surfsidekick,vx2,targetsaver,AND trojan,help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by timma05, May 10, 2006.

  1. timma05

    timma05 Private E-2

    Ok I have been battling with all these nusiances,pop ups coming out of nowhere, browser getting taken over,and i cannot permanently delete these suckers. everytime i run my ad aware it brings up all these so i delete them, then i run norton and it brings these up, and deletes them, but they come right back. Someone please help me end this malware crisis!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. timma05

    timma05 Private E-2

    Alright seemed to have forgotten to include that when my computer starts up a white form shows up in the middle of my screen, there are no words just a one row ten column blank form shows up. Ok i tried running the panda scan, but it doesnt work on firefox. my hijackthis log is included.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not ask for a HijackThis log as the first step. You must run ALL steps in the procedure I gave to you. HijackThis is the last step and you must install it properly too. Please follow the directions already given. Use IE to run the online scanners when you get to step 6 but steps 0 thru 5 must be run before 6.
     
  5. timma05

    timma05 Private E-2

    Alright 24 hours later I have completed the entire scavenger hunt.. err to do list lol, so whats the next step
     
  6. timma05

    timma05 Private E-2

    Oh and another update, the pop ups have been slowed, but now i get 2 blank UL windows that just pop up together out of nowhere
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Complete the instructions as given in message # 2.
     
  8. timma05

    timma05 Private E-2

    Ok, all the scanners found were trojan clickers, and the VX2 files.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must attach the logs from the scanners! No logs! No help! And you need a bunch! I need the other logs to workup a complete cleaning procedure.

    Did you run Windows Defender?
    Did you install HJT properly yet?
    Did you uninstall Messenger Plus 3 like step 0 of the READ ME recommends?
     
    Last edited: May 13, 2006
  10. timma05

    timma05 Private E-2

    Yeah i know about the norton, been trying to get rid of it and get back to my avast, but that hjt log was before i went thru all the steps, and i didnt see that i was to uninstall msn messenger plus. I have the logs from the scanners saved, whichdo you need at this time?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need exactly what I requested in message # 2 along with a HijackThis log that was obtained AFTER running the online scanners, after installing it correctly, and after all other steps in the READ ME have been completed including Windows Defender.

    Step 0 of the READ ME has a blurb about Messenger Plus!
     
  12. timma05

    timma05 Private E-2

    Ok, all logs as requested
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below shows that step 7 was still not followed. This is exactly where we do not want HJT installed and it is stated in step 7.
    C:\Documents and Settings\Kyle\My Documents\HijackThis.exe

    Hmmm! I thought you said
    Clearly not the case.
     
  14. timma05

    timma05 Private E-2

    Ive tried installing it out of that since it was a temp folder and all but it seems that no matter where i save it the root is still the same. Ive even tried moving it to the desktop but it only makes a shortcut
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You also did not obtained the Bitdefender log properly as the directions in step 6 indicate. The file should be an HTML file with a .txt extension which is much easier to read than what you posted. Please follow directions properly to avoid delays in getting help. It will now take me longer to read thru this file to see what was fixed and what remains.
     
  16. timma05

    timma05 Private E-2

    I saved it as html, but couldnt post that so i went through and saved it as a txt so i could attach it,sorry
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The procedure tells exactly how to save it to a .txt file that maintains the HTML code. And .txt files can be attached. Then all I have to do is rename the .txt to .html after downloading and I can read a nicely formatted file. It also requires no work on your part to edit the file.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Read the directions!
    Create a folder named C:\Program Files\HJT

    Then move or copy the hijackthis.exe file into the above folder. Run Windows Explorer and locate C:\Program Files\HJT\hijackthis.exe and double click! That's all it takes! If you want a shortcut to it on your Desktop you can do that to but it must reference the C:\Program Files\HJT\hijackthis.exe
     
  19. timma05

    timma05 Private E-2

    Ok ok sorry was doing all this at 3 in the morning after working all day. i just re-installed hjt as instructed
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! Just hang in there! I've been working up a fix! I'll be posting soon. There's a bunch to do.
     
  21. timma05

    timma05 Private E-2

    Alright thanks alot, at least the steps got rid of all of the pop ups. and by the way im hanging by a thread, past 4 nights been up til 2-3 am trying to figure it out lol
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall Zenosearch if found in Add/Remove programs

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Command Service ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    cmdService

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.


    Make sure viewing of hidden files is enabled (per the tutorial).
    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\defender1.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
    O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
    O4 - HKLM\..\Run: [keyboard] C:\\keyboard18.exe
    O4 - HKLM\..\Run: [newname] c:\\newname18.exe
    O4 - HKLM\..\Run: [defender] C:\\defender1.exe
    O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\pwinpqaf.exe CORN004
    O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\pwinpqaf.exe
    O16 - DPF: {00000000-0000-0000-0000-100000000002} - http://code.jcash.biz/l/900bfa571675...a24fc4f_13.exe
    O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://promo.dollarrevenue.com/activ...36342D2D2D.exe
    O20 - Winlogon Notify: Applets - C:\WINDOWS\system32\guard.tmp (file missing)
    O20 - Winlogon Notify: URL - C:\WINDOWS\system32\zepfldr.dll (file missing)
    O20 - Winlogon Notify: winmfu32 - C:\WINDOWS\SYSTEM32\winmfu32.dll


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (some of these may not be found, just continue):
    C:\Documents and Settings\Kyle\Start Menu\Programs\Startup\Zeno.lnk
    C:\Program Files\winupdates <--- delete this folder
    C:\WINDOWS\temp <--- delete all files in this Temp folder
    c:\windows\keyboard181.dat
    C:\WINDOWS\installerwnus.exe
    C:\WINDOWS\visfx500.exe
    C:\WINDOWS\S3lsZQ\ma5Ptk.vbs
    c:\windows\system32\MYDLL.dll
    C:\WINDOWS\system32\winmfu32.dll
    C:\WINDOWS\system32\pwinpqaf.exe
    C:\WINDOWS\system32\regperf.exe
    C:\WINDOWS\system32\reglogs.DDD
    C:\WINDOWS\system32\mvn2l95o1.dll
    C:\WINDOWS\system32\atmclk.exe
    C:\ZICORN004.exe
    C:\keyboard18.exe <--- delete any files using the starting with the text KEYBOARD and ending in .exe (like KEYBOARD1.exe, KEYBOARD2.exe...etc)
    c:\newname18.exe <--- delete any files using the starting with the text newname and ending in .exe (like newname1.exe, newname2.exe...etc)
    C:\mousepad18.EXE <--- delete any files using the starting with the text mousepad and ending in .exe (like mousepad1.exe, mousepad2.exe...etc)
    C:\defender1.exe <--- delete any files using the starting with the text defender and ending in .exe (like defender1.exe, defender2.exe...etc)

    Also look for files named keyboardxx.dat, newnamexx.dat, mousepadxx.dat, defenderxx.dat (where xx is any number).


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  23. timma05

    timma05 Private E-2

    I dont have a Command Service in the list
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note that one item may give us trouble. This:
    O20 - Winlogon Notify: winmfu32 - C:\WINDOWS\SYSTEM32\winmfu32.dll

    It may note go away. Sometimes we need a slightly different procedure to delete this kind of infection. We will see. If it comes back, we will get it in the next procedure!
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just continue thru ALL steps! It had been in one of your logs (not ALL logs) so a kept a procedure in to fix it it was still hiding.

    As I said, just run ALL steps now from beginning to end no matter what happens. When you come back you can tell me of any other problems and then attach a new HJT log.

    I have to run now! 2:15 am and I have to get up at 6 am tomorrow! G'night!
     
  26. timma05

    timma05 Private E-2

    Lol understood, ill be at work here
     
  27. timma05

    timma05 Private E-2

    Alright,my bed time also, Ill be able to get back on here late sat night
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not notice earlier that you had skipped step 3 in the READ ME. You have both Avast and Symantec antivirus applications installed. You must pick the one you prefer and uninstall the other.

    Other than the above and MessengerPlus! 3, you are clean.

    How are things working?

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link! Make sure you do all steps. You don't need to uninstall MS Java. You already have Sun Java but your version is out of date.

    How to Protect yourself from malware!
     
  29. timma05

    timma05 Private E-2

    I had just norton at the time of all the steps, just got avast back bc norton needs activated so thats y you didnt see it, i followed the step lol. i got avast back, seems like a better program, but i couldnt get rid of it at the time, now it is gone. thanks for all the help, give me an D for following instructions but a B for effort lol
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! As long as you have a working antivirus and you only have one installed, then all is good. Norton can be as difficult to remove as malware is. So be ready for problems in fully removing it from your PC.

    Can I now assume you have no more malware problems?
     
  31. timma05

    timma05 Private E-2

    yes sir, thanks a million
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds