Please, I need serious help.

Discussion in 'Malware Help (A Specialist Will Reply)' started by charliethered, Dec 3, 2007.

  1. charliethered

    charliethered Private E-2

    This situation is terrible. I made the mistake of downloading a .rar file yesterday around noon and as soon as I extracted it, my computer went haywire. I've been trying to fix it for the past fifteen hours.

    Almost immediately I began Malaware.exe pop ups and Udefender and so on and so forth. I tried posting at another forum but no one responded. After a restart I found that my task bar and start menu were gone and I could not right click the wallpaper. As a result, I'm having to do everything through task manager, and even then my options are still limited.

    So far I have run every possible Spyware and Anti-virus scan I could.

    I've run CCleaner, set up ms config for normal install, I'm running PeerGuardian due to all of the people trying to access my computer, and updated the latest log of HiJack This!

    In addition, I've run multiple scans with AVG, Spyboy S&D, Spyhunter (which was a rip off), SmitFraudfix.exe, Deckard's System Scanner, and gotten mixed results from all of them.

    I tried to use ComboFix but after the scan my computer said the script failed.

    I've tried running the command prompts for Explorer.exe with no luck...it appears to be completely gone from my system.

    Here are some of the things that happened before explorer disappeared so maybe you can have a better idea as to what we're dealing with. I will post the Deckard System Scan, VundoFix, and HiJackThis! logs immediately afterward.

    Win32.Murlo.ff.rtk (Spybot S&D found this)
    Win32.Tiny-II
    Win32.Virtob
    Win32.Agent-NMK
    Zlob trojan
    MalAware
    iTunes randomly trying to download onto my computer before the crash
    Multiple suspicious and aggressive anti-spyware ads that were hogging my resources.
    And lastly, the disappearance of explorer.exe

    Attached here are the logs for HiJackThis, Deckard System Scanner, and the latest from VundoFix (which supposedly already cleared everything out).

    The ones to look out for are e404 (i think that's the zlob), malaware, and any suspicious looking .dll. It's clear to me that some registry items have been changed and explorer.exe is nowhere to be seen. If you fellas could just help me get rid of this thing and get explorer back on here, I would owe you my life. My career is already on the line because of this.

    EDIT - Sorry, MGLogs are now attached and ready for viewing.
     

    Attached Files:

    Last edited: Dec 3, 2007
  2. charliethered

    charliethered Private E-2

    This is not a bump...the situation has changed.

    The virus is Virtob...it has infected every system file i've got. Everything is quarantined...but what do I do next?
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0"
    Java 2 Runtime Environment, SE v1.4.2
    Viewpoint Manager (Remove Only)"
    Viewpoint Media Player

    Reboot and install:
    Java Runtime 6

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  4. charliethered

    charliethered Private E-2

    Is there any other way I can avenger besides a zip? My computer is now saying that I do not have the necessary permissions to run this. It says the same for internet explorer and appwiz.cpl, also.

    Is there another way I can delete those files? And how can I fix my registry?

    I cannot run MGTools either...here's the new HiJack this report.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't understand ....you were able to attach the MGlogs.zip in your first post ...are you unable to do "run the C:\MGtools\GetLogs.bat file by double clicking on it" this now?

    Also..the HJT log that you attached is not the one in the MGTools folder ..its from your desktop and not what we want.

    As to the files and folders in the avenger fix ...you can always try using windows explorer to find and delete them.

    Download this file to your desktop - Combofix.exe
    Double click combofix.exe & follow the prompts.
    When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Then try running the MGTools\GetLogs.bat again and attach the zip with the combofix log.
     
  6. charliethered

    charliethered Private E-2

    Now, for many of these programs, it is saying that I may not have the user access level for programs such Internet Explorer, Notepad, and Winzip/Winrar. In addition, the Winrar icons are missing.


    My options are very limited here and I'm sorry if it seems like I'm being uncooperative. My computer is being very picky about the things I can and cannot do.

    Upon trying to load ComboFix I receive the same message...and now MGTools won't work either.

    C:\WINDOWS\System32\cmd.exe

    "Windows cannot access the specified path, file, or device. You may not have the appropriate permissions to access this item."

    Remember, I don't have Windows Explorer right now. It seems to completely gone, and the only remnant I've found of it was an Virtob infected explorer.exe in my Windows System directory under DLLCACHE.

    I'm going to delete those files manually...is there a way I can make those fixes to the registry without using notepad?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is becoming a very common problem these days for malware to change SeDebugPrivilege on administrator type accounts. They do this to prevent you from running various tools to help in the removal of malware.

    Download SeDebug-Restore
    Save to your desktop and double click to run.

    Now see if you can run those items.
     
  8. charliethered

    charliethered Private E-2

    Thanks for all of the help TimW.

    Is there supposed to be a prompt for this program, because all I get is a black dos screen that pops up and disappears rather quickly...
     
  9. charliethered

    charliethered Private E-2

    Sorry, I just realized this.

    Avast has quarantined all of my files from the SYSTEM32/DLLCACHE directory due to all of them being infected by Virtob.

    Would this be causing the problems, and if so, should I release them from quarantine?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right click any of the folder icons (ComboFix, Notepad, etc.) and go to properties ...do you have a security tab? If so ...is your user account listed with full permissions?
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes.....release them and turn off avast when you do the fixes!!

    Only re-enable it when you get back on the web to attach your resulting logs.
     
  12. charliethered

    charliethered Private E-2

    No security tab shown in either, TimW, and I also checked internet explorer and nothing there either.

    EDIT - Alright Tim, those files are restored and Avast is closed down.

    Still cannot access any of the mentioned applications, however.

    Christ, I can't even access regedit.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your XP cd?

    Can you still run HJT ...if so lets do this:

    run HijackThis and Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {FED51DF2-9644-4C58-9104-90244EDD6EEC} - C:\WINDOWS\system32\ljjklif.dll
    O4 - HKUS\S-1-5-21-1687860382-3441232167-3212832416-1007\..\Run: [Sonic RecordNow!] (User '?')
    O4 - HKUS\S-1-5-21-1687860382-3441232167-3212832416-1007\..\RunOnce: [gi1294448309] "C:\DOCUME~1\HOME\LOCALS~1\Temp\giK0NM3C.exe" /resume:"C:\DOCUME~1\HOME\LOCALS~1\Temp\2QK0N5U2" /exename:"C:\Documents and Settings\HOME\Desktop\SpyHunter-3.2.0000-Installer.exe" (User '?')
    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\E404 Helper
    C:\Program Files\Gsfxudgt
    C:\Program Files\mlypuhux

    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\WINDOWS\SYSTEM32\e404d.dll
    C:\WINDOWS\SYSTEM32\hggghge.dll
    C:\WINDOWS\SYSTEM32\ljjklif.dll
    C:\Documents and Settings\All Users\Application Data\juxedozg.dll
    C:\Program Files\mlypuhux\qfqdqdmn.dll
    C:\Program Files\Gsfxudgt\jpnkyerf.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Tell me what happens.
     
  14. charliethered

    charliethered Private E-2

    Sorry TimK...your help was great...but unfortunately, I think I'm just going to reformat the disk.

    I'm from a different computer right now...before I had the chance to see your tips, I was automatically logged off of my account. When I tried to log on again, I would just get booted.

    After trying again in Safe Mode with the Administrative account, I was no longer able to run task manager. I don't know what kind of virus this is (no site I've looked at made virtob sound this bad), but it seems like every possible step towards a solution I take, the system just acts worse and worse.

    If you have any final recommendations, I'd appreciate it, but this is looking pretty bleak to me.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    My suggestion would be to do a repair installation before you give up .....then see if you can start the cleaning again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds