Sohanat.AJ.worm Yahoo Messenger related

Discussion in 'Malware Help (A Specialist Will Reply)' started by Foreverunstopable, Nov 28, 2006.

  1. Foreverunstopable

    Foreverunstopable Private E-2

    Hey Guys. I'm new here. Never needed to remove a trojan/worm before. Great site. I followed the post.

    Background. I got a PM from a friend on Yahoo Messenger. It liked me to a site that was pretty much jibberish and characters. Next thing I know my messenger is hijacked and sending links to everyone I know, trys to open my email and who knows what else. Attached are the filed the post asks, I hope this helps. A few questions.

    Do I need to change all my passwords now?

    How can I regain access to regedit/run without rebooting in safemode? keeps reverting upon restart.

    Again thanks guys/girls great site!!
     
  2. Foreverunstopable

    Foreverunstopable Private E-2

    Text
     

    Attached Files:

  3. Foreverunstopable

    Foreverunstopable Private E-2

    Text2
     

    Attached Files:

  4. Foreverunstopable

    Foreverunstopable Private E-2

    Any help would be appreciated. Thanks:)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    I guess you did not read this sticky! Don't Bump! It Only Hurts You!!! This last post cost you another day in the queue.

    If you ever have to attach a log from Bitdefender again, please follow the directions to attach the properly formatted log. You are supposed to give us the HTML file but just rename it to have a .txt extension.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6

    Now install the current version of Sun Java from: Sun Java Runtime Environment


    Your Windows OS version is way out of data and represents and MAJOR security risk and is also the main reason for your current infection. You MUST get updated after we remove your malware problems.

    Let's continue by downloading a tools we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\Luke\Local Settings\Temp\object1.exe
    C:\Documents and Settings\Luke\Local Settings\Temp\object2.exe
    C:\Documents and Settings\Luke\Local Settings\Temporary Internet Files\Content.IE5\78J6HPHC\clip2[1].exe
    C:\Documents and Settings\Luke\Local Settings\Temporary Internet Files\Content.IE5\78J6HPHC\popup[1].htm
    C:\Documents and Settings\Luke\Local Settings\Temporary Internet Files\Content.IE5\78J6HPHC\popup[1].php
    C:\Documents and Settings\Luke\Local Settings\Temporary Internet Files\Content.IE5\H8BHAFKO\clip1[1].exe
    C:\Documents and Settings\Luke\Local Settings\Temporary Internet Files\Content.IE5\H8BHAFKO\clip2[1].exe
    C:\Documents and Settings\Luke\Local Settings\Temporary Internet Files\Content.IE5\JEUKN4KG\clip1[1].exe
    C:\WINDOWS\system\svchost32.exe
    C:\WINDOWS\system\svhost.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Administrator\Local Settings\Temp

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Nov 30, 2006
  6. Foreverunstopable

    Foreverunstopable Private E-2

    Here are the attached files requested. I was having problems restarting in Normal mode. It would only let me do the selective restart outside of safe mode.

    You mentioned updates, what do I need to update to get my computer safe?
    What firewall and AV do you suggest? Are any free? Hopefully Im clean now. Again thanks for all the support and your assistance!!
     

    Attached Files:

  7. Foreverunstopable

    Foreverunstopable Private E-2

    Well as soon as I started yahoo messenger I got the attached screen shots of the project one hijacking my messenger again, then it changed my home page and I cant run the other programs as It says I cant edit my registry.

    Should I just delete yahoo all together?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is all happening because your OS is so out of date and because your PC is not properly protected. Don't run anything from now on accept what I request. And don't do any other surfing or use things like Yahoo or other messengers until I say we are done! In fact for now I recommend uninstall your Yahoo Messenger.

    Now download and install this firewall: ZoneAlarmFree

    I now will need new logs from GetRunKey, ShowNew and CounterSpy (run a new scan with CounterSpy and fix what it finds).
     
  9. Foreverunstopable

    Foreverunstopable Private E-2

    I did as you asked. Removed Yahoo messenger, did counter spy which had no detections, loaded Zone Alarm which tells me I need an anti-virus program, ran the two other programs which are attached. Can you suggest an anti-virus program?
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First we need to cleanup some left over items from you having Symantec installed at one time.

    Uninstall these:
    Norton WMI Update
    Symantec Network Drivers Update

    Now attach a new HJT log so I can check to see if the Symantec Service were removed.
     
  11. Foreverunstopable

    Foreverunstopable Private E-2

    I could only find the Norton in my Add/Remove. I did a search for the Symantec and deleted all files found. Attached is the HJT log. If there are any non essential things you think I can get rid of please by all means let me know I dont use internet explorer for anything and see alot of that google, image shack stuff.

    O23 still shows symantec but says the file is missing.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you saying you don't use and don't want the below? If so, uninstall any that you do not want.
    Google Earth
    Google Toolbar for Internet Explorer
    ImageShack Toolbar for Internet Explorer


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Symantec Network Drivers Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteSNDSrvc into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.
    After reboot install this: AVG Free Edition

    Now attach new logs from HJT and ShowNew.
     
  13. Foreverunstopable

    Foreverunstopable Private E-2

    Removed toolbars, loaded AVG, attached are the files.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not according to your logs! Steps must always be followed in the order written.

    Can this Symantec Network Drivers Update be uninstalled? If not, use the below to uninstall it:

    Your Uninstaller! 2006



    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  15. Foreverunstopable

    Foreverunstopable Private E-2

    Thanks for all the help!! Attached are the files one last time to make sure its taken care of. Can you tell what programs I will no longer need after all the updates and spyware removal. I have chosen to go with the Zone Alarm free, AVG and spyware blaster. Again thanks so much!
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you use Your Uninstaller! 2006 to uninstall the Symantec stuff yet? If does not look like it. You don't need Your Uninstaller once Symantec is uninstalled. Most everything else is mentioned in message # 14.

    Also you seem to have messed up ShowNew. You need to extract all the files again into the folder. Once you start the cleanup I gave you in message # 14 you cannot start posting new logs since you will have deleted files necessary to run ShowNew and GetRunKey.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds