some serious hijacking or something, HJT and other logs attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by The Persian Menace, Jan 28, 2007.

  1. The Persian Menace

    The Persian Menace Private E-2

    hi

    my browser has been hijacked, internet explorer ads and new tabs in mozilla pop up all the time, and antivir keeps on picking up stuff like :\Documents and Settings\omeedo\Local Settings\Temp\osopiaul.dll' [TR/Virtumod.EB.2

    and oh btw ive lost documents and settings, like it doesnt exist, i mean its not visible in c drive!confused

    i keep updating my spyware stuff - like spybot and adaware and a^2 and running scans which pick up the mess the rootkit is making

    PLEASE HELP ME!:cry

    ps
    whats in it for you guys apart from the good feeling of helping us computer illiterates?

    note this is my first post ever, on any website anywhere
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please attach the other three logs requested!
    CounterSpy
    AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
    Bitdefender - from step 6
    Panda Scan - from step 6


    Also is this supposed to be HijackThis or is it malware:
    C:\Program Files\Explosives\explosives.exe

    Naming files and folders as we suggested would avoid this possible confusion. Please rename it as we requested.

    You also skipped step 3 of the READ ME. Uninstall ALL but one antivirus application.

    Also you are using MSconfig. Please see step 0 of the READ ME and stop using it to control startups. You must be in Normal Startup mode.

    You will have to also attach new HJT and GetRunKey logs now after you stop using MSconfig.


    Also to get started, uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 8
    J2SE Runtime Environment 5.0 Update 9

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
     
  3. The Persian Menace

    The Persian Menace Private E-2

    these logs came late because it took me a long time to try and get them working, most of them didnt work, particularly the online scanners despite turning off avast and getting active x and clicking on installing plugins and going into normal windows mode

    i renamed explosives, sorry about that


    an error loading windows system32\kqsajcow.dll always comes up when i start the computer, note tht this is part of startups

    YUTUMS_A.EXE, what is it?

    what is MSXML 4.0? it has nothing viewable in the folder

    Function F4 for sleep does not work anymore

    docs & settings is gone!

    i am surrounded by virus scanning ads
    please help!
     

    Attached Files:

  4. The Persian Menace

    The Persian Menace Private E-2

    HJT log
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where is the AVG Anti-Spyware log?

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\omeedo\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Security\CounterSpy

    Continue by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)
    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of mxlsp.dll once and then click the kill button. After you have killed all of the mxlsp.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of mxlsp.dll and kill it. (If you do not find the dll, just continue on.)

    Next double click on iexplore.exe and again click once on each instance of mxlsp.dll and kill it. (If you do not find the dll, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} - C:\WINDOWS\system32\daqluont.dll
    O2 - BHO: (no name) - {7BE1E372-1A67-40C3-A975-685314CF0A51} - C:\WINDOWS\Cursors\mxlsp.dll
    O2 - BHO: PrintViewBHO Class - {D4E0C464-30CE-4075-9A10-71FD106C2847} - C:\PROGRA~1\PRINTV~1\PRINTH~1.DLL (file missing)
    O4 - HKLM\..\Run: [YNTUMS_A.EXE] YNTUMS_A.EXE
    O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\kqsajcow.dll",setvm
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O20 - Winlogon Notify: mxlsp - C:\WINDOWS\Cursors\mxlsp.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\All Users\Application Data\addr_file.html
    C:\Program Files\Common Files\{156813FD-0707-1033-1219-05121305002c}\Update.exe
    C:\WINDOWS\IFinst27.exe
    C:\WINDOWS\system32\tkaimvjo.dll
    C:\WINDOWS\system32\daqluont.dll
    C:\WINDOWS\system32\eRLog.ini
    C:\WINDOWS\system32\wocjasqk.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\Common Files\{156813FD-0707-1033-1219-05121305002c}

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
     
    Last edited: Feb 4, 2007
  6. The Persian Menace

    The Persian Menace Private E-2

    i didnt know you wanted the AVG anti spyware log, i was able to run counterspy and get a log
    remember:
    "AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy"

    i searched for the sunbelt folder to delete it using the windows search because i cant see documents & settings
    and i couldnt find it, when i changed the options to search all files, inclusive of hidden ones it found the folder. so i deleted it and then because it was in doc & settings i could keep going up folders till i got to the doc & settings folder, i unchecked its hidden attribute, and applied it to all sub folders hooray!!
    :D

    i got a runtime error 0 message when opening ccleaner, which is strange because i've opened this program before
    but anyway i reinstalled it and got it going

    i did all of your steps (well i hope i have haha) and attached that getkeys log,
    anymore cleaning?
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that! I should have said more in that message. Since were not able to post Bitdefender and Panda logs and because I saw you had AVG Antispyware installed, I figured a log from it would be useful.

    You only had problems finding things because you never did step 2 of the READ & RUN ME. My last instructions gave you a fixme.reg patch for the registry which automatically completed what was in step 2 of the READ ME. So now you would have no problem locating those files even if hidden. Also note those instructions and their result of unhiding things only applies to Windows Explorer where you look for the file thru manual navigation which is much faster than using Windows Search. And as you saw, you had to change options in search too!

    The end of my previous instruction got chopped off. I also needed a new ShowNew and HJT log. Please attach them.

    How are things working?
     
  8. The Persian Menace

    The Persian Menace Private E-2

    nice work with the fixme registry but i beat u to it,
    if i wanna make my files hidden again will the fixme get in the way?

    i havent seen adware in days which is great news!!!

    i have attached a report for an AVG anti spyware scan done in safe mode, tho only 2 tracking cookies were found (and cleaned)
    and newfiles and HJT logs
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No!


    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  10. The Persian Menace

    The Persian Menace Private E-2

    hi again,

    attached is a pic of an avast scan
    i forgot to change the settings of avast to save reports till after i did the scan
    so i just printed screen twice of the two infections (which i deleted successfully)there may be more of a war yet:major
    the adware has gone tho

    oh and whats tht vstoolbar.dll in the picture?
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a problem! Read the end of step 6 in the READ ME again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds