New Dot Net and others....

Discussion in 'Malware Help (A Specialist Will Reply)' started by MsApril, Nov 25, 2006.

  1. MsApril

    MsApril Private E-2

    This computer has not been maintained at all. Spybot found over 300 things...not to mention the other scans that I ran. Spybot found New Dot Net but could not remove it. I have followed the steps in "Read and Run Me First" and have attached all of the requested documents less the Panda scan I closed it before I was able to save it. Should I run it again? The following post will have the rest of the attachements.

    Thank you so much,
    April
     

    Attached Files:

  2. MsApril

    MsApril Private E-2

    I think that is everything. Let me know if there is anything else needed. Thanks again, April
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run this Using SDFix and attach the requested log.

    Now run this Disable/Remove Windows Messenger and remove Windows Messenger.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
  4. MsApril

    MsApril Private E-2

    I followed the steps in your last post and attached to requested logs. The computer seems to be running much smoother after running those steps.

    I am getting an error message everytime I restart:

    Error loading w81d69cf.dll
    The specific module could not be found

    I don't know if it is significant but thought that I would let you know incase it was.

    Also, I'm getting quite a few pop-ups.

    Thanks again,
    April
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach the logs from ComboFix and ShowNew as requested. Please attach them so we can continue.

    It looks to me like you may not have run ComboFix. At least not in the order the instructions were written. Some items it normally fixes are still showing in your HJT log.
     
    Last edited: Nov 26, 2006
  6. MsApril

    MsApril Private E-2

    I'm so sorry about that...Here are the logs. I ran them all again.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see you have Window Live installed. Does this contain an antivirus program and antispyware and maybe even a firewall???? Why are you running this at the same time as all of the Norton stuff?

    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2_01
    RelevantKnowledge <-- this is malware


    What is in the below folder?
    C:\WA6P

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\WINDOWS\system32\??chost.exe
    C:\WINDOWS\system32\PPPATC~1\ntvdm.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: (no name) - {A114473C-FF84-AF7E-D6A8-D728EA7432C0} - C:\WINDOWS\system32\ruyoy.dll
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: (no name) - {A114473C-FF84-AF7E-D6A8-D728EA7432C0} - C:\WINDOWS\system32\ruyoy.dll
    O4 - HKLM\..\Run: [w81d69cf.dll] RUNDLL32.EXE w81d69cf.dll,I2 0019011e081d69cf
    O4 - HKCU\..\Run: [Npmmtosy] C:\WINDOWS\system32\??chost.exe
    O4 - HKCU\..\Run: [Lerm] "C:\WINDOWS\system32\PPPATC~1\ntvdm.exe" -vt ndrv

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\Daniel\Application Data\ZangoToolbar <--- the whole folder
    C:\WINDOWS\NDNuninstall7_14.exe
    C:\WINDOWS\system32\wcpsvtr.exe
    C:\WINDOWS\system32\ruyoy.dll
    C:\WINDOWS\system32\w81d69cf.dll
    C:\WINDOWS\system32\PPPATC~1\ntvdm.exe

    Now please delete the below. Note that the Questionmarks represent unprintable characters that were found during the scans, but they may appear to you as normal characters when you locate them using Windows Explorer. I will add comments in RED next to each item. Note the date of the folders which will help you to locate them:
    Code:
    "C:\Program Files\"
    WNSXS~1       Nov 25 2006              "W?nSxS"  [B][COLOR=red]<-- may look like WinSxS[/COLOR][/B]
    
    "C:\WINDOWS\system32\"
    chost~1.exe   Oct 25 2006      438272  "??chost.exe"  [COLOR=#ff0000][B] [/COLOR][/B][B][COLOR=red]<-- may look like svchost.exe [/COLOR][/B]
    [B][COLOR=red][COLOR=purple]DO NOT DELETE the real svchost.exe[/COLOR] [/COLOR][COLOR=purple]Locate this bad one by the file date and size.[/COLOR][/B]
    
    Now run Ccleaner.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\
    C:\Documents and Settings\Daniel\Local Settings\Temp\

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. MsApril

    MsApril Private E-2

    To answer your question about Windows Live and Norton -I don't know why they are both on here. The people who had it last must've been running both. I know that the Norton stuff is not up to date so I should probably just delete it. I'll have to check out the Windows Live -I have never heard of it -do you recommend that I keep it or get rid of it to? I could download AntiVir or something like that.

    I uninstalled Java 2 Runtime Environment, SEv1.4.2_01 successfully but was not able to find RelevantKnowledge

    I deleted C:\WA6P it didn't have anything in it.

    I successfully killed the following processes:

    C:\WINDOWS\system32\??chost.exe
    C:\WINDOWS\system32\PPPATC~1\ntvdm.exe

    I successfully fixed the following lines:

    R3 - URLSearchHook: (no name) - {A114473C-FF84-AF7E-D6A8-D728EA7432C0} - C:\WINDOWS\system32\ruyoy.dll
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: (no name) - {A114473C-FF84-AF7E-D6A8-D728EA7432C0} - C:\WINDOWS\system32\ruyoy.dll
    O4 - HKLM\..\Run: [w81d69cf.dll] RUNDLL32.EXE w81d69cf.dll,I2 0019011e081d69cf
    O4 - HKCU\..\Run: [Npmmtosy] C:\WINDOWS\system32\??chost.exe
    O4 - HKCU\..\Run: [Lerm] "C:\WINDOWS\system32\PPPATC~1\ntvdm.exe" -vt ndrv


    When I booted into safe mode I was able to find and delete
    C:\Documents and Settings\Daniel\Application Data\ZangoToolbar

    I couldn't find the following:
    C:\WINDOWS\NDNuninstall7_14.exe
    C:\WINDOWS\system32\wcpsvtr.exe
    C:\WINDOWS\system32\ruyoy.dll
    C:\WINDOWS\system32\w81d69cf.dll
    C:\WINDOWS\system32\PPPATC~1\ntvdm.exe

    I couldn't find either of these to delete:

    "C:\Program Files\"
    WNSXS~1 Nov 25 2006 "W?nSxS" <-- may look like WinSxS

    "C:\WINDOWS\system32\"
    chost~1.exe Oct 25 2006 438272 "??chost.exe" <-- may look like svchost.exe

    I found C:\WINDOWS\WNSXS but nothing in program files.

    I found 2 svchost.exe
    svchost.exe 12/29/05 428KB
    svchost.exe 03/30/03 14KB

    I could not find the one dated Oct 25 2006.....

    I ran Ccleaner and Reset Web Settings and have attached the new logs.

    Thank you again for your time,
    April
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please go back to the READ & RUN ME step 2 to and complete those instructions properly. Then look for the files you said you could not find. They are there. They are in your newfiles.txt log. See for yourself. The only one that disappeared are
    C:\Program Files\W?nSxS
    C:\WINDOWS\system32\w81d69cf.dll
    and possibly C:\WINDOWS\system32\PPPATC~1\ntvdm.exe

    And if you see c:\windows\system32\svchost.exe with the following date and size 12/29/05 428KB Then delete it! Don't touch the 14k file because it is valid.
     
    Last edited: Nov 30, 2006
  10. MsApril

    MsApril Private E-2

    I have ran all the steps in Read and Run again. I hope that this helps. I found one of the files that I couldn't find before. Anyway...attached are the requested scans.

    Thanks again,
    April
     

    Attached Files:

  11. MsApril

    MsApril Private E-2

    Here are the other 3!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay those rescans removed some more of the problemsl however you told CounterSpy to ignore some of the items rather than having it fix the problems it found. Please rescan with CounterSpy and fix everything that it finds this time and attach a new log. There is no sense in scanning only to choice ignore.
     
  13. MsApril

    MsApril Private E-2

    Yeah...I did that because I could not create a restore point in Safe Mode...I meant to rescan and forgot.

    Here it is...

    Thanks,
    April
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall CounterSpy as it may be getting in our way. Then do the below.



    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-86BD-FD60BB9AAE3A} - (no file)
    O2 - BHO: (no name) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
    O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-86BD-FD60BB9AAE3A} - (no file)
    O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\backup\TB041029.DAT
    C:\WINDOWS\system32\wcpsvtr.exe

    Now run Ccleaner.
    MAKE SURE NO BROWSERS ARE OPEN AT THIS POINT!
    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.
    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  15. MsApril

    MsApril Private E-2

    I fixed the following in HJT:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    In normal mode and safe mode but they still show up in the scan...is this normal.

    I successfully deleted:
    C:\WINDOWS\backup\TB041029.DAT
    But I could not find:
    C:\WINDOWS\system32\wcpsvtr.exe
    I looked in C:\WINDOWS\system32 and I just couldn't find it.

    The computer is running 100% better!

    Thanks, April
     
  16. MsApril

    MsApril Private E-2

    Ooops...forgot to attach the scans...
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your logs you did not do this:
    Is there a reason you did not follow those steps exactly as written? Please follow those steps exactly. You can always set your start page back to Yahoo later when we finish.
     
  18. MsApril

    MsApril Private E-2

    I did do that step "Reset Web Settings" I didn't change my homepage...I didn't realize that it had to be "changed" I thought that you were just supposed to put the home page that you wanted in there...sorry.

    I did it again...

    Thanks, April
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sometimes I can tell that the Reset actually worked by looking at the logs. Other times I cannot be sure. Based on your logs it looks like the Reset did not work at all. Thus if you do it again (make sure to click the Reset Web Settings button) and then change the home page to majorgeeks (at least for the time being) I can tell what is working and what is not. There could be some other issues here.

    You did not attach a new log yet so make sure you have done the above and then attach a new log.
     
  20. MsApril

    MsApril Private E-2

    Sorry it took me so long to get back but I got really busy and didn't have time to get on the computer at all.

    Anyway...here are the new scans.

    Thank you,
    Apirl
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's try to do this a different way!

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.majorgeeks.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR

    After clicking Fix, exit HJT.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now get a new HJT log and attach it!
     
  22. MsApril

    MsApril Private E-2

    Here is the new HJT scan.

    Also, I have been running spybot daily and it is still finding NewDotNet and I just wasn't sure if it should...just wanted to let you know.

    Thanks,
    April
     

    Attached Files:

    Last edited: Dec 6, 2006
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's better!

    Did you follow the directions EXACTLY in the READ & RUN ME for setting up Spybot and fixing the Ignore Products bug???? Double check.

    Attach a log from Spybot if still having a problem.
     
  24. MsApril

    MsApril Private E-2

    I double checked to make sure that everything under All Products tab in ignore products was deselected. It still finds it but will not remove it. Here is the latest scan.

    Thanks,
    April
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try fixing it with the below. Make sure that you have ALL browers closed and exit all other unnecessary applications before continuing. Also make sure you are logged in to an account that has administrator priviledges.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Check a Spybot log now.

    Did we get it?

    If not, there may be a registry ownership issue that needs to be fixed.
     
  26. MsApril

    MsApril Private E-2

    I think that it really worked but the other issues that are showing up in this report keep popping up too. It says that it is removing them but when I rescan it shows up again.

    I'm so sorry to be such a pain.

    Thanks,
    April
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are no other real issues in your log. Cookies are not problems (see: step 11 of How to Protect yourself from malware! )

    And for the other message about
    This is probably not due to malware. Someone or some software changed a setting on your PC. I will give you a patch to try and set it back to default.

    But first here is some information you can read about this registry key and what it is used for in the below.

    http://www.phdcc.com/xpsp2.htm


    You may also find the below of interest:
    http://www.microsoft.com/windows/ie/community/columns/improvements.mspx


    Make sure that you have ALL browers closed and exit all other unnecessary applications before continuing. Also make sure you are logged in to an account that has administrator priviledges.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  28. MsApril

    MsApril Private E-2

    I want to thank you so much Chaslang. You have been WONDERFUL (and patient :confused: )!

    The computer is running great!

    Thanks again,
    April
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds