Infected 1

Discussion in 'Malware Help (A Specialist Will Reply)' started by uncpchelp, Nov 20, 2006.

  1. uncpchelp

    uncpchelp Private E-2

    Attached Files:

  2. uncpchelp

    uncpchelp Private E-2

    Re: Infected 1 - the rest of my requested files

    here are the rest. I'm at a loss at what to do next. THANKS!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please disable MSconfig per the directions in step 0 of the READ & RUN ME. Then continue onto the below instructions.
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    4. and the log from Combox fix in a second message!
    Make sure you tell me how things are working now!
     
  4. uncpchelp

    uncpchelp Private E-2

    So since running all the freeware from the original instructions my computer does seem to be running slightly quicker, but it still says infected with the combofix scan. Originally I noticed the change when my computer got really slow, I couldn't connect to my own wireless set up, when I clicked on view available wireless networks the screen would say I was running some program that did not allow me to make changes. That is no longer occuring it seems. Also, I noticed a red drum icon on my desktop screen with the name 1.exe, there was also a 2.exe present
     

    Attached Files:

  5. uncpchelp

    uncpchelp Private E-2

    Here is the combofix file.
     

    Attached Files:

  6. uncpchelp

    uncpchelp Private E-2

    I also just ran microsoft update, it included the service pack 3 and some security updates.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.0
    Viewpoint Manager (Remove Only) <--- should have been uninstalled in step 0 of the READ ME
    Viewpoint Media Player <--- should have been uninstalled in step 0 of the READ ME


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: (no name) - {6F97091E-95AC-B021-82FC-C6693EAFDCC1} - C:\WINDOWS\system32\waltzzo.dll (file missing)
    O2 - BHO: (no name) - {6F97091E-95AC-B021-82FC-C6693EAFDCC1} - C:\WINDOWS\system32\waltzzo.dll (file missing)

    After clicking Fix, exit HJT.:

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. uncpchelp

    uncpchelp Private E-2

    Also, i just found a folder saved in my c drive called qoobox
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's right! It is from running ComboFix. We will clean up all of this later when we finish removing all malware.



    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) -
    O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
    O20 - AppInit_DLLs:

    After clicking Fix, exit HJT.

    Now reboot in normal mode

    Now attach a new HJT log.


    How are things running at this point?


    After clicking Fix, exit HJT.:
     
  10. uncpchelp

    uncpchelp Private E-2

    I noticed that two of the files asked to be deleted were still present when i reran the scan, i tried to fix it again, but both of the following popped back up.

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try this!

    Disable Windows Defender's realtime protection:

    Disable Windows Defender:
    • Open Windows Defender
    • Click Tools
    • Click General Settings
    • Scroll down to Real Time Protection Options
    • Uncheck Turn on Real Time Protection (recommended)
    • Close Windows Defender
    Now try fixing those two lines. MAKE SURE no browsers are open or that could also block the fix.

    Once your log is clean you can re-enable Windows Defender Real Time Protection.
     
  12. uncpchelp

    uncpchelp Private E-2

    I disabled windows defender and I did not have any browser's open, but the two files keep reappearing after I fix twos two lines. Anything else I can try?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall Windows Defender and reboot. Then do the below.


    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    How does it look now?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds