My Thread

Discussion in 'Malware Help (A Specialist Will Reply)' started by AllThrtl, Jul 23, 2010.

  1. AllThrtl

    AllThrtl Private E-2

    This laptop doesn't get used much, but last week I noticed it was very slow, homepage was hijacked, took forever to boot, all the usual stuff. I ran thru all the "read me first" and xp cleanup proceedures and everything seemed to be back to normal speed and working fine. Then a couple days ago it started acting up again, this time it won't let you go to any websites, it won't let you start certain programs, won't let system restore start. So once again I followed the same cleanup proceedures. However, on boot up I get an error that the system can't find zyagp.dll and I get an error when trying to run ComboFix "The NTVDM CPU has encountered an illegal instruction at ...." I may have had the same problem with Combofix the first time around, but I'm not sure because I had someone else running thru the clean up procedures for me.... I'm just not sure... Sooo, now, outside of the error message on startup, the system seems to run fine but I cannot go to any wesite other than my homepage. When I start internet explorer, the homepage comes up and I can navigate around within that site just fine, but if I attempt to follow a link to another site, or if I type another site into the navigation bar it cannot display the page. And, if I try to navigate away from the homepage then type in my homepage to go back, it won't pull up. I can only go back to my homepage if I click on the homepage icon on the toolbar...weird.

    Here are my log files, except Combofix, which won't run.... Thanks
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Whilst I review your logs I want you to do the following:


    Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.


    Next I would like for you to rename combofix to kestrel.com, reboot into safemode after ensuring combofix is indeed directly on your desktop, and attempt to run it again. Reboot back into normal mode...

    Attach the cf log if you are successful and also the new log from sas.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    As I said complete the sas update and try and get combofix run if you can. I have a fix ready to post that I have been working on, and I shall be back later on this evening to post again. :) Hang in there.
     
  4. AllThrtl

    AllThrtl Private E-2

    Ok, thanks... SAS is scanning now, I'll post up the logs once complete...
     
  5. AllThrtl

    AllThrtl Private E-2

    Ok, scanned with new SAS, log is attached. Combofix still wouldn't run in safe mode with the name changed. A cmd window will flash for a split second, but then nothing else happens....
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay let's start the fix then. :)

    What exactly are you using for anti virus at the moment??

    Do you know what these files relate to? They are sitting inside the C:\Windows folder.
    Without clicking on any of the contents of the following emboldened directory, please let me know what's in there.

    What does this relate to?

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program

    If you did not deliberately set this proxy yourself then please include it in the HJT fix below:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\WINDOWS\System32\zyagp.dll
    C:\WINDOWS\ovutehobekey.dll
    C:\WINDOWS\sinapap.dll
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\kkwpgpxiy\gphxsiutssd.exe 
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\uueijvpem\ytfnsxdtssd.exe 
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\ygefdwnaq\wyvgnrhtssd.exe 
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\bdjanlnst\nocsfbptssd.exe
    C:\WINDOWS\ajaxozoquqisef.dll
    C:\WINDOWS\anopicericoxepod.dll
    C:\WINDOWS\arimuraranawi.dll
    C:\WINDOWS\emoteroq.dll
    C:\WINDOWS\Fqekanite.dat
    C:\WINDOWS\idugisohunirumec.dll
    C:\WINDOWS\ifededuvaka.dll
    C:\WINDOWS\ifepezupewada.dll
    C:\WINDOWS\iqokonej.dll
    C:\WINDOWS\odohuhon.dll
    C:\WINDOWS\omudutod.dll
    C:\WINDOWS\Onajoxajijohapu.bin
    C:\WINDOWS\system32\drivers\ixjbdeh.sys
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\kkwpgpxiy
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\ygefdwnaq
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\bdjanlnst
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\uueijvpem
    C:\Documents and Settings\Administrator\Local Settings\Application Data\kpohmhanl
    C:\Documents and Settings\Administrator\Local Settings\Application Data\tdjbmriqe
    C:\Documents and Settings\Administrator\Local Settings\Application Data\vyaosvlyh
    C:\Documents and Settings\Administrator\Local Settings\Application Data\xbwqhocxy
    C:\Documents and Settings\Administrator\Local Settings\Application Data\xgyiguxnj
    
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Vceduzeqiji"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "sta"=-
    "Qsino"=-
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "cowwelqu"=-
    "eixpvqfj"=-
    "pparrlqq"=-
    "mvqgpkct"=-
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    Now run Ccleaner!

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this, also include the log from OTM.

    Also you MUST address any questions that I may have asked!

    Let me know how things are running now, that should have smoothed it out for you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds