My computer is infected...

Discussion in 'Malware Help (A Specialist Will Reply)' started by sighlentex, Jul 17, 2007.

  1. sighlentex

    sighlentex Private E-2

    It's been quite a long time since I've had to do this...but I have managed to catch a nasty bug. After two days of dealing with it...I'm too tired to try and figure it out myself...so I've run all of the scans and things that were requested and will attach the logs that were requested.

    Thanks in advance for your help.
     

    Attached Files:

  2. sighlentex

    sighlentex Private E-2

    ...the rest of the logs.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well actually you caught a bunch of problems! Let's begin with the below which should make a dent in some of the problems. Then we will move on to manually cleaning steps.

    First go back to step 2 of the READ ME and complete the instructions in that step properly.


    Now let's remove some issues with the below steps.
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now uninstall the below old versions of software as requested in step 6 of the READ ME. These old versions left you susceptible to the Virtumonde infection you picked up:
    J2SE Runtime Environment 5.0 Update 3
    Java(TM) SE Runtime Environment 6 Update 1

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!
     
  4. sighlentex

    sighlentex Private E-2

    Thanks for your help, Chaslang. If me not having any popups is any indication of whether or not my computer is fixed, then everything seems to be great. ..attatching logs.
     

    Attached Files:

  5. sighlentex

    sighlentex Private E-2

    ..and the HJT log.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that''s a good start! ;)

    You need to go back to step 2 of the READ ME and uncheck the option that says to hide extensions for known file types. This was why you have analyese.exe.exe (two extensions) instead of analyse.exe Also you will not be able to find a file I will list below unless you do this.

    Do you know what the below folder is for?
    Code:
    "C:\Program Files\Internet Explorer\"
    labupu~1 Jul 16 2007 246 "labupufo38"
    Did you copy MSconfig from another OS to this PC?
    Code:
    "C:\WINNT\system32\"
    msconfig.exe  Jul  7 2007      158208  "msconfig.exe"
    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {23B4EAC5-C05E-4401-BA4A-D9F6250D0EDF} - C:\Program Files\Cmak\hopeve83122.dll (file missing)
    O2 - BHO: (no name) - {361D6CF6-DF6D-DDBC-1A10-FC8DBC258ECD} - C:\WINNT\system32\ftwdjcu.dll (file missing)
    O2 - BHO: 0 - {B40132A5-32CF-405B-B5A2-1204CDD45E39} - C:\Program Files\Internet Explorer\labupufo38.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINNT\wulgm0578.exe

    Now run Ccleaner

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     
  7. sighlentex

    sighlentex Private E-2

    No, I don't know what it is. Should I delete it?

    Not that I know of...?


    ...and followed all your directions...here are the newest logs.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes delete the C:\Program Files\Internet Explorer\labupufo38 folder and also delete the C:\WINNT\system32\msconfig.exe file since you did not copy it there and it is a recent addition (from July 7th).

    After deleting the above you will be clean!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds