They got me

Discussion in 'Malware Help (A Specialist Will Reply)' started by zzpaul, Apr 8, 2008.

  1. zzpaul

    zzpaul Private E-2

    Thought I had everything secure butthis blew right in ( a.dll of some sort) I was notified by Spyware Detector but said it couldn't stop it.
    Now the explorer v 6 stalls as if in a time out but does work after a while.

    ok down to bus
    windows 2000 pro and explorer 6 all updated to the lates ver of everything on a dell precision workstation 530mt dual cpu 2.0 1gb
    Had Max Registry Cleaner and Spyware Detectore running at the time of intrusion.
    attached a hijackthis log

    thanks in advance
    paul
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. zzpaul

    zzpaul Private E-2

    Ran all the steps and found 1 trojan and some adware . Computer is a little smarter but the slow and deliberate explorer problem is still with me.
    please find the attachments
    thanks again
    paul
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach the log from Malwarebytes Anti-Malware. Please attach it.


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to SDService
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.

    Uninstall the below software:
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 0 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME
    ewido anti-malware <-- This was discontinued and replaced by AVG Antispyware a long time ago.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan
    O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
    O4 - Startup: Check for TWS Updates.lnk = C:\Jts\WiseUpdt.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. zzpaul

    zzpaul Private E-2

    I'm trying
    This time I printed out instructions and ticked them off.

    Report: When I open Internet Explorer I get a blank explorer window for 90 seconds. This will happen each time I open a explorer window even when I go from one MajorGeeks window to the next.

    I have a very fast cable connection and usually a window will open in 1 or 2 seconds.

    I really must thankyou so much for helping me. Left on my own I would be formating by now .
     
  6. zzpaul

    zzpaul Private E-2



    good news bad news
    first the scan found "Trojan Agent" did a quarentine and remove
    c:\winnt\system\sysregc.dll
    Internet Explorer still takes 90 seconds to load a page.

    badder news
    my second computer (identical to this one) is now doing exactly them thing with Internet Explorer.
    did all the scans and tweaks and came up with Rogue.Evidence Eliminator in file GLKB.TEMP and did a remove
    problem is still with me.
    I will load up the new logs
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have not attached the log from Malwarebytes as request in the READ ME and also in message # 4 I asked for it again. Please attach it now.

    sysregc.dll is not a problem. It is from installing Max Registry Cleaner. Did you purchase this?

    Your problems with IE may not be due to malware. Your logs are pretty clean now. I do question one file that I'm not sure about and that is C:\WINNT\ddedll.dll Can you please put it into a ZIP file and attach it here?

    And do you know what this C:\Program Files\Synergy3 program is?

    The problem may be due to all the toolbars you have loaded. You may want to look into uninstalling some (or all of them). But let's also do a couple more things. One is to run a rootkit scan just to be on the safe side.


    Please run this Using Sophos Anti-Rootkit and attach the requested log.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  8. zzpaul

    zzpaul Private E-2

    Attached mban.log and sarscan.log and ddedll.dll.zip
    looked on microsoft support site and unchecked third party browser extentions in internet explorer ( cured the slow explorer problem) I removed the google toolbar.
    I keep getting this Trojan.Agent and keep removing it with Malware
    Synergy is a program from sourceforge.com which allows me to use one keyboard and one mouse over many computers. ( it does open the lan up to intrusions) but is just the best little program .

    the registry entry fixme.reg was a success message.

    thanks for your persistence
    paul
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That DLL appears to be okay. It may have something to do with myspace.


    I'm happy to hear you were able to fix this. As I had stated I did not believe it was malware.


    This is not problem! Remember in my previous message where I said.
    Malwarebytes is incorrectly identifying this as a trojan.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds