quick question...

Discussion in 'Malware Help (A Specialist Will Reply)' started by masterofpuppets, Feb 6, 2005.

  1. masterofpuppets

    masterofpuppets Private E-2

    Hello all,

    I stupidly let my brother on my PC and he's installed some bad stuff... (comedy-planet.exe) anyway I'm working through the instructions in the FAQ in order to solve the issue.

    Has anyone come across a problem where your recycle bin simply wont delete the problem files? (its norton protected) It claims two files are in there, yet when opened nothing is there.

    Anyone know a way to get rid of the files?

    This is really stressing me out & any help would be gratefully received
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's a VX2 infection. You have some work cut out for you. But first the standard cleanup must be done.

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. masterofpuppets

    masterofpuppets Private E-2

  5. masterofpuppets

    masterofpuppets Private E-2

    Hi Chaslang,

    I've followed your instructions to the letter and nothing was found after using all the tools in safe mode etc.

    As requested, here is my Hijack This log file.

    I await your advice.

    Thanks again.
     

    Attached Files:

  6. masterofpuppets

    masterofpuppets Private E-2

    I forgot to mention that the following have been downloaded as advised and are ready to be used on your say so

    L2MeFix Tool
    Generic Detection Tool - NT/2000/XP
    VX2.BetterInternet Finder XP/2k - Version Msg126
    Pocket KillBox
    LSP - Fix

    thanks
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please explain why you did not run the TrendMicro online scan!

    And when you said
    Do you mean no scans found any problems at all?

    First Step:

    Now run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the aklsp.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move aklsp.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.

    Second Step:

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\wrifil32.exe
    C:\WINDOWS\system32\wowfg32.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O4 - HKLM\..\Run: [xsEP32j] wrifil32.exe
    O4 - HKCU\..\Run: [gBxFRSH6T] wowfg32.exe
    O9 - Extra button: Wallpaper - {c23dd370-cb79-11d2-898a-00c04f80a47f} - C:\Program Files\Internet Explorer\Toolbar\toolbar.hta
    O9 - Extra 'Tools' menuitem: &Toolbar Wallpaper - {c23dd370-cb79-11d2-898a-00c04f80a47f} - C:\Program Files\Internet Explorer\Toolbar\toolbar.hta
    O23 - Service: koijxwjwinrz - Unknown - C:\WINDOWS\system32\bczeptug5.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\wrifil32.exe
    C:\WINDOWS\system32\wowfg32.exe
    C:\Program Files\Internet Explorer\Toolbar <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  8. masterofpuppets

    masterofpuppets Private E-2

    Hi Chaslang,

    Sincere apologies for my stupid oversight… it was getting late last night (I’m the UK) and I overlooked that instruction…. I’m very sorry.

    I can only assume that it’s safe to carry on with your latest instruction and that my mistake does not mean I should start your instructions from scratch.

    In answer to your question about the scans… When I used CC cleaner it cleared out a load of temp files. I then used Spybot which fixed 17 problems, then Adaware which deleted just the 1 tracking cookie. I then followed point 4 of the instructions (recommending me to use all the other downloaded tools). I did this and nothing was found or fixed. For the record, I definitely used the latest versions, plugins and updates for all the tools :)

    I will follow your latest instruction when I get home from work this evening. (Unless you say otherwise)

    Thanks for your continued help and support; it’s very much appreciated!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! Thanks for the additional info. It is important for us to know that information. It gives us a better understanding of what has been going on with your PC.

    Just continue with the instructions! You can run TrendMicro later as an additional safe guard. Sometimes it is surprising to see the results of these online scanners when you think you are clean.
    I had one case where a user's HJT log looked okay and his Symantec AV said everything was fine. And a scan with TrendMicro found 25 trojan files.
     
  10. masterofpuppets

    masterofpuppets Private E-2

    Hi Chaslang,

    Sorry for the late reply. I have just followed your latest instructions and have the following to report:

    Everything was going fine until I was in the ‘open process manager’ section of HJT – the two processes you instructed me to kill were not listed.

    I then carried on and fixed everything you told me to except:

    O4 – HKLM\..Run: [xsEP32j] wrifil32.exe
    O4 – HKLM\..Run: [gBxFRSH6T] wowfg32.exe

    As they were not anywhere to be seen on the list.

    After booting into safe mode I could only delete the
    C:\Program Files\ Internet Explorer\ Toolbar as the other two exe’s were not there. (There were other ‘wow’ related files, but I did not want to touch anything I wasn’t told to, as my understanding of such things are limited).

    I then completed a full system Trend Micro scan (still in safe mode) which found:

    ‘Troj Agent BT’ which was classed as non-cleanable, location – C:\Windows\system32\akrules.dll

    It gave me the option to delete the file, which I did.

    I am still unable to empty my recycle bin, and am still receiving pop-ups when browsing, so obviously something is still very wrong :s

    Is there anything I can do? Or should I give up now and buy a Mac? (wish I could afford one!)

    I have posted another HJT log if you’d be so kind as to check out for me and any further instructions will be gratefully received!

    Thanks for your time.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! We'll get to everything in due time. Let's continue with the below steps!

    First Step:

    Extract all the files from the Generic Detection Tool into its own folder.
    Then run find.bat. Post the log it creates back here as an attachment . Make sure you wait long enough. A notepad window should popup when complete. Don't do anything else while this is running.

    Second Step:
    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log.

    NOTE: Please do not run any other options or files in the l2mfix Folder!

    Third Step:

    Come back here and post as attachments the l2mfix log the find.bat log (normally already named output.txt). Based on those logs, we will determine the next steps. Please DO NOT REBOOT after scanning for these logs!! Otherwise problems may mutate and spread. Wait for me to get back to you with the next steps.
     
    Last edited: Feb 8, 2005
  12. masterofpuppets

    masterofpuppets Private E-2

    I've followed your instructions and here are the reports you asked for.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Step 3:

    Print or save these instructions locally now because you will have to be disconnected with no browsers open in the next step.

    Please make sure ALL Browser Windows are Closed and also you should physically disconnect from the Internet by unplugging your cable.

    Go to the L2MFix Folder on your Desktop and DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.
    Your computer will go bazonkers (now there's a great technical term!) for a bit, but just let it run. It should eventually spit out another log in Notepad.

    Again, don't run any other files in the L2MFix folder.

    Okay after doing the above DO NOT REBOOT.

    Step 4:
    Get a new HJT log


    Now reconnect to the internet and come back here and attach the L2MeFix Log and the new HJT log.
     
  14. masterofpuppets

    masterofpuppets Private E-2

    Hi Chaslang,

    Here are the latest logs after following your instructions:
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side.
    Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\Program Files\AutoUpdate\AutoUpdate.exe
    C:\WINDOWS\system32\regcz1.exe
    C:\Program Files\CxtPls\CxtPls.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll
    O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
    O4 - HKCU\..\Run: [gBxFRSH6T] regcz1.ex

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\AutoUpdate <-- the whole folder
    C:\WINDOWS\system32\regcz1.exe
    C:\Program Files\CxtPls <-- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Let me know if you have any problems finding or deleting any of these files.

    Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  16. masterofpuppets

    masterofpuppets Private E-2

    Hi Chaslang,

    I was able to follow every part of your latest instructions without a hitch! :cool:

    My recycle bin is empty! *does a dance*

    As requested, I've posted my (final?) HJT log for you to check:

    I await your instructions.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  18. masterofpuppets

    masterofpuppets Private E-2

    I seriously can't thank you enough for all your help, time and patience.

    It's reasuring to know that there's people like you out there to counter-act the scum that make these problems in the first place.

    Thanks a million Chaslang! :)
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're quite welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds