Malware Help (HJT, ActiveScan & Bdscan logs included)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Weballlergy, Jul 10, 2006.

  1. Weballlergy

    Weballlergy Private E-2

    Hello there. Recently I've been having a fair amount of trouble with my computer. Slow start-up times, lots of spyware and adaware troubles and many viruses. I've went through all of the Read & Run Me steps plus a few proceedures of my own. I've been getting popups very frequently and some viruses have been deleted but it's also saying on occasion that some aren't going away. I can't quite remember what wasn't deleted but I saved a log from SPD (Spyware Docter) Which I'm going include in a reply (This log was taken when it said a problem couldn't be removed.

    I'm having some trouble with dfndrd_5.exe which couldn't be disinfected of deleted by Bitdefender when I ran it.

    I'm running Windows XP on a Toshiba Laptop with wireless connection and a USB hub, I really don't know if there's any other info I should post about my setup, but i'm connected through a d-link router to my computer downstairs (Both have Interenet connection). If there's anything else that would be helpful let me know and i'll post it.

    This is what I've run so far to try to clear up the problems;

    CCleaner
    HDcleaner
    Ad-Aware SE
    SpyBot - Search & Destroy
    Microsoft Windows Defender
    Microsoft Windows Malicious Software Removal Tool
    CWShredder
    Kill2me
    Bitdefender
    Panda
    AVG
    Registery Mechanic (FV)
    Spyware Doctor (FV)
    HDcleaner


    After running of all of this and following everything in the readme I'm still getting popups and very slow startups sometimes in which the computer locks up and I have to shut it down.

    I'm hoping the logs will reveal what's wrong, and i'll be very appreciative if someone could help because as you can see.. I've tried a lot. I've just finished all of those scans in sequence, followed all of the steps and whatnot, and rebooted. I'm not getting the popups right now but I want to post the logs just to make sure. I also get about: blank when I open my IE.

    One more question. I have Windows Firewall and Zonealarm, which should I use?

    Thanks SO much!

    PS - If you have any suggestions about what I should not be running or whatever I could do to improve speed, it'd be great.
    -Justin.
     

    Attached Files:

  2. Weballlergy

    Weballlergy Private E-2

    Spydoctor Log as well.

    ALSO

    I did NOT run in safe mode for any of these proceedures because it messes up. I ran without cables plugged in for the most part.
     

    Attached Files:

    Last edited: Jul 10, 2006
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If FV means free version, then uninstall Spyware Doctor. It is of no use to you unless you buy it and it wastes to many resources and could conflict with Windows Defender. And if Registry Mechanic is free, does it provide any useful functionality to justify keeping?


    ZoneAlarm of course and it should have automatically disabled the Windows Firewall when you installed it.

    Look in Add/Remove Programs for the below and uninstall if found:
    SpyKiller or SpyKiller 2005
    Maxifiles
    MediaGateway
    MyToolBar
    P2P Networking or P2P Networking V123

    Is the below process valid? Is it for a flash drive?
    O4 - HKLM\..\Run: [Verbatim Store 'n' G] c:\program files\verbatim store n go\verbatim store 'n' go.exe sys_auto_run C:\Program Files\Verbatim Store N Go

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\Program Files\Common Files\{34E67641-07CB-1033-0520-030218200001}\Update.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - blank (file missing)
    O4 - HKLM\..\Run: [defender] C:\\dfndrd_5.exe
    O4 - HKLM\..\Run: [keyboard] C:\\kybrdd_5.exe
    O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O20 - Winlogon Notify: Controls Folder - C:\WINDOWS\

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Common Files\svchostsys <--- the whole folder
    C:\Program Files\Common Files\simtest <--- the whole folder
    C:\Program Files\MediaGateway <--- the whole folder
    C:\Program Files\SpyKiller <--- the whole folder
    C:\Program Files\Mozilla Firefox\plugins\npclntax.dll
    C:\WINDOWS\system32\P2P Networking v123.cpl
    C:\WINDOWS\keyboard1.dat
    C:\dfndrd_5.exe
    C:\kybrdd_5.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. Weballlergy

    Weballlergy Private E-2

    Actually the FV meant Full Version.. But I got the keys off the net (Not something usual of me, i was desperate to fix everything) Anywho! Spyware Doctor is gone but registery mechanic is a great help.

    The firewall issue is odd, because now that i've disabled windows firewall (on my own) it says my wireless connection and LAC are not firewalled anymore. Will ZA act as a firewall agent for them?

    None of these were found.

    I have a USB hub, but i know relatively nothing about it other than it allows me to have a bunch of extra USB ports. It's and EDO "High Speed" USB 2.0 Hub. I have no idea if it's associated with verbatim, but i'm guessing so. Could you help me out here? This is a weak area =P.

    I followed EVERY tedious task in that tutorial except running certain things in safe mode.

    There was one of these and I killed it. It's back though, in the new log. I found it also in C:\Program Files\Common in explore again and it has Services.dll and Update.exe within it.

    Killed everything here.

    The only one I found was C:\Program Files\Mozilla Firefox\plugins\npclntax.dll and it's gone now.

    Did all of this. about: blank is now www.majorgeeks.com =D!

    Sorry for the play by play, i just want to get this done and over with.

    Here's my HJT log.

    PS - I had some troubles earlier and all kinds of services got shut down including sound among other things. I'm going to post three images of my services and if you could help it would be great. I have no idea what to do considering how windows audio and the such were disabled :O. I already posted about it, but i'd like a second opinion before doing what Hipster Doofus said. Not degrading his work, i'd just like to see if i have any alrternatives before comparing lists. here's the link http://forums.majorgeeks.com/showthread.php?t=96806

    Everything seems to be running a lot smoother now thanks to you :D !!!! but I think somethings deep down messed up with the services and possibly that foolish update.exe.

    And by the way

    THANK YOU SO MUCH!
    -Justin
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please continue with the below scans. They run really fast.

    Now run the below procedure and attach the runkeys.txt log.
    Now run the below procedure and attach the newfiles.txt log.
     
  6. Weballlergy

    Weballlergy Private E-2

    Here you go;

    I made a new copy of one of the logs, hence the wrong name.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ZoneAlarm should protect everything, however you may have confused all the software in your OS by having two firewalls on at the same time. ZoneAlarm normally defaults to being enabled and it disables the Windows firewall automatically. So how you had the Windows firewall turned on and also why, is strange.


    Sorry but I'm too busy in this forum to look into non-malware issues.


    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\Program Files\Common Files\{34E67641-07CB-1033-0520-030218200001}\Update.exe

    Now exit HijackThis and do the below!

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot and then delete the below folder:
    C:\Program Files\Common Files\{34E67641-07CB-1033-0520-030218200001}

    Let me know the results and also attach a new HJT log and a new runkeys.txt log.
     
  8. Weballlergy

    Weballlergy Private E-2

    Well after doing all of this, and as my pc was rebooting a little thing popped up in my taskbar that i've never seen before telling me "New hardware detected: CD ROM drive" and another I couldn't make out. It's weird because the cd rom drive has worked the whole time i've had this computer.. I don't know, you told me to tell you what happened :p

    That's it; here's the logs.
     

    Attached Files:

  9. Weballlergy

    Weballlergy Private E-2

    Also..This is kind of strange. I found this in my received files. I'm afraid to delete it because of the warning. Is it malware or should I post somewhere else for help?

    http://i1.tinypic.com/1zvrioh.jpg
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds