Problem, a Major Problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by bobothebionicmonkey, Dec 30, 2005.

  1. bobothebionicmonkey

    bobothebionicmonkey Private First Class

    Ok guys it seems like the good folks here at major geeks are the best at helping fix problems i have. Well here is a doosey of a problem.
    But before i start i want everybody to know that i have read the help threads here that say "read this before posting" and have tried what i thought might help. and mow i come to you guys!

    My dad has a computer, compaq with 56mb RAM 40GB hard drive (that is all the specks i know i'm a bit of a computer novice) Well my dad is even less computer savey than me, so when he saw something on his desktop that wasn't normally there he clicked it. a whole mess of crud came poping up. after clearing it all away by exiting everything, he deleted the unknown icon. His norton systemworks then chimed in telling him that he has had some risky files on his computer for the past two days. he does some stuff, i am not sure what, but finally he comes to me and asks for help. I get on there and find that the norton system works is now not running because it says some of its files are missing. when i attempt to get to there support page over the internet the internet window sends me to C:\\windows\system32\msblank.html. then asks me to install active X controls when i don't the internet takes me to a cannot display page, when i do it reroutes me like a hijacker.
    I knew for sure there were problems so i ran all three adware removal tools i have, "Adaware" "Yahoo spyware remover(the one that comes with the tool bar" and "Spy bot" after clearing out the stuff they found i'm still having the same problems. oh yeah and besides some of the stuff on the start button menu going MIA there is also a "removeware" toolbar (not sure of the name but it is something like that) on his internet window as well.

    I did all i can do and now I ask you. How the heck should i go about solving this problem? Is there some virus that is messing up my computer?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must run and follow ALL the instructions in this Sticky thread READ & RUN ME FIRST Before Asking for Support Make sure you run everything and do them in the order indicated. Make sure you check against our version numbers and get all updates.



     
  3. bobothebionicmonkey

    bobothebionicmonkey Private First Class

    I read sticky's thread but i can't do that for my dad's computer because i can't go anywhere on the internet i keep being stopped by the highjacker. i can't download and scan those tools.
    also i found out that whatever has gotten on the computer is randomly deleting files from it.
    so i now have a bigger problem.
    any thoughts?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can't you download files onto your PC and copy them to CD or flashdrive etc and then copy to the infected PC?

    If you cannot do anything to help get the procedure started, we cannot help you. We need alot more information and it would take you along time to write it down and then type it into a message. What tools and version numbers are already on the PC?
     
  5. bobothebionicmonkey

    bobothebionicmonkey Private First Class

    hi again,
    it took some fiddling but i got on the internet and followed the steps it sticky's thread. the computer still has some problems. here is my hijack this log. if you have any thoughts please speak up.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I guess you did not run step 6 of the READ ME???

    You have a Wareout infection and more.

    Look in Add/Remove programs for UnSpyPC and uninstall if found.

    Please download FixWareout from one of these sites:
    http://downloads.subratam.org/Fixwareout.exe
    http://swandog46.geekstogo.com/Fixwareout.exe
    • Save it to your desktop and then run it by double clicking on it. It creates a folder named c:\fixwareout.
    • Click Next, then Install.
    • Then make sure Run fixit is checked (this runs C:\fixwareout\fixit.bat). And then click Finish.
    • The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so.
    • Your system may take longer than usual to load; this is normal.
    • When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan, and check the following items if they still exist:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\system32\msblank.html
    R3 - URLSearchHook: (no name) - {8BEC06FB-14CC-8782-74BA-6E2D048B7196} - (no file)
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
    O2 - BHO: (no name) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
    O2 - BHO: (no name) - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - (no file)
    O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
    O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
    O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
    O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
    O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
    O3 - Toolbar: (no name) - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - (no file)
    O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
    O4 - HKLM\..\Run: [trycrt] xwiz.exe
    O4 - HKLM\..\Run: [ParisM] ParisM.exe
    O4 - HKCU\..\Run: [UnSpyPC] "C:\Program Files\UnSpyPC\UnSpyPC.exe"
    O4 - HKCU\..\Run: [browsebar] Brong32.exe
    O4 - HKCU\..\Run: [media64] driver64.exe
    O4 - HKCU\..\Run: [prgsys0984] mozilla-text.exe
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (no file)
    O17 - HKLM\System\CCS\Services\Tcpip\..\{11058CD5-5A74-405A-8C9E-B26B21E238EB}: NameServer = 85.255.113.195,85.255.112.223
    O17 - HKLM\System\CCS\Services\Tcpip\..\{EDC2FD8E-C7EE-4D60-8B78-E0E27CA62052}: NameServer = 85.255.113.195,85.255.112.223
    O17 - HKLM\System\CS1\Services\Tcpip\..\{11058CD5-5A74-405A-8C9E-B26B21E238EB}: NameServer = 85.255.113.195,85.255.112.223

    After clicking Fix Checked, close HijackThis, and click OK to proceed.

    At the end of the fix, reboot into safe mode and use Windows Explorer to double check for the below files and delete if found:
    C:\WINDOWS\system32\msblank.html
    C:\WINDOWS\system32\xwiz.exe
    C:\WINDOWS\system32\ParisM.exe
    C:\WINDOWS\system32\Brong32.exe
    C:\WINDOWS\system32\driver64.exe
    C:\WINDOWS\system32\mozilla-text.exe
    C:\Program Files\UnSpyPC <--- delete the whole folder

    Now reboot into normal mode and please attach the contents of the logfile C:\fixwareout\report.txt

    Also attach a new HijackThis log.
     
  7. bobothebionicmonkey

    bobothebionicmonkey Private First Class

    I can't believe it but you were right i apparrently did skip sticky's step 6 sorry.
    I did what you told me and here are the logs. the computer is starting to shape up, but not as up to snuff as it used to be. if there is anything else i need to do please tell me.

    I also just want to say thank you for all the help you are giving me.
    THANK YOU!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! I would like you to run step 6 of the READ ME and attach the logs but before doing that a few steps will help to make those scans go faster and keep the logs smaller.

    1) run Ccleaner on all user accounts to clean up all the cookies and temp files
    2) empty the Recycle Bin
    3) Also since you use Norton N-Protect to protect the Recycle Bin you must empty it. See this: Emptying the Norton Protected Recycle Bin
    4) Empty any quarantine folders for your virus scanner

    Now immediately after doing the above, run step 6 of the READ ME and attach the logs.

    Also tell me if things are running any better. If not please describe the exact problems your are having in more detail.
     
  9. bobothebionicmonkey

    bobothebionicmonkey Private First Class

    here are the reports from step 6. the computer is working alright but i want to make sure there is nothing wrong with it.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not do what I requested in my last message. Look at the BitDefender log. You still have items in the Quarantine folder and in Recycle and the Norton N-Protect.

    Please follow those directions.

    Also delete the below files:
    C:\WINDOWS\SYSTEM32\howiper.exe
    C:\WINDOWS\cpbrkpie.ocx
    C:\Downloads\SinglesMSetup-dm[1].exe
     
  11. bobothebionicmonkey

    bobothebionicmonkey Private First Class

    man i just can't follow directions. I know i must be getting on your nerves. sorry about that. This time i ran ccleaner then emptied the norton protected files in the recycle bin and deleted everything in the quarentine filessection of my norton anti virus. i ran the two programs in step 6. Then i checked for the files you told me to delete in the end of your last message, and deleted theon i found. then i emtied norton protected files in the recycle bin. i went and checked the quarentine files again but didn't find anything.

    thanks for your help and patience. the computer is rinning good. Do you think i have any more to do to clean it?
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! One file is still left: C:\WINDOWS\cpbrkpie.ocx

    Did you miss that one?

    Try again. Afterwards it is time to complete step 1 of the READ & RUN ME to dump all bad System Restore points. And then you should move on to the below:

    How to Protect yourself from malware!
     
  13. PhilliePhan

    PhilliePhan Guest

    Hey guys,

    Don't forget to look for and delete the baddies identified in the FixWareout Log, should they remain:

    C:\WINDOWS\SYSTEM32\CSNQL.EXE
    C:\WINDOWS\SYSTEM32\CSRJS.EXE
    C:\WINDOWS\SYSTEM32\DMKNL.EXE

    Happy New Year!
    PP :)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks PP! I forgot about adding those to my list in message # 10.

    I wonder why they have not made the script smart enough to nor show ipsec6.exe yet.
     
  15. bobothebionicmonkey

    bobothebionicmonkey Private First Class

    I did everything you told me to, but i didn't post the reports because neither program found anything. the computer is running great and clean now. Thank you a lot for all your help and i hope you have a very happy new year!

    thanks again.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds