Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by robopp, Apr 13, 2006.

  1. robopp

    robopp Private E-2

    First off, thank you in advance for any help offered.

    Now to the problem.
    I have some form of virus/malware that I cannot get rid of. I have run CCleaner and SpyBotS&D and they did find suspicious files, which were repaired to no avail! I have ran multiple virus scans using Norton Antivirus in both safe mode and normal mode and it has found some issues but I continuously get Nortor Virus Alerts in Normal mode that it has detected a virus. First is complains that ym11_[2].exe (with some random variation on the _[2]) then it downloads files to my C:\WINDOWS\TEMP directory with a different name each time. I can delete these files in safe mode but the virus keeps downloading new files. The virus has disabled my firewall and my virus protection on startup. The situation has gotten better but still not 100%. Please help. Here is my Hijack this log after norton detected the above mentioned virus's.

    Edit by chaslang: Inline log removed. Cleaning steps not followed.
     
    Last edited by a moderator: Apr 14, 2006
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please do not post any logs inline. Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments. Also HijackThis must be installed properly.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. robopp

    robopp Private E-2

    Thank you for your response.

    I have followed all the steps including step 6 and 7 and have attached Bitdefender, Panda Scan and HijackThis logs. Bitdefender found 225 problems and repaired all but four files. My problem still exists and on power up the windows firewall is disabled and norton auto protect is disabled as well. Thank you for any help your can provide.

    Regards,
    Rob
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not empty your Norton AntiVirus\Quarantine as requested in step 0 of the READ ME. Please do that now.

    Now download: HSFix.zip

    Extract the tool from the ZIP File to a folder you can easily find (preferably in its own folder - like C:\HSFix).

    Now please boot to Safe Mode and DoubleClick hsfix.bat to run the tool.

    Allow it as long as it takes to run, then Reboot to Normal Windows and look for a log at C:\hslog.txt . Please attach that log now before continuing on to the steps below.


    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
    O4 - HKLM\..\Run: [SysTray] c:\Program Files\paytime.exe
    O4 - HKLM\..\Run: [Microsoft Windows System] syshost.exe
    O4 - HKLM\..\RunServices: [Microsoft Windows System] syshost.exe
    O4 - HKCU\..\Run: [Key] C:\DOCUME~1\Rob\LOCALS~1\Temp\1D.tmp
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O20 - Winlogon Notify: cdscsix3 - cdscsix3.dll (file missing)
    O20 - Winlogon Notify: directpt - directpt.dll (file missing)
    O20 - Winlogon Notify: SensSrv - C:\WINDOWS\SYSTEM32\senssrv.dll
    O21 - SSODL: SysTray.Exbr - {6368D1FC-6F5C-4f1b-B164-E67214F678E9} - (no file)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    c:\Program Files\paytime.exe
    C:\WINDOWS\system32\directprt.sys
    C:\WINDOWS\system32\oleext.dll
    C:\WINDOWS\system32\senssrv.dll
    C:\WINDOWS\system32\syshost.exe
    C:\WINDOWS\system32\cdscsix3.dll
    C:\WINDOWS\system32\directpt.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  5. robopp

    robopp Private E-2

    Chaslang,

    Thank you very much, I believe my malware has been completely removed after following the steps outlined in your most recent post. I have disabled and re-enabled system restore, but I would appreciate if you could look over my HJT log. This time i purged norton protected files then immediately ran HJT.

    Once again, thank you.

    Regards,
    Rob
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach the C:\hslog.txt file.
     
  7. robopp

    robopp Private E-2

    Sorry about that.

    Regards,
    Rob
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! It found the hidden file I was worried about and deleted it.

    If you are not having any other malware problems, you should work thru the below link:

    How to Protect yourself from malware!
     
  9. robopp

    robopp Private E-2

    Great thank you.

    Regards,
    Rob
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds