Malware Test 1 - for chipper

Discussion in 'Malware EDU' started by chaslang, Aug 24, 2007.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Alex,

    This is a first test. Below is a post made by a user. Post exactly what you would post if you could answer this message. Post your answer just like you would do it if you were posting and answer to this user.


    =======================
    I have tried running the READ & RUN ME procedure but I'm still having all kinds of problems. Here is my HijackThis log.

    Logfile of HijackThis v1.99.1
    Scan saved at 4:57:02 PM, on 8/24/2007
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\windows\system\hpsysdrv.exe
    C:\WINDOWS\system32\ps2.exe
    C:\WINDOWS\System32\S3tray2.exe
    C:\Program Files\Java\jre1.6.0\bin\jusched.exe
    C:\Program Files\Common Files\{5CC1D10D-0681-1033-1216-021113020001}\Update.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\U.S. Robotics 802.11g WLAN\USRWLANG.exe
    C:\Program Files\Webshots\WebshotsTray.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Documents & Settings\Owner\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://nkvd.us/1507/ (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://nkvd.us/1507/ (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://nkvd.us/1507/ (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nkvd.us/1507/ (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://nkvd.us/1507/ (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://nkvd.us/1507/ (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://4-counter.com/?a=2
    R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://4-counter.com/?a=2
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://195.225.176.8/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - _{0428FFC7-1931-45b7-95CB-3CBB919777E1} - (no file)
    R3 - URLSearchHook: (no name) - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
    F2 - REG:system.ini: Shell=Explorer.exe
    N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\xb7is59e.slt\prefs.js)
    O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_19_0.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {4EA1C17B-B8F0-8AC3-439C-09C0CECB97B2} - C:\WINDOWS\System32\natophh.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\System32\absxwsmb.dll
    O2 - BHO: (no name) - {B1CC69D6-119C-4B30-A505-C1AAFBB31889} - C:\WINDOWS\System32\pmnnk.dll
    O2 - BHO: (no name) - {F484F1A6-3028-4EF6-B554-467A9DA56284} - C:\WINDOWS\System32\vtstu.dll (file missing)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_19_0.dll
    O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
    O4 - HKLM\..\Run: [BlockTracker] c:\hp\bin\BlockTracker.exe
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [winactive] C:\Program Files\Window Active\winactive.exe
    O4 - HKLM\..\Run: [AGNTWDKQ] C:\WINDOWS\AGNTWDKQ.exe
    O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
    O4 - HKLM\..\Run: [yty] C:\documents and settings\owner\local settings\temp\yty.exe
    O4 - HKLM\..\Run: [sfpsvr] C:\WINDOWS\system32\sfpsvr.exe
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\System32\vxjujelr.dll",setvm
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\Money Express.exe"
    O4 - HKCU\..\Run: [System Soap Pro] C:\Program Files\System Soap Pro\soap.exe min
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [Spyware Vanisher] C:\spywarevanisher-free\FreeScanner.exe -FastScan
    O4 - HKCU\..\Run: [SPYKILLER] C:\Program Files\Anonymizer\sk\SpyWareKiller.exe /BOOT
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
    O4 - Global Startup: U.S. Robotics 802.11g Wireless Network Utility.lnk = ?
    O8 - Extra context menu item: &Search - http://kb.bar.need2find.com/KB/menusearch.html?p=KB
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod2\v4\yhexbmes.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod2\v4\yhexbmes.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: HushEncryptionEngine - https://mailserver1.hushmail.com/sha...tionEngine.cab
    O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/game...ts/y/st2_x.cab
    O16 - DPF: {0FFFFFFF-0FFF-0FFF-0FFF-0FFFFFFFFFFF} - http://www.h-desk-soft.com/hdesk_off...eskSetup_A.exe
    O16 - DPF: {11111111-1111-1111-1111-111555555555} - ms-its:mhtml:file://C:\document.mhtml!http://www.ultra-galleries.com/count...chm::/init.exe
    O16 - DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} - http://www.spywarenuker.com/product/...rInstaller.exe
    O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minib...ransporter.cab?
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yaho...st20040510.cab
    O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yaho...ymmapi_416.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pu...sh/swflash.cab
    O18 - Filter: text/plain - {D1878FA8-A234-4630-A6D6-DC0720ADDDDB} - C:\WINDOWS\System32\lakd.dll
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: pmnnk - C:\WINDOWS\System32\pmnnk.dll
    O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
    O23 - Service: Windows Network Security Management Service (nsms) - Unknown owner - C:\Windows\system32\1.tmp
    O23 - Service: Remote Procedure Call (RPC) Remote (RpcRemote) - Unknown owner - C:\Windows\system32\remote.exe
    O23 - Service: Microsoft sdk core (sdk) - Unknown owner - C:\Windows\lsass.exe
     
  2. chipper_atmacneil

    chipper_atmacneil Private First Class

    OK chaslang, you have some serious issues here, but I'm sure we can help.

    Final Considerations
    When your PC is clean again, visit How to Protect yourself from malware to learn more about how to prevent malicious software from invading your computer again.
     
    Last edited: Aug 27, 2007
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's analyze how you answered.

    First let's cover MG processes/procedures.

    The user said they ran the READ ME however here are all the things wrong with that:
    1. HijackThis log posted inline and it must be an attachment
    2. HijackThis.exe not renamed and this is very important especially for some of the infections this user has like Virtumonde
    3. CounterSpy was not installed or run and no log is attached
    4. If CounterSpy could not be run AVG Antispyware must be used in its place and again a log is required
    5. BitDefender Online Scan was not run and no log is attached
    6. PandaActiveScan was not run and no log is attached
    7. GetRunKey not run, no log is attached
    8. ShowNew not run, no log is attached
    Thus all of the above indicated that the user made no attempt at all to run the READ ME and did not explain any reasons why any of those steps could not be run.

    In most cases, it will be necessary to run the READ & RUN ME to properly remove all malware. As we state in the READ ME and in other stickies. This is a malware removal forum not a HijackThis log reading forum. HijackThis logs are totally inadequate by themselves and do not show all malware and also using only HijackThis (even along with the other tools you mentioned at the end) this PC would not be cleaned properly.

    Ccleaner is part of the READ & RUN ME and should be run as requested in the sticky and where requested. You should not use the Issues tab. It can actually be dangerous especially while infected and in addition it has nothing to do with fixing the malware problems. If this was to be run, a better place would be to run it after removing all malware and before sending the user to the How to protect yourself final steps. However I suggest that you not use the Issues tab in the Malware Forum.

    Now let's discuss the actuall fix you posted.

    This is not a fix that any of the people coming here from help can use. In fact it would possibly lead to them messing up their PC and removing things they should not remove.

    Don't use HijackThis readers. They are totally inaccurate. You need to read the logs and determine what to fix. You personally can use the reader yourself to get ideas if you cannot read the logs but as stated above you cannot trust them. What you posted has many flaws. Some of the items labeled suspicious are clearly valid

    C:\Program Files\U.S. Robotics 802.11g WLAN\USRWLANG.exe
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

    and some of them are clearly dangerous malware (including Virtumonde).


    The O12 lines in this log are not malware and should not be fixed without consulting with the user. You must take care to fix malware only. The exception to this would be when a user is also complaining that operation seems slow. Then fixing unnecessary startups, that you know for sure the user does not new, can be fixed. Things like qttask.exe, jusched.exe, realplayer...etc.

    Your fixes have to be complete and detailed or you will find that users cannot follow them or that they will break something. Don't put things in there that should not be touched. Only post what should be fixed and exactly how to do it. I would say that 99% of all people coming here will not know what to do with the below:
    In addition you cannot simply delete NT Services with HJT before taking other steps. And you did not explain to the user how to fix it before using. You must tell them how to Stop and Disable the service first and then you can use HJT to Delete the NT service but you must tell them how to do this.

    Let's discusss your Step 3 instructions.
    • Norman should not be run. The READ & RUN ME should be run. It covers everything that is required in our normal cleaning procedures. If at some point after running the READ ME, you think other tools are required to fix a certain problem, that is fine but it should be necessary and you should know exactly why you are running it and what you think it will fix. Norman has never been required to fix anything yet in my experience. Could it be useful....perhaps but I don't see what it would fix here that could not be fixed by running the READ ME and normal manual steps.
    • If you were to run VundoFix it would be better to run it first and then get new logs (actually the full READ ME is necessary to properly fix Vundo) and then work up a procedure after see the new logs.
    • Symantec LOP removal procedure is not require as there is no LOP infection and for the majority of LOP infections that do still occur, Symantec's tools have proven less than effective. Winactive.exe is a homepage Hijacker process the changes your default homepage to a new homepage that displays advertisements. (see: http://vil.nai.com/vil/content/v_125025.htm ) Yes there has been a winactive.exe file sometimes associated with LOP but it is not this one.
    Don't mention the How to protect yourself link until you get to the point where follow up logs have been determined to be clean. I know you said "when your PC is clean" but many people will assume after running what you just gave them, that they were clean. They could really mess things up if they start those steps in the middle of malware cleaning especially if they start doing Windows Updates while infected.

    You never gave the user any procedure to actually remove the malware files. Just running HJT and fixing lines will not necessarily remove the malware files and folders. No fix is complete unless you remove the malware itself. Removing a registry key that loads a malware process may stop it from loading right now, but the malware is still there and could be run by the used by mistake or another hidden process or registry entry (not seen in HJT) could make use of the file still being present. Thus the result is reinfection or a mutation of the infection.

    So in reality to start this user off, the proper answer would have been to have the inline HijackThis deleted (these are Major Geeks site requirements because HJT logs are clogging up the search engines make them less effective tools). And then you would suggest that they run the VundoFix procedure and then follow that up with requesting them to run the READ & RUN ME and then attaching all the logs. Which in this case would be:
    • VundoFix
    • CounterSpy - only for Windows XP, 2K, & NT users
    • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
    • SuperAntispyware - only if CounterSpy or AVG Antispyware could not be run which is primarily for Win9x & ME users
    • Bitdefender
    • Panda Scan6
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis
    Continued in my next message to be posted.
     
    Last edited: Aug 27, 2007
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Below is a guide I have written up to explain the basic malware cleaning process that is almost always followed or at least most of it is. I call it Basic Principles of Cleaning Malware or Malware 101 ;)

    ===========================

    Basic guidelines and general concepts of cleaning up malware (Malware 101)

    - normally READ & RUN ME FIRST Before Asking for Support
    sticky is the first step

    - logs must be attached but only accept them after the READ ME has been run, unless malware prevents READ ME execution. We require that HJT logs be attached, but I ask that all logs (from any tool) be attached because the thread is less cluttered that way.

    - HJT should be installed properly. Any non-Desktop, non-temp, and non-Documents and Settings folder is really OK. It should be in its own folder. It should almost always be used from normal boot mode.

    - Basic steps for removal
    • Try Add/Remove programs
    • Unregister any DLLs that may need to be unregisted. While we should do this more often, we rarely do since it would make procedures so much longer. Thus, if you have a problem removing a DLL, try unregistering it first.
    • Exit ALL browsers before running HJT. It is important to do this because some malware (LOP for one) can cause IE sessions to be running and it brings it to your attention. Also see two bullets down.
    • Kill processes (use HJT process manager or Process Explorer or similar - Task Manager does not cut it)
    • Use HJT to fix entries. No browsers should be open when fixing because it can block certain fixes.
    • Boot to safe mode and delete bad files & folders. We now often use a program like The Avenger or Pocket Killbox to do this for us. It avoids user error, noob errors, and deletes things that may be difficult to remove.
    • Cleanup any necessary registry entries. Where possible I use patches that can be merged into the registry. You cannot trust most users to be playing with any registry editors. If regedit (I like Registrar Lite ) or similar is going to be used, a backup should be made first. Sometimes registry patches may need to appear at a different point than this. i.e., before reboot to safe mode or before using Killbox or Avenger.
    • Reset Web Settings where needed (one example where always need is with any of the dozens of hijackers that take over Start, Search, and Defaults).
    • Reboot normal mode
    • Rerun a drive cleaner (CCleaner or ATF-Cleaner). May not be needed if nothing was manually deleted and if logs showed the Temp folders to be basically empty or up to date.
    • get new logs from GetRunKey, ShowNew and HJT....etc (as required) to double check
    • Repeat as necessary and alter add steps as needed too.
    While this is not always the exact process it is pretty close and many steps are permutations of this. Obviously there are a whole bunch of baddies requiring special tools and steps to ID baddies and get to remove them too. We can teach these as we go. For one example: we use Pocket KillBox quite a bit to delete files when they are stubborn. It also has some other nice features tied in. More recently in spring 2007, Pocket Killbox frequently failed to remove malware thus it became more efficient to just use The Avenger by Swandog46 to begin with and it also has the ability to remove stubborn registry keys and values.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now I will show you how a detail procedure would be written up to fix things. I will ignore the fact that we would not work up a fixed solely based on an HJT log at this time just to get the procedure aspect accross. I will also ignore the fact the Add/Remove programs should be checked to see if certain malware can be uninstalled. This is also covered in the READ & RUN ME. In addition, I will show the proper kind of steps required to fix Virtumonde although with just and HJT log, you cannot make a full fix. After you read thru this, ask questions and let's have a discussion on everything thus far ( as necessary ) before we move onto another test. ;)

    First you would request that HijackThis be properly installed and renamed. You can refer to step 7 in the READ ME or you can tell them they have this:
    C:\Documents & Settings\Owner\Desktop\HijackThis.exe

    and it needs to be this:
    C:\Program File\HijackThis\analyse.exe


    Now let's remove some bad services. Be careful while doing the below and follow instructions exactly reading the names of the services carefully. Be sure to match exactly what is given. There are other valid services you will see that make use of the words Remote Procedure Call (RPC). You must only fix exactly what is requested!
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Content Monitoring Tool
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • Windows Network Security Management Service
      • Remote Procedure Call (RPC) Remote
      • Microsoft sdk core
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste msCMTSrvc into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • nsms
      • RpcRemote
      • sdk
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Continue by downloading a tool we will need

    - Process Explorer

    Extract it to its own folder somewhere that you will be able to locate it later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    Make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of any of the below DLL files (if found) and then click the kill button.
    pmnnk.dll
    After you have killed all instances of any of the above DLLs under winlogon click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on explorer.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    pmnnk.dll

    After you have killed all instances of any of the above DLLs under Explorer click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on iexplore.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    pmnnk.dll

    After you have killed all instances of any of the above DLLs under iexplore click ok.
    (If you do not find these DLLS, just continue on.)

    Now back at the main Process Explorer window look for the below processes and if found right click on them and select Kill Process.

    C:\Program Files\Common Files\{5CCBDF4D-06C1-1033-0106-050602200002}\Update.exe

    Now just exit Process Explorer.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://nkvd.us/1507/ (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://nkvd.us/1507/ (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://nkvd.us/1507/ (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nkvd.us/1507/ (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://nkvd.us/1507/ (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://nkvd.us/1507/ (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://4-counter.com/?a=2
    R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://4-counter.com/?a=2
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://195.225.176.8/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - _{0428FFC7-1931-45b7-95CB-3CBB919777E1} - (no file)
    R3 - URLSearchHook: (no name) - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
    O2 - BHO: (no name) - {4EA1C17B-B8F0-8AC3-439C-09C0CECB97B2} - C:\WINDOWS\System32\natophh.dll
    O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\System32\absxwsmb.dll
    O2 - BHO: (no name) - {B1CC69D6-119C-4B30-A505-C1AAFBB31889} - C:\WINDOWS\System32\pmnnk.dll
    O2 - BHO: (no name) - {F484F1A6-3028-4EF6-B554-467A9DA56284} - C:\WINDOWS\System32\vtstu.dll (file missing)
    O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
    O4 - HKLM\..\Run: [winactive] C:\Program Files\Window Active\winactive.exe
    O4 - HKLM\..\Run: [AGNTWDKQ] C:\WINDOWS\AGNTWDKQ.exe
    O4 - HKLM\..\Run: [yty] C:\documents and settings\owner\local settings\temp\yty.exe
    O4 - HKLM\..\Run: [sfpsvr] C:\WINDOWS\system32\sfpsvr.exe
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\System32\vxjujelr.dll",setvm
    O4 - HKCU\..\Run: [System Soap Pro] C:\Program Files\System Soap Pro\soap.exe min
    O4 - HKCU\..\Run: [Spyware Vanisher] C:\spywarevanisher-free\FreeScanner.exe -FastScan
    O4 - HKCU\..\Run: [SPYKILLER] C:\Program Files\Anonymizer\sk\SpyWareKiller.exe /BOOT

    I highly recommend not using online poker sites like below! Consider uninstalling PartyPoker and fixing the below line if still found.
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe

    O16 - DPF: {0FFFFFFF-0FFF-0FFF-0FFF-0FFFFFFFFFFF} - http://www.h-desk-soft.com/hdesk_off...eskSetup_A.exe
    O16 - DPF: {11111111-1111-1111-1111-111555555555} - ms-its:mhtml:file://C:\document.mhtml!http://www.ultra-galleries.com/count...chm::/init.exe
    O16 - DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} - http://www.spywarenuker.com/product/...rInstaller.exe
    O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minib...ransporter.cab?
    O18 - Filter: text/plain - {D1878FA8-A234-4630-A6D6-DC0720ADDDDB} - C:\WINDOWS\System32\lakd.dll
    O20 - Winlogon Notify: pmnnk - C:\WINDOWS\System32\pmnnk.dll

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now at this point we would normally be asking for the below follow up logs but that assumes that the full READ & RUN ME has already been completed.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!
     
  6. chipper_atmacneil

    chipper_atmacneil Private First Class

    It took me a few sessions to build the courage to face the criticism, but it feels much better now that I did.

    So, to begin, HijackThis! is not an appropriate tool for malware removal in itself, because, like other antimalware software, its ability to detect viruses and spyware has certain limitations, it cannot detect all files and processes on the computer, and hence, if no attachments of logs from the other scanning tools are present, that's a serious clue that MG procedure has not been followed by the user. No wonder HijackThis! is rated as a MajorGeek-level tool, it's way too easy to overestimate how powerful it is, and provide a fix with serious flaws.

    Before any procedure can be run, we need to make sure that the user has followed the steps in READ and RUN ME FIRST. This is done by checking for logs from the antivirus and antispyware programs mentioned in the malware troubleshooting post.

    Question: How can we be sure if the procedure to uninstall malware programs through Add/Remove or Programs and Features (Vista users only), has been run?

    The part about BitDefender and Panda ActiveScan is easy to understand, but say I'm dealing with logs from a user running Vista. As per the instructions in the link, they skip 6A because it will not work on any flavour of NT6.0. Am I out of line to ask them to run Trend Micro Housecall 6.6 and provide a log from the scan? They are listed as Alternative Scans in the procedure prior to a post.

    I used Housecall in troubleshooting frequently myself because of its ready availabilty, and its compatibility with Mozilla Firefox is an added bonus. The other online scan I find useful is Kaspersky, which thankfully is even provided on the MajorGeeks.com main page, and like Housecall, will work in Vista. Unlike Housecall, it will not work with Firefox, however.

    Those are the first two questions I can think of now, I will post more later as they come to me.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't feel that way. This is about learning. That is the focus. Just take it as I truly mean it and that is just to teach you as quickly as possible. :)

    Correct. In reality now adays more fixes are performed with tools other than HJT. And remember my comment about HJT readers. They really are not trust worthy. I never ever use them. If you really know the Windows OS and file systems, and if you have reasonable knowledge of 3rd party tools, you can quickly read thru HJT logs and remove the known goods and then decide on known bads and the I don't know's yet. ;)

    More clue's to the READ ME not being run.
    • If a log is inline, it is obvious that the READ ME is not being followed.
    • If HJT is not installed and renamed properly, it is obvious that the READ ME is not being followed
    • If the other logs are not attached and no explanation is given as to why they are not attached, it is obvious that the READ ME is not being followed
    • If they say they ran Bitdefender and or Panda and they found nothing, you can check the HJT log for signs that BitDefender was run (O16 lines) and you can look in the log from ShowNew in the uninstall programs list to see if PandaActiveScan was installed. Some people will lie to avoid running the tools which really is only hurting themselves.
    Not exactly. In many case the READ ME will be required to properly do a malware cleaning, but there will be exceptions where you can quickly resolve a problem. However no HJT logs are accepted without the READ ME being run reasons already stated above. You just cannot tell some one they are clean based on a HijackThis log alone. There will be cases where a HijackThis log will show no malware at all but there are malware issues.

    Sometimes based on what a user states in their message, I may know they have an infection like SmitFraud, Virtumonde,..etc and I may run a specific procedure for those first but I will not ask for a HijackThis log or work up a fixed based on one even if they attach it and it is the only thing attached. I will then after running the specialty tool, often say that they really need to run the READ ME even if there problems appear to be fixed since other problems could be hiding. This is especially true for Virtumonde infections where there is always more hiding.

    Yes like I stated above in the other clues. Also you must check to make sure they have proper versions of tools like Spybot 1.4, the versions shown for GetRunKey and ShowNew, HJT version, and for anything else you can check. You'll be surprised at how far out of date people are with everything including their OS. And I sure you know, but never update and out of date OS until all malware is removed. Part of my final instructions include that in this link: How to Protect yourself from malware!

    You will see a dump of the uninstall list from the registry at the end of the ShowNew log (newfiles.txt). This will help you see things that are still installed and that should be uninstalled. Note however, sometimes things will appear in this list but not in Add/Remove programs. A typical problem where things were not uninstalled completely or malware did this to hide. Often times you need make a registry patch to remove it from the registry.

    No that's fine. You can always ask for another tool to be run to help resolve a problem. What I try to avoid is having to user labor for many hours working thru the READ ME and then immediately after they post there logs make them run another time intensive scan. But if it is necessary, that's fine. If you know for a fact that HouseCall now works fine for Vista (and I know you said it does), we can add it back into the READ ME. It used to be there but more than 60% of people coming for help always had problems running Housecall in the past. Does it all run if using FireFox on Vista? I currently do not have Vista so I'm limited in what I know about Vista. I have been adding things into ShowNew.bat for specifics of Vista but I have been using Halo as my beta tester to see how things work on Vista. This version of ShowNew (and also GetRunKey) will be coming soon and they will be in a self-extracing EXE that will auto install and also auto run, the batch files (3 of them) and ZIP the logs so that one file needs to be uploaded and it will be smaller because ZIPing.

    Kaspersky is also in our Alternative Scanslink. I rarely use it for a variety of reasons:
    • it does not fix anything
    • have seen to many false positives
    • also the way it reports things, it make people think they have problems when they don't
    • they add the KAVICHS alternate data stream (ADS) to every file they scan and many other scanners will now detect all those files as potentially infected due to the ADS and it can also make the files look like they were changed.
    Keep on posting as many as you want. This is the purpose of this training and remember, don't take anything I say in my posts the wrong way. Everything is meant to help you learn our procedures here on MGs and also learn the tools, tricks, ...etc for malware removal.

    I need to work up another test for you. In the meantime:
    • have you read thru and do you follow the logic in the Malware 101 steps?
    • have you read thru and do you follow how and why my fix written? Notice how it is specific on what to do?
    • Also start familiarizing yourself with the threads in our hidden forum: http://forums.majorgeeks.com/forumdisplay.php?f=39 It is hidden but accessible. All the special removal links point here and so do some links given in the READ ME.
     
  8. chipper_atmacneil

    chipper_atmacneil Private First Class

    Housecall 6.6
    This version of Trend Micro Housecall works fine with Vista. It can be found at the link Housecall 6.6 arrived--Try the new version now.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's the same link we already have in the Alternative Scanswhich is given in step 9 of the READ ME.

    I did modify the READ & RUN ME (see step 6B) to allow for Vista users (or others who could not use the other online scanners) to run HouseCall. I made a procedure for HouseCall, but it needs some more work to explain getting a log.
     
    Last edited: Aug 30, 2007
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well I'm rethinking adding HouseCall to the READ ME for many of the same reasons as previously removed. I experimented with it yesterday and today of two different PC. One with Win2K SP4 and one with WinXP SP2.

    Results:
    • too many false positives - on both PCs
    • terrible method of reporting problems - needs a full complete easy to read report. The other verbage should be left to show by clicking a more info type button if you want it. The form is too small and scrolling back and forth is necessary to try and see exactly what is being reported. In addition you cannot see exactly what is reported unless you the Select individual action button. Also this has to be done for every single item found. TOOOOO annoying.
    • terrible method of fixing problems - too complex for most users due to all the above mentioned items.
    • never finished while trying selective fixes on Win 2K and when I closed the IE browser since it never finished the fix, the process still was running and had to be killed. Even after that the CPU was overloaded. Had to reboot.
    • seems to use an extremely large amout of system resources
    • NO LOG!!!
    I'm not going to keep this in the READ ME even if it does support Vista. It is not worth it in my opinion.
     
  11. chipper_atmacneil

    chipper_atmacneil Private First Class

    I just tested it again yesterday, and coming back to it today, like you said, there is no log. I'd never used it for logs before so I hadn't realized it wouldn't leave one. :( I'm sorry about that. I didn't know it was bad for false positives, my experience with HouseCall had been that it was helpful up to this point.

    On the plus side, I've been studying the HijackThis tutorial during the week and I'd like another chance to interpret a log. The concepts are still new to me, but I think I can wing it.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's not your fault. We did have it as a required tool way back in time but I eventually removed it due to to many issues with it. Yes it can find a many problems just like the other scanners but the downsides are just too much to deal with.

    You will be getting another test if I can get to it this weekend. I will be away all day tomorrow and may of may not be back until Monday (not sure yet). If I get time, I'll post something tonight. Otherwise odds are it will be Monday. Have you been looking at the other things I gave you to study?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Test # 2

    Okay we begin round two. Based of the below post from a user work up a complete step by step fix. Note that for simplicity I'm just going to put all of the logs into a ZIP file named test2.zip and attach it to reduce messages in this thread.

    =================================
    I have had alot of new programs on my task manager list. They arent always on the list though, only at some points. So i dont know if they are on their right now. But i spybot and adaware has found some smitfraud stuff like. Smitfraud-C. something. I have been having pop ups which i have never had before. Spybot and Adaware said they deleted it, but i am still getting pop ups. Here is my logs from running the Read & Run Me.
     

    Attached Files:

  14. chipper_atmacneil

    chipper_atmacneil Private First Class

    Re: Test # 2

    chaslang,

    Welcome to MajorGeeks! Listen, I realize you're in a bind and this situation must be very frustrating for you, but you haven't completed all of the READ & RUN ME steps as printed. Your scans are polluted with cookies, what that tells me is that CCleaner still needs to be run. Secondly, you have not gone through Add/Remove Programs for malware on our list to uninstall. I have a list from your scan of detected malware, but it's still very important that you go through the list and uninstall anything you find that matches the threats in Uninstall Malware through Add/Remove Programs. You did, however, remember to rename HijackThis! and install it in its own folder in Program Files as analyse.exe, which will help get this issue resolved faster.

    Follow the following procedure, then post new logs for CounterSpy, BitDefender, ActiveScan, GetRunKey, ShowNew, and HijackThis:

    Uninstall the following programs through Add/Remove Programs:
    ClearSearch
    Kazaa
    MyWay
    MyWebSearch
    ncase
    Need2FindBar
    WeatherBug
    WinTools

    Run the following Special Removal Procedures:
    Virtumonde
    Win32.Zlob

    Finally, go back to READ & RUN ME FIRST and carefully follow all the steps listed there, that includes following steps in links as they apply. Make sure every step is run before you post logs again. Your system will be in a much more readable state and we will be able to clean it up from there.

    Thank you for your time,

    Chipper ;)
     
    Last edited: Sep 10, 2007
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Test # 2

    And the user answers with the below. Now what?
    Also I would not recommend saying:
    Cookies are not problems and are not a reason to have the user rerun any scans. Yes they make logs and scans take longer but they are not issues to be concerned with.

    Question: Why did you want him to run the SpywareQuake & SpyFalcon Removal Procedure ?
     
    Last edited: Sep 10, 2007
  16. chipper_atmacneil

    chipper_atmacneil Private First Class

    Re: Test # 2

    Hi Charlie,

    I thought from reading the boards that that procedure was also for removing the Zlob malware. I remember finding Zlob there while looking through the scans. I'll go over them again and show you where I found it. I'll be back to post my full answer on Tuesday. Thanks for the pointer about the cookies, they are more of an annoyance to me, and I thought they interfere with the accuracy of malware scans. I won't do that again.

    Alex (Chipper) :)
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Test # 2

    I'll be waiting! ;) Also I will show you two newer, better, and easier mehods for Zlob aka SmitFraud removal.

    Don't worry about it! You are here to learn and that is exactly what you are doing. :) We run things like Ccleaner and ATF-Cleaner which will remove cookies but the main reason they are run is to remove all the temp junk that can accumulate (including malware in temp folders). Removing all of this junk and also the cookies before the other scans are run, results in faster scanning times and smaller logs which is the main focus. If we see cookies in the logs afterwards, we ignore them unless we notice that the user did not install/run CCleaner. We would then just request that CCleaner be installed and run.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds