I need help.....AGAIN

Discussion in 'Malware Help (A Specialist Will Reply)' started by Whatsername851039, Jul 8, 2007.

  1. Whatsername851039

    Whatsername851039 Private E-2

    Well after we got my mom's computer fixed I had to dump mine because I was having a lot of problems and there was literally nothing I could do to fix it. So after dumping I reinstalled all my usual things as far as antivirus, antispyware even a rootkit detector. Well I'm getting pop ups like mad from my antivirus saying that I have all these trojans in my WINDOWS folders. I'm really at a loss of what to do. I have a hijack this log, antispy log, and a bdscan log but I couldn't get the panda scan to work for some reason and I don't know where to find the getkey or the shownew? Also I ran Spybot and it found a Virtumonde? It gave me the location and it is listed as a Registry Key. If anyone can help that is great! Also I need a bit of advice on what I'm doing wrong because before I dumped it I never had viruses or if I did they were rare and easy to get rid of. Thanks again!
     
  2. Whatsername851039

    Whatsername851039 Private E-2

    Here are 3 of the scans I did..
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Same with the Shownew log.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT. Then uninstall it and re-download it properly. It should be renamed to Analyse ----> not: C:\Hijackthis\HijackThis.exe.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach the logs for:
    Avenger
    HJT
    ShowNew
    Getrun
     
  4. Whatsername851039

    Whatsername851039 Private E-2

    Here's a hijack this log from today. I found and downloaded a vundofix program that comes up clean now and I've ran my super antispy that says there's nothing. I haven't had any pop ups either. So this is I guess for closure. I've looked over the tutorial on hijack this and I can't seem to find anything wrong but to me that doesn't mean much. I could always overlook something. Thanks so much for the help!
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Was there a problem doing this:
    Is there a reason that you did not attach the ShowNew and GetRun Logs?

    Many new malware attacks are finding ways to recognize and hide from HJT - which is why we ask you to rename it!

    You did not attach the log from Avenger - did you run it?

    I can not tell what is going on in your system without the requested logs.
     
  6. Whatsername851039

    Whatsername851039 Private E-2

    I finally found the get run key and the show new. Here's the scans for those. My AVG just deleted 14 infected files.
     

    Attached Files:

  7. Whatsername851039

    Whatsername851039 Private E-2

    Oh here's the avenger sorry I meant to post that before. But all it said was the files weren't found. I am running through a router and I know most if not all routers have firewalls. Could it be my firewall is turned off? Or do you know if I need to reinstall the disk to the router after I dumped my computer?
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 11
    Java 2 Runtime Environment, SE v1.4.2_05
    Reboot and install:
    Java Runtime 6

    Run CCleaner! You still have a lot of crap in your temp folders!

    This is exactly where we tell you not to install HJT ...and you did not rename it as instructed!
    Please uninstall it and re-install correctly.
    C:\Documents and Settings\Whatsername\My Documents\Installed\Comp protection\Hijackthis\HijackThis.exe
    Should be: C:\Program Files\HJT\analyse.exe
    Continue by downloading a tool we will need - since you are having problems with Avenger
    Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
  9. Whatsername851039

    Whatsername851039 Private E-2

    Everything seemed to go fine. I didn't get any errors when I ran Ccleaner it said that the file I think it was win24 the one you told me to delete in hjt was missing. And I couldn't find it in the hjt log. So I'm guessing it was deleted when I unistalled something possibly. But here are the logs that you wanted. I'm a bit confused though. If this is clean how can I keep it from happening again?
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Close but no cookie ....
    C:\Hijackthis\HijackThis.exe --rename it: open the folder and right click the exe file / rename to analyse!

    Killbox is not killing these:
    Try to do it again with Avenger (unless you feel comfortable with finding them using windows explorer to delete them).

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach the logs for:
    Avenger
    HJT
    ShowNew
    Getrun
     
  11. Whatsername851039

    Whatsername851039 Private E-2

    Ok I think I did it right this time....I hope I did.
     

    Attached Files:

  12. Whatsername851039

    Whatsername851039 Private E-2

    Here's the hjt log. I renamed the file too.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now this is starting to irritate me! .....You did fine!! This little nasty is going to haunt me!!

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach the logs for:
    Avenger
    ShowNew
    Getrun
     
  14. Whatsername851039

    Whatsername851039 Private E-2

    Here's the log files
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Finally .....Please pay special attention to the last item.

    Your logs look clean. You may uninstall any programs we had you download (including Counterspy).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  16. Whatsername851039

    Whatsername851039 Private E-2

    Thanks so much! I have a question about firewalls. The last time I downloaded one it confused me because things were popping up and some of them I weren't sure of. For some reason I don't remember what it was but I had to start my computer in safe mode and when I did it would let me log in but then the screen was just black and it said safe mode all around it. When I did system restore and it uninstalled the firewall it worked fine. How do I know what to let in and what not to?
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome.....as to firewalls, there are a few good free ones, however each will require you to allow or disallow applications from "getting in or out".

    I would suggest that you pose the question in the software forum where members can advise you as to the operation of each.:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds