Pic1234 removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Anon-1e78cf5a69, Mar 27, 2008.

  1. Anon-1e78cf5a69

    Anon-1e78cf5a69 Anonymized

    I accidently contracted what I believe to be the pic1234 MSN bug which takes over my MSN messenger and sends a link to everyone on my contactlist. I contracted the via a link to a website (and by not thinking straight).

    I have followed the "READ & RUN ME FIRST" post to the letter but I am still having the problem.

    Where do I find the SASlog and the Malbytes AntiMalware logs? My search funtions is acting weird and I cannot find the files.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    If you follow the READ & RUN ME they will be where ever you saved them.

    Please try to attach them so we can properly help you.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {060BB0AB-4B09-4C51-9ECB-9580A6D08D7F} - C:\WINDOWS\system32\vtUolKed.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [Windows live Messenger] msn.com
    O4 - HKLM\..\Run: [BMbfef6909] Rundll32.exe "C:\WINDOWS\system32\wnqprbco.dll",s
    O20 - Winlogon Notify: vtUolKed - C:\WINDOWS\SYSTEM32\vtUolKed.dll


    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Jonas Toppenberg\Local Settings\Temp\

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  3. Anon-1e78cf5a69

    Anon-1e78cf5a69 Anonymized

    Here are the logs for SAS and Malwarebytes.
     

    Attached Files:

  4. Anon-1e78cf5a69

    Anon-1e78cf5a69 Anonymized

    Followed the further directions. Included are avenger and MGTools logs.

    I am currently running MSN messenger to see if it starts sending unwanted messages again.

    My windows search function is still acting strange. When I open the function all I see is a blank window with no searchbar or search options. I included a screenshot of this as well. Canit be related to the malware issue?
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It may be related to what malware has down, and it may not be.

    Try the below to see if it helps!

    Re-register Jscript.dll and Vbscript.dll, see if that solves anything.

    1. Click Start, and then click Run.
    2. In the Open box, type regsvr32 jscript.dll, and then click OK.
    3. Click OK.
    4. Click Start, and then click Run.
    5. In the Open box, type regsvr32 vbscript.dll, and then click OK.
    6. Click OK.


    A couple items from the last fix did not get completely removed.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {060BB0AB-4B09-4C51-9ECB-9580A6D08D7F} - C:\WINDOWS\system32\vtUolKed.dll (file missing)
    O20 - Winlogon Notify: vtUolKed - vtUolKed.dll (file missing)


    After clicking Fix, exit HJT.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.

    Make sure you tell me how things are working now!
     
  6. Anon-1e78cf5a69

    Anon-1e78cf5a69 Anonymized

    Done. Here is the log.

    The search issue is still present.

    MSN Messenger has not resumed sending unwanted messages.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean now.

    Try the below. If this does not help, I suggest you post about this issue in the Software Forum.

    • Make sure your account has administrator permissions.
    • Click Start, click Run, type %systemroot%\inf and then click OK.
    • Locate the Srchasst.inf file.
    • Right-click the Srchasst.inf file, and then click Install.
    • This reinstalls the files that Search Companion uses.
    If you are not having any other malware problems, it is time to do our final steps:

    1. Uninstall COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter cmd and click OK to open a command prompt
      • Type cd Desktop at the command prompt and hit enter.
      • The prompt should change to show you are on at your Desktop folder now.
      • Now type cf /u and hit the enter key which should run ComboFix's uninstaller.
        • Note: The space between the cf and the /U, it must be there.
    2. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    3. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    4. After doing the above, you should work thru the below link:
     
  8. Anon-1e78cf5a69

    Anon-1e78cf5a69 Anonymized

    Many thanks for the help and the time.

    In regards to search function issues I will try as recomended or post new thread in Software forum.

    Again many thanks.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds