Need some assistance please.

Discussion in 'Malware Help (A Specialist Will Reply)' started by sprtfrk22, May 22, 2007.

  1. sprtfrk22

    sprtfrk22 Private E-2

    I ran through all the steps that I was suppose to. I Couldn't run in Safe Mode for some apparent reason. I did the best I could. Please help.

    attached is counterspy and 2 online scan texts.
     

    Attached Files:

  2. sprtfrk22

    sprtfrk22 Private E-2

    and attached is the other three--runkey, shownew, HJT.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    Viewpoint Media Player
    Viewpoint Manager (Remove Only)

    Please use windows explorer to find and delete:
    C:\Program Files\Common Files\nibym.dll
    c:\windows\downloaded program files\f3initialsetup1.0.0.15-3.inf
    c:\program files\License_Manager
    C:\WINDOWS\12-b101c483c2fe3ac4a2bd5fae3377ef4f.exe
    C:\WINDOWS\4-efb7bab6499fc415ee93f4097033deae.exe
    C:\Documents and Settings\Freak\Application Data\Viewpoint
    C:\Documents and Settings\Freak\Application Data\.rdr.ini

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\mmllm.ini
    C:\WINDOWS\system32\F3.tmp
    C:\WINDOWS\system32\mmllm.bak
    C:\Program Files\Common Files\nibym.dll
    C:\Program Files\Common Files\T?sks

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
  4. sprtfrk22

    sprtfrk22 Private E-2

    When I was waiting for a post i was removing some things off my startup with ccleaner. I found smanager.7.exe and removed it because i searched it and it was known to come with a trojan.

    Some of the things you told me to remove on HJT were not there.

    attached are the texts you asked for.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We're getting there:

    Please download VundoFix.exe to your desktop.

    * Double-click VundoFix.exe to run it.
    * Click the Scan for Vundo button.
    * Once it's done scanning, click the Remove Vundo button.
    * You will receive a prompt asking if you want to remove the files, click YES
    * Once you click yes, your desktop will go blank as it starts removing Vundo.
    * When completed, it will prompt that it will reboot your computer, click OK.
    * Please post the contents of C:\vundofix.txt and a new HiJackThis log.

    Note: It is possible that VundoFix encountered a file it could not remove.
    In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the
    Scan for Vundo button." when VundoFix appears at reboot.

    Also attach ShowNew and GetRun.
     
  6. sprtfrk22

    sprtfrk22 Private E-2

    I ran vundo fix already but I did as you said and ran it again. Nothing was found.

    Attached is the three things you asked for.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\mmllm.bak2

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
  8. sprtfrk22

    sprtfrk22 Private E-2

    done...here's the texts you asked for.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    1. Download this file - ComboFix
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Attach new logs for GetRun, ShowNew and Combofix.
     
  10. sprtfrk22

    sprtfrk22 Private E-2

    here's combofix and others.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download The Avenger by Swandog46 to your Desktop.
    • Double click on Avenger.zip to open the file and extract avenger.exe to your Desktop
    • Copy the below quoted text (which is a script for Avenger) into your clipboard by highlighting it and pressing
      CTRL+C
    • Now, run The Avenger program by double clicking its icon on your Desktop.
    • Under "Script file to execute" choose "Input Script Manually".
    • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
    • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
    • Click Done
    • Now click on the Green Light to begin execution of the script
    • Answer "Yes" twice when prompted.
    The Avenger will automatically do the following:
    • It will Restart your computer. (When the script being executed contains "Drivers to Unload",
      The Avenger will actually reboot your system two times.)
    • On reboot, it will briefly open a black command window on your desktop, this is normal.
    • After the reboot, it creates a log file that should open with the results of Avenger’s actions. This log
      file will be located at C:\avenger.txt
    • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped
      them and moved the zip archives to C:\avenger\backup.zip.
    Please attach the c:\avenger.txt file to your next message.
     
  12. sprtfrk22

    sprtfrk22 Private E-2

    When I follow your steps I get two error messages and it doesn't follow through.

    First: "are you sure you want to execute the commands in the selected script?"

    second: "error: selected file does not appear to be a valid script."

    third (another error message): "Press OK to log error and continue or Cancel to abort." I select OK.

    fourth: "Error code: 0" -- I press OK and nothing goes.

    I searched those files...the first one I can't find but the second one i can: t3.tmp. i tried doing that one allone and it still didn't follow through...same messages.

    The log file is just an error message.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you delete the file?

    Retry with this script:
     
  14. sprtfrk22

    sprtfrk22 Private E-2

    The script still didn't work, but F3.tmp i could delete manually. The other TSKS~1 does not exist and I have hidden files shown. Here is 3 logs.

    Everything seems to be running faster without any popups. Is there anything else I need to do?
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is still showing:

    "C:\Program Files\Common Files\T?sks

    Run ComboFix again and see if it picks it up this time.
     
  16. sprtfrk22

    sprtfrk22 Private E-2

    That was weird. I ran combofix.exe and it didn't find it. I went to where it was located and found the folder tasks. When I opened the folder the status bar read it as the file with the question mark (C:\Program Files\Common Files\T?sks). So I went back and manually deleted it. Combofix didn't find anything before or after manual deletion. Here are three more logs.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't know why ComboFix wouldn't pick it up ....some of the nasties are getting smarter.
    Your logs look clean. You may uninstall any programs we had you download (including CouterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    One last thing....could you tell me what these are.....if you don't know, delete them.
    "C:\Documents and Settings\Freak\Application Data"
    LOUDDA~1 Feb 27 2007 "Loud dale mode"

    "C:\Documents and Settings\All Users\Application Data"
    PLUSPI~1 Feb 27 2007 "pluspileslowbat"

    "C:\Program Files"
    LOUDDA~1 Mar 22 2007 "Loud dale mode"

    download HOSTER and then follow the below steps.

    * Unzip Hoster to a convenient folder such as C:\Hoster
    * Run Hoster.exe, click Restore Original Hosts and then click OK.
    * Click the X to exit the program
     
    Last edited: May 24, 2007
  19. sprtfrk22

    sprtfrk22 Private E-2

    I didn't unzip the folder for combofix.exe. I think that's why it didn't work. All works well...thank you very much.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem.....safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds