Please Help Me Save My PC!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by drukore, Jan 29, 2008.

  1. drukore

    drukore Private E-2

    Major problem here. First off thank you for reading.

    Yesterday evening I opened a keygen that I scanned and was deemed save by AVG. The hell was unleashed. The Smitfraud C.Core bug went to town on my IE and from there it systematically punched and kicked my PC untill the Virtumonde bug was sent in to finish the job.

    This is where I stand right now.

    I can only boot into safe mode.
    Booting into normal mode no windows will populate. No My Documents, no My Computer, no folders or programs. Thus, running anything is impossible.

    Running into safe mode I can run Spybot Search and Destroy, HJT and other small programs.....but nothing past that.

    This computer is where I house nearly 24 gigs of multimedia for my career. While I have some of it backed up, newer projects that are half done are not.

    Please help. I'll the HJT log from safe mode. I would do the other tasks in the READ ME FIRST section but a lot of them won't work with my computer in it's current state.

    Anyone? Thank you in advance.
     

    Attached Files:

  2. drukore

    drukore Private E-2

    out of curiosity, how long does it normally take to get a reply from a Mod on this stuff? for work purposes I'm desperate for some help.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is no specific time frame. It depends on how busy things are and how many of us are around to help out. For the last 3 months, the forums are extremely busy and there are only a couple of us posting regularly.

    This last post you made cost you more than a day of additional waiting time since you lost your place in the queue. This explained in theDon't Bump! It Only Hurts You!!! sticky thread.


    You need to try and do as much of the READ & RUN ME FIRST. Malware Removal Guide sticky thread as possible and you need to explain what runs and what does not run and give us any error messages. Our ability to help you is limited by you ability to help us help you. If you could run HijackThis, there are other steps in those instructions that you can follow. You should probably be able to run the MGtools procedure that was requested. I assume you ran HijackThis via the Task Manager. You should be able to do the same to get access to other programs to copy files to your PC. If you cannot do this, I will give you something to try below but odds are that it will not work since HijackThis cannot normally fix most of the problems related to Vundo and SmitFraud because much of what the infection has done does not appear in a HijackThis log.

    Try the below to get started.


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: 0 - {6643C30F-D94D-4855-DD9E-E61CA4B582B7} - C:\Program Files\ComPlus Applications\lavuqaf.dll (file missing)
    O2 - BHO: (no name) - {8428064f-f21c-402e-879b-21a0ffa874ff} - C:\WINDOWS\system32\qttdncy.dll
    O2 - BHO: (no name) - {98663E21-9CCE-4CF6-863C-911A9523A66F} - C:\WINDOWS\system32\ssqnmmk.dll
    O2 - BHO: {892263b0-e961-2239-b0c4-7b055abce0a9} - {9a0ecba5-50b7-4c0b-9322-169e0b362298} - C:\WINDOWS\system32\rgwwehgg.dll
    O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\taevhccp.dll
    O2 - BHO: (no name) - {CE19D479-549D-4F55-805A-D5F73C81C89C} - C:\WINDOWS\system32\vtstr.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    O4 - HKLM\..\Run: [ipmon] ipmon.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [8c08184f] rundll32.exe "C:\WINDOWS\system32\qgxiqjyr.dll",b
    O4 - HKCU\..\Run: [DDC] C:\WINDOWS\system32\gugwfppi.exe
    O20 - Winlogon Notify: ssqnmmk - C:\WINDOWS\SYSTEM32\ssqnmmk.dll
    O20 - Winlogon Notify: taevhccp - C:\WINDOWS\SYSTEM32\taevhccp.dll

    After clicking Fix, exit HJT.
    Now reboot again into safe mode and use Windows Explorer to delete the below files:
    C:\WINDOWS\system32\gugwfppi.exe
    C:\WINDOWS\system32\ipmon.exe
    C:\WINDOWS\system32\qttdncy.dll
    C:\WINDOWS\system32\rgwwehgg.dll
    C:\WINDOWS\SYSTEM32\ssqnmmk.dll
    C:\WINDOWS\SYSTEM32\taevhccp.dll
    C:\WINDOWS\system32\vtstr.dll

    You may have problems finding or deleting some of the above. This is why the READ & RUN ME and being able to run other steps and download other tools is important.
    At anyrate after attempting to delete the above files and no mattter what you find or get deleted, see if you can boot in normal mode.
    If you can boot normally, get started on all steps of the READ & RUN ME immediately.
     
  4. drukore

    drukore Private E-2

    Thanks for responding first off. I know you all are very busy with a million requests. And from what it looks like, everyone and their mom is getting the Smitfraud C.Core.Services. Hey, LIKE ME!

    I went ahead and did some work on the READ ME FIRST and looks like I was able to get rid of the Virtumonde bug. At least I hope. It was appearing like gangbusters on Spybot S&D but after a bunch of scans and reading some threads, I think I got rid of it.....still Smitfraud remains.

    I followed your instructions and didn't find much in the way of the .dll's so I backed tracked, did the READ ME FIRST steps...and here is where my PC stands.

    I was able to run all this in normal mode. My PC runs fine untill I go online. Then the popups strike again. My headache ensues.

    Ran Combofix - attached the log for you.
    C:\temp\tn3
    C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete
    were the two first things I noticed.

    Ran Spybot S&D
    Found - Smitfraud C.Core.Services.
    In normal mode it won't delete, in safe mode it will. This has been ongoing since I first posted.

    Ran AVG Spyware
    "Dropper.Agent.dbj" that has been consistant the last few days. Didn't pop up this scan though.
    Instead I got these beauties. I quarantined them all.
    "Downloader.PurityScan.fj"
    "Trojan.Agent.edq"
    "Downloader.Agent.hvj"
    "Downloader.Agent'hvx"
    "Downloader.vb.cge"

    Ran MGtools - Attached zip file.

    Hope this helps. I await your next commands. Thanks again for your help with this.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below does not belong on your Desktop. See the READ ME. It should be C:\MGtools.exe
    C:\Documents and Settings\Drukore\Desktop\MGtools.exe

    However ComboFix.exe MUST be on your Desktop and you did not save it there. You must do this now or you will not be able to do the following steps.

    Run this Disable/Remove Windows Messenger to remove
    Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: 0 - {6643C30F-D94D-4855-DD9E-E61CA4B582B7} - C:\Program Files\ComPlus Applications\lavuqaf.dll (file missing)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O20 - Winlogon Notify: efcyvur - C:\WINDOWS\
    O20 - Winlogon Notify: mllmj - C:\WINDOWS\
    O20 - Winlogon Notify: pmnno - C:\WINDOWS\
    O20 - Winlogon Notify: scom - C:\WINDOWS\

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    Driver::
    mff
    hvpyxiwx
    iutbuvhw
     
    File::
    C:\vqrcgfml.txt
    C:\WINDOWS\system32\drivers\core.cache.dsk
    C:\WINDOWS\system32\drivers\mff.sys
    C:\Program Files\kqxirdft.txt
    C:\Program Files\analyse.exe.exe
    C:\DOCUME~1\Drukore\LOCALS~1\Temp\~DPC3.exe
    C:\WINDOWS\system32\1321A260DA.sys
    C:\WINDOWS\system32\E8DB5BBB53.sys
    C:\WINDOWS\system32\drivers\hvpyxiwx.sys
     
    Folder::
    C:\TrustedAntivirus
    C:\WINDOWS\system32\comg9
    C:\WINDOWS\system32\ets1
    C:\WINDOWS\system32\nGpxx01
    C:\WINDOWS\system32\nip4
    C:\WINDOWS\system32\wnis6
    C:\temp\tn3
    C:\Program Files\Web Buying
     
    Registry::
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\efcyvur]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mllmj]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnno]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java
    Runtime Environment


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. drukore

    drukore Private E-2

    Alright, so here's the deal!

    What I did:
    Made sure I moved MGtools.exe off the desktop.
    Put Combofix.exe on desktop

    I didn't find Windows Messenger anywhere. I looked through add/remove programs
    and it wasn't there. The only thing I found from it was a folder in program files that gave
    a "you shouldn't delete this folder" type message. So I left it. But I didn't see it as
    being installed anywhere.

    Ran all steps you suggested after which.

    Java was already installed as newest version so I just reinstalled it.

    attached requested logs.

    Also, because I'm a moron, I've been using IE instead of Firefox, and I've heard that Firefox is a safer browser. So I installed that....
    SO FAR SO GOOD! no pop ups or any problems...looks like we fixed it....

    My last question is about Spyware Terminator. I have it, and I'm using it for a real time scanner...what would you suggest I use however as far as the best program to be able to match the capabilities of it.....like, what would you use? Just looking for some quick advice...

    THANK YOU! Your help is #1! I can go back to working on my tasks. Without you I'd be throwing my PC out the window or reformatting the whole darn thing. You rock man.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Spyware Terminator is okay. It is even one of the tools in the link I will give you below on How to protect yourself. This link will give you a whole bunch of recommended things to do and use. Personally I would not have installed the Crawler Toolbar with Web Security Guard with Spyware Terminator. You could uninstall the Toolbar unless you happen to like it.

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds