Is this the apocalypse?

Discussion in 'Malware Help (A Specialist Will Reply)' started by bhall, Aug 1, 2006.

  1. bhall

    bhall Private E-2

    Hi,

    I'm having tremendous problems. My symptoms are that browsers keep popping up to various websites (not porn related) and occasionally I get winlogon errors that seem to reboot my pc. I'm not very computer savvy so I followed the read & run me first steps to the best of my ability but had a few problems. I couldn't uninstall kazaa because of some file missing. Bitdefender wouldn't run and I had trouble getting sun java. BEcause of this, I did not run panda. When I rebooted in safe mode with networking, I was still getting browser popups. I think that means all my work was futile, right? Anyway, all I have is the hijackthis log file to attach. I'm very sorry, I really tried all steps. Anyway, any help is sincerely appreciated.

    bhall
     

    Attached Files:

  2. bhall

    bhall Private E-2

    Sorry, I think I ran my first log in safe mode. Attached is in normal mode.

    Thanks in advance
    bhall
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Why didn't you run Windows Defender? If it would not run, you were supposed to run CounterSpy and attach the log from CounterSpy.

    Goto Add/Remove Programs and uninstall AdwareAlert if found!

    Is your copy of Spyware Doctor a paid version or free trial version?

    Please run PandaActiveScan and attach the log! Then complete the below steps!

    Run this Look2Me VX2 Removal and then attach the requested log.


    Run the below procedure and attach the newfiles.txt log.
    Now attach a new HJT log from Normal Boot mode. You did not attach it in your last message.
     
    Last edited: Aug 1, 2006
  4. bhall

    bhall Private E-2

    Hi - Thanks for your help. Since I ran Look2Me removal after reboot - no popups. I also ran back and re-did all of the read & run steps. The only unsuccessful run was Bitdefender. I had a remaining execution time of over 6 hours so I figured something was wrong - went straight to Panda since that's what you wanted anyway. So, here are all of the files after everything was run. Do you see anything of concern? I noticed now that I can't turn on my firewall, it's disabled. That's concerning to me. Anyway, I appreciate your help! I'll have to reply again with the hjt log.

    Thanks
    bhall
     

    Attached Files:

  5. bhall

    bhall Private E-2

    Hjt log

    Thanks again!

    bhall
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please install HijackThis exactly how it was requested in the READ ME and don't forget to rename it. This is very important. Then attach a new HJT log.

    You also did not attach the requested log from running Look2Me Destroyer. I need the log.

    Did you run ShowNew before running the Look2ME Removal???? It sure looks like the order of execution was wrong. I see dozens of things in the logs that should have been removed by Look2Me-Destroyer. Please get a new log from ShowNew and attach it.
     
    Last edited: Aug 2, 2006
  7. bhall

    bhall Private E-2

    Sorry.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! That looks much better than the past ShowNew log.


    Start by downloading - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.


    Make sure you have rebooted in Normal Mode (do not open any other processes)

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:



    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
    R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\720NWU3T\drsmartload45a[1].exe
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\IMPYI3YF\cas2setup[1].exe[plugin.dll]
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\IMPYI3YF\loader[1].exe
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\U2O715GF\kybrdef_7[1].exe
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WNS6F26M\bbqa[1].cab[zqskw.exe]
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WNS6F26M\dfndref_7[1].exe
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WNS6F26M\drsmartload292a[1].exe
    C:/WINDOWS/Downloaded Program Files/RdxIE.dll
    C:\WINDOWS\keyboard1.dat
    C:\WINDOWS\NDNuninstall4_94.exe
    C:\WINDOWS\is-5d6eh.exe
    C:\WINDOWS\rundll.exe
    C:\WINDOWS\system32ghynf.exe
    C:\WINDOWS\system32bez6n4r21.exe
    C:\WINDOWS\system32n9nyb.exe
    C:\WINDOWS\SYSTEM32\bez6n4r21.exe
    C:\WINDOWS\SYSTEM32\iqqr.exe
    C:\WINDOWS\SYSTEM32\n9nyb.exe
    C:\WINDOWS\SYSTEM32\tsuninst.exe
    C:\WINDOWS\SYSTEM32\wfxqhv.exe
    C:\WINDOWS\SYSTEM32\zqskw.exe
    C:\WINDOWS\SYSTEM32\redist.dll
    C:\WINDOWS\SYSTEM32\w2a5caef3.dll
    C:\WINDOWS\SYSTEM32\xeymi.dll
    C:\GatorPatch.log
    C:\kybrdef_7.exe
    C:\kybrdfg_7.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot use Windows Explorer to delete the below folders if found:
    C:\Program Files\Common Files\okqi
    C:\Program Files\System Files

    Now attach a new HJT log and tell me how the steps went.

    Also attach a new log from ShowNew.

    Make sure you tell me how things are working now!
     
  9. bhall

    bhall Private E-2

    Hi Chaslang,

    Thanks for the help. Attached are the files you requested. After the delete on reboot prompt, I did NOT receive the Pending FileRename Operations prompt. Rebooting seemed slightly slower than normal, but only slightly and explorer was slow at first but then got back to normal.

    Let me know if I need to do anything else!

    Thanks
    bhall
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds