Need some help please!

Discussion in 'Malware Help (A Specialist Will Reply)' started by armadillo666, Jul 29, 2007.

  1. armadillo666

    armadillo666 Private E-2

    I followed all the steps sequentially and here are my txt files. I would appreciate if someone could look at them and let me know how my computer can be cleaned. Thanks.
     

    Attached Files:

  2. armadillo666

    armadillo666 Private E-2

    Here are the rest of the files
     

    Attached Files:

  3. armadillo666

    armadillo666 Private E-2

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please read this: Don't Bump! It Only Hurts You!!!

    Re-Run AVG Anti-spyware and have it fix/quarantine everything it finds. It is of no use to run it without having it fix the problems.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT.


    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt
    Attach new logs for:
    ShowNew
    GetRUn
    HJT
    Avenger
     
  5. armadillo666

    armadillo666 Private E-2

    Thanks for your reply. I did as you told and here are the files. I ran hijack this at the very end also one more time for you to see the end result (the file is named "07-29-07 (2) hijackthis.log". The first hijack this run is called "07-29-07 hijackthis.log".

    I also wanted to note that after I posted my first message I did go into Virtumundo thread and ran a program to fix that (Since I saw several references to virtumundo in my scans). That program did take out some dll files. This is probably the reason why avenger did not find some of these dlls.

    Please let me know if you need to know anything else or if you need me to do anything else.

    When I first got the virus the pop ups were really bad. Right now, I do not have any pop ups but still am concerned with my machine. One other thing is, it is not a big deal but annoying. System32 folder opens up every time the computer boots. Is there anyway to get rid of that?
     

    Attached Files:

  6. armadillo666

    armadillo666 Private E-2

    Here are the rest of the attachments.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    Java 2 Runtime Environment, SE v1.4.2
    LiveReg (Symantec Corporation)"
    LiveUpdate 2.5 (Symantec Corporation)
    Sunbelt CounterSpy ---we no longer need this.

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt
    Attach new logs for:
    Shownew
    Avenger
     
  8. armadillo666

    armadillo666 Private E-2

    I removed the programs you told me to then I ran avenger and pasted the text you sent me to remove those files. I got an error message. I am attaching the error message. I looked into system32 folder those files are still there. I ran shownew and am attaching the text file also.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you certain that you copied everything from the quote box?

    Download this file - Combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Attach the log in your next reply.
     
  10. armadillo666

    armadillo666 Private E-2

    You were right. I failed to copy the top part so I reran avenger. Reran shownew and finally ran combofix. Here are the attachments.
     

    Attached Files:

  11. armadillo666

    armadillo666 Private E-2

    Here is the last attachment.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That looks better!

    We need to remove a service from CounterSpy that did not get uninstalled.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Sunbelt CounterSpy Antispyware
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteSBCSSvc into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but and reboot when it tells you it needs to.
    Are you having any remaining malware problems?

    Your copy of Spyware Doctor is way out of date. Is this a paid version or free trial version? If free, you should uninstall it to avoid wasting the system resources on it since it will not remove anything.
     
  13. armadillo666

    armadillo666 Private E-2

    I did what you told me to do however I did not find Sunbelt Counterspy as one of the ones on the list. I can not remember when or if I installed Counterspy. Counterspy was always in system tray and when I tried to run it it seemed like it was trying to open turbotax which made me suspicious about this program. When I tried to remove it, it never removed. I manually deleted it from Programs which is not the best thing to do. I just did a search all folders/files and typed sunbelt but that did not bring up anything. Let me know if this is something I need to worry about.

    I took off what you told me to in HT program but it gave me an error message that said "service "sbc s svc" was not found in registry. Make sure you entered the short name of the service". As you said I expected this error. I exited and HT never told me to reboot. I will reboot the machine myself after sending this message.

    Now to your question about malware problems. I don't necessarily have any pop ups or anything like that anymore. However I have a second hard disk (F drive) and 2 folders named "Recycler" and "System Volume Information" are in there that I did not create. Recylcer has a folder name "S-1-5-21-2702649744-887722240-1295260173-1007" that has the recycle bin picture in it. When you open that folder nothing is in it tough the folder is 8kb. I may need an overall cleanup of miriads of programs that I recently downloaded lately to get this malware off.

    I think last time I rebooted system32 folder did not open on its own but if it does what is the cure for that not opening on every reboot.
    As far as the spyware dr I downloaded that for free and will take it out per your suggestion. Any other suggestion that will minimize items in system tray or programs that I can remove to speed up my machine, I will appreciate if you let me know about that.
     
  14. armadillo666

    armadillo666 Private E-2

    I hastily sent my response and saw that what I said about Counterspy did not make sense. To clear up what I said, simply I may or may not have installed Counterspy. What I mean by that is hopefully when I recieved the malware it did not install a fake Counterspy program that tried to actually download information from Turbotax to funnel the information to ID theft people.

    As I was explaining everytime I tried to run it, it tried to open a Turbotax application (basically what happened was when you try to run the program a box opened that automatically tried to install Turbotax cd or program. I had to hit cancel few times before it stopped trying to download turbotax. At that point I tried to remove it through remove programs. I was not successful so I did it manually. What is puzzling is you still see from my previous text files that it is still in my computer somehow. I did a search and there is no counterspy anywhere in the computer. At least not per search through windows.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In the last HJT log you attached in message number 6 the below line appeared:

    O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Unknown owner - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe (file missing)

    Do you still see it in a new HJT log?

    These are respectively your Recyle Bin and your System Restore folders which are part of Windows.

    This is not normally a malware issue. It is usually caused by a bad registry key. Does it still happen.

    I'll take a quick look but many things that are not malware related have to be determined by you the end user. We cannot know what you use or don't use. I'll let you know of I see any no brainers.
     
  16. armadillo666

    armadillo666 Private E-2

    I am attaching the latest HT log. The Counterspy message does not show anymore.

    The reason I mentioned Recycler and system information folders popping up on my F drive is there is nothing but music, picture files on that drive. Before running all these programs these folders were not there. My C drive is the one that contains all programs and Windows folders for the operating system. It is weird for these folders to show up now.


    I still have system32 folder popping up when I turn on my computer or reboot. This is very annoying.

    For the last 2 times I also have this message that says Do you want to a)block b)allow running c)ask me later for the program called Connection Manager. The publisher shows as Microsoft.


    I would really like to get rid of the 2 pop up stuff (system32 and Connection Manager) in booting. Thanks.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it is not weird. Step 2 of the READ ME enables viewing of hidden and system files which is what these were. They were always there.


    It could be due to a poorly formed startup command for your Sound Blaster. The below looks incomplete:

    O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG


    What program is popping up saying this?



    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
    O4 - Startup: PowerReg Scheduler V3.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot in normal mode

    Now attach the a new HJT log
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you uninstall the old Spware Doctor yet? I still saw it in your HJT log.
     
  19. armadillo666

    armadillo666 Private E-2

    The system32 folder is still popping when I restart and reboot the computer. The other Security Alert message regarding "Connection Manager" program did not show up when I rebooted just 2 minutes ago.

    Also, the bottom 2 "09" lines was not in HT so I could not put a check to remove it. I did use CCleaner between the time I messaged you and you messaged back. Maybe CCleaner removed those files. Anyways, here is my latest HT hopefully I am 1-2 steps away from getting rid of everything.
     

    Attached Files:

  20. armadillo666

    armadillo666 Private E-2

    I did uninstall all Spyware Dr files.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it was in your previous log but not this one.

    Did you miss fixing the below from my previous message? They are still in your log. Make sure you shutdown your browser before fixing and make sure you put a check on each line.

    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
    O4 - Startup: PowerReg Scheduler V3.exe


    After fixing them. Make sure you get a new HJT log. DO NOT get the log first!!
     
  22. armadillo666

    armadillo666 Private E-2

    Here is the latest HJT file. There is only few "file missing" ones left and I am not sure if those are important.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still see the below lines! Are you forgetting to fix these?


    O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
    O4 - Startup: PowerReg Scheduler V3.exe

    If you are sure you fixed them, shut down AVG Antispyware and then try again.

    Are you still having malware problems?
     
  24. armadillo666

    armadillo666 Private E-2

    I closed AVG and avast and ran HJT and tried to remove those 2 files however they do not get deleted.

    Malware wise I don't think I have any problems. I don't have any popups anymore. The only problem is system32 folder pops up everytime I turn on the computer. How can I get rid of this problem?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's strange. Normally when line like this will not go away it is due to protection software blocking the changes. Uninstall AVG AntiSpyware and then try again.

    Not sure but you may have to address it elsewhere. But I still suspect that possibly the Sound Blaster item I'm trying to get fixed could be causing it. In fact I would bet on it.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Attach a new log from GetRunKey.

    Goto the below folder:

    C:\Documents and Settings\SARP SEVINC\Start Menu\Programs\Startup

    Do you see this file? PowerReg Scheduler V3.exe
    If so, delete it. Did that remove it from your HJT log?
     
  26. armadillo666

    armadillo666 Private E-2

    I manually deleted powerreg like you told me to. Here are the 2 log files you requested. I don't see audigy on there either. I am going to reboot to see if the system 32 folder is popping up still.
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's better! ;)

    It shouldn't! As I said, I really think it was the silly Sound Blaster line. Let me know.
     
  28. armadillo666

    armadillo666 Private E-2

    system32 does not pop up anymore. Everything looks normal. Only thing left is for you to look at the latest HJT files and let me know if you see anything suspicious. If not I appreciate all the help.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Already did and it is clean!


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  30. armadillo666

    armadillo666 Private E-2

    I did all you said. I think I am ok now. Thanks for the help.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds