Need help with removal of Pipas.A

Discussion in 'Malware Help (A Specialist Will Reply)' started by Bill44, Aug 29, 2006.

  1. Bill44

    Bill44 Private E-2

    Greetings,
    I have completed the steps(at least I think I have) as outlined in the Read and Run me first before asking for support.
    I am attaching the Bitdefender and the Panda Scan .txt files as well as the HJT scan file.
    I was not able to boot up in the safe mode. My computer seemed to try and boot up in the safe mode, but it just stopped and left me with a black screen with small type "safe mode" in all four corners. I tried this six or seven times and gave it over 15 min. to load -- no luck.
    The online scans seemed to work OK and the only program that found anything (other than Panda and Bitdefender) was the Spybot. It looks like it is fixing the problem, but when I fix the problem and reboot it returns.
    I hope I have done all I am supposed to do before posting as I really don't want to waste your time.

    Please be kind -- I am a newbie to the Malware problems.

    Thanks for any help and best regards,
    Bill
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi Bill, Welcome to Majorgeeks, your not wasting anyones time, so dont worry about that, we or more so the malware experts here will go at your speed and try to help you through this with easy instructions as they are very good at that,

    But do you also have the



    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat

    logs from section #4 of the guide, they will want to see what items they show up.
     
  3. Bill44

    Bill44 Private E-2

    Thanks for the warm welcome. I did run both of those applications and just forgot to attach the .txt files. I remember reading that only three files at a time, but forgot to send a second reply.
    thanks,
    Bill
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run MSconfig and select Normal Startup as requested in step 7 of the READ ME.

    Now run this WareOut Removal and attach the requested log.

    Then also attach new logs from HJT and GetRunKey.
     
  5. Bill44

    Bill44 Private E-2

    Hi Chaslang,
    I did have the MSConfig pointed to start up in normal. I reset to normal and hit apply and restarted. I hope I did the rest of what you asked correctly. The HJT, getrunkey and wareout logs are attached.
    Thanks,
    Bill
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not according to your previous GetRunKey log. It showed the below:
    But now you have it correct because it shows:
    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080
    O1 - Hosts: 172.20.12.14 mail
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MT....com/shop_phones.jsp?startPhone=motorola_razr
    O17 - HKLM\System\CCS\Services\Tcpip\..\{58560511-2542-4AA4-A581-63BA7148CE88}: NameServer = 85.255.115.2,85.255.112.7
    O17 - HKLM\System\CCS\Services\Tcpip\..\{9590430C-F78B-4BE0-9E65-713B412D2E88}: NameServer = 85.255.115.2,85.255.112.7
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.2 85.255.112.7
    O17 - HKLM\System\CS1\Services\Tcpip\..\{58560511-2542-4AA4-A581-63BA7148CE88}: NameServer = 85.255.115.2,85.255.112.7
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.2 85.255.112.7
    O17 - HKLM\System\CS2\Services\Tcpip\..\{58560511-2542-4AA4-A581-63BA7148CE88}: NameServer = 85.255.115.2,85.255.112.7
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.2 85.255.112.7


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (if found):
    C:\WINNT\SYSTEM32\CSKEC.EXE
    C:\WINNT\SYSTEM32\DMJZO.EXE

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  7. Bill44

    Bill44 Private E-2

    Hi Chaslang,
    I was still not able to boot in safe mode. I did run the HJT and fix, some of the 017 fixes that you show did not show up on the list to fix. I fixed the ones that I saw on your list. I also fixed one that I will more than likely have to replace ( it was the 172.20.12.14 mail listing) This is one that I use to access some company mail on a VPN.
    I was able to find and delete the cskec.exe file and the dmjzo.exe file, but again I had to delete them in the normal mode as the safe mode would not boot.
    BTW - I don't think that I mentioned that I am using W2K - not sure if that makes any difference. I ran the HJT with log attached after I completed the steps you requested.
    My computer seems to be running faster and is not locking up like it was before. I was getting 100% CPU usage whenever I started any program before and it is not doing that now. I also don't seem to be getting redirected when I do a Yahoo search.
    Please advise if I need to do anything else and Thank You so much for your help and time so far.
    Bill
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sometimes this is just a problem with screen resolution.

    • Boot into safe mode
    • Right click the desktop
    • Select Properties
    • Select the Settings tab
    • There are 2 things to change here. First is the Screen resolutuion. drag the slider to the right and select the highest resolution allowed
    • Second is the Color quality. Select the highest allowed
    • Select Apply and OK your way out of this window.
    Did that help? If no change was seen immediately, does it help after a reboot. If not, tell me exactly what happens when you boot into safe mode. This is probably not a malware isse. It may even be necessary to reinstall your graphics card drivers.
     
  9. Bill44

    Bill44 Private E-2

    I tried to reboot in Safe mode three times. I get a dialog box that says Windows in loading and then I will get the sign on w/ password box. After I sign in, a few minutes will pass and then I can see where is says loading personal preferences... the nothing happens. The screen stays black with "safe mode" in all four corners. I have type across the middle of the screen at the top that says Microsoft Windows.... then give the version number and service pack number. I have use of a cursor, but I cannot not get any activity with a right click anywhere on the screen. I can use the "ctrl+alt+del" and get a window to come up. I used the new task feature and navigated to the program file and looked for the files
    C:\WINNT\SYSTEM32\CSKEC.EXE
    C:\WINNT\SYSTEM32\DMJZO.EXE
    they were not there. I still have no clue why it will not boot in safe mode. When I use the "ctrl+alt+del" to shut down I get a message that says something like Program - Sample is shutting down, if you end now you will lose data...
    Things in the computer seem to be better. I can now run Adaware, Spybot and Defender and they say no Spyware or Malware.... The Adaware would freeze up before we ran the other fixes.
    Sorry to be so long winded with this response. I hope I have given you enough information.
    thanks!!
    Bill
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay since you cannot right click but you can open Task Manager in safe mode. Boot into safe mode again and open Task Manager and click File, New Task (Run...) and enter Desk.cpl

    Then in the next window

    Select the Settings tab
    There are 2 things to change here. First is the Screen resolutuion. drag the slider to the right and select the highest resolution allowed
    Second is the Color quality. Select the highest allowed
    Select Apply and OK your way out of this window.

    Did that help? If no change was seen immediately, does it help after a reboot.

    This is not a malware issue. It may even be necessary to reinstall your graphics card drivers. If the above does not help, I suggest posting a message in the Software Forum.
     
  11. Bill44

    Bill44 Private E-2

    Hey,
    FINALLY !!!! I was able to get the desktop to come up in safe mode after some additional gyrations with the settings. Basically after I reset the Scheme to Windows Classic and did a reboot the desktop came up.
    So, I await further instructions on what to do.
    I checked again for the C:\WINNT\SYSTEM32\CSKEC.EXE
    C:\WINNT\SYSTEM32\DMJZO.EXE files and they were not there.
    thanks,
    Bill
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you still having any malware problems?
     
  13. Bill44

    Bill44 Private E-2

    I don't seem to be having any other Malware problems. I ran another Bitdefender scan last night and it came back clean. The last two scans with Adaware and Spybot also came back clean. So, I guess the bad stuff is gone.
    Thanks a bunch for your help!
    Bill
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds