Malware/Antiviruspro2007/pop ups, plz help

Discussion in 'Malware Help (A Specialist Will Reply)' started by KiLL CraZy, Apr 19, 2007.

  1. KiLL CraZy

    KiLL CraZy Private E-2

    Ok, for some reason yesterday I started to get pop ups and my Symantec AntiVirus also pop up a few times saying I had a trojan and it kept removing them. A lot of the pop ups I realized where from the antiviruspro 2007 saying to buy it and this and that but i knew it was a pop up.

    Which is weird b/c im not a noobie at clicking things and im really aware of things I click and i really have no idea how I started to get this popups.

    I followed the malware guide and here are my logs. I had no trouble performing any of them. Please help me out.

    Also, what is recommend to use? Symantec AntiVirus Corporate Edition (which i am usuing currently) or Norton 2007? I have no idea whats the difference between the 2 and just wanna know which one is better to have on the pc.

    P.S. I am currently in normal mode so for any instructions that are going to be given to me, plz let me know if I should stay in normal mode or boot into safe mode.

    Ill post the logs in a few mins... Im doing the last scans now

    EDIT: Here are the logs
     

    Attached Files:

  2. KiLL CraZy

    KiLL CraZy Private E-2

    Here are the final 3, thanks in advance
     

    Attached Files:

  3. KiLL CraZy

    KiLL CraZy Private E-2

    can someone please help?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you read the top sticky about bumping? This post cost you about 6 to 8 hrs more waiting time!


    Start by running this: Virtumonde aka Trojan Vundo Removal attach the requested VundoFix log.

    Then also attach new logs from ShowNew and HJT.
     
  5. KiLL CraZy

    KiLL CraZy Private E-2

    Im terribly sorry about that, literally right after I posted that I started to look at the sticky threads and then said oh sh** to myself. This will never happen again.


    and as to this... here are the logs

    a little problem occurred while trying to remove 2 files that VundoFix found

    jkhfd.dll
    dfhki.ini

    those 2 files kept saying that it wasn't able to delete them and to click ok to reboot and try and delete them like that, which I tried and still it said it wasn't able to. I also rebooted into safe mode and still, it said could not remove those 2 files.

    Now also when I rebooted into normal mode, as my pc was starting up, i got an error message saying:

    Error loading C:\WINDOWS\system32\mqiayswa.dll
    The specified module could not be found.

    And just as a side note I also got a popup right when the pc finished rebooting.

    Ill post a screen shot of the error on a new post
     

    Attached Files:

  6. KiLL CraZy

    KiLL CraZy Private E-2

    here is the screenshot.

    Im gonna go to bed now and turn my pc... Ill await your reply until then on what to do...

    Thank you sir for your future help. :)

    P.S. Im running s WinXP SP2... that's just a vista skin i have on with windowsblinds just in case you was wondering
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not uninstall Messenger Plus Live in step 0 of the READ ME. Do you realize that it is the cause of your Virtumonde infection and has been the cause of tens of thousands of infected PCs on the internet!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really should begin by uninstalling Messenger Plus! Live

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Continue by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)
    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of jkhfd.dll once and then click the kill button. After you have killed all of the jkhfd.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    vtusrrr.dll

    Next double click on explorer.exe and again click once on each instance of jkhfd.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    vtusrrr.dll

    Next double click on iexplore.exe and again click once on each instance of jkhfd.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    vtusrrr.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\jeehlgqs.dll
    O2 - BHO: (no name) - {3F9D0C61-737D-44D1-BD80-91AF857061CC} - C:\WINDOWS\system32\vtusrrr.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {C0A513A0-EC6D-40B3-949B-A13176EE4583} - C:\WINDOWS\system32\jkhfd.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [xloadnet] "C:\Program Files\xloadnet\xloadnet.exe"
    O4 - HKLM\..\Run: [runner1] C:\WINDOWS\updater.exe 61A847B5BBF72810329B385473F001F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
    O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\mqiayswa.dll",setvm
    O15 - Trusted Zone: *.sxload.net (HKLM)
    O20 - Winlogon Notify: jkhfd - C:\WINDOWS\system32\jkhfd.dll
    O20 - Winlogon Notify: vtusrrr - C:\WINDOWS\SYSTEM32\vtusrrr.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Program Files\xloadnet\xloadnet.exe
    C:\WINDOWS\updater.exe
    C:\WINDOWS\system32\mqiayswa.dll
    C:\WINDOWS\system32\jeehlgqs.dll
    C:\WINDOWS\system32\jkhfd.dll
    C:\WINDOWS\system32\vtusrrr.dll
    C:\WINDOWS\system32\mmllm.tmp
    C:\WINDOWS\system32\dfhkj.ini
    C:\WINDOWS\system32\mmllm.ini
    C:\WINDOWS\system32\mmllm.ini2
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.

    Now please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  9. KiLL CraZy

    KiLL CraZy Private E-2




    just a quick question as to b4 I uninstall this... Is this a good tool to prevent malware from coming on the PC? Because if it is I would rather leave it on to prevet future stuff from happening. Please let me know of you suggestion about it and right now im gonna do the rest of the steps.
     
  10. KiLL CraZy

    KiLL CraZy Private E-2

    I did all the steps you said without any problems what so ever.

    Here are the log files.

    How do things look now?

    And as of right now, my PC seems to be running smooth again without any pop ups or my virus scanner poping up.

    Wow, dude, you are the man. You have no idea how thankful I am.

    Question though, just out of curiosity... what the heck happened with my pc? just spyware and stuff?

    Also, what virus scanner do you recommend? Because I have both Norton 2007 and Symantec AntiVirus Corporate Edition (this is the one im using) but im guessing this doesn't work to good since it's allowing stuff liek this to happen to my pc?
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you plan on buying it? It is only a trial and will not work after the 15 day trial period. It is a pretty good program however some people feel that it slows down there boot up and also impacts normal run time performance too much. I really don' t think these are valid issues since, you need this kind of a tool and you are not typically rebooting that frequently. Thus what's the big deal about boot time. As you found, your Norton Antivirus is totally inadequate as its main focus is virus protection. Thus it misses many things that are not considered a virus.

    At any rate, you should uninstall it unless you are going to buy it.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I said in my other messages, you installed Messenger Plus! Live which gave you a Virtumonde infection.

    Personally we don't like Symantec for a few reasons:
    • it misses many things
    • it does not remove/fix some things that it finds
    • it is a massive resource hog which slows PCs down and people are always coming to the malwar forum complaining of slow PCs when the problem is Symantec/Norton and not malware. Since you seem to only have the Antivirus part and not the massive Internet Security Suite hog, you should not notice Symantec slowing your PC down as dramatically as other who install the Suite.
    You have two more files to delete fromt he Vundo infection. Delete the below:
    C:\WINDOWS\system32\dfhkj.tmp
    C:\WINDOWS\system32\dfhkj.tmp2


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. KiLL CraZy

    KiLL CraZy Private E-2

    i see 3 files of that sort... here is a pic

    should I delete all 3 of them? and by delete you mean just right click, and choose delete right?
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes delete all 3 of them. Try right click and delete, if that does not work your options are using Pocket Killbox or trying again after booting in safe mode.
     
  15. KiLL CraZy

    KiLL CraZy Private E-2

    woot! I was able to delete the 3 files, I did the system restore, and my PC is running like new again.

    Dude, thank you so much, you have no idea how appreciate I am, Thank you!

    ROCk ON!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds