Malware Help please?

Discussion in 'Malware Help (A Specialist Will Reply)' started by stephenmiller99, Jan 18, 2007.

  1. stephenmiller99

    stephenmiller99 Private E-2

    Malware problem HELP

    Symantec Email Proxy Keeps Trying To Send Dozens and Dozens Of Emails, but They Fail and Bring Up Like 30 Pop Up Windows Saying The Messages Have Failed To Be Sent, and They All Have Random Email Subjects(?).....My Anti-Virus Software Scans and Comes Up Empty, Same With My Spyware Remover.....Please Help Me.

    I have had to uninstall Norton temporarily as the pop ups were too annoying - this solves the problems, but i've paid for the program so I want to use it again - and when I install it the problem keeps re-curring.


    Please help, i'm new to all this and really stuck. Thanks! :(
     
  2. stephenmiller99

    stephenmiller99 Private E-2

    Can anyone help me with a malware problem please?
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  4. stephenmiller99

    stephenmiller99 Private E-2

    Hi, I have followed ur previous email and will now attach all the scans to see if u can fix the original problem.

    I really would appreciate it,if u can find an answer. I know there are others out there but I don't want to do something that the logs may differ on.
    Thanks

    Attachment 1 - counterspy
    Attachment 2 - BitDefender
    Attachment 3 - PandaActiveScan
     

    Attached Files:

  5. stephenmiller99

    stephenmiller99 Private E-2

    Other attachments:

    Attachment 4 - runkeys.txt
    Attachment 5 - newfiles.txt
     

    Attached Files:

  6. stephenmiller99

    stephenmiller99 Private E-2

    Attachment 6 - Hijack_This! log

    Thanks again!!! :wave
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Copy the text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Go to Start / Run and type "cleanmgr" without quotes ....have it clean Temp. Internet files, and Temp files.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://webact.
    symantec.com/webact-redirect.jsp?PCODE=AU&SO={F073BDC9-0D67
    -4ff0-879E-27241C843828}&VER=2&actreq=%2F880004%2F0DKX4NMCyNCdk%2F%
    2F%2F%2F5%2FW5CCF2YM%2FDEDGw18G%2Fe%2F5NZuZFBK%2FABm2q2qD4
    jSWzDjKx5gA1CouJ%2FXPS8GRIVC7XUAAYI%2F003100079374460033045675463
    &plang=sym:EN&oslang=iso:ENG&oslocale=iso:GBR

    O2 - BHO: (no name) - {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} - (no file)

    O3 - Toolbar: (no name) - {0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} - (no file)

    O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - (no file)

    O23 - Service: ieupdater (Microsoft IE Updater) - Unknown owner - C:\DOCUME~1\Miller\LOCALS~1\Temp\ieupdate.exe (file missing)

    After clicking Fix, exit HJT.

    Please attach a new:
    GetRunKeys
    ShowNew
    HJT


    Be sure to tell us how things are running.
     
  8. stephenmiller99

    stephenmiller99 Private E-2

    Hi Tim, Thanks for your help. Same problem same thing keeps happening. I've attached an error doc along with updated logs for HijackThis, Runkeys and shownew.

    Errors still popping up saying "Your mail message was unable to be sent because your mail server rejected the message SS4 DEnied [CS] (mode:normal)

    Others show messages being processed to send with emails i have not sent. No mail accounts are open when this takes place. Everthing runs ok without Norton, but still don't want to not have Norton. Househole computer - please help!
     

    Attached Files:

  9. stephenmiller99

    stephenmiller99 Private E-2

    Here's that pic of the error that occurs.
    Thanks
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    Quote:


    IMPORTANT: Do NOT run any other options until you are asked to do so!
    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Quote:
    Now reboot into normal mode and attach this new rapport.txt log here.
    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?
     
  11. stephenmiller99

    stephenmiller99 Private E-2

    Here is the results of my smitfraudfix i.e. rapport.txt attached

    Thanks!!!
     

    Attached Files:

  12. stephenmiller99

    stephenmiller99 Private E-2

    Hi. I have new logs from rapport.txt attached, getrunkeys and shownet will post HJT on the next reply.

    No pop-ups as of yet. System when loaded, desktop looked different and had deleted google as default web to uk.msn, is that normal?

    Stephen
     

    Attached Files:

  13. stephenmiller99

    stephenmiller99 Private E-2

    Here's my new HJT

    Cheers :)
     

    Attached Files:

  14. stephenmiller99

    stephenmiller99 Private E-2

    Hi, just an update. It is just as bad. I walked away from the computer and there was hundreds of the messages. Obviously more frequent when i'm using a web page.

    Any ideas?
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HJT and delete this item:

    O20 - Winlogon Notify: partnershipreg - C:\Documents and Settings\All Users\Documents\Settings\partnership.dll

    After clickin Fix, close HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\WINDOWS\dbmio32.dll
    C:\WINDOWS\system32\daoprint.dll
    C:\Program Files\Video ActiveX Object\pmsngr.exe
    C:\\Program Files\\Video ActiveX Object\\isamonitor.exe
    C:\WINDOWS\atmoun.exe
    C:\WINDOWS\system32\vcodec.exe
    C:\Documents and Settings\All Users\Documents\Settings\partnership.dll

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
  16. stephenmiller99

    stephenmiller99 Private E-2

    Here's the following logs:

    The 020 on Hijackthis log remains there even after I have deleted - don't know what this means but just an observation.

    So far so good and no pop-ups but i will let you know as normnally doesn't start for a bit.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look good. Let me know if this changes.

    You can now uninstall any programs that we asked you to install.

    Turn off system restore, restart the computer and turn it back on.

    Be sure to read How to Protect yourself from Malware
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds