Need Virus/spyware help please

Discussion in 'Malware Help (A Specialist Will Reply)' started by Rbuttrick, Dec 20, 2006.

  1. Rbuttrick

    Rbuttrick Private E-2

    This is my first post on this forum so I appreciate any help you guys can give me. Well first of all I'll start with the problems: The most obvious problem is the large number of pop ups, they used to be pretty much only winantivirus something but now it could be pretty much anything. My computer has also been significantly slower since this has begun, especially when it comes to the time it takes to load all the programs after startup. The cause of all this i know for sure is a trojan that was in a something I downloaded for AutoCAD 2007, I scaned the file before i opened it but it didnt catch it. Symantic anti virus can detect the trojan in "wuauclt.exe" but cannot permanently delete it.

    I currently have symantic antivirus and AVG installed and running, I have also completed all of the steps the "read and run me first" sticky. Here are the logs that these scans produced as well as the Hijackthis file.

    The two other logs will be added to the next post.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not if you have both AVG and Symantec installed. Read step 3 of the READ & RUN ME again and correct this now. After fixing this you will need to attach new logs from ShowNew and HijackThis.

    Make sure you also attach the missing logs (GetRunKey, CounterSpy and HJT).
     
  3. Rbuttrick

    Rbuttrick Private E-2

    Well i have to keep symantic installed on my computer because thats what my university requires, but for now its turned off and AVG is running. Heres the HJT and the Counterspy logs, the GetRunKey log wont attach, i'll post that in a minute when i figure it out.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it is not turned off! The only way to do that is to uninstall it. See the below from your HJT log showing all the stuff from Symantec that is loading and running:
    If you must keep Symantec, then you must uninstall AVG now.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your CounterSpy log seems to be missing information at the beginning. Did you edit the log?
     
  6. Rbuttrick

    Rbuttrick Private E-2

    There we go, this should be the last one.

    Thanks for the help


    Let me check the on counter spy log
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you see message number 4????

    After you uninstall AVG, please run the below.
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Then move on to my next message to be posted in a minute.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After completing the steps in message # 7, continue here.


    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?
     
  9. Rbuttrick

    Rbuttrick Private E-2

    Heres the log from post 7. The next two steps may take a bit longer but i'll go as fast as I can. Thanks for the help.
     

    Attached Files:

  10. Rbuttrick

    Rbuttrick Private E-2

    Heres the first step of post 8
     

    Attached Files:

  11. Rbuttrick

    Rbuttrick Private E-2

    Heres the next series of logs. HJT in next post
     

    Attached Files:

  12. Rbuttrick

    Rbuttrick Private E-2

    There seems to be no improvements up to this point, i have been getting pop ups throughout this process, and my wallpaper is now gone since the reboot.
    Am I susposed to click "fix checked" after the HJT scan is done?
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In reality there has been significant changes. You had a lot of infections and a bunch have now been fixed. I have to go thru your new logs now to see what else remains.

    That is due to the SmitFraud problems you had being fixed by SmitFraudFix. You will be able to reset it later.


    NOOOOO!!!!! You only fix what we tell you to fix. HijackThis is not a malware detection tool. It is not reporting malware. It is only showing you a list of running processes and a variety of registry keys. None of this means they are bad.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have HijackThis installed here:

    C:\Documents and Settings\Bob Buttrick\My Documents\anti virus\analysis.exe

    That is exactly where we specified not to install it. Please install it where reqested. And note that HijackThis is not an antivirus tool!!!!
     
  15. Rbuttrick

    Rbuttrick Private E-2

    Alrighty thanks, actually it does seem like the pop ups arnt quite as bad anymore.

    Opps forgot about that part, want a new log once its installed correctly?
     
  16. Rbuttrick

    Rbuttrick Private E-2

    Ok installed correctly now
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Much Better!! ;) Now for the rest of your problems (as I said...you had a lot of them).

    First run this Disable/Remove Windows Messenger to remove Windows Messenger a frequent contributor to popups!

    Now Uninstall CounterSpy now to avoid problems with it getting in the way of our remaining removal tasks! Do this before continuing.

    Also uninstall the below software:
    J2SE Runtime Environment 5.0 Update 6
    Mozilla Firefox (1.5.0.9)
    Safety Bar <-- should have been uninstalled in step 0 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME
    Viewpoint Toolbar <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox


    After completing ALL of the above instructions, continue here!

    Downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of gebcy.dll once and then click the kill button. After you have killed all of the gebcy.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of gebcy.dll and kill it. (If you do not find the dll, just continue on.)


    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {3FD6B99C-A275-46ea-8FD1-3D63986E51E4} - C:\WINDOWS\system32\snracbmo.dll (file missing)
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O2 - BHO: (no name) - {BBD539D5-BADB-4BA5-A2D6-A0E6AADFC0CC} - C:\WINDOWS\system32\gebcy.dll
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O3 - Toolbar: (no name) - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\xpvkkuul.dll",setvm
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Scbu] "C:\DOCUME~1\BOBBUT~1\APPLIC~1\ASEMBL~1\wuauclt.exe" -vt ndrv
    O20 - Winlogon Notify: gebcy - C:\WINDOWS\system32\gebcy.dll


    After clicking Fix, exit HJT.


    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\WINDOWS\system32\wapisvtr.exe
    C:\WINDOWS\system32\gebcy.dll
    C:\WINDOWS\system32\klhasexv.dll
    C:\WINDOWS\system32\mgjoskdu.dll
    C:\WINDOWS\system32\rqxeitdp.dll
    C:\WINDOWS\system32\xpvkkuul.dll
    C:\WINDOWS\system32\ycbeg.tmp
    C:\WINDOWS\system32\luukkvpx.ini
    C:\WINDOWS\system32\ycbeg.ini
    C:\WINDOWS\system32\ycbeg.ini2
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folders and delete if found:
    C:\Documents and Settings\Bob Buttrick\Local Settings\Application Data\Viewpoint
    C:\Program Files\Spyware Doctor
    C:\Program Files\Common Files\Viewpoint

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  18. Rbuttrick

    Rbuttrick Private E-2

    Everything up through this point has worked fine except i could not delete C:\Program Files\Common Files\Viewpoint an error came up saying access denied because it was in use by another program. Should I boot in safe mode and try it again? But anyways, here the the new logs you requested.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can try deleting it in safe mode. If that does not work, let me know and I will give you something else to run.

    You had a couple new baddies show up just today! Let's get them fixed before they spread anymore.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {3FD6B99C-A275-46ea-8FD1-3D63986E51E4} - C:\WINDOWS\system32\cbfqcyty.dll
    O2 - BHO: (no name) - {DF5D8180-CEDE-402D-B4DE-54C0609F31AF} - C:\WINDOWS\system32\gebcy.dll (file missing)

    After clicking Fix, exit HJT.


    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\cbfqcyty.dll
    C:\WINDOWS\system32\ohwvxvdg.dll

    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.
    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  20. Rbuttrick

    Rbuttrick Private E-2

    Things seem to be doing much better now, my computer seems to start faster and I haven't had one pop up yet today. Heres the next set of logs you requested.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay the only thing remaining is C:\Program Files\Common Files\Viewpoint

    Run this ViewpointKiller

    Then reboot into safe mode and if that folder is still found, try deleting it. Let me know the results.
     
  22. Rbuttrick

    Rbuttrick Private E-2

    I ran that program then rebooted in safe mode but viewpoint is still there and wont let me delete it. An error comes up saying "Cannot delete FotomatShellExt.dll: Access is Denied." If thats what i think it is then it has to do with the software that I installed for my digital camera.

    Another thing that i have noticed is that some of the time when i try and shutdown or restart the computer, I will click the start menu then click shutdown, the computer goes back to the desktop and just freezes the box thats supposed to come up about restart, shutdown etc. never comes up and i cannot click on anything else. After that sits for a minute w/o doing anything I'll just do ctrl-alt-delete and shut it down that way. At that point windows logs off and goes to the "windows is shutting down" blue screen and just sits there until i manually hit the power button to shut it down.

    Other than those things, it seems to start up much faster as well as to this point have no pop ups.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not as far as I know. I believe it is always installed with Viewpoint. Try right click on FotomatShellExt.dll and select rename. Change it to FotomatShellExt.ddd. Now reboot your PC. Can you delete the file and folder now?

    You could have some Windows files system corruption. It may or may not have been cause by malware. You may be better off trying to debug this one in the Software Forum. But just for the heck of it, let's run two rootkit scanners just make sure nothing else is hiding from us:

    Please download Blacklight Beta
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please post contents of the BlackLight log.


    Now run the following tool and also attach a log from it: AVG Anti-Rootkit
     
  24. Rbuttrick

    Rbuttrick Private E-2

    That took care of the viewpoint file nicely. I dont think that either of the scans came back with anything, i'll post the log from the first scan, it doesnt look like theres even a log to post for the 2nd one.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not expect that they would find anything but I wanted to be sure.

    You should try running the below but at this point I think you no longer have malware and will need to continue in the Software Forum.

    Click Start, Run, and enter sfc /scannow and click OK. If this finds any system file errors, it may ask you for your Windows XP SP2 boot CD so that it can fix the problems. So you will need to have this CD available.

    Since we are finished with your malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  26. Rbuttrick

    Rbuttrick Private E-2

    I couldnt find my XP disk right now so that step will have to wait, but i got everything else done. My computer seems to be running much faster with no pop ups now, thanks a lot I dont know what I would have done w/o your help....actually I do, i'd have to take it to some guy who would have done all this for me and charge me a lot for doing it...thanks again.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds