

    Thanks very much for your help. I really appreciate it.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds