My PC is infected with malware and viruses...Please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by MATRIXX003, Nov 17, 2007.

  1. MATRIXX003

    MATRIXX003 Private E-2

    I have followed and completed the Read me first malware removal guide. I have a windows xp pc and was infected after a download. (Believe me ive learned my lesson) I will attach the logs in two sepearate posts. I ran AVG Antispyware instead of counterspy.
     

    Attached Files:

  2. MATRIXX003

    MATRIXX003 Private E-2

    Please Help...Pc is loaded with malware and viruses

    I have followed and completed the Read me first malware removal guide. I have a windows xp pc and was infected after a download. (Believe me ive learned my lesson) I will attach the logs in two sepearate posts. I ran AVG Antispyware instead of counterspy.
     

    Attached Files:

  3. MATRIXX003

    MATRIXX003 Private E-2

    Re: Please Help...Pc is loaded with malware and viruses

    I am getting a error trying to upload the next set of logs. Its telling me I already uploaded to another post??
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi Merged them all for you.
     
  5. MATRIXX003

    MATRIXX003 Private E-2

    Thank you so much Halo. I cant attach the bdscan file because its 1.41MB which is over the limit.
     
  6. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Try zipping it up and see if that creates it under the limit.
     
  7. MATRIXX003

    MATRIXX003 Private E-2

    Great idea, thanks again Halo.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmmmm! Too many infected torrent or P2P download being saved based on your log. You said "a download". There was a hect of a lot more than a download. You should stop this practice which is more than likely the root cause of all of your infections and there are a lot!!! As you will see in the length of this fix.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 3
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\tmrsr.exe,C:\WINDOWS\system32\userinit.exe
    O2 - BHO: (no name) - { - (no file)
    O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
    O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
    O2 - BHO: (no name) - {01CD0B31-9154-45F2-9414-F5D64B74EAF6} - C:\WINDOWS\system32\mljhhfd.dll (file missing)
    O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
    O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
    O2 - BHO: (no name) - {0C7C83F6-7ED0-4050-BA53-FD6671EB6739} - (no file)
    O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
    O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
    O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
    O2 - BHO: (no name) - {39B812A4-BFF8-4968-8E67-F5BDC39808B5} - (no file)
    O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)
    O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
    O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
    O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
    O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
    O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
    O2 - BHO: (no name) - {73BA4E12-6B47-486E-92D8-6DC2B2456BAA} - C:\WINDOWS\system32\awtsq.dll
    O2 - BHO: (no name) - {7acda0ab-a9da-48ab-b9bb-3d077452fd51} - C:\WINDOWS\system32\xtmptgpa.dll
    O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
    O2 - BHO: (no name) - {978D635A-FA13-460A-B69E-9C99195AC367} - (no file)
    O2 - BHO: (no name) - {9EAA1B77-FE08-4BA7-B175-D1C57B1F3290} - (no file)
    O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
    O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\aptvftfj.dll (file missing)
    O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
    O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file)
    O2 - BHO: (no name) - {BBA439BA-4774-4BE7-8638-81AB8B7448B2} - (no file)
    O2 - BHO: aivskurq.msdn_hlp - {BF442538-BE32-4055-A549-2F3B699F55EB} - C:\WINDOWS\system32\aivskurq.dll
    O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
    O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
    O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
    O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
    O2 - BHO: {a035c4da-6ad8-1fe9-c014-d20b81485e1d} - {d1e58418-b02d-410c-9ef1-8da6ad4c530a} - C:\WINDOWS\system32\nxcoohjl.dll
    O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
    O2 - BHO: (no name) - {E7DCC722-87CC-41E4-B567-5E951B16068C} - C:\Program Files\Windows Media Player\ryzyf555077.dll
    O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
    O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
    O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)
    O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\aptvftfj.dll (file missing)
    O4 - HKLM\..\Run: [20fbe4bd] rundll32.exe "C:\WINDOWS\system32\ptsgyacq.dll",b
    O20 - Winlogon Notify: aptvftfj - aptvftfj.dll (file missing)
    O20 - Winlogon Notify: mljhhfd - mljhhfd.dll (file missing)
    O20 - Winlogon Notify: winwim32 - C:\WINDOWS\SYSTEM32\winwim32.dll
    O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\nquacybj.exe (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Download this file - combofix.exe
    1. Double click combofix.exe & follow the prompts.
    2. When finished, it will produce a log ( C:\combofix.txt ) for you. Attach this log to your next reply See: HOW TO: Attach Items To Your Post
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. ComboFix
    3. GetRunKey
    4. ShowNew
    5. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  9. MATRIXX003

    MATRIXX003 Private E-2

    Hey Chaslang...I realize now how badly infected this pc was. There are multiple users so im going to try and change how they use this comp. Also to mention the almost non-existent anti-virus software on here which im going to change once we clean this up. I followed the procedure you posted which seemed to do what it had to. I am going to attach the new logs. As far as the computer it seems a little better than before but I still get a ton of pop ups, overall slow performance, icons still highlighted and one of the other user names still has the black wallpaper which says "Warning Spyware threat has been detected on your PC.
     

    Attached Files:

  10. MATRIXX003

    MATRIXX003 Private E-2

    Last two...Thank you again for getting me this far.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run ComboFix before running Avenger??? Based on your logs it looks like it. You must remember to always run steps in the order written and only run one scanner/tool at a time.

    You said something about not having an antivirus. You had McAfee installed.

    Note: Every user account has to be cleaned separately. Thus if other accounts are having problems, you will need to clean them after this first account has been totally cleaned.


    I'm look thru your logs now.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    On further look, I wonder if when you did the Avenger fix that you did not copy the WHOLE quote box. You may have skipped the top line which says Files to delete:

    Is that what you did???

    Re run the Avneger fix now and then attach the new Avenger log and then new logs from HJT and ShowNew.

    Did you do the fixME.reg patch? Did it say it was successful? Try it again and check.
     
  13. MATRIXX003

    MATRIXX003 Private E-2

    I ran Avenger first then Combofix. I followed the read me first procedure and the steps below in the order you specified right down to the T. I may have missed the files to delete part. Im attaching the new avenger, HJT and shownew logs. And yes the fixme.reg was successful the first time.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that looks better! You did miss the Files to delete part the first time. Some new stuff found its way onto your PC. Thus we have another iteration to perform. I'll post another fix in a few minutes.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you recognize the below folder?
    Code:
    C:\Program Files\
    AKL(2)        Nov 10 2007              "akl(2)"[
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you forget to run the below?


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {1A00A28B-D791-4D35-AFC7-37AD23638B1a} - (no file)
    O2 - BHO: (no name) - {32CE0D1B-3B8E-46C3-B82F-E2AA3D137CBE} - C:\WINDOWS\system32\pmkjj.dll (file missing)
    O2 - BHO: (no name) - {E12BFF69-38A7-406e-A8EF-2738107A7831} - C:\WINDOWS\system32\ayqyqapp.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    After clicking Fix, exit HJT.

    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run ATF-Cleaner again like last time!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!
     
  17. MATRIXX003

    MATRIXX003 Private E-2

    I dont recognize that folder. Nov 10 is when everything started so im gonna say its bogus. I didnt forget to disable/remove windows messenger, I removed it from the add/remove programs in control panel prior. I just performed the exe program from the link anyway and uninstalled it there. I dont see any of those 5 entries when I run a system scan in HJT. I ran avenger and ATF cleaner again. I did notice my icons are normal now and the pop ups seemed to have stopped. I cant believe my comp is back. Here are the logs. Again no HJT because I didnt see the entries.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  19. MATRIXX003

    MATRIXX003 Private E-2

    I will check to make sure everything is back to normal one last time and perform the final steps tonight. Also I will follow the How to protect against malware document. I cant thank you enough Chaslang!!!!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds