New poster - Hoping I can get some help cleaning up a few things

Discussion in 'Malware Help (A Specialist Will Reply)' started by Davan, May 8, 2006.

  1. Davan

    Davan Private E-2

    Guess I got a little to cocky that I could clean anything that might come my way by myself and I ended up with something nasty last night. Followed steps 0-7 in the "Read & Run me First" sticky, and am still having issues. Heres the rundown on what Im experiencing, + log files.

    -After I received the malware/trojan etc., began receiving insane popups (10 or more) every 30 seconds or so. Many of them with loud audio attachements

    -Rebooted into safe mode, ran Adaware, Spybot and Trendmicro, which all found 200+ threats and claimed to clean then

    -Rebooted into Windows, I didnt immediately see any problems, but there was a new icon on my desktop (Do not recall the name) which I clicked once, with the intent of moving to the recycle bin. When I did so, it sent my computer into a tizzy, loading all sorts of crazy Windows and adware. I deleted and closed as much as I could, then began prepping for the more complete cleaning posted here.

    -Followed steps 0-7, which have helped immensely. No longer am I seeing popups, but the performance and security of my system seem to be heavily degraded.

    • Booting into Windows take an extremely long time, when previously it did not
    • I cannot shut down/close CounterSpy. Attempting to do so produces no effect
    • I regularly see error messages from Avast that say "some IP address attack blocked" which I see enough that I told it to stop showing the message.
    • I attempted to patch a program I use, and doing so was taking an extremely long time, and while it was patching the screen would occasionally turn completely white, then go back to the desktop, then white again. I eventually killed it with ctrl+alt+del.

    Im sure extended use would turn up more issues but I want to nip it in the bud asap. Log files attached.

    P.S. Even though all software shows my OS as Windows XP SP2, its actually XP SP2 +MCE, which might explain why Windows Defender wouldnt run. So I had to use CounterSpy.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Why didn't you allow CounterSpy to fix what it found? You told it to ignore! Run it again and let it fix what it finds.

    You did not follow the directions in step 7 of the READ ME. The below shows how you are running HijackThis:
    C:\DOCUME~1\JOHANN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    This means you are running it from the ZIP file which step 7 specifically instructs you not to do. Please follow the step 7 directions and install HijackThis exactly how requested. Then continue!

    Look in Add/Remove programs and uninstall anything related to Zeno or ZenoSearch if found.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKCU\..\Run: [zwzq] C:\PROGRA~1\COMMON~1\zwzq\zwzqm.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    c:\windows\kwv2.dat
    C:\WINDOWS\Sm9oYW5uZXMgQnJhaG1z\mA6CsqcRtrg0kBL1u3YW.vbs
    C:\WINDOWS\system32\kwintqaf.exe
    C:\Program Files\Common Files\zwzq <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  3. Davan

    Davan Private E-2

    Sheesh I musta been really tired or paying no attention at all cause I screwed up like 3 steps didnt I :) Oh well, thank you for having patience with me and helping me to work through this I really appreciate it.

    I did everything you asked, and new logfile is posted below. Everything seems to be running much smoother now, although it is still somewhat lengthy on booting. It might be attributable to Avast/CounterSpy loading up at startup where they never did before. I was able to close CounterSpy on bootup, and the patching of the program that previously locked and produced full white screens breezed right through on this attempt. I havent seen any more Avast error messages (although since I told it to stop displaying the message anyways I probably wouldnt know one way or the other.)

    So unless you see something else interesting in the log Im going to, for the time being, consider this a succesfull cleaning and thank you very much if so!!! :)
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds