Some problems that I need to fix

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jeeez, Jul 2, 2007.

  1. Jeeez

    Jeeez Private E-2

    I've been having some weird encounters with Trojans in the past few days; yesterday, I thought I had fixed them, for when I scanned with AVG Anti-Spyware nothing came up. Just this morning, when I booted up around 11:00 AM mountain time, IE opened by itself a few times and went to random ad pages. When I did an AVG A-S scan, about 9 things (2 high-risk ones labeled hijacker, the rest "tracker cookies") came up and I deleted them. Also, AVG Anti-Virus caught about 3 trojans that I immediately healed. I restarted the computer in Safe Mode and ran AVG A-S again, and those same things came up. I was about to do HijackThis myself, but was afraid I might mess something up. I want to post my log, but I don't know how to attach it to my message.

    P.S. I posted 2 days ago in the Spybot forums, but already my thread is on the 7th page of the forum and hasn't had any views since the day I posted it. I can't wait another 2 days to post it in the "waiting-list", so I came here. Sorry, but I need help ASAP.

    edit: I went through the "read this first" post and did everything in it I could, but it didn't help.

    edit again: I just found how to attach a file, here's my HJT log if anyone needs to see it.
     

    Attached Files:

    Last edited: Jul 2, 2007
  2. Jeeez

    Jeeez Private E-2

    Sorry for "bumping" the thread, that is unintentional. I have all the recommended logs attached.
     

    Attached Files:

  3. Jeeez

    Jeeez Private E-2

    Here are the others.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You must rename HijackThis as requested in step 7 of the READ ME. You have the exact infection that makes this an absolute necessity if you want to see the problems.

    Also you must uninstall ALL but one antivirus program as requested in step 3 of the READ ME.

    The continue on with the below instructions.

    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the below new logs and tell me how the above steps went.

    1. ComboFix
    2. GetRunKey
    3. ShowNew
    4. HJT
    Make sure you tell me how things are working now!
     
  5. Jeeez

    Jeeez Private E-2

    AVG doesn't pop up with Trojan reports anymore. As for the other Anti-Virus, it's an outdated TrendMicro Office Scan, that I cannot uninstall because it requires a password to do anything. Neither I nor my dad knows the password, so I don't know how to get rid of it. It doesn't seem to do anything, though. (Just in case you were wondering, it isn't malware, it was on this computer since we first got it.)

    Here are the new logs.
     

    Attached Files:

  6. Jeeez

    Jeeez Private E-2

    And the new HJT log (I renamed HijackThis.exe to analyse.exe).
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see what we can do about this while we are fixing your problems. You cannot allow this to remain on your PC. It is conflicting with your AVG Antivirus and ZoneAlarm firewall.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to OfficeScanNT RealTime Scan
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • OfficeScanNT Personal Firewall
      • OfficeScanNT Listener
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste ntrtscan into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • OfcPfwSvc
      • tmlisten
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Now uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03



    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
    O4 - HKCU\..\Run: [Snte] "C:\PROGRA~1\STEM~1\dvdplay.exe" -vt yazb
    O20 - Winlogon Notify: urqnkig - urqnkig.dll (file missing)

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds