New User.. went through all steps!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jos1003, Sep 11, 2006.

  1. Jos1003

    Jos1003 Private E-2

    Hey how are you guys? I tried everything. Here are the major problems. I can't open windows firewall, was getting a winlogon error, IE crashes, can't install alot of programs, and getting squares in my task manager for processes. So please take a look.

    Thank you

    Josh R.
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome,

    Going through the steps as actually following them are two different things, your ran your Hijackthis log from the very place you advise not to with also mising the change of name from hijackthis.exe to analyse.exe

    yor log was run from Safe Mode, which is not the rigth place to run it from as its does not highlight all the running processess on your PC.


    So best bet to fully remove any malware from your PC is to follow the below guide and and attach all the requested logs and the malware expets here on majorgeeks can give them a look through and if any maining malware is still resident on your PC they will post some tailored instructions to remove them.



    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:

      • [*]runkeys.txt - the log from GetRunKey.bat
        [*]newfiles.txt - the log from ShowNew.bat
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis

    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. Jos1003

    Jos1003 Private E-2

    I will try to do this but I can not install any of the showkey and runkey programs, nor can I install spybot. I will try this again and see what I can get but I can only run in safemode with networking. Memory goes to 100% with normal then freezes?

    Josh Thank you
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why not? They don't actually install. You just need to unzip them and then run them. You are going to need to be able to download tools like this that require no installation but may need to be extracted from a ZIP file. If you cannot do the extraction on the infected PC, try doing it on another PC and then copy all files to the infected PC using a CD, flashdrive, floppy, etc..

    Did you move HijackThis to the proper folder, and did you rename HijackThis.exe as required?
    If so, attach a new HJT log.
     
  5. Jos1003

    Jos1003 Private E-2

    This is what I was able to get. Hope you can help.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why didn't you run ShowNew? If you could run GetRunKey, you should be able to run ShowNew.

    Why did you have 5 Internet Explorer sessions opened while getting the HijackThis log? No browsers should be running per the READ ME.

    The below is also not the correct location to install HJT. It is exactly where we specify not to install it.

    C:\Documents and Settings\Owner\Desktop\Analyzethis.exe

    You should move it into C:\Program Files\HJT before you continue otherwise you risk loosing all backups that HJT makes and even possibly loosing the Analyzethis.exe file too.

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of brigvvep.dll once and then click the kill button. After you have killed all of the brigvvep.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs(If you do not find the dll, just continue on):
    igjjkvbn.dll
    mcconfig.dll
    saybcylx.dll
    vjrlhtnd.dll

    Next double click on explorer.exe and again click once on each instance of brigvvep.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    igjjkvbn.dll
    mcconfig.dll
    saybcylx.dll
    vjrlhtnd.dll

    Now just exit Process Explorer.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\WINDOWS\system32\srshost.exe
    C:\WINDOWS\system32\RegSrvc.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: Shell=Explorer.exe,wbdbasrv.exe
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wbdbasrv.exe,C:\Documents and Settings\Owner\Application Data\Explorer\wbdbasrv.exe
    O2 - BHO: (no name) - {A9B7A097-9298-4B09-855B-EBCB2A64C95e} - C:\WINDOWS\system32\rvfjlhfw.dll
    O2 - BHO: CIEPl Object - {F85E86D8-F796-4C97-AAA2-26664A98A42C} - C:\WINDOWS\system32\mcconfig.dll (file missing)
    O4 - HKLM\..\Run: [Terminal Component] C:\WINDOWS\system32\wbdbasrv.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [srshost.exe] C:\WINDOWS\system32\srshost.exe
    O4 - HKCU\..\Run: [Terminal Component] C:\WINDOWS\system32\wbdbasrv.exe
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O20 - Winlogon Notify: brigvvep - C:\WINDOWS\SYSTEM32\brigvvep.dll
    O20 - Winlogon Notify: igjjkvbn - C:\WINDOWS\SYSTEM32\igjjkvbn.dll
    O20 - Winlogon Notify: mcconfig - mcconfig.dll (file missing)
    O20 - Winlogon Notify: saybcylx - C:\WINDOWS\SYSTEM32\saybcylx.dll
    O20 - Winlogon Notify: vjrlhtnd - C:\WINDOWS\SYSTEM32\vjrlhtnd.dll
    O21 - SSODL: IEFilter - {7D3D0216-81EA-4B3F-91B7-02610BF63259} - IEFilter1.dll (file missing)
    O21 - SSODL: Internet Explorer - {E6C09994-7994-4C10-90A9-A03E821374F9} - C:\WINDOWS\system32\more_860.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\Owner\Application Data\Explorer\wbdbasrv.exe
    C:\WINDOWS\system32\combo.exe
    C:\WINDOWS\system32\srshost.exe
    C:\WINDOWS\system32\RegSrvc.exe
    C:\WINDOWS\system32\wbdbasrv.exe
    C:\WINDOWS\system32\rvfjlhfw.dll
    C:\WINDOWS\system32\mcconfig.dll
    C:\WINDOWS\SYSTEM32\brigvvep.dll
    C:\WINDOWS\SYSTEM32\igjjkvbn.dll
    C:\WINDOWS\SYSTEM32\mcconfig.dll
    C:\WINDOWS\SYSTEM32\saybcylx.dll
    C:\WINDOWS\SYSTEM32\vjrlhtnd.dll
    C:\WINDOWS\SYSTEM32\IEFilter1.dl
    C:\WINDOWS\system32\more_860.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete it if found:
    C:\Program Files\PartyPoker

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\temp

    Now attach a new HJT log and tell me how the steps went.

    Also attach a new logs from ShowNew and GetRunKey.

    Make sure you tell me how things are working now!
     
  7. Jos1003

    Jos1003 Private E-2

    Hey thanks for the help info. But I can't even install processexplorer. I don't know whats on here but it sure is messing with everything?

    anything I can do with just hjt it seems to be the only thing that will run.

    josh
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not need an install. You just need to extract it from the ZIP file just like you did for HJT and for GetRunKey.

    HJT by itself cannot fix these malware problems. The other tools are required for a complete fix. But you can try running thru all other steps anyway and some of them may get fixed which could help. Make sure you try to use Pocket Killbox to delete the files. It does not need to install. You just run the file that is downloaded. If you cannot run Pocket Killbox, delete the files yourself after booting in safe mode.
     
  9. Jos1003

    Jos1003 Private E-2

    Alright things are getting better still alot of popups and some other stuff. so is here is the hjt show and end.

    Josh thanks alot
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you now run ProcessExplorer? If so, I will work up a new fix using it.

    You have a ton of bad DLL files I need to checkout. This will take some time. I may be able to do this tonight! In the meantime, do the below.

    Goto Add/Remove programs and uninstall SmileyDistrict Optimizer

    Now delete the below two folders:
    C:\Program Files\Media-Codec
    C:\Program Files\Common Files\WinAntiVirus Pro 2006

    Now use Pocket Killbox to delete the below file (you cannot use Windows Explorer to find this file - use Killbox):
    C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N91M1807NetInstaller.exe

    Attach a new ShowNew log after doing all of the above and make sure you tell me if you can use ProcessExplorer now.
     
    Last edited: Sep 15, 2006
  11. Jos1003

    Jos1003 Private E-2

    I can run explorer now! But I can not delete smily some type of error windows/system32/msconfig "this specified module could not be found"

    So thanks alot see whats next guess

    Josh
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We will come back to SmileyDistrict later.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Service ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Service

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that later.

    Now run the below and attach the requested Ewido log.

    Running Ewido Anti-Malware
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds