hmmm where to begin?

Discussion in 'Malware Help (A Specialist Will Reply)' started by dashadowman20002, Jun 26, 2007.

  1. dashadowman20002

    dashadowman20002 Private E-2

    well i go to work one day, come home and sisters have been on comp. i ran scans for about a full day in normal boot, and safe mode, after my panda came up with over 69,000 infected files, i thought maybe id be a little better. log back into normal boot, and a strange command prompt came up saying Inetget2 installation. which i never had anything of that name on my comp. first browser i open i get a few unwelcomed pop-ups, figured i did all i know. and it was time to come to the geeks :D did everthing i found in the run and read me, and every single one of em found a bunch of crap. but i got the logs here and hopefully can get rid of this problem. havent really checked much as to if im still getting pop ups after i ran all the scans, but i want to be sure after all the time i spent scanning myself and stuff that it is gone and gone for good. oh and a side note i have had ewido before so just to be sure i wasnt gonna have any problems i just got avg and ran that instead rolleyes .. oh and my avg found so much stuff it was 15,000 kb.. so i had to zip it up to attach it
     

    Attached Files:

  2. dashadowman20002

    dashadowman20002 Private E-2

    and becasue i can only attach 3 heres my 2nd post with last 3 logs
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Uninstall Ewido now! It was replaced by AVG AntiSpyware which is the same program but newer. Ewido was discontinued quite awhile ago.

    Uninstall the below as requested in step 0 of the READ ME.
    Morpheus 1.9
    Viewpoint Media Player

    Also uninstall the below as requested in step 6 of the READ ME:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9

    You have three left over services from having Symantec installed at one time. They need to be removed.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Symantec Network Drivers Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • LiveUpdate
      • Automatic LiveUpdate Scheduler
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste SNDSrvc into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • LiveUpdate
      • Automatic LiveUpdate Scheduler
    • Now exit HJT and reboot if it tells you it needs to.


    It appears like yo may not have installed and run GetRunKey and ShowNew properly. Please make sure you followed the directions on the download pages exactly and then attach new logs. It looks like you did not extract all files from the ZIPs and/or that you did not run the .bat files from outside of the ZIP file.
     
  4. dashadowman20002

    dashadowman20002 Private E-2

    alright so i ran the atf scanner or whatever it was. cleaned out like 350 some odd MB for main and about 20mb for firefox, then i went and uninstalled ewido. but when i tried to uninstall morpheus, i click remove, the thing flashes for a second, and then comes back. so dunno whats going on with that. i dont even get a prompt saying hey retard u cant get rid of me. but anyways, i got rid of veipoint manager, then i went into the service thing-a-ma-bob, all of them were already stopped, but i made them disabled in the start up. then i did the hjt thing, the first one said its critical to my computer (but i say if i said i wanted to get rid of it it should let me.. stupid things). but the other 2 worked just fine. then as for getrun and shownet. i know i extracted it all and stuff.. but i think my compter just hates dos. so.. what i did was to show ya what i mean by that. i took some screen shots. got em zipped up. and it shows i have everthing extracted. i click the dot bat. and it says that it doesent like dos, and it refueses to run it.. well kinda. but ull see what i mean. then it gives me a log anyways, after it ignores a few processes. and thats prolly why the logs came out wrong. so i have the log anyways still. hope it helps :)


    oh and before i did those last couple things i noticed that while runing IE on my comp randomly when im going to sites or clicking links. it will redirect my page to search.mywebsearch.com/blahblahblah=the-link-i-wanted-to-use or it could have been mywaysearch i think the mywaysearch sounds right. but either way.. its not anything i would want on my comp :D

    ok so i went to see if i still had the mywaysearch thing. so i typed in first url i thought of.. i typed neopets.com. i was redirected to this page
     

    Attached Files:

    Last edited: Jun 28, 2007
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still need to follow the direcions on the download pages for GetRunKey and ShowNew. That error message you posted a snapshot of was explained there. Read everything on the download page.

    We have not removed all of your malware yet so don't worry about myway! I need proper logs from GetRunKey and ShowNew so that we can continue.
     
  6. dashadowman20002

    dashadowman20002 Private E-2

    lol amazing what directions can do for someone rolleyes . ok read em.. and im pretty sure i did it right this time.. heres the 2 logs
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes things do go better when directions are followed ;).......and speaking of that, see step 0 of the READ ME and put your system into Normal Startup mode. You are using MSconfig to control startups which you must not do.

    Then continue on to the below steps!

    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!
     
  8. dashadowman20002

    dashadowman20002 Private E-2

    went to about 10 different websites i know of, and so far no pop-ups and no redirecting so all is looking good. heres the logs from the first couple lines i read id say it did what it was supposed to :D


    oh and i changed into normal boot before i ran combofix
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We still have some more to do, but I need the new HJT log I requested so that we can continue.
     
  10. dashadowman20002

    dashadowman20002 Private E-2

    alriught heres hjt
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try using this Your Uninstaller! 2006 to uninstall Morpheus 1.9. If it does not work, then run this Getting Uninstall Programs List From The Registry and attach the request log.


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
    O4 - HKLM\..\Run: [sunasServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
    O4 - HKLM\..\Run: [sunasDTServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
    O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
    O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
    O4 - HKLM\..\Run: [FastTrack Accelerator] C:\Program Files\KaZaA Lite\Speed Up.exe
    O4 - HKLM\..\Run: [3sFg34j] conbrand.exe
    O4 - HKCU\..\Run: [IBwmRQHqR] cmupy.exe
    O16 - DPF: {FF791555-FDAC-43AB-B792-389E4CC0A6E5} (Toontown TestServer Installer ActiveX Control) - http://download.test.toontown.com/sv...st/tt_test.cab
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetUnKey log
    2. Avenger
    3. GetRunKey
    4. ShowNew
    5. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  12. dashadowman20002

    dashadowman20002 Private E-2

    ok so the first uninstall thing worked. so i didnt have to do the uninstall key thing. added in some new registrys, then i did the avenger thing. it seemed to start off fine. and after i pressed the traffic lights it said it had deleted the things and needs to reboot (like u said it would) but then it reboots and a command prompt thing comes up and says cannot find this file, cannot find this file, cannot find this file. and it said that a few times, then it comes up with the log, and its completely blank confused and said something like cannot find the log or something like that and would i like to make a new one? so i said yes cuz the log was blank anyways... but long story short.. ran program, log is empty, so no point in posting it right? :p

    well heres the other 3 logs ya needed
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some of the items I asked you to fix are still showing in your HJT log:

    O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
    O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
    O4 - HKLM\..\Run: [FastTrack Accelerator] C:\Program Files\KaZaA Lite\Speed Up.exe
    O4 - HKLM\..\Run: [3sFg34j] conbrand.exe

    Did you forget to fix these? Try again?

    Did you ty to fix them and they came back? If so, Windows Defender may be blocking the changes. You would then have to disable Windows Defender's realtime protection.

    Disable Windows Defender:
    • Open Windows Defender
    • Click Tools
    • Click General Settings
    • Scroll down to Real Time Protection Options
    • Uncheck Turn on Real Time Protection (recommended)
    • Close Windows Defender
    Once your log is clean you can re-enable Windows Defender Real Time Protection.

    After disabling Windows Defender you can then try fixing those lines again.

    Also delete the below folder:
    C:\Documents and Settings\fun2nite\Application Data\Viewpoint


    Attach a new HJT log after attempting to fix these again. If you run into problems, tell me what happened.
     
  14. dashadowman20002

    dashadowman20002 Private E-2

    well i knew i was sure i checked those ones when i did fix the first time, so i disabled my defender and redid it. then when i rescanned to get the log they werent there. also deleted viewpoint folder. heres hjt log
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  16. dashadowman20002

    dashadowman20002 Private E-2

    alright thanks alot chaslang :D thanks for all the help, hope i dont need the forums help anytime soon now ;) peace out :dood

    btw, i love ur sig :p

    thanks again, and good luck helpin everyone else :)
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds