Please help! virus/pop-ups

Discussion in 'Malware Help (A Specialist Will Reply)' started by jl2122, Sep 26, 2006.

  1. jl2122

    jl2122 Private E-2

    Hi guys, there has been some problems with my computer. I've been getting popups and have no idea how to remove them. Also when i boot up my computer i get a prompt that says "error loading w51c5e03.dll the specified module could not be found.

    I've also gone through all the steps of scanning my computer with:
    Ccleaner, Microsoft Windows Malicious Software Removal, CounterSpy, Bitdefender, and PandaActiveScan.

    Also i have the logs to:
    getrunkey, shownew, counterspy, virtumonde fix, and hijackthis

    Please help!
     

    Attached Files:

  2. jl2122

    jl2122 Private E-2

    here are the other logs
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You did not follow all the directions in the READ ME.
    1. You did not uninstall the below as requested in step 0:
      • Viewpoint Manager (Remove Only)
      • Viewpoint Media Player
      • VSToolbar for Internet Explorer
    2. You did not install the version of Spybot specified in the READ ME and did not check against what you are already using. You have Spybot - Search & Destroy 1.3 (RC 3) which has not been used in almost 2 years.
    3. You did not download and install the current Sun Java version as recommended. And note your FireFox version is way out of date too.
    4. You did not complete step 7 and attach a HijackThis log. You also seem to have installed HijackThis improperly into the C:\Program Files base folder. You must move it into its own folder like C:\Program Files\HJT
    5. You also need to run MSconfig and select Normal Startup mode before using HijackThis.
    Thus, goto Add/Remove programs now and uninstall the below:
    • Viewpoint Manager (Remove Only)
    • Viewpoint Media Player
    • VSToolbar for Internet Explorer
    • Spybot - Search & Destroy 1.3 (RC 3)
    • Java 2 Runtime Environment, SE v1.4.2_05
    • Mozilla Firefox (1.0.7)
    Now REBOOT your PC! After reboot delete the C:\Program Files\Spybot - Search & Destroy folder.

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Now go back to the READ & RUN ME and follow the directions in step 4 for downloading, installing, and configuring the correct version of Spybot Search & Destroy. Then complete a scan with the new version of Spybot.

    Now make sure you have set Msconfig for Normal Startup before continuing with the below.

    Now attach a HijackThis log and a new log from ShowNew.


    Questions:
    1. Is CounterSpy a paid or free trial version?
    2. Is Ewido a paid or free trial version?
    3. Is SpySweeper a paid or free trial version?
     
    Last edited: Sep 27, 2006
  4. jl2122

    jl2122 Private E-2

    Sorry about that. I've uninstalled the listed programs and downloaded the newer versions of java, mozilla, and spybot.

    Also here are the new shownew and hijackthis logs.

    In regards to the questions

    1. Counterspy - free version
    2. Ewido - trial version
    3. Spysweeper - paid, but have not resubscribed

    Thanks for the help!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then uninstall CounterSpy and Ewido now before continuing!

    Also considered resubscribing to SpySweeper. It is a good program and you need realtime active protection like it provides.

    Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to the following key and take ownership of it (explained further down):

    HKEY_LOCAL_MACHINE\software\microsoft\mssmgr

    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the Menu
    • Select Take Ownership
    • Now leave RegistrarLite running and continue
    • Now run the REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate to HKEY_LOCAL_MACHINE\software\microsoft\mssmgr
    • Does the above mssmgr key still exist! If so, right click on it and select Delete.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    After completing ALL of the above instructions, continue here!

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of xxwww.dll once and then click the kill button. After you have killed all of the xxwww.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of xxwww.dll and kill it. (If you do not find the dll, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
    O2 - BHO: (no name) - {278B661A-14A8-D8B0-6AF4-03088B866149} - C:\WINDOWS\System32\unaoakg.dll (file missing)
    O2 - BHO: SSL encrypt - {746455FE-D059-47e7-AF0E-140E03F5A447} - C:\WINDOWS\System32\nslFF.dll
    O2 - BHO: (no name) - {AE032AB4-25F8-2CD7-31DA-243DE12E33CD} - C:\WINDOWS\Dhmzwjvn.dll (file missing)
    O2 - BHO: (no name) - {EF36A672-1104-4CA8-BF55-A4B72325701D} - C:\WINDOWS\System32\xxwww.dll
    O3 - Toolbar: Search - {849E7956-D52A-5978-3D62-8C05F5679140} - C:\WINDOWS\Dhmzwjvn.dll (file missing)
    O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
    O4 - HKLM\..\Run: [zggwajnaxrwpl] C:\WINDOWS\System32\lnnzrq.exe
    O4 - HKLM\..\Run: [xoteb495] RUNDLL32.EXE w51c5e03.dll,n 004eb4910000000251c5e03
    O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O15 - Trusted Zone: *.elitemediagroup.net
    O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgUS2404.exe
    O20 - Winlogon Notify: winiqr32 - winiqr32.dll (file missing)
    O20 - Winlogon Notify: xxwww - C:\WINDOWS\System32\xxwww.dll

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\JuLiCiouZ\Start Menu\Programs\Startup\TA_Start.lnk
    C:\Program Files\Common Files\{7071CDE7-0A19-1033-1203-020211270001}\Update.exe
    C:\Program Files\Common Files\{7071CDE7-0A19-1033-1203-020211270001}\services.dll
    C:\WINDOWS\Digital Signature 20040927.htm
    C:\WINDOWS\Justin.exe
    C:\WINDOWS\SnVsaWEgTGFt\mBpPuqH0n3IQ.vbs
    C:\WINDOWS\uninstall_nmon.vbs
    C:\WINDOWS\System32\lnnzrq.exe
    C:\WINDOWS\system32\mwinppes.exe
    C:\WINDOWS\system32\unaoakg.dll
    C:\WINDOWS\system32\w51c5e03.dll
    C:\WINDOWS\system32\__delete_on_reboot__o_o_d_s_r_e_g_n_._e_x_e_
    C:\WINDOWS\system32\mwinppes.exe
    C:\WINDOWS\system32\oeeimudu.exe
    C:\WINDOWS\system32\awtuv.dll
    C:\WINDOWS\system32\cyltrqwg.dll
    C:\WINDOWS\system32\ddcab.dll
    C:\WINDOWS\system32\ddcbx.dll
    C:\WINDOWS\system32\ddcya.dll
    C:\WINDOWS\system32\dwdsregt.exe
    C:\WINDOWS\system32\gebxw.dll
    C:\WINDOWS\system32\geebb.dll
    C:\WINDOWS\system32\iifff.dll
    C:\WINDOWS\system32\jkhgf.dll
    C:\WINDOWS\system32\jkhih.dll
    C:\WINDOWS\system32\khfcc.dll
    C:\WINDOWS\system32\ktmliuoa.dll
    C:\WINDOWS\system32\ljhee.dll
    C:\WINDOWS\system32\mljki.dll
    C:\WINDOWS\system32\mllml.dll
    C:\WINDOWS\system32\nnlkh.dll
    C:\WINDOWS\system32\nslFF.dll
    C:\WINDOWS\system32\oeeimudu.exe
    C:\WINDOWS\system32\qomnl.dll
    C:\WINDOWS\system32\rqrpq.dll
    C:\WINDOWS\system32\sstqp.dll
    C:\WINDOWS\system32\urspo.dll
    C:\WINDOWS\system32\ursqo.dll
    C:\WINDOWS\system32\xxwww.dll
    C:\WINDOWS\system32\xxyvt.dll
    C:\WINDOWS\system32\yayvw.dll
    C:\WINDOWS\system32\wwwxx.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete it if found:
    C:\Program Files\BullsEye Network
    C:\Program Files\Common Files\{7071CDE7-0A19-1033-1203-020211270001}

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\JuLiCiouZ\Local Settings\Temp

    Now attach a new HJT log and tell me how the steps went.

    Also attach a new log from ShowNew and a new log from GetRunKey.

    Make sure you tell me how things are working now!
     
  6. jl2122

    jl2122 Private E-2

    Alright! I've uninstalled CounterSpy and Ewido. Ran the registry patch and recieved no error messages. After this I rebooted my computer in normal mode and the prompt that started up in the beginning didn't show up anymore.

    After that, I ran Process Explorer and deleted all the xxwww.dll in winlogon.exe and explorer.exe. Then I ran HijackThis and fixed the lines you listed for me. Reset the web settings, changed my homepage address, deleted cookies and files. Then I double-clicked the fixme.reg file i made.

    Ran Pocket Killbox and folowwed those directions. Everything went well there, did not receive any prompts and rebooted my computer again.

    I found only this folder:
    C:\Program Files\Common Files\{7071CDE7-0A19-1033-1203-020211270001}
    and deleted it.

    Deleted all the temp files.

    I've attached HijackThis.log and logs from ShowNew and GetRunKey.

    And everything seems to be working perfectly at the moment! :D

    I really do appreciate all the help you have given me!!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Okay things look good! Now let's do some final cleanup.

    Run Pocket Killbox and select File, Cleanup, Delete All Backups!

    Also the fixme.reg and fixWLK.reg files from your Desktop.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link. You need to get an antivirus, antispyware blocking tool (like Spy Sweeper - looks like you uninstall it too????) and a software firewall install ASAP!


    How to Protect yourself from malware!
     
  8. jl2122

    jl2122 Private E-2

    Thanks! i'll go through all these steps when i get home! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds