Infected....hellllpppp

Discussion in 'Malware Help (A Specialist Will Reply)' started by griggi63, Nov 24, 2005.

  1. griggi63

    griggi63 Private First Class

    running windows xp......everything slowing down...internet connection(cable) keeps hanging up, loading slow, or hits the "page not found" screen. seems to go in cycles. ISP totally useless for tech support.
    ran bitdefender or finder what ever it was, came up with "WIN32.SOBER.AD@mm and also TROJAN.GLEIDER.I1 , how do i get this out. i did the first 4 steps of the ccleaner,adaware,spybot, and microsoft antispyware. i ran avast virus remover i got from MG it found nothing eventhough the bitfinder (or whatever) said the sober virus was there. helllppp.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. griggi63

    griggi63 Private First Class

    yes i did all the steps, and i already have hijck this on my c drive in its own folder.
     
  4. griggi63

    griggi63 Private First Class

    oh yeah, i also installed and ran "webroot spysweeper" i'm off to turkey dinner with the folks, will be back later. I can't thank you enough for responding in the first place. any help will be appreciated. when i get back i will post the events up to what has brought me to this point as accurately as i can. thanks again, be back in a few hours.
     
  5. griggi63

    griggi63 Private First Class

    ok, let me give you a little history.
    About 2 weeks ago my pc started acting up. my internet connection (cable) was interupted. called ISP and it seemed my router malfunctioned. OK fine, disconnected it. problem seemed resolved. the next few days, web pages started loading slower or not at all (page could not be found) and outlook express started timing out. Back to the ISP...they said they saw nothing wrong on their end. some days would be ok , some days real slow or dead, started affecting non internet programs. Back to ISP, still insisting its on my end, that i had software corruption. The only thing i could remember doing to change software was to update KODAK for my digital camera.
    Since they said software corruption, i started uninstalling many programs, including spyware finders and adaware and stuff. things have not improved.
    i have cleaned out many programs and have not reinstalled them, ran disc cleanup and defragged. still no luck.
    i have dont the (read this first) part of the tutorial for removing spyware and crap, and have run some of the online scanners. came up with different results from different scanners , have them all saved in txt files. let me know what you would like for me to do next.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Complete what I already gave you in message number 2.
     
  7. griggi63

    griggi63 Private First Class

    i have hjt downloaded already, the only exception is that i don't have it under my program files directory, it is directly in a folder under the C drive. is this acceptable?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's fine as long as it is not in a Documents and Settings or Desktop subfolder.
     
  9. griggi63

    griggi63 Private First Class

    well i moved it anyway. and i ran it and have a log file saved in a folder.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's nice but I can't see it there! ;)
     
  11. griggi63

    griggi63 Private First Class

    i'm having a problem uploading the attachment
     
  12. griggi63

    griggi63 Private First Class

    hope this worked
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You log does not show any true malware. A few minor things that can be fixed are below, but this is not malware:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)

    The O23 service will probably come back and we will have to use a special procedure to remove it.

    Are you still getting detections from anything?
    If so, post exactly what is being reported.
    Did a SpySweeper scan show anything? Can you post the log?

    Try running the following and post the log as an attachment:

    Running Ewido Security Suite
     
  14. griggi63

    griggi63 Private First Class

    i have logs from many tests. i will attach, also with the most recent HJT. will now do ewido, (did this before, was told by ISP to remove it, cannot remember the results.) will do it now, be back in a little, if i remember correctly took a decent amount of time to run.
     

    Attached Files:

  15. griggi63

    griggi63 Private First Class

    acouple more
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Content Monitoring Tool (or if not found look for msCMTSrvc) ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Content Monitoring Tool

    If that does not work try entering the short name: msCMTSrvc

    Now exit HJT and then reboot. After reboot check to see if the O23 line is gone.

    As far as the other items your scans detected. That Bitdefender log is not useful and seems incomplete. It gives no indication of where it found what.

    You should clean up the stuff in your Outlook email folder that Kaspersky found.
     
  17. griggi63

    griggi63 Private First Class

    ok heres the log from ewido, going to try and locate the files in outlook , it says its in the deleted files, but i set my outlook to dump those whenever i close outlook. the 023 thing is gone.
     

    Attached Files:

  18. griggi63

    griggi63 Private First Class

    i cannot seem to locate the files in outlook., if i go through explorer, i can get through the path to the folders that have the long series of numbers , but the folders themselves are empty. is this info already gone, or am i looking in the wrong place?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete the below if found (make sure viewing of hidden/system files is enabled):

    C:\webex <--- the whole folder

    Kaspersky show the below path info, see what you can find using Windows Explorer:
    C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{04634C30-14E4-448F-ABFF-2B83D0DA6603}\Microsoft\Outlook Express\SPAMfighter.dbx
    /[From "Grigghouse" <grigghouse@charter.net>][Date Wed, 02 Nov 2005 09:41:26 +0900]/Health_and_knowledge.zip/text.exe
    C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{04634C30-14E4-448F-ABFF-2B83D0DA6603}\Microsoft\Outlook Express\SPAMfighter.dbx/[From "Grigghouse" <grigghouse@charter.net>][Date Wed, 02 Nov 2005 09:41:26 +0900]/Health_and_knowledge.zip
    C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{04634C30-14E4-448F-ABFF-2B83D0DA6603}\Microsoft\Outlook Express\SPAMfighter.dbx
    C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{35396089-FE3C-4C07-A854-83A8AABE7B71}\Microsoft\Outlook Express\Deleted Items.dbx/[From info@optonline.net][Date Tue, 22 Nov 2005 16:21:29 GMT]/UNNAMED/reg_pass-data.zip/File-packed_dataInfo_exe.VIR
    C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{35396089-FE3C-4C07-A854-83A8AABE7B71}\Microsoft\Outlook Express\Deleted Items.dbx/[From info@optonline.net][Date Tue, 22 Nov 2005 16:21:29 GMT]/UNNAMED/reg_pass-data.zip
    C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{35396089-FE3C-4C07-A854-83A8AABE7B71}\Microsoft\Outlook Express\Deleted Items.dbx/[From info@optonline.net][Date Tue, 22 Nov 2005 16:21:29 GMT]/UNNAMED
    C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{35396089-FE3C-4C07-A854-83A8AABE7B71}\Microsoft\Outlook Express\Deleted Items.dbx

     
  20. griggi63

    griggi63 Private First Class

    ok, i found the .dbx files you mentioned to get rid of, i hope i did it right. i had to do it through explorer, it was the only way i could find them, it appeared i was actually deleting .dbx folders which i hope contained the files you meant. i deleted them , then emptied the recycle bin.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So how are things working now?

    Is Outlook working okay too?
     
  22. griggi63

    griggi63 Private First Class

    ok, webex is gone to, ran ccleaner just to clear out all the crap. hope that was ok
     
  23. griggi63

    griggi63 Private First Class

    seems to have picked up somewhat...i would like to reboot. do you think i can unoad the spysweeper and ewidos? the spysweeper sure makes booting up hang for a while. i'm trying to run a couple browsers at ethe same time to see if i can get it to stall. but at least for the last few minutes its seems ok
     
  24. griggi63

    griggi63 Private First Class

    running a lot better...still stalling off and on, but i haven't gotten outlook to hangup yet , just IE
     
  25. griggi63

    griggi63 Private First Class

    i guess i was wrong, still hanging up , and outlook timing out. not happening everytime, but still getting the :"page not found" and the big yellow! with outlook. seems to run in cycles. i looked through symantec to see about getting the win32.sober.y tool, but that one didn't exist. was going to use it just to be sure since that is what that kapersky results found. still a little lost. but i do really appreciate all you have done, pc is running better, just seems to have internet issues right now.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can uninstall Ewido and SpySweeper now to help things speed up.

    Also post a new HJT log from normal boot mode.

    Then please run Panda Online Scan. After the scan attach the log to your next post.
     
  27. griggi63

    griggi63 Private First Class

    ok , ewido is uninstalled, here is the latest hjt log. going to run panda scan now will post results when finished.
     

    Attached Files:

  28. griggi63

    griggi63 Private First Class

    results from panda active scan
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have HJT fix the below left over line from Spy Sweeper:

    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    Exit HJT.

    Run Windows Explorer and locate and delete: C:\WINDOWS\inf\host.inf

    Additional step to delete turbo.inf :
    - Click Start, Run, and enter cmd in the box and click OK. This opens a commend prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s turbo.inf
    del turbo.inf
    exit

    Are you still having any malware problems?
     
  30. griggi63

    griggi63 Private First Class

    ok. followed your last set of directions, here is the latest hjt log. i just got back online, am going to surf around see if it starts stalling again.
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Your log is clean!
     
  32. griggi63

    griggi63 Private First Class

    well Chas, you did me severe justice...seems to be working great...not hanging up, email not stalling anymore. any advice for me to keep this thing clean. i have ccleaner, ad-aware, spybot s&d. My antivirus is what the isp supplies...i'm not too sure about keeping it, because in order for it to function, i had to turn off the email scanning for virus option (this i was told to do by the tech from my ISP) which i believe is how this whole mess started in the first place. Cant thank you enough for all you have done.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I guess you are referring to Authentium Antivirus! It's not high on my list of things to use.
    Neither is stuff from Zero Knowledge.

    Check out what we recommend here: How to Protect yourself from malware!

    You're welcome!
     
  34. griggi63

    griggi63 Private First Class

    well 2 days and all seems fine. i have the zero knowledge ( i guess you already know that.) what do you think of AVG free? read on pcworld that it is pretty reputable. or would you reccommend that i go with a paid subscription like norton or mcafee? i have not unistalled the freedom yet, but i would like to , i dont feel safe without having some kind of protection for email scanning.
     
  35. griggi63

    griggi63 Private First Class

    disregard that last post, i just started reading the link you sent me to.
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you like Zero Knowledge and feel comfortable with it, then by all means keep it. But you do need a better antivirus. You can see some of the software we recommed from the link I gave you.
     
  37. griggi63

    griggi63 Private First Class

    Hey Chas, things still running good. What i meant was, I DO NOT like the freedom zero kknowledge and would like to change it, i have downloaded AVG and Zonealarm and am preparing to shut down windows firewall and uninstall freedom. i save them to a folder and will disconnect from the internet before uninstalling and reinstalling the new software. Just one more question, should i run any kind of registry cleaner?
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I do not typically recommend using registry cleaners except in certain cases and then I would only run them after having made a full backups. The reason I say this is because to many people get themselves into big trouble but just letting registry cleaners fix everything they report. This is not always a good idea.
     
  39. griggi63

    griggi63 Private First Class

    okee dokee....i'll stay away from that then. just wanted to get rid of any dead paths or whatever is not needed, but if that stuff doesn't affect anything, i'll leave it go. Again, can't thank you enough for all your help!!!! Have a great holiday!!!
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I said you can run one to clean stuff like that. But make sure you have a registry backup first. Many cleaners even allow you to make one first. And then to avoid headaches, just be careful what you allow it to fix.
     
  41. griggi63

    griggi63 Private First Class

    Hey chas, things still good on this end. i have uninstalled the freedom zero knowledge (well most of it, some of it wont come out even with the cleaner supplied by the ISP...it still shows up in my add/remove program menu) but anyway, i loaded norton antivirus and ran all the updates, it ran a full system scan and came up with a detected spyware...it was named "osrouter.dll" located in my c:\windows\system32. it would not let me delete it, when norton tried it said "delete failed" and skipped to the next window to exclude the file from deletion...at least that is the meaning i'm getting from it. do you know of this file, if it is dangerous or something i don't have to worry about?
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds