Malware and Virus - registry changed

Discussion in 'Malware Help (A Specialist Will Reply)' started by samuel21, Oct 27, 2006.

  1. samuel21

    samuel21 Private E-2

    Hi, my laptop was infected with malware and viruses. I read your post on "READ & RUN ME FIRST Before Asking for Support " and attempted the steps, which seemed to fix the viruses and malware. However, I still experience these problems:

    1. Windows running very slowly, seemed to be at 100% CPU.
    2. 2 x iexplorer.exe shown in task mgr.
    3. 2 x realplay.exe shown in tak mgr
    4. explorer.exe taking up much memory about 60000kb
    5. Cannot change desktop wallpaper and cannot change any settings to wallpaper - registry key changed
    6. when i have several windows open, e.g. IE, wmplayer, folder, the IE window takes precedence. i.e. i cannot control (close, resize, bring to front) other windows without first minimizing the IE window first.

    Pls refer to attched txt files, as instructed. Will attach other required files in follow-up thread

    Hope I can get help.

    thanks!
    samuel21
     

    Attached Files:

  2. samuel21

    samuel21 Private E-2

    Hi, my laptop was infected with malware and viruses. I read your post on "READ & RUN ME FIRST Before Asking for Support " and attempted the steps, which seemed to fix the viruses and malware. However, I still experience these problems:

    1. Windows running very slowly, seemed to be at 100% CPU.
    2. 2 x iexplorer.exe shown in task mgr.
    3. 2 x realplay.exe shown in tak mgr
    4. explorer.exe taking up much memory about 60000kb
    5. Cannot change desktop wallpaper and cannot change any settings to wallpaper - registry key changed
    6. when i have several windows open, e.g. IE, wmplayer, folder, the IE window takes precedence. i.e. i cannot control (close, resize, bring to front) other windows without first minimizing the IE window first.

    Pls refer to attched txt files, as instructed. Will attach other required files in follow-up thread

    Hope I can get help.

    thanks!
    samuel21[/QUOTE]
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You did not follow the directions for obtaining a log for BitDefender online scan. As a result you posted information that is not helpful. Don't bother with another scan now but if there is a next time, please follow the directions given.

    You also have HijackThis installed exactly where we specify not to install it. Please fix this now before continuing!

    Did you knowingly install PopCap Browser Plugin? If not, uninstall it.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2

    Now install the current version of Sun Java from: Sun Java Runtime Environment
    • Now Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to host Service For Windows
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pastemshost into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Continue by downloading a tools we will need - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\TEMP\win5D28.tmp

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F3 - REG:win.ini: load=C:\WINDOWS\rundl132.exe
    O2 - BHO: (no name) - {367A043F-11A4-FAC6-1A53-06559C9311B3} - C:\WINDOWS\system32\vgnjkhj.dll
    O2 - BHO: (no name) - {4BBC1A4D-DD20-4980-A645-2E13F6FC286D} - C:\WINDOWS\system32\3721.3.dll
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [pybdwsh.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\pybdwsh.dll,ectzfae
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\RunServices: [winsys001] ialykffe.exe
    O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users\Documents\Settings\winsys2f.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\Samuel\Application Data\Install.dat
    C:\Program Files\Internet Explorer\PLUGINS\system16.sys
    C:\WINDOWS\system32\3721.3.dll
    C:\WINDOWS\system32\mlnwinmc3.exe
    C:\WINDOWS\system32\swiool.scr
    C:\WINDOWS\Temp\win5D28.tmp
    C:\WINDOWS\system32\hlpwinmlt4.exe
    C:\WINDOWS\system32\pybdwsh.dll
    C:\WINDOWS\system32\vgnjkhj.dll
    C:\WINDOWS\system32\mini3tone.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Samuel\Local Settings\Temp

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds