Need help getting rid of Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by frantikfran, Feb 13, 2006.

  1. frantikfran

    frantikfran Private E-2

    I have read and followed the Read and Run Me First thread. Everything I have run has found things, fixed things and left things. Too many things to list. I started with 208 bad things. I am sure there are fewer things now, but I want there to be NO things and I don't want them to come back. This happened a month ago and a "professional" removed them for me, but I don't think he really got them and now "they're back".

    Amongst the 208 things, I did see references to Qoologic, SurfsideKick and Smitfraud and Hacktool.rootkit and Hacktool.HideWindow and msdirectx.sys.

    I ran the special procedures for Qoologic and SurfsideKick. I could never get the RunThis.bat to run on the Smitfraud special procedure thread. Lastly, I ran Hijack This.

    I am attaching the quoologic log, the rkfiles log, the WinPFind log, the BitScan log, the Panda Active Scan Log and the Hijack This log.

    Can you please take a look at these and see what I need to do to get rid of these bad things once and for all?
     

    Attached Files:

  2. frantikfran

    frantikfran Private E-2

    I reach the maximum number of uploads in the last message, so now I am sending the RKFiles log and the WinPf logs.
     

    Attached Files:

    Last edited: Feb 13, 2006
  3. frantikfran

    frantikfran Private E-2

    By the way, please tell me when I am supposed to turn off the System Restore. The directions are confusing. Don't turn it off until you are clean. But, I'm not ever clean, so I don't have it off. Should I?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First empty your Recycle Bin and Norton Quarantine folders.

    You have a few nasty problems.

    Let's try to use Spy Sweeper to fix some of them for us. Run the steps in the below link and attach the spysweeper.txt log.

    Running Spy Sweeper

    Then also attach a new HJT log.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Leave system restore alone for now. We will tell you when you are clean and should toggle it.
     
  6. frantikfran

    frantikfran Private E-2

    OK. I've run Spy Sweeper and Hijack This again and the new log files are attached.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Spy Sweeper fixed a ton of problems already but we still have more to do.
    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    O2 - BHO: (no name) - {AC9F1944-A70F-5A4C-D7F0-E71B10C19AFA} - C:\WINDOWS\Phjlcnab.dll
    O3 - Toolbar: Search - {940BE922-41A6-5563-FCBB-3E5E2337B64E} - C:\WINDOWS\Phjlcnab.dll
    O4 - HKLM\..\Run: [fresxstyle] lockbar.exe
    O4 - HKLM\..\Run: [LonPS2] c:\windows\system32\repcale.exe c:\windows\system32\palsp.exe
    O4 - HKLM\..\Run: [Task manager] taskmgr.exe
    O4 - HKLM\..\Run: [Pomggi] C:\Program Files\Wsvop\Azkv.exe
    O4 - HKLM\..\Run: [Network] C:\Program Files\Network\network.exe
    O4 - HKLM\..\Run: [freexstyle] lockbr.exe
    O4 - HKLM\..\RunServices: [fresxstyle] lockbar.exe
    O4 - HKLM\..\RunServices: [Task manager] taskmgr.exe
    O4 - HKLM\..\RunServices: [freexstyle] lockbr.exe
    O4 - HKCU\..\Run: [freexstyle] lockbr.exe
    O4 - HKCU\..\Run: [fresxstyle] lockbar.exe
    O18 - Filter: text/html - (no CLSID) - (no file)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Wsvop <--- the whole Wsvop folder
    C:\Program Files\Network <--- the whole Network folder
    C:\WINDOWS\Phjlcnab.dll
    C:\WINDOWS\system32\lockbar.exe
    C:\WINDOWS\system32\lockbr.exe
    c:\windows\system32\palsp.exe
    c:\windows\system32\repcale.exe
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    I also want to search your system for a couple of files. Just search don't do anything else. But first you must configure Windows XP Search properly as below:

    Click Search and the Select "All files and folders"
    Enter the msdirect in the "All or part of the file name:" box
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    • Search system folders
    • Search hidden files and folders
    • Search subfolders
    Then click the Search button.


    Now do another search but this time for: taskmgr.exe

    Tell where (if any) matches are found for both files.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. frantikfran

    frantikfran Private E-2

    Okay. I followed all the instructions.

    I could not find the files: C\WINDOWS\system32\lockbar.exe or C:\WINDOWS\system32\lockbr.exe or C:\WINDOWS\system32\repcale.exe so I could not delete them.

    I am attaching the new HJT log.

    In searching for the two files, there were no matches for the msdirect, but there were several matches for taskmgr.exe. There was taskmgr.exe found in C:\WINDOWS\system32, as well as a taskmgr.exe.tmp in the same location. There was also a taskmgr.exe in C:\WINDOWS\system32\dllcache and a taskmgr.exe in C:\WINDOWS\Software Distribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819.

    Its hard to tell how things are working because I haven't really done anything, but nothing has popped up yet.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please tell me the file sizes & dates for each of the taskmgr files you found (including the taskmgr.exe.tmp file too).
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you miss fixing the below in HijackThis?


    O4 - HKLM\..\Run: [fresxstyle] lockbar.exe
    O4 - HKLM\..\Run: [LonPS2] c:\windows\system32\repcale.exe c:\windows\system32\palsp.exe
    O4 - HKLM\..\Run: [Task manager] taskmgr.exe
    O4 - HKLM\..\Run: [Pomggi] C:\Program Files\Wsvop\Azkv.exe
    O4 - HKLM\..\Run: [Network] C:\Program Files\Network\network.exe
    O4 - HKLM\..\Run: [freexstyle] lockbr.exe
    O4 - HKLM\..\RunServices: [fresxstyle] lockbar.exe
    O4 - HKLM\..\RunServices: [Task manager] taskmgr.exe
    O4 - HKLM\..\RunServices: [freexstyle] lockbr.exe

    If you did fix them, try again. If they still remain. Either disable all of SpySweeper and MS Antispyware or uninstall them. Then fix those lines again and then attach a new HJT log.

    Your system should be noticeably better already.
     
  11. frantikfran

    frantikfran Private E-2

    The taskmgr.exe found in C:\WINDOWS\system32 was 126 kb dated 7/16/2003. The taskmgr.exe.tmp, found in the same location was 114 kb and had the same date. The taskmgr.exe in C:\WINDOWS\system32\dllcache was 126 kb and had the same 7/16/2003 date. The taskmgr.exe in C:\WINDOWS\Software Distribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819 was 133 kb and was dated 8/4/2004.
     
  12. frantikfran

    frantikfran Private E-2

    I did fix them, so I went in and fixed them again and they seem to be gone. Check out the hjt log I am attaching. Anything more on the taskmgr stuff. I provided you with file sizes and dates in last post. Let me know what else I need to do.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay your log is clean!

    As far as the taskmgr files go, the 126 k one is the correct size for your OS. Delete the taskmgr.exe.tmp file. The one that is 133 k is probably for SP2. Why aren't you running SP2 if you download the distribution files? Did you download SP2 but never install it?

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  14. frantikfran

    frantikfran Private E-2

    I don't know why I am not running SP2. This is my son's computer, one of 4 computers in the house. I thought I updated everyone's, but it is possible that I started working on his and got distracted by virus problems. I just can't remember. But, I am guessing that part of the reason he is having so many problems is that I failed to install SP2.

    So, is the taskmgr tmp file the only one of the taskmgr files that I should delete?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!

    When you start working on the How to protect link, you will see that the first step is Windows Update. Doing that should get up to SP2 level.
     
  16. frantikfran

    frantikfran Private E-2

    I just wanted to thank you for your help. I seem to be virus free and I've updated successfully to SP2. Thanks!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds