Ran through all steps, still having problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by dsmo, Oct 21, 2007.

  1. dsmo

    dsmo Private E-2

    OK, so I came home from college this morning to fix my sister's computer. 10 hours later and I now have to spend the night at home trying to fix it. I am pretty sure she has some kind of virus/malware, I don't really know what to do beyond running all of the scanners.

    Pages will not load at all in Firefox for her. Most websites still work in IE, but many don't (I know of Gmail and my college mail site, web.mail.umich.edu ). I also could NOT run Spybot S&D. When I tried to open it, it said I needed to update my files, when I tried to update, the program said it could not find a network connection.

    I've ran CounterSpy, Trend Micro, they detected some stuff but didn't solve my problem.

    Doing research and everything I came up upon these names a few times, I think she might have something derived from these:
    TROJ_ROOTKIT.H
    BCDR_IRCBOT.H

    I tried going through the steps for TROJ_ROOTKIT.H on TrendMicro's website but that didn't work either.

    Anyways, here are all of my logs, I hope somebody can help me out.

    Thanks,
    Dave
     

    Attached Files:

  2. dsmo

    dsmo Private E-2

    From CounterSpy:

    Scan History Details
    Start Date: 10/21/2007 4:57:57 PM
    End Date: 10/21/2007 6:21:02 PM
    Total Time: 83 Min 5 Sec
    Detected security risks

    VX2.Transponder Browser Plug-in more information...
    Details: VX2 is an Internet Explorer Browser Helper Object that monitors web page requests and data entered into forms, sending this information to its home server, and opens pop-up advertisement windows. VX2 also collects and sends personal information.
    Status: Quarantined

    Files detected
    c:\WINDOWS\system32\zgzsupv.exe

    Registry entries detected
    HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN


    Unclassified.Spyware.BHO.B Browser Plug-in more information...
    Details: This spyware browser helper object was identified by SpyNet and is currently being classified.
    Status: Quarantined

    Files detected
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software\CounterSpy\Quarantine\{E2AF0B29-4219-4F0C-98FF-8B8A95B3EE40}
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Uninstall the below old versions of software:
    Ad-aware 6 Personal <--3 years out of date
    J2SE Runtime Environment 5.0
    Mozilla Firefox (2.0.0.7)
    Spybot - Search & Destroy 1.4 <-- Out of date! Get the version in the READ ME.
    Sunbelt CounterSpy <-- We are finished with this trial now
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 0 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [Iinl] C:\Documents and Settings\USER\Application Data\emia.exe
    O4 - HKCU\..\Run: [Mdmfi] C:\WINDOWS\system32\m?iexec.exe

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. dsmo

    dsmo Private E-2

    Ok, Firefox still will not load any webpages, Gmail does not load in IE.

    Here are the files after following these steps:
     

    Attached Files:

  5. dsmo

    dsmo Private E-2

    And my HJT log


    As I said, I still have the problem of firefox not loading pages and sites like Gmail not loading in IE.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you uninstall CounterSpy as requested? I still see it.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! It also looks like ATF-Cleaner did not work or it was not run on the account with the name USER. Did you run ATF Cleaner with the options requested?

    Is AOL Toolbar used? It appears to be broken.

    You need to check to make sure you are not blocking access to any of the pages you are trying to goto in your firewall.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One more question! What is the below file?
    Code:
    C:\
    zia02056      Oct 22 2007    33412243  "zia02056"[
     
  9. dsmo

    dsmo Private E-2

    OK, running through everything again seems to have fixed it...I really don't have any more time to check out why because I need to drive back to school this morning, fighting rush hour traffic, etc.

    If anything, I will have to come home again on Friday and check out what has happened. I will reopen this thread if it is the same kind of problem.

    Thanks a ton!
    Dave
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm suspecting that you may still have some problems that need to be fixed. I'll wait to hear back from you.
     
  11. dsmo

    dsmo Private E-2

    ok, almost the same problem.

    On Monday morning, I think what happened is that she was blocking firefox from accessing the internet through internet security or something.

    I got a call Thursday that my family couldn't get on gmail or anything again. Going on websites, it appears the only pages that are blocked are encrypted web pages. Gmail, my college mail, ebay, paypal, etc. all of these login pages do not work.

    Firewalls are all off as far as I know, I am leaving this just to let you know I am having problems if you can think of anything right now. I am going to start the scan process again so I can post all of my logs for you to take a look at.
     
  12. dsmo

    dsmo Private E-2

    UPDATE: I am just restoring the system to its factory settings, thanks for giving it a shot chaslang, but I need to make sure it is fixed because I won't be coming home again until Thanksgiving.

    I really appreciate your help, does this site have anywhere I can make a donation to support the costs?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes there were definitely more problems indicated in your logs that needed to be fixed but you had said everything was fine. Thus I was waiting to hear back from you. We could have fixed this; however if you have restored to factory settings we won't need to do that. However you should do the below:

    How to Protect yourself from malware!
     
  14. dsmo

    dsmo Private E-2

    Will do. I don't doubt we could have did it, just that I only have about 2-3 hours to work with, and the anti-virus scans take forever to run through.

    I am interested in making a donation to support this site, if possible. I wouldn't doubt that in a few months my sister will have a new batch of crap on this computer and I'll probably need the help of you guys.

    Best
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But we were already finished with those and would not have needed them again. All we would have been doing was using HJT, Avenger, and then getting new logs from GetRunKey, ShowNew, and HJT. All of this runs quickly.

    We don't have a facility in place that to accept direct donations but you can support the site in a few ways:
    1. Purchase Geek Wear This link is also on the main page in the right column.
    2. Do all of your downloading from Major Geeks
    3. Spread the good word and send all of your friends here
    Thanks for asking about this! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds