I need a little help, please.

Discussion in 'Malware Help (A Specialist Will Reply)' started by givey, Apr 8, 2007.

  1. givey

    givey Private E-2

    I have picked up something. I'm not sure what it is. I have run AVG7.5, Spybot S&D, Adaware SE, and CCleaner. Everything comes up ok. However, when I open IE, it is popping open other windows with all kinds of different searches, spy-somethings, and other undesirable things.

    Also, there is an icon in the tooltray that won't go away. It is a circled question mark that flashes and changes to a red circle with a red line through it diaginally. Then a "help bubble" pops up and says a number of active spy ware applications have been detected on my system, and that I should click it to fix. When I clicked, pop up for something called Spylocked comes up.

    Thanks.

    Aaron
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    How are things working now?
     
  3. givey

    givey Private E-2

    Here's number 1
     

    Attached Files:

  4. givey

    givey Private E-2

    Here's number 2.
     

    Attached Files:

  5. givey

    givey Private E-2

    Things seem better. Let me know if there is anyhting else I should do.

    Thanks
     
  6. givey

    givey Private E-2

    Nope, I was wrong. OK, the flashing question mark and red circle are gone, but IE got jacked again a minutes ago. Typing in a site, then the window either un-highlights (curser goes away and I have to click in the window to get back to work) or get sent to another generic search of some sort.

    Also, to let you know I had completed the READ ME AND DO FIRST thing before we got started.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Until all 6 logs requested in the READ ME are attached, we do not consider the READ ME as being run.

    You need to attach the 6 requested logs! And you also need to run the below:

    WareOut Removal

    And then attach this 7th log ( the FixWareOut log) too.
     
  8. givey

    givey Private E-2

    Ah, sorry about that. Here they are.
     

    Attached Files:

  9. givey

    givey Private E-2

    ...and the rest.
     

    Attached Files:

  10. givey

    givey Private E-2

    and finally.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run AVG Antispyware again and this time do not ignore all the problems like you did last time. Either Quarantine or Delete all the problems. Save and attach a new log.


    1. Now Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!
     
  12. givey

    givey Private E-2

    New AVG report
     

    Attached Files:

  13. givey

    givey Private E-2

    combofix log
     

    Attached Files:

  14. givey

    givey Private E-2

    GetRunKey
    ShowNew
    HJT
     

    Attached Files:

  15. givey

    givey Private E-2

    System is still running the same. Also noticed that the status bar on IE keeps disappearing. Don't know if that matters, but I thought I mention it.

    Thanks for your time on this.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {017D610D-3FE6-4A1C-8C79-C4F5A5DAF75F} - C:\Program Files\Online Services\hokepote.dll
    O2 - BHO: 0 - {0B71F6CA-24CE-4A96-9CB8-B60B60C62BC1} - C:\Program Files\MSN\lavu.dll
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3A657372-1B7D-4D34-9B1C-FDCAE541EF79}: NameServer = 85.255.116.137,85.255.112.23
    O17 - HKLM\System\CCS\Services\Tcpip\..\{50E0D202-0906-446C-918A-A34335F8E349}: NameServer = 85.255.116.137,85.255.112.23
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.137 85.255.112.23
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.137 85.255.112.23

    After clicking Fix, exit HJT.


    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\Program Files\Online Services\hokepote.dll
    C:\Program Files\MSN\lavu.dll
    c:\windows\NDNuninstall6_38.exe
    C:\WINDOWS\b122.exe
    C:\WINDOWS\itpb_3.exe
    C:\WINDOWS\rk.exe
    C:\WINDOWS\stub_mma3.exe
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\VYUOIESH\rk2[1].exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.
    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     
  17. givey

    givey Private E-2

    When I double click on Killbox.exe. I get the following message:

    "Component 'MSCOMCTL.OCX' or one of its dependencies not correctly registered:a file is missing or invalid'

    I will wait to hear from you before proceeding with anything else.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  19. givey

    givey Private E-2

    Completed as requested, I did not receive a PendingFileRenameOperations prompt. And the status bar is hanging around now. Also don't sem to notice any pop-up adds on the web pages. I'll keep an eye on this for a day or so.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We have one more file to delete which can sometime be quite difficult.

    Download FileASSASSIN and save to your desktop

    Create a new folder on C:\ called FileASSASSIN and extract (unzip) it to that folder.
    • Now print the below instructions because you need to reboot into safe mode and keep all browsers and other unnecessary applications closed before doing the below.
    • Once in safe mode, open the C:\FileASSASSIN folder and double-click on FileASSASSIN.exe.
    • Select the following file to delete by copy and pasting it onto the text area or select it using the (...) browse button.

      C:\WINDOWS\system32\drivers\core.cache.dsk


    • Select a removal method. Start with "Attempt FileASSASSIN's method of file removal."
    • Click delete and the removal process will begin.
    • If that did not work then, start FileASSASSIN again and this time check "Use delete on reboot function from windows.".
    After doing the above, reboot into normal mode and attach a new log from ShowNew.

    Are things still running OK?
     
  21. givey

    givey Private E-2

    It removed it with...

    Select a removal method. Start with "Attempt FileASSASSIN's method of file removal."
    Click delete and the removal process will begin.

    Here is the new ShowNew log.

    Things seem to be running normal.
     
  22. givey

    givey Private E-2

    Forgot to put this on.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds