Many viruses and spyware?

Discussion in 'Malware Help (A Specialist Will Reply)' started by mlmorg, Jan 17, 2007.

  1. mlmorg

    mlmorg Private E-2

    Hi,
    My dad seems to have an infected computer. In the bottom right hand corner a popup keeps appearing about the networm.i.virus. IE explorer does not open anymore, he double clicks and it just flashes and goes away very quickly. This has made it hard for me to get him antivirus programs but NIS is on the computer and we first checked with that. Then we used Adaware SE , then tried Spyware Doctor which was unable to start. There were many infections found, about 70 so they are all gone but the popups keep happening he says. On the Hijack This log I found things that looked bad like isamonitor.exe, pmsngr.exe, pmmon.exe, isamini.exe, isaddon.exe, uwasdc.exe, and gwquvw.dll is missing. He tells me that he is constantly getting popups etc. saying to use WinAntispyware because he has things like networm.i.virus and Trojan-Spy.Win32@mx. He hasn't clicked on any of the popups but doesn't understand how he got this since he uses NIS. It takes a while to fix it because I have to get him to get on Trillian and then I send the downloaded programs (since IE doesnt work!). So any help would be greatly appreciated. Thanks! Matt


    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.
     
    Last edited by a moderator: Jan 17, 2007
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.


    How are things working now?
    If you are still having problems at this point (and it would be a good idea to do them anyway) continue on to the below instructions.


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. mlmorg

    mlmorg Private E-2

    Ok so he has done step one. Here is the rapport.txt file. He will do Step 2 soon but is busy for a little while so may take an hour or so to reply...bear with us! Thanks for the help so far! Greatly appreciated! Matt

    If there's anything I should know before doing Step Two then tell me. Thanks again. Here's the log:

    SmitFraudFix v2.132

    Scan done at 15:07:08.08, Wed 01/17/2007
    Run from C:\Documents and Settings\Philip Morgan\Desktop\SmitfraudFix\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
    The filesystem type is NTFS
    Fix run in normal mode

    »»»»»»»»»»»»»»»»»»»»»»»» C:\


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Philip Morgan


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Philip Morgan\Application Data


    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

    C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND !
    C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\PHILIP~1\FAVORI~1

    C:\DOCUME~1\PHILIP~1\FAVORI~1\Online Security Test.url FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» Desktop

    C:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url FOUND !
    C:\DOCUME~1\ALLUSE~1\Desktop\Security Troubleshooting.url FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

    C:\Program Files\Video ActiveX Object\ FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="About:Home"
    "SubscribedURL"="About:Home"
    "FriendlyName"="My Current Home Page"


    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{8d8c2387-7f80-4022-9be6-43630a969558}"="carbinyl"

    [HKEY_CLASSES_ROOT\CLSID\{8d8c2387-7f80-4022-9be6-43630a969558}\InProcServer32]
    @="C:\WINDOWS\system32\gwquvw.dll"

    [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8d8c2387-7f80-4022-9be6-43630a969558}\InProcServer32]
    @="C:\WINDOWS\system32\gwquvw.dll"



    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=""


    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "System"=""


    »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


    »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


    »»»»»»»»»»»»»»»»»»»»»»»» End
     
  4. mlmorg

    mlmorg Private E-2

    Here's the new rapport.txt log file: He said IE is now working! and everything seems fine. Should he still try and go through the sticky message on what else to do? Thanks for all the help! Matt

    <div class="moz-text-flowed" style="font-family: -moz-fixed">SmitFraudFix v2.132

    Scan done at 17:00:23.76, Wed 01/17/2007
    Run from C:\Documents and Settings\Philip Morgan\Desktop\SmitfraudFix\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
    The filesystem type is NTFS
    Fix run in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{8d8c2387-7f80-4022-9be6-43630a969558}"="carbinyl"

    [HKEY_CLASSES_ROOT\CLSID\{8d8c2387-7f80-4022-9be6-43630a969558}\InProcServer32]
    @="C:\WINDOWS\system32\gwquvw.dll"

    [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8d8c2387-7f80-4022-9be6-43630a969558}\InProcServer32]
    @="C:\WINDOWS\system32\gwquvw.dll"


    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

    C:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url Deleted
    C:\DOCUME~1\ALLUSE~1\Desktop\Security Troubleshooting.url Deleted
    C:\DOCUME~1\PHILIP~1\FAVORI~1\Online Security Test.url Deleted
    C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
    C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted
    C:\Program Files\Video ActiveX Object\ Deleted

    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "System"=""


    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

    Registry Cleaning done.

    »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{8d8c2387-7f80-4022-9be6-43630a969558}"="carbinyl"

    [HKEY_CLASSES_ROOT\CLSID\{8d8c2387-7f80-4022-9be6-43630a969558}\InProcServer32]
    @="C:\WINDOWS\system32\gwquvw.dll"

    [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8d8c2387-7f80-4022-9be6-43630a969558}\InProcServer32]
    @="C:\WINDOWS\system32\gwquvw.dll"



    »»»»»»»»»»»»»»»»»»»»»»»» End

    </div>
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must remember to attach logs. Attach is the key word! Notice I did not say post logs. This is all covered in the sticky thread procedures that you should have read before posting. For future reference, see: HOW TO: Attach Items To Your Post

    Yes you should run the other procedure. The type problems you had often come with other hidden problems.
     
  6. mlmorg

    mlmorg Private E-2

    Ok I will tell him to do those. Sorry about the HJT log and the posted rapport logs...I am new here and did not fully read your stickies as you noticed...I am very very sorry. I will *attach* the new logs from all the programs suggested and from HJT once he has been able to do all that...which may take a while as he's a little computer illiterate and I am away at school. Thankyou very much for your quick and wonderful replies. Again sorry for the bad posting. Matt
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! Yes it does take a while to run all the scans and get the logs attached, but it is worth it in the long run to know your computer is clean and secure.

    Just attach the logs whenever finished.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds