Malware problems, dont know if related to the last one or not.

Discussion in 'Malware Help (A Specialist Will Reply)' started by jukes, Mar 18, 2005.

  1. jukes

    jukes Private E-2

    Hi,

    I just started having trouble last night. My mouse cursor seems to have a mind of it's own, and flies wildly around the browser opening menu items, and then freezes. I rebooted, then reinstalled the optical mouse via the disc. I had to run SpybotS&D and AdAwareSE in safe mode, because they both froze. I did the RAV online scan as well. Spybot and RAV said the machine is clear. AdAware found some items and deleted (2 of them had to be deleted on reboot) The problem seemed resolved last night.

    Today, it's happened a few times now, plus I'm getting booted offline. The computer has frozen a few times and I'm unable to even use my windows key and keyboard commands. I just finished a Panda online scan and in excess of 20 malware items were found. The activescan report is in the attachment.

    I dont know if any of this is related to the last problem I had or not. PhilliePhan did a great job helping me during this:

    http://forums.majorgeeks.com/showthread.php?t=54761

    Please help again?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In a months time, alot can change. You need to begin the cleanup process over again from the beginning.

    To help us to best help you, please follow the steps below closely and in the order given and do not skip anything. If you have any difficulty, please post back letting us know what steps you have completed, what you found while doing the scans if anything along with details about any problems you may have encountered in completing the steps. The more details you can provide the better. Don't be afraid to ask for additional help if you don't understand something!

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. jukes

    jukes Private E-2

    Hi Chaslang and thank you! I did all the steps in the tutorial.

    Symantec online found:

    c:\ezStub.exe is infected with Adware.Ezula
    c:\WrapperOuter.exe is infected with Adware.VirtualBouncer
    c:\!Submit\SSTUP4.DLL is infected with Adware.Look2Me
    c:\!Submit\DXMSSHRN.DLL is infected with Adware.Look2Me
    c:\Program Files\TopConverting\arkanoid\arkanoid.exe is infected with Adware.ClickDLoader.B
    c:\WINDOWS\exdl.exe is infected with Adware.BargainBuddy
    c:\WINDOWS\cxtpls_loader.exe is infected with SecurityRisk.Downldr
    c:\WINDOWS\cxtpls_loader.exe is infected with Spyware.Apropos
    c:\WINDOWS\edow.exe is infected with Adware.Websearch
    c:\WINDOWS\Downloaded Program Files\bridge.inf is infected with Adware.WinFavorites
    c:\WINDOWS\Downloaded Program Files\webdlg32.dll is infected with Adware.Iwantsearch
    c:\WINDOWS\Downloaded Program Files\YSBactivex.dll is infected with Adware.Istbar
    c:\WINDOWS\SYSTEM\setup_incred_1.exe is infected with Adware.Incredifind
    c:\WINDOWS\SYSTEM\mqexdlm.srg is infected with Adware.BargainBuddy
    c:\WINDOWS\SYSTEM\laptreg.exe is infected with Spyware.Apropos

    TrendMicro Houscalls found:
    (not easy since they didn't include an option to log, so I shot a screen shot and copied from that)

    TROJ MIEWER.A NONCLEANABLE C:\SYSTEM\1803.dll
    TROJ MIEWER.A NONCLEANABLE C:\SYSTEM\pop7.dll
    HTML COOLWEB.A NONCLEANABLE C:\application data\S...
    TROJ RBLAST.DLL NONCLEANABLE C:\WINDOWS\Downloaded Prog...
    TROJ SMALL.ACD NONCLEANABLE C:\WINDOWS\d8.exe

    my Stinger scan came up clean. (?)

    It's hard for me to fathom why all these different scans all say something different.

    It's all still happening, and rather frustrating.

    My hijackthis.txt is in the attachments, and thank you again for help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did the scans fix the problems (i.e., delete files ) or did they just detect them?

    Were you able to the run online scans in safe mode!
     
  5. jukes

    jukes Private E-2

    They merely detected them, nothing was fixed.

    I cannot run the online scans in safe mode, the computer wont connect at all in safe mode.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should boot into safe mode and delete the file manually (if they still exist).
    If you have a problem deleting them that way, boot to an MS-DOS prompt and delete them.

    If you do not know how to do what I have said, tell me and I will explain in more detail.

    You HJT log was clean. I just have a question on whether the below two entries are things you use:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.metacrawler.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.garageband.com/bbs/online.pl?Cat=

    You do not appear to have an antivirus application installed you really need to have one.
    See the below thread for a bunch of steps you should be doing including getting an AV package:
    How to Protect yourself from malware!
     
  7. jukes

    jukes Private E-2

    I'll give it my best shot.

    It's been a long time since I eradicated MTX from my oldest computer (2000) so I dont remember how to do a ms dos prompt and deletion. Maybe doing the safe mode boot and deletion will work, as I remember ms dos was really complicated.

    I know that IE homepage seems a bit odd to anyone else, but I am the help faq moderator at garageband.com and pretty much live there and have since 2000. That is their "who's in the BBS?" page and when my machine works I might hit that page several hundred times a day. I use Metacrawler as my default search page, and have hot keys to it on my keyboard.

    The latest victim in my system is now my xkeys supplimental keyboard isn't working, or I'd be able to hit one key and the quote tags would enter without me having to type them.

    will do, and I guess I better get to work. Thank you for help!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Let me know the results and if you need more help just tell me!
     
  9. jukes

    jukes Private E-2

    I do need more help, no matter what I do, it's now worse. Now, I cant even use the machine for more than a few minutes without it freezing up and requiring restart, regardless of regular or safe mode. I started a scan online, but it froze. (I'm posting from my laptop now.) the mouse cursor still flies all over the screen just before it freezes. I cant stay online on it for more than a few minutes usually.

    I've looked in the files when I can manually, and don't see any of the malware I'd listed before has come back, but obviously something is going on that isn't being picked up by scans. I just wish I would have made back up copies of all my files a little more recently than last year.

    I installed the AVG, but it says the machine is clear.. gut instinct and current events tells me something is still wrong.

    (I should have chosen computers for electives in highschool, instead of music and sports)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In the third message of this thread you list some files. Are you sure you list them properly? For example:
    C:\SYSTEM\1803.dll
    C:\SYSTEM\pop7.dll
    C:\application data\S...

    These do not look correct I would expect them to be something with C:\windows at the beginning. Like for one example.
    C:\Windows\System\1803.dll
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I have to run here is as far as I can give you without answers to my questions. Complete these steps and let me know how things look.

    Click Start and select Shutdown and in the Window that comes up choose the one that says Restart the computer in MD-DOS mode.

    When it boots you will be at the command prompt (full screen) enter the below commands each followed by the enter key. Let me know if you have any problems or get any error messages during these steps (tell me the exact error message).

    Now in command prompt window do the following:

    cd \
    attrib -s -h -r ezStub.exe
    attrib -s -h -r WrapperOuter.exe
    del ezStub.exe
    del WrapperOuter.exe

    The !Submit folder is left over from using Pocket Killbox!
    cd \!Submit
    del *.* <--- answer yes to the prompt to remove all files

    cd c:\Windows
    attrib -s -h -r exdl.exe
    attrib -s -h -r cxtpls_loader.exe
    attrib -s -h -r edow.exe
    attrib -s -h -r d8.exe
    del exdl.exe
    del cxtpls_loader.exe
    del edow.exe
    del d8.exe

    cd c:\WINDOWS\Downloaded Program Files\
    attrib -s -h -r bridge.inf
    attrib -s -h -r webdlg32.dll
    attrib -s -h -r YSBactivex.dll
    del bridge.inf
    del webdlg32.dll
    del YSBactivex.dll


    cd C:\WINDOWS\SYSTEM
    attrib -s -h -r setup_incred_1.exe
    attrib -s -h -r mqexdlm.srg
    attrib -s -h -r laptreg.exe
    del setup_incred_1.exe
    del mqexdlm.srg
    del laptreg.exe

    cd c:\Program Files\TopConverting\arkanoid\
    attrib -r -h -s *.*
    del *.*
    cd c:\Program Files\TopConverting
    rd arkanoid
    cd c:\Program Files
    rd TopConverting

    exit <--- this will get you back to windows
     
  13. jukes

    jukes Private E-2

    That was how they were listed on the scan report. I did find those and deleted them.

    When I was here before, I was grabbing the link to the page (tutorial) that had the scans on them. Apparently, even though I did check here for any new information in this thread, I didn't see any then. Glad I see them now, and just downloaded the tool, and copied your instructions on MS DOS prompt to a word pad so if needed I can use those. I'm unable to redo any of the online scans on this machine. Gotta go before the few minutes online is up before this posts.
     
  14. jukes

    jukes Private E-2

    Since the desktop computer is compromised, I'll be checking for updates in this thread with this laptop computer.. considering what happened before. My humble apologies that happened. I'm running the tool on the desktop now, and realized I needed the MSDOS info on this computer, since I wont be able to read a wordpad doc on the other. I can read them from the laptop while I work on the desktop.
     
  15. jukes

    jukes Private E-2

    I ran the istbar fix which said:

    Symantec Adware.Istbar Removal Tool 1.0.7


    Adware.Istbar has not been found on your computer.

    Panda online scan said:


    Adware:Adware/eZula No disinfected
    Windows Registry
    Adware:Adware/SaveNow No disinfected C:\WINDOWS\Downloaded Program Files\WUInst.inf
    Adware:Adware/BHO No disinfected
    Windows Registry
    Adware:Adware/DelFinMedia No disinfected C:\keys.ini
    Adware:Adware/SBSoft No disinfected C:\WINDOWS\Application Data\SBSoft
    Adware:Adware/TopConvert No disinfected
    Windows Registry
    Spyware:Spyware/YourSiteBar No disinfected C:\WINDOWS\Downloaded Program Files\YSBactivex.???
    Adware:Adware/ExactSearch No disinfected C:\WINDOWS\SYSTEM\javex80.vxd[nvms.dll]
    Adware:Adware/ExactSearch No disinfected C:\WINDOWS\SYSTEM\javex80.vxd[nls.exe]
    Adware:Adware/SBSoft No disinfected C:\WINDOWS\Downloaded Program Files\webdlg32.inf
    Spyware:Spyware/YourSiteBar No disinfected C:\WINDOWS\Downloaded Program Files\ysbactivex.inf


    Symantec online scan earlier said:

    c:\_RESTORE\TEMP\BRIDGE.0 is infected with Adware.WinFavorites
    c:\_RESTORE\TEMP\WEBDLG32.0 is infected with Adware.Iwantsearch

    I will try the msdos eradication, but this computer is acting really messed up. It's taken me about four hours just to do those two scans, (to stay online) and to post this.
     
  16. jukes

    jukes Private E-2

    problem 1.

    Before starting the MS DOS, I ran registry mechanic which said there were no problems. (and according to that earlier scan, there was) I did this in safe mode, as well as AdAwareSE, and SpybotS&D. Spybot said there were no problems, and AdAwareSE found only the usual Alexa, and removed that.

    Problem 2.

    that option doesn't exist on my winME shutdown menu. Only standby, restart and shutdown.

    So... I found my old rescue disc floppy, and somehow stumbled my way into ms dos, but in A:\, figured out how to get it to C:\

    Then, I typed in:

    cd \ (and hit enter key)
    attrib -s -h -r ezStub.exe (enter key)

    and the error that came up was "bad command or file name".

    with this one "cd c:\Windows" I got the error:
    "Too many parameters - c:\Windows"

    same with "cd c:\WINDOWS\Downloaded Program Files\"

    When I tried just typing in WINDOWS\Downloaded Program Files, I got
    "bad command or file name"

    I'm thinking best to stop here, and wait until you see the two scan results I printed in one of my latest posts. Then follow the directions which may now differ. Thank you again, for your help and patience
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If your getting the above, you have not disabled system restore which is the first step we give you in the cleanup process. You must do that now. And do not re-enable until you are all cleaned up.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I forgot that WinMe does not have that boot option like Win98.

    So yes you would need a WinMe Startup disk to boot from. If you made a real WinMe startup disk and boot from it, you should not be having a problem locating the commands I gave you since the startup disk should have created a Path variable and initialize it with info the configures the path to include c:\windows and c:\windows\command. The c:\windows\command folder is where the attrib.exe command is located. Also a WinMe Startup disk creates a RamDisk an copies a bunch of DOS commands from the C:\windows\command folder onto the RamDisk and they are added to your path too.

    If you do not have or cannot create the WinMe Startup disk, then after booting with the floppy you have, do the following first before executing my previous commands:

    At the command prompt when you finish booting from the floppy:
    set PATH=c:\;c:\windows;c:\windows\command;a:\ <-- this will set up a path to locate commands
    c: <-- this gets you to the C drive


    Then execute my previous commands. You can add to the list that I made up, similar commands to delete other bad files you are finding in your scans.
     
  19. jukes

    jukes Private E-2

    chaslang, here's what is so strange (see attached screen shot)

    Actually, that box remained checked from when PhilliePhan helped me with that last mess. I'd forgotten to uncheck the box afterwards, and I was surprised when I went to go disable it, that it was still off. The hiddens are all still checked to show as well. This computer isn't acting the way it should (insert totally perplexed look here)

    I'll go get the laptop, copy all of the above and get to work, and thank you!
     

    Attached Files:

  20. jukes

    jukes Private E-2

    (from laptop, with ms dos eradication going on desktop)

    I just wanted to let you know that last process is working. Most of what is coming up is "file not found" which I hope is a good thing, and means that my original deletion is still holding.

    My question now would be, is there a ms dos command which addresses those which are in the registry? Since Registry Mechanic, AdAwareSE and spybot all claim it's clear, yet that scan shows:

    Adware:Adware/eZula No disinfected
    Windows Registry

    Adware:Adware/BHO No disinfected
    Windows Registry

    Adware:Adware/TopConvert No disinfected
    Windows Registry

    or is that a step beyond where I am now?

    thank you!
     
  21. jukes

    jukes Private E-2

    I just hit a snag on this:

    cd c:\WINDOWS\Downloaded Program Files\

    the error that comes up: "Too many parameters - Program"
     
  22. jukes

    jukes Private E-2

    I need to go do the laundry that I put off yesterday. am leaving the machine on in the section I got stuck at (downloaded program files) and will get back as quick as I can.
     
  23. jukes

    jukes Private E-2

    back, and still stuck at this step:

    thank you in advance
     
  24. jukes

    jukes Private E-2

    someone suggested this:

    cd c:\windows\downlo~1

    and I can now continue with the steps
     
  25. jukes

    jukes Private E-2

    except that no matter which I type in, the error "bad command or file name" comes up.


    attrib -s -h -r bridge.inf
    attrib -s -h -r webdlg32.dll
    attrib -s -h -r YSBactivex.dll

    plus those in the newer list in this section.
     
  26. jukes

    jukes Private E-2

    thank you chaslang for trying.

    Life is just too short for me to beat this dead horse any longer, I'm now restoring it to factory defaults.
     
  27. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please allow him some time to post you a fix as he is extremely busy. Hang in there a little longer:)
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay if system restore is disabled, let's see if you can delete those two files you mentioned:
    c:\_RESTORE\TEMP\BRIDGE.0
    c:\_RESTORE\TEMP\WEBDLG32.0
    I would guess that you cannot delete them but let's see.

    With your problem executing this:
    cd c:\WINDOWS\Downloaded Program Files\

    That is another strange thing with WinME. If you put quotes like below it will work:
    cd "c:\WINDOWS\Downloaded Program Files\"

    Also the shortened 8 character name like you mention can be used too. But anytime you do something like that, you need to determine what that shortened 8 character name is. But for this instance what you used is fine.


    For the above problem it still appears that your PATH is not set properly. Either that or for some reason you no longer have the attrib.exe file. You could try looking for it in:
    c:\windows\command\attrib.exe

    If it is there, you could try changing the attrib command above to the full path like for one example:
    c:\windows\attrib -s -h -r bridge.inf

    This should not be necessary though if the path is setup properly as I gave earlier.
     
  29. jukes

    jukes Private E-2

    chaslang, there is no need for any of the eradication techniques now. I gave up, restored the computer and it is as clean as virgin snow now. (well okay, perhaps snow in some desolate area far from any city pollution!) First three stops were here to grab AVG and Zone Alarm downloads, create the rescue discs... and I will install all the MS updates and the zillion other things I need in my day to day surfing tomorrow. (AdAwareSE, SpybotS&D, etc etc etc)

    I am very grateful for all your efforts, but frankly, this machine not only stole three days of my life, but I'd simply had enough. It was either that or sledgehammer in the driveway. Enough is enough and I called out "Dégagé!!" after my seventh attempt to click the one button promising my freedom from being held hostage by this compromised machine. There it beckoned, one click away, yet the mouse kept freezing. Finally, I was able to click "restore to factory defaults"

    During Friday's eradication, I was unaware that my roof leaked into the piano causing major damage to it and I didn't find out until 9am Saturday. My child doesn't understand now why she cant play the piano or her little games on "mommy's computer". Something had to give, or I was soon to wind up in a rubber room over it.

    I'm also very grateful for all the easy downloads your site has set up, so I didn't have to risk surfing all over the place to get the utilities I need to protect it, now that it is clean.

    What I discovered when reinstalling my keyboard and mouse, is that the mouse hardware was shot, and I retired it to the great cheese wheel in the sky and set up my Christmas present... a wireless mouse. Everything is running just garoovy now, and I am off to bed to rest up for a long long long long day of accepting EULAs, setting prefs and wrangling this machine back to where I had it, (sans.... the cooties, naturally ;) ).

    Thank you again for being there!
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds