Malware continues to live, need some help.

Discussion in 'Malware Help (A Specialist Will Reply)' started by koochman, Jul 14, 2006.

  1. koochman

    koochman Private E-2

    I have tried all I can myself, and I think it is time for help. I have followed the Read and Run Me First thread twice with the exception of Hijack This!. I will tell you what I have done, and what problems I have, then hopefully someone can tell me what I am doing right or wrong, and what I should do next.

    My problems started when what appeared to be a friend on MSN Messenger sent me a link. It has since infected my computer and I am struggling to get rid of it.

    My homepage has been hijacked and is set to virushelpzone.com. My Norton virus protection will not work, virus/spyware help sites are blocked, and msconfig will not function or stay open for more than a couple seconds.

    I did manage to click fast enough and get my computer to run in Safe Mode.

    Spybot finds 62 Windows.RedirectedHosts, FakeMSN8Beta which contains 6 entries.

    Ad Aware finds some data miners, the log file is attached.

    Windows Defender finds one problem, but currently it is not showing up.

    CWShredders finds a MSconfig problem file.

    Like I said before, I have done the steps in the Run thread twice, on different days, yet I still have all the same problems right after. My problem may lie in System Restore. While in Safe Mode, I cannot disable System Restore. Once I restart in normal mode, then disable restore, restart and enable, the problems and malware are back.

    Even immediately after malware removal, I cannot get into the Bitdefender site. I did run the Panda Active Scan and I will include the log file from that scan as well.

    I have not run HJT. Anytime I open the program, it is immediately closed so I am unable to run any scans.

    I have honestly tried. If I have missed something, I apologize. I would appreciate any help. Thanks!

    P.S. I have a Compaq Presario R3000, 2.4Ghz AMD 64, 512mb RAM, 32mb graphics card, and 40gb HD.
     

    Attached Files:

    Last edited: Jul 14, 2006
  2. koochman

    koochman Private E-2

    I guess you guys need the HJT log first. I can't run it though. Any ideas?

    It might possibly run in Safe Mode after I run all the other scans, but I thought it needs to be run in Normal mode?
     
    Last edited: Jul 14, 2006
  3. koochman

    koochman Private E-2

    Any ideas? I know the log file for Ad Aware was not asked for, but I thought I would include it. Sorry if it is not needed.

    I am at a loss at this point.
     
    Last edited: Jul 14, 2006
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First try renaming HijackThis.exe to myhjt.com and then run myhjt.com. If that does not work, try running it in safe mode.

    The logs you posted thus far show no problems at all.

    Also do the below:


    Run the below procedure and attach the runkeys.txt log.
    Now run the below procedure and attach the newfiles.txt log.
     
  5. koochman

    koochman Private E-2

    Ok, I tried changing the file name to myhjt.com but HJT still crashes, so I had to run it in safe mode.

    I also ran the 2 additional requested scans while in safe mode. All 3 logs are attached.

    Thanks, I appreciate the help! :)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a problem in your OS and some files are missing. Do one of the below based on which version Win XP you have.

    For Windows XP Pro: download and run XPproFix
    For Windows XP Home: download and run XPHomeFix

    Also make sure you extract both files from ShowNew.ZIP into the same folder. You previous log was incomplete. However it did find to malware files in system32 and deleted them. It only deletes a few known bad files if found. It is mostly just a scanning tool to provide lists of new files if a few folders. These are not necessarily bad! They are just new.

    Then run ShowNew again and attach a new log. Run it in Normal Boot mode.

    Also Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Then get a new runkeys.txt log from Normal Boot mode and attach it here.
     
  7. koochman

    koochman Private E-2

    Missing files? That doesn't sound good...

    Ok, so when I run XPHomeFix, the default settings are to unzip all files to C:\Windows\System32. Is this what I do?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!
     
  9. koochman

    koochman Private E-2

    Ok I ran XPHomeFix. I saved the bolded text the way you described, but when I double click it, I get an error that says: "C:\Documents and Settings\Kooch\Desktop\fixme.reg is not a valid Win32 application."

    Fogive me if I am missing something.
     
  10. koochman

    koochman Private E-2

    Here are the new ShowNew and GetRunKey logs after the XPHomeFix but without the fixme.reg.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below which I modified slightly, but if it does not work, you are not saving it properly or your registry editor (regedit.exe) is broken or missing.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Delete all files in the below folder! Windows will have a few from the current date in use. Just work around them and delete all others.
    C:\Documents and Settings\Kooch\Local Settings\TEMP


    Attach new runkeys.txt log (only if the registry patch worked - otherwise skip )

    Also attach a new log from ShowNew.
     
    Last edited: Jul 16, 2006
  12. koochman

    koochman Private E-2

    Ok deleted all files out of the TEMP folder.

    fixme.reg still will not work. I am saving to the desktop with 'Save As' set to 'All files'. I get the same error as before. I did a search for regedit.exe just for fun and here's what I got:

    New ShowNew log attached.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, Run, and enter regedit and click OK! Does the registry editor open?

    If not, click Start, Run, and enter c:\i386\regedit.exe and click OK. Does the registry editor now open?

    Several bad files in your system32 folder are not deleting.

    Download the newest version of ShowNew (just updated) and get a new log
     
    Last edited: Jul 17, 2006
  14. koochman

    koochman Private E-2

    Yes but it closes almost immediately.

    Also opens but closes almost immediately.

    I assume the latest version is updated in the link you provided me earlier? If so, I redownloaded and ran a new log, it is attached.

    I also ran regedit in safe mode just for fun, and it will run stable. No, I did not change anything.

    Thanks again for all your help, I really owe you!:D
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Apply that registry patch in safe mode.

    Also while in safe mode let's delete two files that seem to either be coming back or that are not deleting when ShowNew deletes them.

    While in safe mode click Start, Run, and enter cmd and click OK. This will open a command prompt window. In the command prompt windows enter the below command strings each followed by the enter key (note there are spaces between the -h and the -s arguments)

    cd c:\windows\system32
    attrib -h -s netstat.com
    attrib -h -s taskkill.com
    del netstat.com
    del taskkill.com
    attrib -r -s -h *.exe
    dir *.exe > c:\exefiles.txt
    exit

    The last command (exit) will close the command prompt window. Now reboot into normal mode and get a new log from ShowNew and attach it. Also attach the below file which was created in the above process:

    c:\exefiles.txt

    Also attach a new runkeys.txt log.
     
  16. koochman

    koochman Private E-2

    When I try to apply the patch fixme.reg in safe mode, I still get the same error message I was getting before. The registry editor will open in safe mode however.

    I entered the above strings while in safe mode. I've included the requested logs. It appears from the viewing the newfiles.txt log that the bad files still did not delete.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you logging on with administrator priviledges?

    Have you also tried booting in safe mode as the User Account named: Administrator ?

    I see the below in your runkeys.txt log which indicates that registry editing and admin accounts is disabled?

    You will need to run Gpedit.msc to change the Group Policy that has disable registry edits. You can run Gpedit.msc by clicking Start, Run, and entering gpedit.msc in the box and clicking OK. See if their is a policy indicating that registry editing has been disabled.
     
    Last edited: Jul 19, 2006
  18. koochman

    koochman Private E-2

    My profile is has Administrator privledges. I did try logging in as the Administrator as well. Both yield the same results. No dice.

    I also tried running gpedit.msc in both normal and safe mode, in my profile and in Administrator.

    I get an error message stating that Windows cannot find gpedit.msc. So I did a search for it and it was not found.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have your Windows XP CD?

    Can you create a new user account on this PC?

    Download and install Registrar Lite Then try running it! Does it run?
     
  20. koochman

    koochman Private E-2

    Yes I do.

    This is my personal computer, so if I need to, yes I can.

    Yes. The program will open and stay open in both normal and safe mode.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Locate the gedit.msc file in the i386 folder and copy it to you C:\windows\system32 folder

    What I meant by that question was for you to actually see if you could (were allowed) to create a new user account.


    OK! Run RegisrtrarLite and Copy and paste the below into the Address box of registrar lit and hit the Enter key.


    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System

    Then click the Security pull down on the top menu and choose Take Ownership. Click OK in the next window to approve it.

    Now look for the below values in the right window pane! Select them one at a time by right clicking on them and choose Delete

    DisableRegistryTools
    NoAdminPage

    Let me know if this all works or if you get any error messages! If you get an error, tell me the exact error.

    If it works, try to use that registry patch I gave a while pack. Does it work?
     
  22. koochman

    koochman Private E-2

    I hoped to make some progress tonight, but this is not the case.

    The file gedit.msc or gpedit.msc as you said before, cannot be located on my Windows Operating System CD. Only 1 .msc file could be found, however, is it not the one we are looking for. My father has XP Media Edition, could I take the file from that disc, or no?

    I was allowed to create a new user account with no problem. I did delete the new account.

    When I delete the 2 values you said to delete, they appear to be deleted, but if I open the Policies\System folder again, they remain there. I tried multiple times with the same results. I received no error.
     
  23. koochman

    koochman Private E-2

    Hmm, apparently I cannot edit my last post.

    I would just like to add that if I try deleting the 2 values with Reg Lite in safe mode, they will delete and remain so until I restart to normal mode.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's add more to the list to fix with Registrar Lite, but first let's uninstall Windows Defender. Do this now!!!

    Now using Registrar Lite naviagate to

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System

    And delete the below two keys like last time!
    DisableRegistryTools
    NoAdminPage

    Then navigate to

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

    And delete the below key:

    csrss

    Then navigate to

    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run


    And delete the below key:

    csrss

    Now double check while in safe mode that the above keys have actually been deleted.

    Also while in safe mode locate the below folder and delete it:
    C:\WINDOWS\system32\uyhererli

    If you cannot find this folder, please run Windows Search and look for csrss.exe as show below and tell me exactly where you find it. The ones in C:\WINDOWS\SYSTEM32 and in C:\WINDOWS\SYSTEM32\DLLCACHE are valid (there could be a couple other valid ones too like in an i386 folder or a SoftwareDistribution folder). But. Anyone found in a strange folder name like above is not valid and should be deleted.

    Click Start and select Search
    Now Select "All files and folders"
    Enter the csrss.exe in the "All or part of the file name:" box
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    • Search system folders
    • Search hidden files and folders
    • Search subfolders
    Then click the Search button.

    This rogue csrss.exe entry is the item I have been trying to remove since message # 6 and is most likely the cause of all these problems.


    Let me know the results! Please attach a HijackThis log from normal boot mode if possible!
     
    Last edited: Jul 20, 2006
  25. koochman

    koochman Private E-2

    Yahoo! Progress at last!

    I deleted the specified values using Registrar Lite, then verified that they were in fact deleted. Next I sought out the uyhererli folder. I found it simply by changing the folder options to show hidden files and folders. Deleted the folder, emptied the recycle bin, and restarted to normal mode.

    Once I logged in, I received 2-3 errors stating that the folder filepath ending in uyhererli could not be found. So I opened MSconfig, which now runs stable! There are 3 instances of csrss, 2 of which came from the folder uyhererli. I did not, however, change anything.

    HJT will also run stable in normal mode, so I have a new log attached.

    What's next? :)
     

    Attached Files:

  26. koochman

    koochman Private E-2

    Oh, and just out of curiousity, why did we uninstall Windows Defender?
     
  27. AbbySue

    AbbySue MajorGeeks Administrator

    As chas has left for his much deserved vacation I'll answer this for you. Windows Defender will protect (prevent) certain changes from being made to the system if you have allowed something access or told the program to protect it. Certain services, etc. are protected by default when Windows Defender is installed and as you are seeing, Malware can be sneaky with the file names. In your case, the malware was being protected so efforts to eradicate it were futile. Once Windows Defender was uninstalled you made some progress.:) Once your system is verified to be clean it would be a good time to reinstall it if deemed necessary.

    Someone will look over your HJT log ASAP and get back to you with any further steps you may need to complete.
     
  28. koochman

    koochman Private E-2

    Thanks for the explanation AbbySue! chaslang is on vacation now huh? Didn't even get to thank him again. I look forward to help from the others here!:D
     
  29. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    Post a fresh HijackThis log.
     
  30. koochman

    koochman Private E-2

    Ok, downloaded Pocket Killbox and Explorer XP. The file C:\WINDOWS\system32\uyhererli\csrss.exe was previously deleted when chaslang instructed me to do so. I did do as requested though with Killbox, but the file was not found using ExplorerXP.

    A new log is included. Thanks for the help!
     

    Attached Files:

  31. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  32. koochman

    koochman Private E-2

    Yes, clean at last!

    I do have a some questions for you if you don't mind.

    Ad-Aware still finds an object in the vulnerabilty category. The object is: HKEY_CLASSES_ROOT:regfile\shell\epen\command[\b]. I have included a log as well. If it is nothing to be concerned about, then so be it.

    Also, my friend who's malware problems first started mine has the same symptoms as I did. Could I attempt to solve his problems with what we did here, or would it be better to start a new thread with the proper logs from his PC? I think I may have just answered my own question.

    chas, SPD, and AbbySue, thanks you so much for you time, patience, and help!! I really really appreciate it!:) :D
     

    Attached Files:

  33. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Concerning your problem with Ad-AwareSE;

    Go to Start > Run, type REGEDIT, and press Enter.
    Does the Registry editor start?

    If so, go to Start > Run, and paste the following in bold into the box, then click OK:
    regedit /e C:\reg.txt HKEY_CLASSES_ROOT\regfile\shell\open\command
    This will create a file called C:\reg .txt . Post reg.txt.

    Your firend should start his own thread; starting by running through the Read Me First.
     
  34. koochman

    koochman Private E-2

    Ok I will have him start a thread after we run through the Read Me first thread.

    Yes the Registry Editor will run. Here is the file:
     

    Attached Files:

    • reg.txt
      File size:
      230 bytes
      Views:
      4
  35. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    That's the normal value for that registry key. Ad-Aware was warninig of a vulnerabilty at that key. False Positive.
     
  36. koochman

    koochman Private E-2

    Ok thank you.

    I apologize, but I have on last question. As far as protection goes, I have removed Norton and installed AVG, and ZoneAlarm, and I also have Ad-Aware, CCleaner, Spybot, and Spyware Blaster. Is this adequate and how often should I run scans? Also, should the scans be run in normal or safe mode?
     
  37. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    I would add Windows Defender as a program that should be installed and used. How frequest you run scans really depends on your surfing habits. Once a week should be sufficient, I usually run scans in Normal Mode and only go to Safe Mode if I need to.
     
  38. koochman

    koochman Private E-2

    Ok sounds good. Again, thanks for the help! :)
     
  39. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You're welcome
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds