malware problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by khrisgil, Nov 24, 2006.

  1. khrisgil

    khrisgil Private E-2

    Hi i have followed the instructions for getting rid of malware, i am not certain everything has been removed. I am attaching the logs for your review
     

    Attached Files:

  2. khrisgil

    khrisgil Private E-2

    malware problems 2

    here are the rest of the logs
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: malware problems 2

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.2_03

    Also if CounterSpy is the free trial version from the READ ME, you should uninstall it now since you have Windows Defender installed and since you already scanned with it.

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Continue by downloading a tools we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [NI.UWA6P_0001_N91M1807] "c:\documents and settings\christian d. gil\application data\winantiviruspro2006freeinstall[1].exe" -nag
    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\zyaeih.exe
    C:\WINDOWS\system32\zyaeih.dat
    C:\WINDOWS\system32\zyaeih_nav.dat
    C:\WINDOWS\system32\zyaeih_navps.dat
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. khrisgil

    khrisgil Private E-2

    Hi there, things went fine when running the previous steps. internet is working fine and after rebooting (from the killbox) no popups have appeared so far.
    here are also the new logs.

    best,

    Chris
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks to me like you did not use Killbox to delete the files requested. They don't show in the Killbox backup folder and I still see some of them in your newfiles.txt log. Also some new lines showed up in your HJT log.

    Let's try again.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:O4 - HKLM\..\Run: [zyaeih] c:\windows\system32\zyaeih.exe zyaeih
    O4 - HKLM\..\Run: [NI.UWA6P_0001_N91M1807] "c:\documents and settings\christian d. gil\application data\winantiviruspro2006freeinstall[1].exe" -nag

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    C:\WINDOWS\system32\zyaeih_nav.dat
    C:\WINDOWS\system32\zyaeih_navps.dat

    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

     
  6. khrisgil

    khrisgil Private E-2

    Thanks again, I did run the killbox before, and i did it again as you suggested in your last email. I have attached the newer 3 logs as requested. When I ran the HJT I noticed the line O4 - HKLM\..\Run: [NI.UWA6P_0001_N91M1807] "c:\documents and settings\christian d. gil\application data\winantiviruspro2006freeinstall[1].exe" -nag was still appearing, so I fixed it again, but to my suprise it appeared after when i repeat the procedure.

    Look forwar to hearing from you soon,

    Chris
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but this time the two files actually deleted. See the difference in your two newfiles.txt logs. Now it shows:
    Code:
    "C:\!KillBox\"
    (1)~1         Nov 23 2006         858  "( 1)"
    (2)~1         Nov  8 2006      239502  "( 2)"
    (3)~1         Nov 26 2006        5829  "( 3)"
    (4)~1         Oct 29 2006      236544  "( 4)"
    zyaeih~1.dat  Nov 23 2006         858  "zyaeih_navps.dat"
    zyaeih~2.dat  Nov  8 2006      239502  "zyaeih_nav.dat"
    Last time the zyaeih.... files did not delete!


    Something may be blocking the removal. Uninstall Windows Defender and shutdown Symantec as best as possible. Then try fixing that same O4 line again. After fixing reboot and make sure it is still gone. Attach a new HJT log.

    How are things working?
     
  8. khrisgil

    khrisgil Private E-2

    Hi there, thanks for helping me out with this. My computer is running so much better now. I work yesterday on it and did not have any pop ups. I uninstalled windows defender, disabled the symantec antivirus and the firewall, I also did the procedure with not network connection and in both modes, normal and safe to remove the winantivirus line but it keeps being there.
    Here is the last log after I did all the above.
    I also have one more question for you, recently I noticed the change in the color of some folders and files, these folders are now very light, they look exactly other folders or files but the color is much toned down, is this normal??
    Best,

    Chris
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure. It could be from something you installed. There are programs that do things like this. Also Windows will show files compressed to save disk space in another color (blue I think).

    Delete the below file from your Desktop!
    C:\Documents and Settings\Christian D. Gil\Desktop\setup.exe


    Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to the below registry keys and take ownership of them (I explained how to do that further down).

    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run



    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the Address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the top Menu
    • Select Take Ownership
    • Now in the right windows pane locate: NI.UWA6P_0001_N91M1807 and right click on it and select Delete.
    • Now click View and then Refresh
    • Double check to see if the NI.UWA6P_0001_N91M1807 key is gone.
    • Let me know if get any error messages while doing any of the above.
    Now attach a new HJT log if the above worked without any error messages!
     
  10. khrisgil

    khrisgil Private E-2

    Hi there, thanks for the last information. I believe that it is clean now. I have attache the last HJT log and saw not track of Winantivirus.

    I want to reiterate my thanks for your help.

    Chris
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds