Infection Report - Help Request

Discussion in 'Malware Help (A Specialist Will Reply)' started by txbajabill, Sep 27, 2006.

  1. txbajabill

    txbajabill Private E-2

    I've followed all steps up to #7 from the READ & RUN ME FIRST Before Asking For Support Thread.

    My problems have become imbedded and I cannot get them out without taking further actions. I have attached the log files.
     

    Attached Files:

  2. txbajabill

    txbajabill Private E-2

    Windows Defender found:

    AvenueMedia.DyFuCA
    NewDotNet
    eZula.TopText
    Claria.GAIN.Trickler
    ZenoSearch
    SearchItQuick Toolbar
    CoolWebSearch.MWSearch
    Mirar
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    First goto Add/Remove programs and uninstall screensaver_rp Screen Saver which is malware.

    While in Add/Remove programs, also uninstall the below old Sun Java versions:
    J2SE Runtime Environment 5.0 Update 1
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6

    Now install the current version of Sun Java from: Sun Java Runtime Environment
    Now download a tools we will need- Pocket KillBox

    Extract it to its their own folder somewhere that you will be able to locate itlater.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: SSL encrypt - {746455FE-D059-47e7-AF0E-140E03F5A447} - C:\WINDOWS\system32\nsn31B.dll
    O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
    O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} - http://cabs.elitemediagroup.net/cabs/mediaview.cab
    O16 - DPF: {79B96C72-C0D0-4DC8-BC7E-9F314A918228} - http://ak.imgfarm.com/images/nocache/myspeedbar/myinitialsetup1.0.0.7.cab
    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.20.19/ttinst.cab
    O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/games/web_games/tikgames/cinematycoon/cinematycoon.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://clubgames.pogo.com/online2/pogop/chuzzle/popcaploader_v6.cab

    After clicking Fix, exit HJT.:

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    c:\windows\downloaded program files\f3initialsetup1.0.0.6.inf
    c:\windows\downloaded program files\myinitialsetup1.0.0.7.inf
    C:\WINDOWS\Downloaded Program Files\ttinst.dll
    C:\WINDOWS\1205.exe
    C:\WINDOWS\Justin.exe
    C:\WINDOWS\MirarSetup_876057.exe
    C:\WINDOWS\s4Setp.exe
    C:\WINDOWS\SYSTEM32\adrot-uninst.exe
    C:\WINDOWS\SYSTEM32\adrotate.dll
    C:\WINDOWS\SYSTEM32\nsn31B.dll
    C:\WINDOWS\system32\safe.tlb
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.


    After reboot locate the below folder and delete it if found:
    c:\program files\common files\Totem Shared

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Christi\Local Settings\Temp

    Now attach a the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. txbajabill

    txbajabill Private E-2

    First, when I try to unistall screensaver_rp Screen Saver, I get an error window: Could not find the file "swflash.ocx"

    I will continue as per your directions with the remaining steps, unless otherwise instructed.

    Thanks for your help! I will repost when complete and let you know how things are working.

    Thanks!
     
  5. txbajabill

    txbajabill Private E-2

    All steps performed smoothly except for #1 (unable to uninstall screensaver_rp Screen Saver

    One thing I noticed on the HJT log was 015 trusted zone *.elitemediagroup.net, but I did not removed it at this time, as I was not instructed to do so.

    ran reg fix okay,

    ran pocket killbox okay,

    deleted folder Totem Shared

    deleted all C:\WINDOWS\Temp

    deleted all but the following files from C:\Documents and Settings\Christi\Local Settings\Temp:
    Perflib_Perfdata_81c.dat 9/27/2006 5:58:07
    Perflib_Perfdata_f9c.dat 9/27/2006 5:56:31

    I have not yet reset system restore, as I await your response to the first item on the list. Otherwise, everything seems to be running well, and I havn't received popups since performing the operations. The HJT log seems clear.

    Thanks!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try using the below to uninstall it:

    Your Uninstaller! 2006

    Let me know it that works! Look in a new ShowNew log for it to make sure it is gone. You will see an Uninstall programs list at the end.

    Yes fix the below line:
    O15 - Trusted Zone: *.elitemediagroup.net


    Other than those you are clean! Once the above have been fixed then you can move on to the below.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  7. txbajabill

    txbajabill Private E-2

    Everything worked like a charm.....

    Thank you so much!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds