hijackthis log (started with a virushelpzone problem)

Discussion in 'Malware Help (A Specialist Will Reply)' started by distractable, Feb 9, 2007.

  1. distractable

    distractable Private E-2

    Initially i could not even get to your site. Each time i tried to get here the browser would just close. The same game of tag occurred when trying to download.

    i did eveything in safe mode in the admin account, there is one other user account on this computer. It would not allow me to to run ccleaner in admin account in safe mode, but was able to run it in the other account. Followed all instructions as per READ & RUN ME FIRST.

    Three reports attached.
     

    Attached Files:

  2. distractable

    distractable Private E-2

    in between when i started this and now, the folder view options were reset to not displaying hidden files...and not by me????

    It will not allow me to upload the txt for getrunkey???

    thanks for any help
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You need to follow the directions in the download links for both GetRunKey and ShowNew exactly as written also take note of whether you are getting any of the error messages describe. You are not running them (at least not ShowNew) properly.

    You also need to attach the log from CounterSpy as requested.

    Also you must only post HijackThis logs from Normal Boot mode. Please do the below and then attach a new log from HJT from normal boot mode.

    Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Now attach logs from the below:
    • CounterSpy
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis
     
  4. distractable

    distractable Private E-2

    Sir,

    i did it all again and think i understand wherei went wrong before. i am hoping that i got it right this time.

    i got no error messages, everything ran fine.

    and ran the hoster thing, clicked on the button as You said...nothing happened, wondered whether it worked, then clicked the button again and same thing...closed it.
     

    Attached Files:

  5. distractable

    distractable Private E-2

    and the hijack this log
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If the below files are important to you, you should not save them on your Desktop. Move them someplace safer and more permanent. If not needed then delete them since they are using over 600 Megabyte of disk space.
    Code:
    "C:\Documents and Settings\rochelle\Desktop\"
    x12-30~1.exe  Jan  7 2007   407010384  "X12-30196.exe"
    x13-11~1.exe  Jan  7 2007   259585360  "X13-11296.exe"
    Make sure to follow the steps below in the exact order written.

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_05
    Mozilla Firefox (1.5.0.9)

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Now shutdown your Symantec Security Center to avoid having it get in the way of fixes.


    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O1 - Hosts: 1.1.1.1 free.grisoft.com
    O1 - Hosts: 1.1.1.1 housecall.trendmicro.com
    O1 - Hosts: 1.1.1.1 usa.kaspersky.com
    O1 - Hosts: 1.1.1.1 ewido.net
    O1 - Hosts: 1.1.1.1 www.ewido.net
    O1 - Hosts: 1.1.1.1 zonelabs.com
    O1 - Hosts: 1.1.1.1 www.zonelabs.com
    O1 - Hosts: 1.1.1.1 bitdefender.com
    O1 - Hosts: 1.1.1.1 www.bitdefender.com
    O1 - Hosts: 1.1.1.1 download.bitdefender.com
    O1 - Hosts: 1.1.1.1 upgrade.bitdefender.com
    O1 - Hosts: 1.1.1.1 spywareinfo.com
    O1 - Hosts: 1.1.1.1 www.spywareinfo.com
    O1 - Hosts: 1.1.1.1 merijn.org
    O1 - Hosts: 1.1.1.1 www.merijn.org
    O1 - Hosts: 1.1.1.1 sysinternals.com
    O1 - Hosts: 1.1.1.1 www.sysinternals.com
    O1 - Hosts: 1.1.1.1 onguardonline.gov
    O1 - Hosts: 1.1.1.1 www.onguardonline.gov
    O1 - Hosts: 1.1.1.1 avast.com
    O1 - Hosts: 1.1.1.1 www.avast.com
    O1 - Hosts: 1.1.1.1 safety.live.com
    O1 - Hosts: 1.1.1.1 www.paretologic.com
    O1 - Hosts: 1.1.1.1 paretologic.com
    O1 - Hosts: 1.1.1.1 services.google.com
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Program Files\Common Files\{60418DA6-0745-1033-0527-051214040001}\system.dll
    C:\WINDOWS\system32\drivers\etc\hosts
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\Common Files\{30418DA6-0745-1033-0527-051214040001}
    C:\Program Files\Common Files\{60418DA6-0745-1033-0527-051214040001}

    Now run Ccleaner!

    Now try rerunning the procedure with Hoster again!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  7. distractable

    distractable Private E-2

    chaslang, (my hero)

    Used add/remove programs to uninstall Sunbelt CounterSpy.
    C:\Program Files\Sunbelt Software this was not found.
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software was not found but C:\...Application\SBSI was and i removed that.

    I did a full system (with hidden files and all) search for Sunbelt CounterSpy with no results.

    Everything else was fine until i got to:

    "Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry."

    i followed the save intrstuctions exactly and can see the funky lil icon on my desktop but when i double click it i get and error message:

    C:\Documents and Setting\rochelle\Desktop\fixME.reg is not a valid Win32 application.

    i also tried selecting the option MERGE from the right click drop down. Same error message.

    thanks for Your help, will await Your instructions...not touching nuttin till You say so.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This normally happens for one of two reasons:
    1. The file was not saved properly
    2. Malware is blocking changes.
    One of the registry keys we are trying to change was set to a value to block registry editing and this is most frequently done by malware. Try the patch again. If it does not work, please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    See if Registrar Lite will run. If so, navigate to the below key by copying and pasting it into the address bar of Registrar Lite

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]

    Now look in the right windows pane for DisableRegistryTools and right click on it and select Delete


    Now navigate to the below key

    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run

    Now look in the right windows pane for winlogon and right click on it and select Delete


    Let me know the results!
     
  9. distractable

    distractable Private E-2

    did everything in Your last post...all without errors

    Currently still have Norton disabled.

    Ready for next step
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to continue on and complete the rest of what I gave you in message number 6! After completing message # 6, enable Norton!
     
  11. distractable

    distractable Private E-2

    Returned to #6.
    Ran killbox as instructed. No errors, no prompts.
    Rebooted.
    Deleted first one, this one didn't show.
    C:\Program Files\Common Files\{60418DA6-0745-1033-0527-051214040001}
    Ran CCleaner
    Ran Hoster, no problems

    Attached updated logs.


    Haven't seen the virushelpzone home page for the last few reboots.

    Do have two questions in all this though...In your opinion if this happens again, would reformatting remove all of these problems and is it worth it to reformat rather than to fix it?

    thanks for your time here though, i kinda like tinkering, cept i have no clue what i am doing...lol

    dis
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not true! Look again! It is still there and you can even see it in your newfiles.txt log.


    It's your choice on what approach you prefer to take. But a new install involves more than you may think. Especially to get back to a level of where your system is at. You have to consider all of the below:
    • you have to backup all you own data, settings, configurations etc and first you have to know what/where all of these are. And you have to have the medium (burnable media, second hard drive, tape drive [yuck] )
    • then you must make sure you have the necessary disks to reinstall not just your OS but all other software you use especially protection before going online
    • then fdisk (repartitioning is better than just a format), format, reinstall the OS
    • now reinstall all your software especially protection
    • get online (requires some setup and config that novices have problems with)
    • download updates for OS
    • download updates for protection software
    • download updates for all other software
    • tweak all software back the way you like it. Including Desktop settings, icons etc.
    • create all the folders that you use for everything in your normally routines
    • re-load from your backups to get data back, to get settings, Favorites,.....etc back
    • now over the next two weeks you will realize that you forgot to backup some stuff and also you will keep finding something else that you need to reinstall.
    In most cases fixing is actually faster!


    We have a little more to do!

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - Startup: winlogon.lnk = ?

    After clicking Fix, exit HJT.

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now locate the below folder and delete it if found:
    C:\Program Files\Common Files\{60418DA6-0745-1033-0527-051214040001}

    Also delete the below file
    C:\Documents and Settings\rochelle\Start Menu\Programs\Startup\winlogon.lnk

    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
    Last edited: Feb 10, 2007
  13. distractable

    distractable Private E-2

    I tried to run Hijack This.

    3 times it came back with the "This program has encountered an error and needs to be shut down." Send report window.

    Then i rebooted once by shutting down. Tried again, same thing.
    Next i just did a restart, tried again, same thing.
    Then i did one of those hold the power button down till the laptop shuts off kind of reboots.

    Now it lets me open the program, but
    when i close all the browsers (am reading Your instructions on the desktop while following them on the laptop) and check the 04 - Startup: winlogon.Ink = ? and hit fix checked ... i get the following:

    "Unexpected error occurred!
    Error #52 (Bad file name or number) in Sub GetLongPath(?.exe).

    Please send a report to merjin@spywareinfo.com, mentioning what you were doing, and what version of Windows you have.

    This message has been copied to your clipboard." OK button


    i click ok. Another error message appears.

    "Unable to delete the file:
    04 - Startup: winlogon.Ink = ?
    The file may be in use. Use Task Manager to shutdown the program and run Hijack This again to delete the file."

    It is a critical process and Task manager will not allow me to close it or end task.

    i cannot get past the two error messages.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Continue on with the rest of the instructions! Make sure you get the below file deleted (mentioned in the previous instructios):

    C:\Documents and Settings\rochelle\Start Menu\Programs\Startup\winlogon.lnk

    Use Killbox to delete it if you cannot delete it manually!
     
  15. distractable

    distractable Private E-2

    ok, i think i am all up to snuff now (in terms of Your instructions?)
    and did have to use KillBox

    here are the latest logs
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you double click on the fixME.reg patch, are you getting a message saying it was added successfully to the registry? It does not appear to be working. Make sure you are not blocking it with Symantec AV. Try again and then attach a new GetRunKey log. If this does not work, we will have to do it another way.
     
  17. distractable

    distractable Private E-2

    "Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry."

    i followed the save intrstuctions exactly and can see the funky lil icon on my desktop but when i double click it i get and error message:

    C:\Documents and Setting\rochelle\Desktop\fixME.reg is not a valid Win32 application.

    Norton is disabled. It is the latest version and just went through and turned eveything off. Is there an easier way to do that than go through all the firewalls and security and antivirus monitoring with one click?
    Cannot seem to get that to happen. Here is Your log though.

    smilesss
     

    Attached Files:

    Last edited: Feb 11, 2007
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must always tell us when you get error messages. Unless you give feedback, all we can assume is that everything is working okay.

    That error message normally means you are not saving the file properly. Try this.

    Download the attached fixME.zip file to your Desktop. Extract the contents (fixME.reg) to your Desktop overwriting the previous file. Now double click on the new fixME.reg file.

    Do you get a success message? If so, attach a new GetRunKey log.
     

    Attached Files:

  19. distractable

    distractable Private E-2

    I did tell you about the error the first time it showed up back in #8, and then when it showed up again now, same message.

    i was careful to make sure that i selected all files, and made sure everything is as it is in Your instructions.

    Overwriting is giving me the same message still. And it added a modal asking if i trusted it and if i wanted to run. I said yes to run and then the modal with the same warning showed up.

    C:\Documents and Setting\rochelle\Desktop\fixME.reg is not a valid Win32 application.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I only said to attach a log if you get a success message! I don't need to see one until you get a successful merge.

    That would be your antivirus application getting in the way! Try shutting it down and then do the following.

    Click Start, Run, and enter regedit and click Ok! This will open the Registry Editor.

    In Regedit, click File, Import. Click Desktop and locate the fixME.reg and double click on it. Do you get a success message this way?
     
  21. distractable

    distractable Private E-2

    Success! That worked. Norton AV had been disabled.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Great! Enable Norton AV now!


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds