Multiple Infections :-(

Discussion in 'Malware Help (A Specialist Will Reply)' started by LdyJne114, Jul 2, 2006.

  1. LdyJne114

    LdyJne114 Private E-2

    It's been a bad day.

    Followed all your instructions in the sticky, and the logs are attached. I don't know what they say, of course, but McAfee is still telling me there are multiple infections of files that are write protected and I can neither delete, clean, nor quarantine them.

    Please help :(

    Do let me know if you need further information.

    Updated to add: One of the symptoms is my home page being redirected to www[dot]sysprotectpage[dot]com.
     

    Attached Files:

    Last edited: Jul 2, 2006
  2. LdyJne114

    LdyJne114 Private E-2

    Sorry, make that www[dot]sysprotectionpage[dot]com. Won't let me edit my post a secind time for some reason.
     
  3. LdyJne114

    LdyJne114 Private E-2

    Anyone? Please?

    Holiday weekend.....bad time to have problems :(
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    You will need to install and run Hijackthis again as this was not the location mentioned in the read guide that it should be installed in?

    C:\Documents and Settings\Tracey\Desktop\Cleanup Info\Hijack This\HijackThis.exe


    should have been C:\Program Files\HJT , it may seem a nit picky thing but is crucial in the removal of your malware.


    Downloading, Installing, and Running HijackThis
     
  5. LdyJne114

    LdyJne114 Private E-2

    Sorry. Too many scans + 2 am = no longer paying attention

    Enclosed...hope this is better.
     

    Attached Files:

  6. LdyJne114

    LdyJne114 Private E-2

    Hmm...I posted this yesterday, saw it posted and yet now it's not there.

    Anyway - here's the log. Again. Sorry.

    *sigh* never mind. After I posted this, then my other post showed up. I think anyway :(
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have about 4 or 5 different infections that we need to remove. Let's start with your SpywareQuake problem that I can see.

    Run the steps in the below and attach the requested smitfiles.txt log.

    SpywareQuake & SpyFalcon Removal Procedure


    Now let's move on to your Winlogonhook (aka Conhook) problem and a few others.

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winetn32.dll once and then click the kill button. After you have killed all of the winetn32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of winetn32.dll and kill it. (If you do not find the dll, just continue on.)

    No look in the ProcessExplorer window for netdde.exe and if found right click on it and select Kill Process.

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {062492AF-392E-479D-BF52-A7A4BCA00307} - C:\WINDOWS\g7959609.dll
    O2 - BHO: (no name) - {5f4c3d09-b3b9-4f88-aa82-31332fee1c08} - C:\WINDOWS\system32\hp100.tmp
    O4 - HKCU\..\Run: [Pxvxnngi] C:\WINDOWS\system32\SEMBLY~1\netdde.exe
    O4 - HKCU\..\Run: [Microsoft Works Update Detection] ???\WkDetect.exe
    O20 - AppInit_DLLs: C:\WINDOWS\system32\msconfig.dll
    O20 - Winlogon Notify: winetn32 - C:\WINDOWS\SYSTEM32\winetn32.dll


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    cd c:\windows\temp

    Now make sure the prompt (what you see at the beginning of each line in the command prompt window) shows that you are in the C:\windows\tempfolder. Then continue.

    del win*.*
    exit

    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.
    C:\Documents and Settings\Tracey\Favorites\Antivirus Test Online.url
    C:\Documents and Settings\Tracey\Local Settings\Temporary Internet Files\Content.IE5\01EXGZOV\srvoys[1].exe
    C:\Documents and Settings\Tracey\Local Settings\Temporary Internet Files\Content.IE5\YHIVK3MH\bgates[1].exe
    C:\WINDOWS\system32\SEMBLY~1\netdde.exe
    C:\WINDOWS\g7959609.dll
    C:\WINDOWS\system32\msconfig.dll
    C:\WINDOWS\SYSTEM32\winetn32.dll



    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now attach a new HJT log and tell me how the steps went.
    Make sure you tell me how things are working now!

    You will have to use another message to contibue with the below because only 3 attachments can be added to a single message.

    Now run the below procedure and attach the runkeys.txt log.
    Also run the below procedure and attach the newfiles.txt log.
     
  8. LdyJne114

    LdyJne114 Private E-2

    Ok, I did the first part (SpywareQuake) and was unable to delete the following files in the Temp folder:

    JET8812.tmp
    ~PFF392.tmp

    Also, in the files you asked me to delete, I found VERY few...I hope that's good. I was only able to find and delete:

    cfgmngr32.dll
    dcomcfg.exe

    There were others that were close (i.e. I did not find stdole3.tlb but had stdole.tlb, stdole2.tlb and stdole32.tlb. I did NOT delete these.

    Not sure what this was supposed to fix however, my homepage is no longer being hijacked, so I hope that was it. My log is enclosed. Continuing on with the other steps now.
     

    Attached Files:

  9. LdyJne114

    LdyJne114 Private E-2

    Here are the other three files. I hope I remembered to attach everything.

    Please note I had some errors....will upload jpegs in my next post.
     

    Attached Files:

  10. LdyJne114

    LdyJne114 Private E-2

    Various errors received during the process. Sorry, one is cut off but you can get the gist of it.
     

    Attached Files:

  11. LdyJne114

    LdyJne114 Private E-2

    BTW...other than the errors I posted above, at this time, all seems well. I am no longer getting McAfee warnings, nor am I seeing any popups. Homepage is still ok.
     
  12. LdyJne114

    LdyJne114 Private E-2

    I'm somewhat confused here. I just ran a scan just to see what was done and not done and it found what you see in the screen shot. Are these false positives....?

    The last screenshot is the error I am now receiving when I try to view jpeg files, which I was not getting before all this.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to be very careful when you are following directions. The above two files are what the SpywareQuake does request that you delete. However for at least one of them, you did not delete the correct file. You deleted cfgmgr32.dll which is a required system file and it is the reason you have one of the error messages that you posted a snapshot of. You will need to replace this file. You can first look in C:\WINDOWS\SYSTEM32\DLLCACHE for a copy of cfgmgr32.dll and then make a copy of it in your system32 folder.

    Are you sure you actually found and deleted dcomcfg.exe or did you delete dcomcnfg.exe which is a required file for Windows. Look in c:\windows\system32 for dcomcnfg.exe and tell me if you can find it. If not, you deleted the wrong file. You can also copy this file from the DLLCACHE folder back into the system32 folder.

    Let me know if you get the above two files restored okay. And also it should help with your error messages.

    Please stop running scans that I did not request. You are only wasting your time looking at things that are not problems. The file in the !Killbox folder is just a backup from what we fixed using PocketKillbox. The other file is in the HijackThis backup folder. These are like Quarantine folders that antivirus and antispyware programs use so you can restore from if removing a file causes you problems.

    Now that we are close to being finished you can delete the !Killbox folder and you can remove the files in the HijackThis backup folder too.

    It was supposed to fix exactly what the procedure said, SpywareQuake and SpyFalcon. And that is what it did!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have a few problems remaining.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O20 - AppInit_DLLs: msconfig.dll
    O20 - Winlogon Notify: winetn32 - winetn32.dll (file missing)

    IGNORE the error message from HijackThis about the AppInit_DLLs line. Just click OK. Then exit HijackThis and immediately reboot into safe mode.

    In safe mode run Windows Explorer and look for the below file names (EXACT MATCHES ONLY) and delete them. Keep track of what you find and do not find and tell me later. Also tell me whether you could or could not delete the files.
    C:\WINDOWS\g6639578.dll
    C:\WINDOWS\SYSTEM32\msconfig.dll
    C:\WINDOWS\SYSTEM32\winetn32.dll
    C:\WINDOWS\SYSTEM32\rqrsttr.dll

    Now reboot in normal mode and get a new ShowNew log (newfiles.txt) and a new HJT log and attach them. Tell me the results of the above.
     
  15. LdyJne114

    LdyJne114 Private E-2

    You will need to replace this file. You can first look in C:\WINDOWS\SYSTEM32\DLLCACHE for a copy of cfgmgr32.dll and then make a copy of it in your system32 folder.

    So in a nutshell, I'm a moron (It's ok, you can say it!)

    I cannot find a copy of cfgmgr32.dll.

    Are you sure you actually found and deleted dcomcfg.exe or did you delete dcomcnfg.exe which is a required file for Windows. Look in c:\windows\system32 for dcomcnfg.exe and tell me if you can find it. If not, you deleted the wrong file. You can also copy this file from the DLLCACHE folder back into the system32 folder.

    dcomcnfg.exe is still in my system32 folder, so I did not delete that file.


    Now that we are close to being finished you can delete the !Killbox folder and you can remove the files in the HijackThis backup folder too.

    Will do.
     
  16. LdyJne114

    LdyJne114 Private E-2

    Let's hope I didn't screw anything else up :rolleyes:

    C:\WINDOWS\g6639578.dll - Deleted
    C:\WINDOWS\SYSTEM32\msconfig.dll - Did not find
    C:\WINDOWS\SYSTEM32\winetn32.dll - - Did not find
    C:\WINDOWS\SYSTEM32\rqrsttr.dll - Deleted

    Logs enclosed.

    Thanks :)
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do a Windows Search for another copy of the file. But search for cfgmgr32.* not cfgmgr32.dll

    Tell me what you find. I guessing you may find cfgmgr32.dl_ in a folder named i386. This would be a compressed for of the cfgmgr32.dll file.

    If you do not find one on your hard disk, you can get one from the i386 folder of your WinXP CD or you can download one from: http://www.dll-files.com/dllindex/dll-files.shtml?cfgmgr32

    How is everything working now?
     
  18. LdyJne114

    LdyJne114 Private E-2

    Found it, pasted it, rebooted and all is well. No errors, no popups, no hijacks. I'm a happy girl.

    Thank you VERY much for your help :D
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good job! ;)

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  20. LdyJne114

    LdyJne114 Private E-2

    Will do - thanks!
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds