Ran the read & run, having some trouble still.

Discussion in 'Malware Help (A Specialist Will Reply)' started by j25jim, Apr 11, 2008.

  1. j25jim

    j25jim Private E-2

    Hi,

    I'm running windows xp. I also have webroot spysweeper installed along with avg antivirus and zone alarms firewall.

    Having trouble with some spyware and trojans. I ran the removal guide(although i was unable to download mgtools for some reason).

    I had virtumonde, smitfraud c.gp, rabio, webhancer? ps2, and a couple of others. I was able to remove most of these.i also noticed one of the logs had jkkhff.dll in the registry.

    I also had a couple of trojan downloaders, I think one was backdoor AGNT.
    AVG and spysweeper pointed to a file (WINDOWS/system32/sqlnmo.dll) that it was unable to remove, tried safe mode, still unable to remove the file. tried it manually and was told it was protected but i could change ownership, i was frustrated so i did that and i was able to delete the file manually.

    When I tried to reboot to post the logs, windows loaded a couple of the startup programs(avg and spysweeper)then it froze and shutdown. After a couple more tries with the same outcome i decided to reboot with the last known good configuration and i was able to boot up. But then the same spyware and trojans were back.

    So i ran everything again, got rid of it all, and i couldn't boot up again.
    I assume I could use the last known config option to boot up again, but then I'll be in the same loop.
    is the sqlnmo.dll a system file that should not be deleted? Three programs said it was a trojan.
    any ideas? other programs I could run?
    sorry for the long post.
    Thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you ran the READ ME and still have problems, you need to finish doing what the READ ME asked you to do and that is to attach the logs that are requested for your Windows version.
     
  3. j25jim

    j25jim Private E-2

    I've attached the logs of everything I was able to run.

    For some reason I can't download Super anti spyware, I even went to a friends house and put it on a cd, but it won't run. I'm probably doing something wrong but I'm not sure what.

    I ran Combofix a couple of times but after it rebooted the computer shutdown each time. I don't think it completed the log, it looks fairly empty, but I'm not sure.

    i ran TWO malware byte scans-I'm attaching the second one here,which was cleanfrom 4/12/08
    I'll attach the previous one on a second post because it fixed a bunch of problems and maybe the info is important.

    anything i google takes me to a site called monster market place and a bunch of other sites I wasn't looking for. Spybot says there aren't any BHO's installed but...

    Thanks.
     

    Attached Files:

  4. j25jim

    j25jim Private E-2

    here is the first malwarebytes scan log i ran. It caught and fixed a few things.
    Maybe it's useful.

    thanks.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are a few problems with your logs.
    1. First it appears that you ran tools while logged into the Administrator account and that you ran others while connected to the owner account. You must run all tools and attach all logs from the same user account and make sure that it is the account that you wish to clean. You ComboFix log showed you tried running it on the owner account and that it did not run properly. Your MGtools log shows you ran it under the Administrator account. Please start over and run the scans on the same user account and attach new logs. You only need to rerun MGtools and ComboFix. When you run ComboFix, shutdown Spy Sweeper first.
    2. You apparently did not accept the license agreement for TrendMicro HijackThis that pops up when you run MGtools. You must click twice on the Accept button to agree to this license otherwise the tool will not run and no log will be produce. Please make sure you do this correctly this tim.
     
  6. j25jim

    j25jim Private E-2

    Here are the updated logs as you requested. Thanks again.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you name the below files like this? They look like something malware would do. Delete them if you don't need them or rename them if you need them.
    Code:
    "C:\Documents and Settings\Owner\My Documents\"
    232483~1.bmp  Apr 13 2008      691254  "??????????23.bmp"
    4bb3~1.jpg    Apr 13 2008      262945  "????????.jpg"


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_08

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. j25jim

    j25jim Private E-2

    one question- I realize updating to the latest version of java is critical to security, however i have been unable to do so since I'm still running xp sp1. I've attempted to update it to sp2, but after many failed attempts and phone calls to Microsoft and HP support they tell me I need the Cd (which I was never given).
    I am going to bite the bullet as soon as I'm able and buy vista or another version of xp.

    The question is, can i skip updating java for now and still execute the fix above successfully?
    or will the fix mentioned above (analyse.exe 09-Extra button etc...) allow me to install the latest Java version?
    Thank you.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not true!! The current version of Sun Java works with SP1. And besides that, you could have update from the almost 4 year old version of Java to many other versions already quite awhile ago.

    Please try the fix exactly as written and see what happens.
     
  10. j25jim

    j25jim Private E-2

    Ok, i ran the entire fix, however I had to run a couple of the steps more than once because i was unable to download windows messenger remover or the java the first go around.
    -First off, did a search, I couldn't find these files you mentioned:
    232483~1.bmp Apr 13 2008 691254 "??????????23.bmp"
    4bb3~1.jpg Apr 13 2008 262945 "????????.jpg"

    -after running combo fix the first time it froze after it rebooted, it did not restore the clock.
    -got online for a bit

    -i was able to download java 6 u6 -the message said it does not support windows sp1 but i was able to install it anyway.

    -then i tried fixreg step and it was successful.

    -ran Ccleaner

    -i finally was able to log on again for a bit so i started over-

    -ran combofix-looks like it went through all the steps but the clock is still on 24 hour time i believe.

    -finally able to download windows messenger remover, i ran it and removed messenger.
    - tried the regedit step again and again it was successful.
    -ran Ccleaner
    -ran Getlogs.bat

    I have attached both logs requested.

    It seems to be working a little bit better-
    It seems I can get online now, but if i do a search on google or yahoo etc., the search results are redirected to sites I wasn't looking for.


    Thanks.
     

    Attached Files:

  11. j25jim

    j25jim Private E-2

    I forgot to mention,
    -I also ran analyse.exe as instructed, but it only found two of the four lines
    (09-extra button, extra tool) mentioned. I selected both and fixed.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.

    However we need to run ComboFix again so if it puts you back into 24 hr mode at least you know how to fix it now.



    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now double click on the fixME.reg patch I had you make in the last procedure and allow it to add to the registry again.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. j25jim

    j25jim Private E-2

    ok, in order I
    -ran combofix
    -double clicked fixme.reg -it was successful
    -ran Ccleaner
    -ran mgtools getlogs.bat

    I attached combofix.txt and mglogs.zip.

    Everything seems to be working fine now!

    - no problems getting online,speed is up to par, google is actually taking me to what I searched for etc.

    Maybe that finally did it.

    I'll await your reply, but in the meantime.
    Thanks alot for your help!
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Two files we were trying to delete did not get deleted. Let's try again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now double click on the fixME.reg patch I had you make a few messages back and allow it to add to the registry again.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  15. j25jim

    j25jim Private E-2

    alright, in order, I:

    -saved Cfscript

    -ran combofix again

    -double clicked fixme.reg-it was successful

    -ran Ccleaner

    -ran MGtools\getlogs.bat

    -attached logs as instructed

    I hope that finally does it.

    Everything seems to be working fine now (I said the same in my previous post, but soon after, a trojan was discovered and deleted by AVG)

    I'll await your reply.

    Thanks again for your help.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Now your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  17. j25jim

    j25jim Private E-2

    Okay, I took all the final steps including deleting combofix, MGtools etc., disabled and enabled system restore.

    Everything seems to be running smoothly.

    I appreciate all your time and effort Chaslang.

    Thanks again.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds