links4all.biz/MSN virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by kiwiabroad, Nov 30, 2006.

  1. kiwiabroad

    kiwiabroad Private First Class

    Hi - back again after so long! Please help re following:

    My son has managed to download problem thru MSN.

    He got a message while on MSN saying 'is this you' thinking it was from a friend and clicked on the link and pressed run. This morning I had problems saying MSN 4.6 couldn't run unless MSN Plus was installed, SpywareBlaster told me my internet was configured in an unstable way (I restored it's recommended defaults): sites such as google, personal banking and email wouldn't load and instead came up with sites such as jamesvideos.com, autoserf.com, dearladies.com, lesbianslumber.com, hqgalls.com and mysqlrblog.com. All these sights looked the same in terms of layout and colour. Other sites that came up in the address bar were jupk.com and picskenso.com. I did a virus scan (Avira) which found 3 files with the same virus (TR/Dldr.Agent.bca) all of which were quarantined and also a Dyfuca virus (access deny). I have got home tonight and found internet 'appears' to be working ok but SpywareBlaster gave me another 'unstable' message and internet options security has been changed from medium (default setting) to custom (I have restored the defaults). Also a blank page after google opens of links4all.biz. I have been thru Add/Remove Programs and removed everything not used or unnecessary including a 'PicMaster' last used yesterday which seems highly suspicious.

    I have the following:

    Windsow XP (home) SP2
    Internet explorer 6
    Sygate Personal Firewall
    Ad-aware SE Personal
    SpywareBlaster
    Spybot Search & Destroy
    SpywareGuard
    AntiVir PE Classic

    The last 5 items are regularly updated and completely up to date and have been run. Ad-aware only found tracking cookies, Spybot found nothing, AntiVir found as above, SpywareBlaster as above.

    I know there are other MSN viruses which ask you about a photo and download Toolbar 888 for example. I have no apparent unusual toolbars.

    Do I need to run HijackThis etc (incidentally, no longer on computer as I removed it about a month ago!)? Please can you help me.

    Thanks in advance to anyone for your time
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and welcome back to Majorgeeks!

    If your running Windows Messenger 4.6, I would suggest you disable/remove it using this Disable/Remove Windows Messenger then download the latest version HERE or Live Messenger 8.1b once the PC is given a malware free all clear, BUT do not install Messenger Plus! if it is on the PC use Add/Remove to uninstall it.




    Then please follow our standard cleaning procedures which are necessary for us to provide you support, these will help start the clean up process for any malware that will/could be on the PC, Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. kiwiabroad

    kiwiabroad Private First Class

    Thanks Halo - I will do the steps requested and get back to you a.s.a.p.
     
  4. kiwiabroad

    kiwiabroad Private First Class

    Hi Halo

    Coming thru are 3 attachments after following the instructions on the Read & Run Me First link. Points to note are:

    1. couldn't do Step 6A in Safe Mode with Networking Support so ran the scans in normal boot mode.
    2. Panta Active Scan would just not work; ActiveX controls appeared to download ok but the update download would appear to download in full but would then come up with an Error saying either the ActiveX wasn't downloaded or a problem with internet connection or space available or access rights etc. I re-started the computer, checked internet connections, etc but still wouldn't work so no Panda Report attached unfortunately - please advise.

    Look forward to your reply and hope I have done everything correctly. Remaining attachments in second reply.

    Regards

    Kiwiabroad
     

    Attached Files:

  5. kiwiabroad

    kiwiabroad Private First Class

    Hi Halo

    ShowNew attachment - GetRunKey won't upload - will try in separate email

    Kiwiabroad
     

    Attached Files:

  6. kiwiabroad

    kiwiabroad Private First Class


    Runkeys.txt won't upload - seems to be because 0kb in Notepad??? What have I done wrong here as it seemed to work ok at the time??
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have to follow the directions on the download pages for both GetRunKey and ShowNew exactly. You are running the .bat files from inside the ZIP file which will not work. You MUST EXTRACT all the files from the ZIP file and then you must open a Windows Explorer session (right click Start and select Explore) and navigate to the folder where you extracted the files to. And then you must double click on the GetRunKey.bat file and then the ShowNew.bat file to run them and get a proper log. After doing this, attach new logs from both of them.

    You should uninstall Messenger Plus! which is the cause for tens of thousands of PCs being infected! We even stated this should be uninstalled in step 0 of the READ & RUN ME. CounterSpy warned you too!!

    You also need to go back and run CounterSpy again and allow it to fix the problems it finds. You told it to ignore everything. There is no sense in scanning unless you fix the problems. Attach a new log from it after doing this.
     
    Last edited: Dec 5, 2006
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way, you also need to run the below procedure and attach the requested log:

    WareOut Removal
     
  9. kiwiabroad

    kiwiabroad Private First Class

    Hi Chaslang

    I will run GetRunKey and ShowNew again and Wareout Removal - thanks for the advice and sorry for not running the first two properly. I realised my mistake with Counterspy and have all ready re-run it and let it fix as per the default recommendations. I think one of the scans I did from the instructions(after this re-run) showed the various viruses in quarantine from Counterspy, 'disinfect failed' and then deleted them?
     
  10. kiwiabroad

    kiwiabroad Private First Class

    By the way - I thought I had uninstalled Messenger Plus! thru the Control Panel. I went on all users and checked as well. What am I missing out?? Do I need to go on as Administrator in safe mode and uninstall?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your CounterSpy log had showed it and you had ignored it. That was the reason for my comment. As to whether it is uninstall or not, I cannot tell until I get the proper logs from ShowNew and GetRunKey.
     
  12. kiwiabroad

    kiwiabroad Private First Class

    Hi Chaslang

    RunKeys and ShowNew files attached - hopefully correct this time. Wareout Removal to follow.
     

    Attached Files:

  13. kiwiabroad

    kiwiabroad Private First Class

    Hi Chaslang

    Wareout Removal log attached
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [adiras] adiras.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\RunServices: [Microsoft Windows DLL Services Configuration] poker3.exe
    O4 - HKCU\..\Run: [Microsoft Windows DLL Services Configuration] newdll2.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{1995D4B0-D220-4175-8057-66CF935FCFA1}: NameServer = 85.255.113.133,85.255.112.143
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.133 85.255.112.143
    O17 - HKLM\System\CS1\Services\Tcpip\..\{1995D4B0-D220-4175-8057-66CF935FCFA1}: NameServer = 85.255.113.133,85.255.112.143
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.133 85.255.112.143
    O17 - HKLM\System\CS2\Services\Tcpip\..\{1995D4B0-D220-4175-8057-66CF935FCFA1}: NameServer = 85.255.113.133,85.255.112.143
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.133 85.255.112.143
    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\SYSTEM32\adiras.exe
    C:\WINDOWS\SYSTEM32\KDYTO.EXE
    C:\WINDOWS\SYSTEM32\newdll2.exe
    C:\WINDOWS\SYSTEM32\poker3.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.
    After reboot locate the below folder and delete if found:
    C:\Program Files\Common Files\{30D52D63-0BB0-1033-0919-03082203002c}
    C:\Program Files\Common Files\{70D52D63-0BB0-1033-0919-03082203002c}

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Dec 10, 2006
  15. kiwiabroad

    kiwiabroad Private First Class

    Hi Chaslang

    I have got as far as saving the fixME.reg to desktop but when I double click it and select ok to merge with registry it comes up with an error - Cannot Import .... error accessing registry. Please advise - I have not carried on with any further steps as yet until I receive your instructions on this.

    Please note - ever since downloading CounterSpy I get little pop up messages saying various things are trying to access Registry but a lot of them have no names. I have been selecting block but am not sure if this is the right course of action. Do I need to change settings somewhere or should I be selecting allow and remember this action?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must not block registry access when this fix is being run. So make sure that you allow the change if CounterSpy pops up! Download the fixme.reg patch again. I made a change to it. The try it one more time. If it still does not work, just continue on with all the other steps.
     
  17. kiwiabroad

    kiwiabroad Private First Class

    Logs attached - hopefully done correctly. FixME.reg still did not work. No other apparent problems/messages with following instructions. Internet and computer appear to be running ok although system tray takes longer to load up than before this problem. Not sure what the situation is with Messenger Plus now??
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Apparently the registry patch worked anyway!

    You should not uninstall CounterSpy since it is only a trial version and this should help speed up your startup a little too.

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  19. kiwiabroad

    kiwiabroad Private First Class

    Hi Chaslang

    Thanks so much for your help and all the advice - you are brilliant!
     
  20. kiwiabroad

    kiwiabroad Private First Class

    Just a P.S. - did I successfully uninstall Messenger Plus then? Is there a quick way to check? And is there a way to prevent my kids installing it again other than threatening them with painful death??!!
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Yes it is gone.

    See step 9 of the How to protect thread.
     
  22. kiwiabroad

    kiwiabroad Private First Class

    Thanks - already done - Step 9 was my Step 1!!
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good but actually the other steps should really be run first. You don't really want to start on the How to without having cleaned up all the remnants, or more importantly, before doing the toggle of System Restore.
     
  24. kiwiabroad

    kiwiabroad Private First Class

    Hi Chaslang

    Sorry - just my sense of humour - I did actually do everything in the order suggested.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Even better! ;)
     
  26. kiwiabroad

    kiwiabroad Private First Class

    Hi again

    Can I just quickly check that I have done System Restore correctly as when I went into it the 'Turn off system restore' was already ticked... is it correct that the 'Turn off system restore' should now be unchecked after the reboot?
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If it was already disabled then you need to Enable it (that means uncheck it). Then if you recheck it after a reboot it should still be unchecked. If this does not happen, something may have broken the System Restore service and it may need to be fixed.
     
  28. kiwiabroad

    kiwiabroad Private First Class

    My system restore is currently unchecked and has remained so after a reboot so I assume this is good?

    In the meantime my AntiVirPE Classic will now not update - it takes quite a while to 'do it's bit' and then comes up with an internet connection error. I have attached the latest log file in case this helps. Not sure whether it's a problem at my end or their end - I suspect mine.

    I'm also not sure I've done the Sun Java installation correctly as there was no visible (to me) option to test my JVM when I finished and I have had one website say I didn't have the correct Javascript - I left it and didn't download anything it suggested like Flash Media. I went thru the link in you 'How to Protect yourself from Malware' and installed the JRE 6. There also didn't seem to be options for Google toolbars and Desktop (which I don't want anyway) but makes me think I have done something wrong. How can I check my installation please?

    My kids can use MSN fine altho when they double click on the Windows Live Messenger icon they get a little box that says 'Error - Access Denied' but then MSN loads up ok. Is this because I have now changed them to limited users or is it something different?

    Sorry to be a pain with these questions but these seem to be the only remaining niggly problems.
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Be careful how you word things! I assume what you mean is that the check box to Turn off System Restore on all drives is unchecked which is good.

    • Download but don't install the current version of Antivir here: AntiVir Personal Edition 7 ( I want to make sure you have the current version )
    • Disconnect your PC from the internet by unplugging the cable.
    • Uninstall AntiVir!
    • Reboot and the delete the folder for it in C:\Program Files
    • Reconnect your cable to the internet and immediately install AntiVir from the file just downloaded.
    • See if it can get the updates!
    Let me know what happens.

    They may not be inserting the Google Toolbar/Desktop by default anymore. (Note: We now have Sun Java at MGs too. It is in the file folder named Browsers on the main page.) Does the new version appear in Add/Remove programs? Did you uninstall all old versions?

    Possibly due to the settings change. You could test that theory by making a temp change back to higher account privies and then change it back just to see what happens.
     
  30. kiwiabroad

    kiwiabroad Private First Class

    Yes - changing them back to higher account privileges does get rid of this problem.

    "You should not uninstall CounterSpy since it is only a trial version and this should help speed up your startup a little too." - this was an instruction given in one of your earlier posts - I assume you meant I should uninstall Counter Spy now?
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes the not should have been now.

    Yes you should delete the MessengerPlus!3 folder.

    So is everything okay now?
     
    Last edited: Dec 16, 2006
  32. kiwiabroad

    kiwiabroad Private First Class

    I did a last run of CounterSpy before uninstalling it and it detected the MessengerPlus adware bundler which default setting was 'ignore' as in previous runs - however, this time I removed it and this appears to have got rid of the MessengerPlus folder.

    At the risk of tempting fate ... yes, everything appears to be ok now.

    Thanks again for all your help.

    Merry Christmas and a happy New Year!:)
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely and enjoy your Christmas and New Year malware free! :D
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds