Malware Problem...

Discussion in 'Malware Help (A Specialist Will Reply)' started by DarkFable, Feb 26, 2006.

  1. DarkFable

    DarkFable Private E-2

    Okay, let me get right into it. I have followed and completed everything on the "READ & RUN ME FIRST Before Asking for Support" page and i'm still experiencing some problems. First of all, under my Processes in the Task Manager, i have unknown .exe's running (win1504.tmp.exe). I've traced that these files come from C:\Windows\Temp and whenever i would end-task all of those .exe's and delete the .exe in the Temp folder, 5 minutes later, a new .tmp.exe would form both on my processes list and the Temp folder. Their name is always slightly changed (eg. winD09.tmp.exe) and if i dont end task it right away, it spawns a few other .exe's (eg. bbbmajpd.exe) and all of these .exe's also get created in the Temp folder. Another .exe that seems to follow these is the MDM.exe. I've posted a screencap of my task manager as well as the results from the scans. Some problems that i think may be caused by this is whenever i'm playing any game, everything 2-3 minutes , everything would get minimized to the desktop, which is really annoying. Any suggestions that could help me?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the directions in step 7 of the READ & RUN ME and install HJT properly. You installed it exactly where the instructions request that it not be installed. Also step 7 requests that msconfig not be used to control startups. We must see all applications that could load on your PC. Note the below is from you log which shows msconfig is being used:

    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    The below folder is not the correct way to install Ccleaner (or any application):
    C:\Documents and Settings\O K U K A\My Documents\Marko's Stuff\marko\CCleaner\ccleaner.exe

    They should be installed in their default folders which is normally under C:\Program Files. That way all users on the PC can run them and they also do not look like possible malware imitators.

    Also it does not appear that yo ran ALL the steps in the READ & RUN ME. I see no signs of Microsoft Windows Defender.

    Finish running ALL steps of the READ ME and address the above issues, then attach a new HJT log so we can get you fixed up. Also note, do not stop or try to fix anything yourself. Just attach a log that shows everything.

    Questions:
    1) Why are you running with no antivirus application?
    2) Why are you running with no antispyware application?
    3) Why are you running with no firewall application?
     
    Last edited: Feb 26, 2006
  3. DarkFable

    DarkFable Private E-2

    Alright, my bad, i sort of skimmed through that Readme. Okay, so i reinstalled CCleaner, HJT and the other programs all under C:\. I redid the scans, and the reason why I didn't do the Microsoft Windows Defender is because there is an error when i try to install it. It says something along the lines of "Try to find a valid Windows Key" and i'm not sure what this means because i received my XP Home with my computer when i bought it premade, and i have no problems installing windows updates. Apart from that, i checked back everything under MSconfig, as you asked, and the reason i dont have any of the protection things (firewall, antivirus etc.) is because first of all, i had windows firewall enabled but recently, every minute it kept popping up a message saying some weird .exe (something like rgUSbfg435.exe) was incorrect ActiveX or something. This got annoying so i turned it off yesterday. And the reason i dont have an antivirus is because i had ZoneAlarm and i got this virus/infection and i wasn't satisfied so i uninstalled it and was waiting to get this problem sorted out and possibly get a new recommended antivirus program. I'll post my new HJT log.

    PS: i'll also post a cap of my task manager, just to show that there are some funky .exe's that i'm unaware of. I circled them.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Windows firewall does not provide adequate protection. You need a reall firewall and you should not be turning it off. When you do that, you allowed the malware full access into and out of your PC. ZoneAlarm is a firewall or did you mean ZoneAlarm with AV. And any AV would be better to have than none.

    If you are getting that error from Windows Defender, you probably do not have a valid license key. I do not see the Windows Genuine Advantage authentication in your HJT log. Microsoft would put this on your PC after verifying it is a valid licensed system. Since it is not there you will not be able to download all MS updates and tools like Windows Defender. You may be able to get some of updates from MS but not all. You should speak to whoever you purchased the PC from and ask them for a valid license key for the software they sold you with the PC. I assume you did not but this from a well known PC dealer?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's see if we can get you fixed up.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Power Manager (if that is not found, look for this name: PowerManager)... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    PowerManager

    If HJT does not find this, don't worry about it. Just continue with the below instructions.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.


    Now downloading two tools we will need:

    - Process Explorer

    - Pocket KillBox

    Extract them to there own folder somewhere that you will be able to locate them later. You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winbug32.dll once and then click the kill button. After you have killed all of the winbug32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of winbug32.dll and kill it.


    Now also look in the process list for the below processes and right click on them and kill them if found ( these one may have renamed if you have rebooted)
    C:\WINDOWS\TEMP\winDE0.tmp.exe
    C:\WINDOWS\TEMP\imjfipmd.exe

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:O20 - Winlogon Notify: winbug32 - C:\WINDOWS\SYSTEM32\winbug32.dll
    O23 - Service: Power Manager (PowerManager) - Unknown owner - C:\WINDOWS\svchost.exe (file missing) <-- this should already be gone

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.

    C:\WINDOWS\svchost.exe
    C:\WINDOWS\TEMP\winDE0.tmp.exe
    C:\WINDOWS\TEMP\imjfipmd.exe

    C:\WINDOWS\SYSTEM32\winbug32.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.


    After reboot, look in C:\Windows\Temp with Windows Explorer and manually delete all files it allows.
    Now post a new HJT log and tell me how the steps went.
     
  6. DarkFable

    DarkFable Private E-2

    Alright, all steps went smoothly. I didn't have any problems with errors or anything. Heres the log.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay just have HJT fix the below remnant:

    O20 - Winlogon Notify: winbug32 - winbug32.dll (file missing)

    Make sure it stays gone by just checking another scan yourself.

    How is everything working now?
     
  8. DarkFable

    DarkFable Private E-2

    Thanks for the quick response. Well everything seems to be in pretty good shape right now. No unknown .exe's in my running processes so that i'm happy about. Thanks once again. ;) Just one more question, can you recommended me a AV/Firewall? Preferably one i could get for free?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's all included in the next steps for you to take! :) If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds