Malware's slapping me around and calling me Susan!

Discussion in 'Malware Help (A Specialist Will Reply)' started by TheGarnisher, Oct 11, 2006.

  1. TheGarnisher

    TheGarnisher Private E-2

    Okay, here's the history as brief as possible.

    I've gone through everything in the read and run me first section. I hope I did it all correctly.

    The only thing I did differently was I rebooted in normal mode before I ran bitdefender and panda Activescan because I couldn't seem to get a connection to the internet otherwise.

    Bitdefender detected some things that said it could not remove which was kinda scary.

    One more thing, towards the end of all this mess, it seems that windows stopped recognizing exe files. Every shortcut for browsers, software like photoshop, even msconfig asked me to associate a program with it when I clicked on it. So I browse in the C drive, find the program and it will usually open, but I don't know how to do that for msconfig.

    Hope you can help me.
     

    Attached Files:

  2. TheGarnisher

    TheGarnisher Private E-2

    here's the rest of the attachments

    Please note I had to break up the bit defender scan into two documents because it was slightly over the 250K limit as one document. Just copy the contents of bdscan2 and paste it into the end of bdscan and it will be the complete file.
     

    Attached Files:

  3. TheGarnisher

    TheGarnisher Private E-2

    I wanted to post the message I get when I try to enter msconfig... image attached...
     

    Attached Files:

  4. TheGarnisher

    TheGarnisher Private E-2

    just checking in... hope someone can help me.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Why are you running your PC without an antivirus and without a firewall? No wonder you are so badly infected with DOZENS of password stealing trojans and more.

    Also is your copy of Spyware Doctor a paid and up to date subscription? Or is it a free trial version?

    Since you have so many password stealer trojans on your PC, you really need to take the below warning seriously.

    First install the current version of Sun Java from: Sun Java Runtime Environment

    Then uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 3
    Java 2 Runtime Environment, SE v1.4.2

    Are the below folders something you created and are you storing information in them? I would think not and they appear to be loaded with Trojan Password Stealers.
    Code:
    C:\
    LSJYAD~1      Sep 15 2006              "LSJYADFASFD"
    LSJYNE~1      Sep  7 2006              "LSJYNEWTRO"
    WIN32A~1      Sep 24 2006              "WIN32APIKING"
    
    If you did not create these folders, DELETE them now. Boot in safe mode if necessary to delete them.


    I want you to scan the C:\WINDOWS\system32\system.dll file using the below online file scanning site. Report back what it finds.

    http://virusscan.jotti.org/

    Just use the Browse button to locate the file on your PC and submit it. Post what it finds back here.

    Now continue on to my next message!!
     
    Last edited: Oct 12, 2006
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please complete the instructions and answer questions from my previous message before continuing with this message!


    Continue by downloading a tool we will need- Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [] C:\WINDOWS\system32\intenat.exe
    O4 - HKLM\..\Run: [dbg85239] RUNDLL32.EXE w0929796.dll,n 00285237000000030929796
    O4 - HKLM\..\Run: [zt] C:\WINDOWS\Intel\rundll32.exe


    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    c:\program files\system.exe
    C:\WINDOWS\system32\intenat.exe
    C:\WINDOWS\system32\w0929796.dll
    C:\WINDOWS\system32\hauc.exe
    C:\WINDOWS\system32\NetSystem.dll
    C:\WINDOWS\system32\Ravdm.exe
    C:\WINDOWS\system32\riwzkn.exe
    C:\WINDOWS\system32\tpsd.exe
    C:\WINDOWS\system32\zkdmg.exe
    C:\WINDOWS\system32\zqskw.exe
    C:\WINDOWS\system32\ztdll.dll
    C:\WINDOWS\system32\vpcrm.exe
    C:\WINDOWS\system32\winasse.exe
    C:\WINDOWS\system32ghynf.exe
    C:\WINDOWS\osrkeanA.exe
    C:\WINDOWS\vbarun.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot, also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Regina\Local Settings\Temp

    Now attach a the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or
     
  7. TheGarnisher

    TheGarnisher Private E-2

    Well no virus because virus interfered too much with other programs. I thought we had windows firewall on but I guess not.

    Okay, I hit a snag... because windows no longer seems to recognize any files that are exe, it wouldn't let me install the latest version of java... I don't know if it was pointless to, but I went ahead and did the other steps you recommended. (I didn't remove the older versions of java since I couldn't install the new one)

    the online scanner found the following...


    File: system.dll
    Status:
    INFECTED/MALWARE
    MD5 47a667c0177e59d6359b9391ac89de30
    Packers detected:
    UPACK
    Scanner results
    AntiVir
    Found Trojan/PSW.Delf.PX.3
    ArcaVir
    Found Trojan.Psw.Delf.Px
    Avast
    Found nothing
    AVG Antivirus
    Found PSW.Generic2.IIB
    BitDefender
    Found Generic.PWStealer.FC0D4AF8
    ClamAV
    Found nothing
    Dr.Web
    Found Trojan.PWS.Legmir.586
    F-Prot Antivirus
    Found nothing
    Fortinet
    Found W32/Delf.PX!tr.pws
    Kaspersky Anti-Virus
    Found Trojan-PSW.Win32.Delf.px
    NOD32
    Found Win32/PSW.Delf.PX
    Norman Virus Control
    Found W32/Delf.RUR
    VirusBuster
    Found nothing
    VBA32
    Found Trojan-PSW.Win32.Delf.px
     
  8. TheGarnisher

    TheGarnisher Private E-2

    Forgot to answer one of your questions... I paid for the spyware doctor program... and it is current.
     
  9. TheGarnisher

    TheGarnisher Private E-2

    Okay, part 2... while working through the next steps... windows started properly recognizing exe files again... So I backed up and installed the current version of Java... but when I went to remove the older version called: Java 2 Runtime Environment SE v1.4.2, it said something about not finding it and said it couldn't unistall... the version 3 one did uninstall though.

    Okay, everything else went like you said it would, no problems and like I said, the fact that the computer runs exe files properly again seems encouraging...

    I've attached the new logs.
     

    Attached Files:

  10. TheGarnisher

    TheGarnisher Private E-2

    So... Am I clear? Spyware doctor seems to run clean these days... but I know things could still be lurking. Let me know so I can start putting up firewalls and what not.
     
  11. TheGarnisher

    TheGarnisher Private E-2

    bump. I do appreciate the help so far... I was just hoping to get a last look here so I can make sure I'm still clean.. Spyware doctor no longer detects anything so that's positive, I went ahead and installed a new firewall... the free one from Filseclab... I'm just holding off on doing the last couple steps of the read and run me first document until it looks like I'm officially clear of malware.

    Thanks.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the below sticky thread. Your bumping and posting of unnecessary messages cost you a few days of extra waiting time.

    Don't Bump! It Only Hurts You!!!


    Since your copy of Spyware Doctor is a paid version, uninstall Windows Defender.

    Funny that Java 2 Runtime Environment, SE v1.4.2 does not show in Add/Remove programs! It is still in your ShowNew log. Use the below registry patch which should remove it:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now use Pocket Killbox (or do it manually in safe mode) to delete the below files:

    C:\WINDOWS\system32\myrx.dll
    C:\WINDOWS\system32\system.dll

    Now attach a new log from ShowNew and also tell me how things are currently running.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and enable System Restore to create a new clean Restore Point.
    4. After doing the above, you should work thru the below link:
     
  13. TheGarnisher

    TheGarnisher Private E-2

    Okay, so I did the steps you told me up until the final steps... I want to make sure you give my files a clean bill of health before I start deleting the backups.

    Thanks for clarifying about bumping... I wasn't sure how if it needed to stay on the front page to get attention... now I know. By the way, you all are saints for providing this help to people.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would like to get some more info on the C:\WINDOWS\system32\system.dll file. Locate it using Windows Explorer and then right click on it and select Properties. Now see if there is a Version tab in the window. If so, select the Version tab and on the next window select each of the listed Item names (one at a time) to get more info about the file. The most important Item is the company name. If there is no Version tab, tell me that too.
     
  15. TheGarnisher

    TheGarnisher Private E-2

    No version tab, just a summary tab that looked like a blank form.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do this next step first!!!

    Run Pocket Killbox and select File, Cleanup, Delete All Backups!

    Now let's try Pocket Killbox one more time.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\system.dll

    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself. Take note of any error messages from Killbox and tell me about them later).

    After reboot, attach the below new log and tell me how the above steps went.
    1. ShowNew
    Make sure you tell me how things are working now!
     
  17. TheGarnisher

    TheGarnisher Private E-2

    Things seem to be running well.

    Here's the latest log. Let me know if I can do the final steps.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean! Yes you can do the final steps as given in message number 12!
     
  19. TheGarnisher

    TheGarnisher Private E-2

    Thanks again for all your help. You rock.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds