Neverending Malware removal...please help.

Discussion in 'Malware Help (A Specialist Will Reply)' started by biophaedia, Mar 19, 2006.

  1. biophaedia

    biophaedia Private E-2

    I've gone through all the steps indicated by this site, I even bought the full version of Panda Activescan so that it would get rid of all the stuff it uncovered.

    Every few minutes, I get a message from IE (though I use firefox) that says something along the lines of "Your Current ActiveX settings prohibit things from being shown...this page may not be displayed correctly".
    After changing some ActiveX settings in IE, I now get a prompt before the warning screen asking me if I want to install these ActiveX controls...I obviously choose no.
    Sometimes after closing both of these prompts, and sometimes completely randomly, I get a popup in IE from various websites. The most recent one was "by Outerlink".
    I will be indebted to anyone who helps me, because I have a shitload of essays to do and these goddamned prompts are driving me insane.

    Thanks,
    Cliff.
    (HJT log attached)
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please see step 3 of the READ ME. You have McAfee and Symantec installed.

    Also please complete step 6 of the READ ME and attach the logs as requested.
     
  3. biophaedia

    biophaedia Private E-2

    I have Norton installed, but have no idea where McAfee came from. I think it is a partial install or something from quite a while ago. I tried to get rid of it from add/remove programs, and it said I must uninstall other McAfee components first...which seems impossible, because there aren't any other McAfee components in add/remove programs, or in my program files folder.
    I went to its folder in program files, and deleted much of it, but cannot delete any files in my "mcafee.com" folder. It is not currently running on my computer (it isn't listed in processes or anything), and I don't recall using it...ever.

    I have attached my hijackthis log, bit defender log, panda activescan log, and smitrem log.

    after going through all these steps a few times (and the spyfalcon/smitrem removal steps), i keep getting the activex prompt, followed by popups from "outerinfo". spyfalcon also spontaneously reappeared on my computer after i removed it once, despite that i have downloaded nothing and visited no websites.

    these problems have also resulted in serious performance impairments on my computer, as well as the cooling fan (its a laptop) running on high virtually on the time.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please always follow directions exactly as written. You did not follow the steps for getting your Bitdefender log as written in step 6. As a result you only attached a log summary which is of no use to us. When the procedure is followed you will be attaching a full log an HTML formatted file but it will have a .txt file extension so it can be uploaded as an attachment.

    Let's get an installed programs list from HijackThis too!

    Run HijackThis, click Open the Misc Tools section
    Click Open Uninstall Manager
    Click Save List (generates uninstall_list.txt)
    Click Save, to save it to a file where you can find it.
    Upload this file as an attachment too.

    Your McAfee SecurityCenter Update Manager is still running and wasting system resources. We will have to fix this manually.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to McAfee SecurityCenter Update Manager (or if not found look for mcupdmgr.exe) ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    mcupdmgr.exe

    Now exit HJT and reboot

    After reboot attach a new HJT log and the uninstall_list.txt log from HJT I requested too.
     
    Last edited: Mar 22, 2006
  5. biophaedia

    biophaedia Private E-2

    Sorry for the mix-up.
    I did everything you told me to do in the last post, and here are the new/updated logs.

    I really appreciate the help so far.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this current HJT log from normal boot mode. I curious as to why some problems that were displayed in your previous log do not show now. Did you run other tools to fix malware or did you fix some items on your own? Or was this a safe mode log instead of a normal boot mode log.

    Before I can give you a fix, I need to know an answer for the above. But you can do the below:


    The below two Java runtimes are old versions which should be uninstalled.
    Java 2 Runtime Environment Standard Edition v1.3.1
    Java 2 Runtime Environment, SE v1.4.2

    LimeWire 4.9.37 <--- may contain malware. And there is a newer version that may not but we don't recommend using any P2P programs.

    Mozilla Firefox (1.0.7) <--- old version. You should update.
    Mozilla Thunderbird (1.0.7) <--- old version. You should update.
     
  7. biophaedia

    biophaedia Private E-2

    sorry. that hjt log is different because i uninstalled outerinfo and used a look2me cleanup tool. it was also done in normal boot mode, i have attached a new log from safemode.

    i made the changes you recommended in the previous post.

    here we are:
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which Look2Me tool did you run? Give a link so I know exactly what you ran.

    Also you misunderstood my last message. We only want Normal Bootmode logs not safe mode. I just wanted to be sure that it was not from safe mode because it looked so different than previously.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's download two tools we will need:

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winaqc32.dll once and then click the kill button. After you have killed all of the winaqc32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of winaqc32.dll and kill it.

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKCU\..\Run: [Aaou] "C:\WINDOWS\system32\SSEMBL~1\scanregw.exe" -vt mt
    O4 - HKCU\..\Run: [Dnemlht] C:\WINDOWS\?racle\chkntfs.exe
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/02b45d74...p/RdxIE601.cab
    O20 - Winlogon Notify: winaqc32 - C:\WINDOWS\SYSTEM32\winaqc32.dll


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.
    C:\WINDOWS\SYSTEM32\winaqc32.dll


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot don't run anything else until you do the below.

    Locate the below with Windows Explorer and delete them (some of them may already be gone but we need to double check)
    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\GDMF41I3\wdinit64[1].exe
    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\GDMF41I3\wdinit64[2].exe
    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\KHAZWHIF\rdgCA2404[1].exe
    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\KHAZWHIF\wdinit64[1].exe
    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\KHAZWHIF\wdinit64[2].exe
    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\KPQ7KDU7\wdinit64[1].exe
    C:\Documents and Settings\cliff\Local Settings\Temporary Internet Files\Content.IE5\3JIHUA11\wdinit64[1].exe
    C:\Documents and Settings\cliff\Local Settings\Temporary Internet Files\Content.IE5\FCYTRBCR\mullbin1[1].exe
    C:\WINDOWS\temp\aaachhmd.exe
    C:\WINDOWS\temp\akgpbimd.exe
    C:\WINDOWS\temp\dioidjmd.exe
    C:\WINDOWS\temp\gbcjdbmd.exe
    C:\WINDOWS\temp\gnddodmd.exe
    C:\WINDOWS\temp\hbdiiemd.exe
    C:\WINDOWS\temp\hicefgmd.exe
    C:\WINDOWS\temp\kmmfmcmd.exe
    C:\WINDOWS\temp\mkogbamd.exe
    C:\WINDOWS\temp\olpiepnd.exe
    C:\WINDOWS\temp\win12.tmp.exe
    C:\WINDOWS\temp\win17.tmp.exe
    C:\WINDOWS\TEMP\win33.tmp.exe
    C:\WINDOWS\temp\win6.tmp.exe
    C:\WINDOWS\TEMP\winA.tmp.exe
    C:\WINDOWS\temp\winE.tmp.exe
    C:\WINDOWS\SYSTEM32\winaqc32.dll
    C:\WINDOWS\?racle\chkntfs.exe <--- this may translate into oracle. Delete the whole folder

    Now attach a new HJT log here in your next message and tell me how the steps went.

    Also make sure you tell me how things are working now!
     
  10. biophaedia

    biophaedia Private E-2

    the look2me link: http://www.atribune.org/ccount/click.php?id=7

    thanks very much for the help. i really appreciate it. so far, no random activex prompts have shown up....but they seemed to come at irregular intervals, so i'll definitely know in a couple of hours.
    in the meantime, here is my new hjt log (in normal boot mode).

    again, thank you.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Good! That is the tool I was hoping you had used!

    Just have HijackThis fix the below left over from the malware:

    O20 - Winlogon Notify: winaqc32 - winaqc32.dll (file missing)

    After that you should be all cleaned up.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds