Pipas.A Removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by microlion, Jan 7, 2006.

  1. microlion

    microlion Private E-2

    Hi,

    Need to remove Pipas.A. I have been unable to remove this... Spybot 1.4 runs real slow and then reports Pipas.A infection.. I have run all the items on your forum website checklist... I am attaching results from scans and HighJackthis pgm. Any help would be greatly appreciated...

    I could not run the scans in safe mode....

    I have not reset system restore yet...


    Thanks,

    Dan

    Here are reports...

    Inline logs attached!
     

    Attached Files:

    Last edited by a moderator: Jan 7, 2006
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  3. microlion

    microlion Private E-2

    Hi..Thanks... I have already ran that and it still shows up when running Norton Internet Security 2006 Scan..

    Dan
     
  4. microlion

    microlion Private E-2

    Opps, sorry.. a little mushy this morning.. up most of the night with this problem... I was thinking of Avira

    Dan
     
  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    After you complete the Ewido scan, reboot and attach this log with a fresh HJT log.
     
  6. microlion

    microlion Private E-2

    Thanks running now...
     
  7. microlion

    microlion Private E-2

    Here are the results of the Ewido scan and a new HighJackthis log...

    Dan

    Inline logs attached!
     

    Attached Files:

    Last edited by a moderator: Jan 7, 2006
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    From now on please ATTACH all logs to your post using the Manage Attachments feature.

    Reboot into Safe Mode and run Ewido once more to see if can clean those found infections.
     
  9. microlion

    microlion Private E-2

    OK.. thanks for the correction.. will be right back..
     
  10. microlion

    microlion Private E-2

    Just a quick question....

    I have different logins, should I run Ewido under each of the different logins..

    Dan
     
  11. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You should run the READ ME for each account as each account has it's own settings and files.

    Run Ewido in safe mode under the Administrator account if possible.
     
  12. microlion

    microlion Private E-2

    ok.. will do and then repost.. Evido and HiJack logs..
     
  13. microlion

    microlion Private E-2

    Ewido said on the screen that it found 4 and fixed.. here are the logs from Ewido and HighJack this..

    Thanks,

    Dan
     

    Attached Files:

  14. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    This HJT log appears to be from safe mode, if you will attach a fresh one from normal mode.
     
  15. microlion

    microlion Private E-2

    ok...here it is....

    Dan
     

    Attached Files:

  16. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add or Remove Programs for the following and Uninstall them if found:

    Ewido

    NEXT:
    Run CCleaner to clean up cookies and temp files.

    Run full scans with Ad-Aware SE & Spybot S&D and have both programs fix what they find.
    Note: Remember to get all updates before doing the scans.


    Download FixWareout by Lonny and save it to your Desktop.

    Please locate your download of FixWareout and INSTALL it.
    Be sure that Run fixit is checked.
    Click Finish to begin the fix.
    Follow the prompts and Reboot when asked to do so.
    Upon Reboot, follow the prompts and HijackThis should open.

    After HJT opens, Click Scan and then Check the boxes for the following, if they should remain:

    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u

    O15 - Trusted Zone: http://www.adobe.com
    O15 - Trusted Zone: http://tucson.cox.net

    O17 - HKLM\System\CCS\Services\Tcpip\..\{E337761F-62E0-475D-A7DF-6EAB05EDF5C9}: NameServer = 85.255.114.10,85.255.112.61

    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After you complete the above, reboot and attach a fresh HJT log along with the log from the Fix wareout utility. (C:\fixwareout\report.txt)
     
  17. microlion

    microlion Private E-2

    ok.. thanks will do as you suggest.. I am in the step of doing the Spybot Scan, but running will slow will post the items as soon as they are done...

    Thanks,

    Dan
     
  18. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Will be awaiting results!
     
  19. microlion

    microlion Private E-2

    Hi,

    When I ran Spybot Pipas.A showed up agin.. Selected fix.. did as you suggesetd Ran FixWareout and two logs are attached.. one before and one after fix. Also ran HighJackThis and log is attached..

    Thanks

    Dan
     

    Attached Files:

  20. microlion

    microlion Private E-2

    Could not get the 2nd report to post as it is the same as the first.. it states that it has already been posted...
     
  21. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download Pocket KillBox
    • Save it to your desktop or a place easy to find.
    • Do not run it yet
    Now scan with HijackThis and Check the Boxes for the following:

    O4 - HKLM\..\Run: [dmdsg.exe] C:\WINDOWS\system32\dmdsg.exe

    Make sure All Browser Windows are Closed when you Click FIX.

    NEXT:
    Run CCleaner to clean up cookies and temp files.


    Locate PocketKillbox
    (Procede with this step even if they do not show in blue)

    Now, Copy and Paste C:\WINDOWS\system32\dmdsg.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your PC to reboot.

    • If you get an error message about Pending Operations, just reboot your computer manually.

    After you complete the above, reboot into Safe Mode. Run the Fix wareout utility once more and attach this log. Close HJT when it opens.
     
  22. microlion

    microlion Private E-2

    Good morning...

    Here is the Fixwareout log...

    Dan
     

    Attached Files:

  23. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Attach a fresh HJT log from normal mode.
     
  24. microlion

    microlion Private E-2

    Here is HighJackThis log..

    Thanks
     

    Attached Files:

  25. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    microlion,

    You seem to be rebooting after attaching these logs, attach a fresh HJT log and DO NOT REBOOT until you hear from me.
     
  26. microlion

    microlion Private E-2

  27. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Attach a current HJT log and wait for my reply before you reboot as this renames the infected file and makes it harder to remove.
     
  28. microlion

    microlion Private E-2

    Here is the log file.. awaiting instructions...
     

    Attached Files:

  29. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Scan with HijackThis and Check the Boxes for the following:

    O4 - HKLM\..\Run: [dmnqz.exe] C:\WINDOWS\system32\dmnqz.exe

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NEXT:
    Run CCleaner to clean up cookies and temp files.


    Locate PocketKillbox
    (Procede with this step even if they do not show in blue)

    Now, Copy and Paste C:\WINDOWS\system32\dmnqz.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your PC to reboot.

    • If you get an error message about Pending Operations, just reboot your computer manually.
    After you complete the above, reboot to SAFE MODE and run the Fix wareout utility once more, close HJT when it pops up. Attach this log to your next post with a fresh HJT log after you have rebooted back to normal mode after running the utility.
     
  30. microlion

    microlion Private E-2

    Here are the logs...

    Thanks...
     

    Attached Files:

  31. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add or Remove Programs for the following and Uninstall them if found:

    Microsoft AntiSpyware

    Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )\

    O4 - HKLM\..\Run: [dmnqz.exe] C:\WINDOWS\system32\dmnqz.exe

    Next, you will be entering items into Pocket KillBox. Please select the “Delete on Reboot” Option. Copy&Paste each of the file names listed below into the box one by one, making sure Delete on Reboot is Checked for each entry. Click the Red X for each entry, but DO NOT Allow your machine to be rebooted until the last item has been entered:

    ** Note: For any of the .dll files, check the Unregister .dll Before Deleting box as well. If this option is not enabled, don't worry about it.

    • If you get an error message about Pending Operations, just reboot your computer manually.
    After you complete the above, attach a fresh HJT log.
     
  32. microlion

    microlion Private E-2

    Here is the latest HJT log.

    Thanks

    Dan
     

    Attached Files:

  33. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    The HJT log looks clean, to assure your clean lets run the below.

    Please see the below thread on how to run WinPfind and attach the log.
     
  34. microlion

    microlion Private E-2

    Running now...

    Thanks

    Dan
     
  35. microlion

    microlion Private E-2

    Here is the WinPFind Log

    Thanks

    Dan
     

    Attached Files:

  36. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Looks good, only one thing that bothers me. Click Start > Run > type in regedit

    Navigate to the following key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

    Right click on Ratings and select EXPORT. Save this to your desktop, ZIP it and attach it to your next post.
     
  37. microlion

    microlion Private E-2

    Ratings is attached.. did not zip only 2k..

    Thanks

    Dan
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You cannot attach .reg files that is why BJ asked you to ZIP it. ZIP it then upload it as an attachment.
     
  39. microlion

    microlion Private E-2

    Sorry on it's way...
     
  40. microlion

    microlion Private E-2

    Here is Ratings.zip

    Thanks, sorry about not following directions.
     

    Attached Files:

  41. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fix.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fix.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    After you complete the above, reboot and let me know how things are running and if any problems remain.
     
  42. microlion

    microlion Private E-2

    I left the machine running...


    Thanks.. I will do this later as I am away from the computer until later this evening... Do you think it wise it reinstall MS Antispyware or run without it...?

    Also, I have Spy Catcher (full Version) to install if you think it wise....

    Should I run Spybot and see if Pipas.A shows up..?

    Thanks again

    Dan
     
  43. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    MSAS is still in Beta, I personally dont use it because its a resource hog and a few other reasons. It's up to you whether you install it or not. Spy Catcher I cant judge because I've never used it, but I believe there are better.

    Yes, run another scan with Spybot, see if it detects the entry. Run the reg fix in my previous post first, then attach the Spybot log.
     
  44. microlion

    microlion Private E-2

    Ok.. will do and let you know this evening...

    Thanks..
     
  45. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I will be awaiting results.
     
  46. microlion

    microlion Private E-2

    I do beleive the machine is clean of Pipas.A..

    I am attaching Spybot report and HighJackthis Report..

    I have just one more question about System Restore.. Should I disable it and then turn it back on to clear it out..

    Also,, I can not express how much I appreciate your help.....

    Thanks....

    Dan
     

    Attached Files:

  47. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your logs are clean!

    You can disable and re-enable system restore if you like. I requested it be done a few steps back but it probably wouldnt hurt to do it again.

    If things are running fine, see this article on How to Protect yourself from malware!
     
  48. microlion

    microlion Private E-2

    Thanks for your help......

    I don't how else to show my appreciation..the interchange was great....


    Dan
     
  49. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your Welcome!

    Surf Safely:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds