Malware Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by chibishinigami, Oct 4, 2006.

  1. chibishinigami

    chibishinigami Private E-2

    My computer is infected with the Malwarewipe program. I found a site with help with a link to this page and followed the instructions here:
    http://forums.majorgeeks.com/showthread.php?t=91572

    It says to post my log afterwards in my post. I tried Spysweeper but it requires that I register. I downloaded McAfee and Windows Defender and they removed some programs. I still get directed to the fake website when I open Explorer though. And when I open task manager, the files in which I am assuming are the little bubbles of warnings I get, still appear there. My computer is running very slowly. Can someone please help me out on this, I am totally at a lost at what to do =(.

    The avenger.txt is zipped in the attatchment. I hope I did this right =(.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please run the below procedure.

    Now Download SmitfraudFix (by S!Ri) to your Desktop.

    Extract all the files to your Destop. A folder named
    SmitfraudFix will be created on your Desktop.

    Open the
    SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter
    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach that log in your next reply.

    Note:process.exe ( which is used my SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. The below is a link to what process.exe is.

    http://www.beyondlogic.org/consulting/proc...processutil.htm


    IMPORTANT: Do NOT run any other options until you are asked to do so!
     
  3. chibishinigami

    chibishinigami Private E-2

    Thanks ^_^!

    McAfee and Spybot Search & Destroy helped a lot. Spybot found a lot of the problems yet McAfee was still doing alerts for some programs like mentioned in the log. My browser and internet is working okay. Notebook is still somewhat slow.

    Also before your post I i was looking through the forums and ran this check:
    http://forums.majorgeeks.com/showthread.php?t=74265

    and did the system scan and found none of the entries listed and searched using Windows Explorer for the other portion and found nothing as well. I didn't run Panda because it interfered with Symantec. It said I would have to uninstall so I did not install Panda. I hope that is okay =(. I did a full scan with Symantec and nothing turned up.

    Here is the results of the scan. Thank you very much ^_^.
     

    Attached Files:

  4. chibishinigami

    chibishinigami Private E-2

    I also wanted to ask, since I do use Windows Task Manager very often, if anything appearing as "Outwindows<followed by various numbers here>" is normal?

    Also I have received alerts from McAfee about the two programs in the previous attachment but Spybot didnt detect them. But I blocked them with McAfee when it made the alert. So everything seems to okay except for those two alerts but I wish to make sure. Do I do this by following the "HijackThis Tutorial" ? My notebook isn't as slow as before, but it still takes a while to start up and load applications/programs. Thanks again ^_^.
     
  5. chibishinigami

    chibishinigami Private E-2

    Okay I take back what I said on my browser running okay. It keeps showing "The page you are looking is probably blocked by adware/spyware on your PC. Remove it with System Doctor Software(linked). CLICK HERE." and the page cannot be dislayed and it shows steps to download the software on the error page =(. Also I tried your link but it's not working =(.
     
    Last edited: Oct 5, 2006
  6. chibishinigami

    chibishinigami Private E-2

    If it helps the name of the site I keep getting is this :
    http://theoptodatesafety.net
    along with a pop-up saying i am infected by some virus and to download their products.

    I can get rid of it. I added it to Symantec's block list but it's still there.
    Right now I am doing the "R&R" steps and I am currently on the online scans part.

    My progress so far:

    0: I removed all unrecognized programs via Add/Remove Programs including the Malwarewipe 1.4

    1: There was nothing to remove in Quarantine for Symantec.
    Downloaded CCleaner

    2:Enabled viewing of hidden files.

    3. I removed McAfee so I am now left with Symantec Firewall and AntiVirus.

    4. Downloaded all the tools. I was able to run Windows Defender so I didnt run CounterSpy.

    5: Rebooted into Safe Mode and ran the following:
    CCleaner
    Spybot
    Windows Defender
    Windows Malicious Software Removal
    * only Spybot found anything. The rest showed up clean.

    6A: I downloaded Sun Java and right now I am at the online scans.

    When done, is it okay to double-check and do the Special Removal Procedures for Malware and the Smitfraud and post the logs? Thanks.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please only run steps that I'm giving you.

    READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING. Ask any questions that you may have before starting.

    Please print out or copy these instructions to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. Again, if there's anything that you don't understand, ask your question(s) before moving on with the fixes.

    Reboot your computer into Safe Mode per the safe directions in the READ & RUN ME.

    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach this log along in your next reply.

    Now reboot into normal mode and attach this new rapport.txt log here.

    If you are still having problems now, you must compelete all the steps in the READ & RUN ME sticky thread and attach the 5 reqauested logs:
    Bitdefender - from step 6
    Panda Scan - from step 6
    runkeys.txt - the log from GetRunKey.bat
    newfiles.txt - the log from ShowNew.bat
    HijackThis
     
  8. chibishinigami

    chibishinigami Private E-2

    I am really sorry for posting the new thread. It's just that I didnt see the "R&R" thread before I posted so I thought I had to and maybe would be of help? x.x;

    As of right now I dont get the pop-ups of systems infections/errors nor the fake homepage. But scans still read I am infected with a Trojan. I can post my results of those in my next reply when I finish the "R&R" steps because I still have a problem with Trojan(s?) showing up on scans. But here is the rapport.exe.

    Thank you again and my apologies.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which scans say you are still infected and when were they run. This is why it is important to follow our directions only and in the order given. Otherwise confusion like this results. At this point I have no idea if the info (the logs) in you other thread that I closed are valid or not and if I work up a procedure based on those I may be telling you to fix things that don't even exist.

    You never properly followed the directions in the READ ME. You have Symantec and McAfee installed. See step 3 of the READ ME and fix this now! Also you need to follow the directions properly for using GetRunKey and ShowNew! Your logs were incomplete and not useful. You must follow the directions exactly to get correct logs. Do this and attach new logs here and also get a current HijackThis log and attach it here. But this time follow the directions for using HijackThis. Logs must be from normal boot mode. And makes sure you are not using MSconfig to control startups!


    Also does the below folder exist? If so, delete it.
    C:\Program Files\VideosCodec
     
    Last edited: Oct 7, 2006
  10. chibishinigami

    chibishinigami Private E-2

    I've removed McAfee. On the Panda it shows my Quarantine files on Symantec along with Trojans in System Volume Information. I tried the R&R of how to remove Quarantine but it doesn't work for me. The options there are different from what I have. Spybot came clean. I am unsure of what you mean when you say not to use MSconfig to control startups. The way I am doing is by clikcing run and typing msconfig like said in the R&R, is that right? Also how would I clean Symantec's Quarantine? I have View>Quarantine>Purge Options.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just empty your quarantine however is appropriate for the version of Symantec that you have. The READ ME explains on how we want MSconfig to be setup. Perhaps it only showed in your HJT log because you were in safe mode instead of normal boot mode as required.

    Follow the directions exactly and attach logs from GetRunKey, ShowNew, and HJT
     
  12. chibishinigami

    chibishinigami Private E-2

    For the BitDefender I am getting:
    "This web site is not authorized to host this ActiveX control."
     
  13. chibishinigami

    chibishinigami Private E-2

    My offline scans are coming clean still ^^. I can run Panda fine, it's scanning right now, only BitDefender is not working for me. Also here are the files you requested.

    Thank you again.
     

    Attached Files:

  14. chibishinigami

    chibishinigami Private E-2

    The scan that showed the Trojan was BitDefender and the attached is an old scan when I was able to run it. Its in System Volume Information which I didnt touch yet on the R&R part: Trojan.Downloader.Zlob.ZI
     

    Attached Files:

  15. chibishinigami

    chibishinigami Private E-2

    I just finished Panda and here are the results ^^. Should the cookies under spyware be deleted? I dont know what the adware/brands is. I still cant get BitDefender to work.

    Thanks again ^_^.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The only infections showing up are still in your Symantec Quarantine folder and also in system restore. Disable System Restore (step 9 in the READ ME if you don't know how to do this). The empty your Symantec Quarantine!

    Now let's remove the McAfee services that are still trying to load even though you now use Symantec.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to McAfee Real-time Scanner ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now repeat the above stop and disable for the following services:
    McAfee SystemGuards

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    McShield

    Now repeat the Delete NT Service steps for:
    McSysmon
    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.
    Now Attach a new HJT log.
    How are things running?
     
  17. chibishinigami

    chibishinigami Private E-2

    Everything is running better now thank you ^^.
    Although for the Symantec Quarantine that is empty. For McAfee Scanner, the service is stopped but i get
    "Unable to open service MCshield for writing on Local Computer.Error 5: Access denied." when trying to disable startup. HJT also couldnt delete Mcshield because it said it was still running.

    But for Panda do I want to delete the files under spyware?
     
  18. chibishinigami

    chibishinigami Private E-2

    Forgot this, sorry.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try it again. Make sure ALL other processes are closed and no browser windows are open. Also shut down your antivirus program first. If it fails in normal boot mode, try booting in safe mode and then run the procedure.

    Cookies are not problems as you will read when I give you my final steps (after we get the McAfee service fixed). You are clean otherwise.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds