pop-ups, trojans, virus; requesting help

Discussion in 'Malware Help (A Specialist Will Reply)' started by semaj, Dec 7, 2007.

  1. semaj

    semaj Private E-2

    Like others in this forum, my machine has been compromised. It appears that trojan.dropper and trojan.vundo (spelling?) have been causing problems, as well as a program called outerinfo (and probably others???). I have attempted to follow the READ & RUN ME FIRST sticky instructions, but have had some problems that I feel warrant an immediate post. I have followed all instructions listed in step one of the sticky, except for the very last part (run CCleaner on each account). At first, I just had pop-up problems. Then Symantec's autoprotect function became permanently disabled. Then a missing DLL file error window started popping up at boot-up. Now, as I try to run CCleaner on all accounts, some of my user accounts will boot up, but no icons (or start menu) will be visible--just wallpaper and a mouse pointer. Since I cannot run CCleaner on these accounts, I thought maybe I should just post my problem and politely request some help. Some other obvious symptoms include: very, very slow running computer, apparently high CPU usage, and no matter how many times I run Symantec and SpyBot, the viruses always seem to come back. I downloaded a vundo fix program from Symantec, which helped temporarily. The computer is now disconnected from the internet (and my network); my attempt to isolate the machine and stop the infections. I can reconnect anytime if necessary. Any suggestions?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Just continue thru all steps doing what you can. And tell us when you come back what you could and could not do. Attach the requested logs when you come back.

    Note: If your other user accounts are infected, they will also need to be cleaned but we must work on only one account at a time to avoid confusion. When we finish the first I will give you abbreviated steps to run on the next one.
     
  3. semaj

    semaj Private E-2

    Thank you for the reply. I trudged through the process today, having to reboot many times (when I had no icons or when system just locked up).

    Okay, here is what I have done:
    1) I think that all house cleaning and setup has been performed on at least one user account. Some items on the list I was able to perform on all user accounts, others I was not not.
    2) Downloaded and/or ran the following tools in this order:
    CCleaner, SpyBot-S&D, Symantec (AV program that was already installed on the machine), Virtumonde aka Trojan Vundo Removal tool, combofix.exe, and MGtools.exe.

    Results:
    1) SpyBot and Symantec both identified Vundo on the machine I deleted the files that these programs isolated as associated with Vundo.
    2) Ran Virtumonde aka Trojan Vundo Removal. Apparently removed problem files (VundoFix.txt attached).
    3) Ran combofix.exe and MGtools.exe; associated files attached (ComboFix.txt and MGlogs.zip). An error window popped up while MGtools ran, but I didn't make note of what it said and MGtools appeared to finish its processes.
    4) Most of the problems listed in my original thread seem to be fixed. However, the Autoprotect funtion on Symantec is still disabled and cannot be enabled. When I attempt to enable Autoprotect, the error messgae reads "Symantec AntiVirus Autoprotect failed to load".

    Forgive me for being paranoid, but I'm not convinved I'm in the clear yet, especially since Symantec is not functioning properly. Please let me know what you think after reading over the attached files. Problems began to manifest about two weeks ago (Thanksgiving week).

    Thanks in advance!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O20 - Winlogon Notify: jkkklmm - jkkklmm.dll (file missing)

    After clicking Fix, exit HJT.

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!

    If you still have issues with Norton, you may need to uninstall, reboot, run the below:

    Norton Removal Tool (SymNRT)

    Reboot again, and then reinstall. DO NOT skip the above mentioned reboots. If this does not work, speak to Symantec or get a better antivirus program.
     
  5. semaj

    semaj Private E-2

    Thanks for your quick and helpful reply!

    I have followed the steps that you lsited in your previous post:
    1) Uninstalled Java - no apparent problems.
    2) Ran HJT as suggested. However, I could not select the two lines that begin with 09 because I didn't see them. The other lines I found, selected, and fixed.
    3) Ran Disable/Remove Windows Messenger - selected option to remove from machine, no apparent problems.
    4) Downloaded/ran Avenger as instructed - no apparent problems (log file attached).
    5) Installed current version of Sun Java. I forgot to install this after running Avenger (as instructed). In fact, I did this step last. Is that OK? No apparent problems.
    6) Run Ccleaner - no apparent problems.
    7) Run GetLogs.bat - (log file(s) attached). An error message came up again when running. This time I wrote it down: It said: "ProcessDLL.exe - Application Error. The application failed to initialize properly (0xc0000135). Click on OK to terminate application." I don't know what this means exactly, but thought I should include it.
    8) Norton still cannot load Autoprotect. I will uninstall and reinstall as instructed ... or I may switch to a better AV program, as suggested. I can take care of this on my own - I just didn't know if it was the work of some kind of Malware.

    I am back online and things seeme to be going well so far. However, I will cautiously wait for your response after you have time to look things over.

    Thanks again!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It just means that you never installed the Microsoft .NET Framework updates from Windows Update.

    It could be the end result of malware but Norton appears to be to easy to break and sometime stays broken which is not good.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps. You will see links for very good free antivirus programs in the link in the last step.
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  7. semaj

    semaj Private E-2

    My computer appears to be back to normal -- I no longer hesitate to connect the network cable! I have already been working on the "How to Protect Yourself ...." link that you supplied.

    I do have one quick quesiton:
    In your original post you mentioned that I may have to clear out the other accounts on the computer separately. The other accounts seem to be working properly now, but you are the expert: Since the logs were clean, does that mean the whole computer is clean or just the one account that I've been working in? I'm just trying to be thorough.

    Once again, Thank you!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some aspects of the scans are verifying the whole computer (meaning it will cover all user accounts), however certain aspects are only for the account that is running the scan. Thus it is possibly that the other accounts could have to be clean; however, there would almost certainly be less to do than in the first account.

    If you want to check, then log into a different user account (pick one) and then run the below and attach the log.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created
     
  9. semaj

    semaj Private E-2

    Alright, I ran GetLogs.bat and attached the MGlogs.zip file ... and actually, I noticed one pop-up while navigating to the MG website. So I suspect that this computer may still be compromised. Please let me know what you find when you have a chance to look the logs over.
    Thank you.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you have a PurityScan infection in this user account. We will need to run ComboFix and then get new logs.


    Download this file - combofix.exe
    1. Double click combofix.exe & follow the prompts.
    2. When finished, it will produce a log ( C:\combofix.txt ) for you. Attach this log to your next reply See: HOW TO: Attach Items To Your Post
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from ComboFix.

    Make sure you tell me how things are working now!
     
  11. semaj

    semaj Private E-2

    I ran combofix and getlogs. The log files are attached. Things seem better for this account -- no more pop-ups. Please let me know how the logs look when you have time.
    Assuming that the logs are now clean, I'd like to do the same for the last two user accounts on this machine. Is that alright?
    Thanks.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKCU\..\Run: [Ncao] "C:\DOCUME~1\WAGEGR~2\APPLIC~1\ICROSO~1.NET\ntvdm.exe" -vt yazb
    O4 - HKCU\..\Run: [Eqohcby] "C:\Program Files\?asks\n?tdde.exe"
    O4 - HKCU\..\Run: [Qezfi] "C:\Documents and Settings\Wage Grade2\Application Data\F?nts\r?gedit.exe"

    After clicking Fix, exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.

    Make sure you tell me how things are working for this user account! If this account is okay now, move on to the next account and do all of what is in message # 10 below.
     
  13. semaj

    semaj Private E-2

    I have carried out the steps you listed, with no apparent problems. I have attached the MGlogs from the current account that we have been working in, but titled it MGlogsOLD to reduce confusion. This account now appears to be working properly.

    Then, I went to the next account and followed the steps listed in post #10, as instructed. I attached the combofix log as well as the new MGlogs file that resulted from running GetLogs.bat. The logs for this new account are titled MGlogsNEW.

    So, to recap:
    1) MGlogsOLD is from the current account that we have been working in.
    2) MGlogsNEW and the combofix log are from the new account that we have not yet worked in.
    I renamed the MGlog.zip files to reduce confusion and because I thought the new file might overwrite the old file if I didn't change its name.

    I look forward to your analysis of the log files. Thank you.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These logs (both accounts) are clean.

    Are you finished with all accounts? Are you having any remaining malware issues?
     
  15. semaj

    semaj Private E-2

    One more account that was having trouble. I ran combofix and GetLogs.bat. Files attached. Let me know how they look when you have time.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This logs are also clean.

    If you are not having any other malware issues, I refer you again to my final instructions posted in message # 6.
     
  17. semaj

    semaj Private E-2

    Awesome!
    No more issues.
    You have been so incredibly helpful! Thank you for seeing me through to the end. I registered with MG to fix my problem, but I'm a fan ... I think I'll stick around!

    thankyouthankyouthankyouthankyouthankyouthankyou....
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely and visit all of the forums. You will learn a lot! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds