Tons of problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by ppreheim, Dec 3, 2004.

  1. ppreheim

    ppreheim Private First Class

    My computer is running very slow and has many problems.
    Symptoms
    1 - Every time I try to go from folder to folder I get an explorer error before I can go to the next folder. This is slowing down the computer immensly.

    2 - Per House call I have 23 viruses that I cannot get rid of. These include
    Troj AGENT.EG (8)
    Troj SMALL.TF
    Troj STILEN.A
    Troj QDOWN.J(2)
    Troj SMALL.JI(3)
    Troj AGENT.BN(2)
    BKDR Padodor.D(2)
    Troj Apropo.D
    BKDR.Sandbox.A
    ADW.Scanportals.A

    I have tried all the tools I trust. These include S&D, Adaware personal, AboutBuster,CWS Shredder, spybot and others. Adaware and S&D find tons of stuff, but both crash when trying to eradicate the vermin. This happens even when running in safe mode. I am at my wits end. Please help!!!
     
  2. PhilliePhan

    PhilliePhan Guest

    Hi Ppreheim,

    Generally, it is a good idea to start with the Cleanup Tutorial HERE:
    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan and Virus Removal

    This will remove a lot of stuff that would otherwise clog a HJT log.

    Please note the steps that you are able to complete and the ones that give you problems. Note that you need to be in Safe Mode with System Restore OFF (if you have it - you didn't give OS) and have the Viewing of Hidden Files ENABLED as per the instructions in the link. Make sure to do the Online Scans.

    Post back and let us know how you fared. Also, send us a HijackThis Log. Make sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.98.2) and MUST be extracted to its own safe folder – C:\Program Files\HijackThis!

    If you need a Fresh Download of HJT, get it HERE: HijackThis 1.98.2

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    Somebody will take a look when they get a chance.

    Best luck :)
    PP
     
  3. ppreheim

    ppreheim Private First Class

    I am following the above steps very deliberately. I have come to a problem in step 4 of the cleaning instructions. I have tried all the places from Major geeks to download kill2me and a few places I found in google. I cannot get the file to download. For some reason my computer won't hook up to any server that will send me the file. It gets stuck at the "getting file desrcription" page. It just stays there and spins its wheels. Any suggestions. I will continue on with step 5 and check back constantly for help. Thanks
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I attached it here but I renamed the ZIP file to renamek2m.zip just in case your problem is due to the name being recognize.
     

    Attached Files:

  5. ppreheim

    ppreheim Private First Class

    Update

    1 - disabled system restore
    2 - no networks services running
    3 - Enabled viewing of hidden folder and extensions
    4 - Downloaded all tools listed except kill2me
    5 - Ran Trend Micros scan and deleted these files
    Troj AGENT.EG (8)
    Troj SMALL.TF
    Troj STILEN.A
    Troj QDOWN.J(2)
    Troj SMALL.JI(3)
    Troj AGENT.BN(2)
    BKDR Padodor.D(2)
    Troj Apropo.D
    BKDR.Sandbox.A
    ADW.Scanportals.A

    - Ran symantics online scan and it found 20 more viruses and trojans. Didnt find a way to clean, but have the log from the findings.
    - Ran Avert Stinger, I think it found and cleaned 8 files
    - Cleaned HD with CCleaner as suggested
    - Scanned with Adaware SE - found 190+ items. Whenever I try to clean it however the computer reboots.
    - Spybot was used and worked effectively
    - CWS Shredder - nothing found
    - Kill2me - couldnt download
    - About:buster - nothing found
    - HSRemove - FOund 8 items and removed them

    At the completion of the above I tried to go back to this forum and post this, but the IE would lock up everytime I got to this page. The home page was changed from About:blank to the HSRemove page. I still get an explorer error every time I try to navigate from folder to folder. I will download the Kill2me on another computer and transfer it to the infected computer via a removable drive. Will post update then. Thanks for all your help.
     
  6. ppreheim

    ppreheim Private First Class

    PS - Running windows XP - Tried to edit last post, but wasn;t allowed to due to the 5 min. rule.
     
  7. ppreheim

    ppreheim Private First Class

    Oops, forgot about this on about:buster. When I ran that program it went through 98% with no problems. When it got to the last 2% it just died. Didnt lock up, but went very slow. Let it run for about 30 minutes and only moved 3 files of the last 30 in that time. Would have edited this info into that post if I could of. Sorry

    I would have posted the HT log if I could have gotten to this webpage without the IE shutting down. Will post it tomorrow after I save it to a removable drive so I can post it from my work computer.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you doing the scans with about:Buster and Ad-Aware SE (actually for all programs) in safe mode? Let about:Buster run longer you could have a load of bad stuff.

    Did you try getting Kill2me from the attachment I added to my previous message?

    Your home page will be set to hsremove by the HSremove program. About:Buster will set your home page to www.google.com
     
  9. ppreheim

    ppreheim Private First Class

    Yep, did the scans in safe mode.
    OK, will let About:Buster run for as long as it takes.
    I tried to get it off your attachment, but the browser kept locking up whenever I got to this page. I would get "not responding" in the task manager every time. Will download it on to a disk from another computer and try again in about an hour. Thanks again
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let me know when you finish that. Also, try to get a HijackThis log posted.
     
  11. ppreheim

    ppreheim Private First Class

    Sorry for the delay. I was on vacation for the last 3+ weeks.

    I have repeated the steps in the before you ask for help list.
    Adaware SE still crashes everytime I run. I also ran avast and ADS Spy. Neither found anything.

    I am posting the Hijack this file. Thanks in advance.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    You have a ton of trojans and do not appear to have an antivirus program installed. And have not run the online scans. You MUST run the online scanners and Stinger now. If you cannot run them in safe mode, run them in normal boot mode.

    You need an antivirus application now!!! Download and install the below and scan with it as soon as installed (run it in safe mode and then in normal mode).

    Avast! Home Edition

    Also run these:
    http://tools.zerosrealm.com/PeperFix.exe
    http://www.memorywatcher.com/uninst.exe

    Run HJT and have it fix all the O1 Hosts lines.

    Then get a new HJT log and post it.
     
  13. ppreheim

    ppreheim Private First Class

    Thanks for the help.

    I had taken the computer off the internet to keep it from getting worse while I was on vacation. I reconnected and ran the online scan. It found 26 trojans and was able to delete 25 of them. Even though I was in safe mode with networking it could not delete

    C:\WINNT\System32\kbdhvl249o.dll (it was in use and could not be deleted)

    I then ran stringer and it did not find anything
    installed Avast Home edition. ran it upon boot and it found and deleted 36 files, (thank you, did not know that program existed)

    Ran Peper fix - No files found
    Ran Uninst.exe - Don't know if it worked or not as the progress bar only got to about 40% when the program closed. Ran it about 5 times and each time it did the same thing.

    Both peper and uninst.exe were run in safe made, as were all the programs.

    Ran HJT and fixed all the O1 Hosts files. Log is below.

    Again - Thank you very much for all of your time. It is greatly appreciated!!!!

    Lates HJT log is attached as 1_10hjt.log
     

    Attached Files:

  14. ppreheim

    ppreheim Private First Class

    Update - After posting the last message I installed the new version of adaware and ran it. I was finally able to run it without crashing. It found 160+ critical items and deleted them. I am posting a new HJT log as it it slightly different after the succesful adaware attempt. Calling this log 1_10hjtb
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is that log from normal boot mode or safe mode? I need normal boot mode. You still have lots of trojans.

    Did you run the the below in normal boot while there was internet access available. (They need it).
    http://tools.zerosrealm.com/PeperFix.exe
    http://www.memorywatcher.com/uninst.exe


    Boot in safe mode and delete all files and sub-folders in the below folder:
    C:\documents and settings\owner\local settings\temp
     
    Last edited: Jan 10, 2005
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After doing what was in my previous message, do the below:

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).


    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side.
    Look for the following process (or processes) and if found, one at a time kill them by selecting it and then click "Kill process". Then click yes.

    C:\WINNT\System32\LgnJ8V3.exe
    C:\WINNT\System32\automove.exe
    C:\WINNT\aqadcup.exe
    C:\WINNT\jawa32.exe
    C:\WINNT\QuickBrowser.exe
    C:\WINNT\jawa32.exe
    C:\WINNT\System32\cabview4.exe
    C:\WINNT\System32\erspolcy.exe
    C:\WINNT\XtTb.exe
    C:\WINNT\SStb.exe
    C:\WINNT\ssqb.exe
    C:\WINNT\System32\seremgmt.exe
    C:\WINNT\System32\serwvdrv.exe
    C:\WINNT\system32\kbdic180m.exe
    C:\WINNT\system32\?hkdsk.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
    O2 - BHO: ServerSide - {7FC56022-4EDA-472E-8830-7CA92CCBD025} - C:\Program Files\NetMeeting\SS\ServerSide.dll
    O2 - BHO: KGhost - {968BC8A3-7660-4B12-B2BF-3334775835E1} - C:\Program Files\NetMeeting\KG\KGhost.dll
    O2 - BHO: (no name) - {F8AF9487-063A-27C8-1953-5CF07ECC6F9F} - C:\WINNT\system32\mddc.dll
    O4 - HKLM\..\Run: [C14o] C:\documents and settings\owner\local settings\temp\C14o.exe
    O4 - HKLM\..\Run: [46W9ZTR4PK2DPL] C:\WINNT\System32\LgnJ8V3.exe
    O4 - HKLM\..\Run: [Adstartup] C:\WINNT\System32\automove.exe
    O4 - HKLM\..\Run: [aqadcup] C:\WINNT\aqadcup.exe
    O4 - HKLM\..\Run: [58UTiJRxt] C:\documents and settings\owner\local settings\temp\58UTiJRxt.exe
    O4 - HKLM\..\Run: [E47ecHL6] C:\documents and settings\owner\local settings\temp\E47ecHL6.exe
    O4 - HKLM\..\Run: [Jawa32] C:\WINNT\jawa32.exe
    O4 - HKLM\..\Run: [3nD] C:\documents and settings\owner\local settings\temp\3nD.exe
    O4 - HKLM\..\Run: [1n8r7SLvH] C:\documents and settings\owner\local settings\temp\1n8r7SLvH.exe
    O4 - HKLM\..\Run: [lV] C:\documents and settings\owner\local settings\temp\lV.exe
    O4 - HKLM\..\Run: [jc] C:\documents and settings\owner\local settings\temp\jc.exe
    O4 - HKLM\..\Run: [iP] C:\documents and settings\owner\local settings\temp\iP.exe
    O4 - HKLM\..\Run: [BECN9] C:\documents and settings\owner\local settings\temp\BECN9.exe
    O4 - HKLM\..\Run: [dzfQZJo] C:\documents and settings\owner\local settings\temp\dzfQZJo.exe
    O4 - HKLM\..\Run: [964786fb1d5a] C:\WINNT\System32\cabview4.exe
    O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
    O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
    O4 - HKLM\..\Run: [QBRSR] C:\WINNT\QuickBrowser.exe
    O4 - HKLM\..\Run: [Jawa322] C:\WINNT\jawa32.exe
    O4 - HKLM\..\Run: [C14o.exe] C:\documents and settings\owner\local settings\temp\C14o.exe
    O4 - HKLM\..\Run: [58UTiJRxt.exe] C:\documents and settings\owner\local settings\temp\58UTiJRxt.exe
    O4 - HKLM\..\Run: [E47ecHL6.exe] C:\documents and settings\owner\local settings\temp\E47ecHL6.exe
    O4 - HKLM\..\Run: [3nD.exe] C:\documents and settings\owner\local settings\temp\3nD.exe
    O4 - HKLM\..\Run: [lV.exe] C:\documents and settings\owner\local settings\temp\lV.exe
    O4 - HKLM\..\Run: [1n8r7SLvH.exe] C:\documents and settings\owner\local settings\temp\1n8r7SLvH.exe
    O4 - HKLM\..\Run: [jc.exe] C:\documents and settings\owner\local settings\temp\jc.exe
    O4 - HKLM\..\Run: [BECN9.exe] C:\documents and settings\owner\local settings\temp\BECN9.exe
    O4 - HKLM\..\Run: [dzfQZJo.exe] C:\documents and settings\owner\local settings\temp\dzfQZJo.exe
    O4 - HKLM\..\Run: [iP.exe] C:\documents and settings\owner\local settings\temp\iP.exe
    O4 - HKLM\..\Run: [xFEO36V] erspolcy.exe
    O4 - HKLM\..\Run: [XtTb.exe] C:\WINNT\XtTb.exe
    O4 - HKLM\..\Run: [SrprcGyy.exe] C:\documents and settings\owner\local settings\temp\SrprcGyy.exe
    O4 - HKLM\..\Run: [MfD6mo.exe] C:\documents and settings\owner\local settings\temp\MfD6mo.exe
    O4 - HKLM\..\Run: [SStb.exe] C:\WINNT\SStb.exe
    O4 - HKLM\..\Run: [ssqb.exe] C:\WINNT\ssqb.exe
    O4 - HKCU\..\Run: [goxERWZpi] seremgmt.exe
    O4 - HKCU\..\Run: [msvcrt] C:\WINNT\System32\msvcrt.exe
    O4 - HKCU\..\Run: [serwvdrv] C:\WINNT\System32\serwvdrv.exe
    O4 - HKCU\..\Run: [kbdic180m.exe] "C:\WINNT\system32\kbdic180m.exe"
    O4 - HKCU\..\Run: [Ewzrpg] C:\WINNT\system32\?hkdsk.exe
    O4 - HKCU\..\Run: [Tpdr] C:\Documents and Settings\Owner\Application Data\roba.exe
    O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINNT\System32\ms.exe (file missing)
    O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINNT\System32\ms.exe (file missing)
    O9 - Extra button: (no name) - {68AB5548-1405-4C9B-A28B-789F4A088BAF} - (no file) (HKCU)
    O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\NetMeeting\SS\ServerSide.dll
    C:\Program Files\NetMeeting\KG\KGhost.dll
    C:\WINNT\system32\mddc.dll
    C:\WINNT\System32\LgnJ8V3.exe
    C:\WINNT\System32\automove.exe
    C:\WINNT\aqadcup.exe
    C:\WINNT\jawa32.exe
    C:\WINNT\QuickBrowser.exe
    C:\WINNT\jawa32.exe
    C:\WINNT\System32\cabview4.exe
    C:\WINNT\System32\erspolcy.exe
    C:\WINNT\XtTb.exe
    C:\WINNT\SStb.exe
    C:\WINNT\ssqb.exe
    C:\WINNT\System32\seremgmt.exe
    C:\WINNT\System32\serwvdrv.exe
    C:\WINNT\system32\kbdic180m.exe
    C:\WINNT\system32\?hkdsk.exe
    c:\counter.cab

    I don't want to delete the below file just yet. So leave it be.
    C:\WINNT\System32\msvcrt.exe

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.


    NOTE: I'm assuming that if you deleted the files I requested in my last message in the temp folder the below files will be gone.
    C:\documents and settings\owner\local settings\temp\58UTiJRxt.exe
    C:\documents and settings\owner\local settings\temp\E47ecHL6.exe
    C:\documents and settings\owner\local settings\temp\3nD.exe
    C:\documents and settings\owner\local settings\temp\1n8r7SLvH.exe
    C:\documents and settings\owner\local settings\temp\lV.exe
    C:\documents and settings\owner\local settings\temp\jc.exe
    C:\documents and settings\owner\local settings\temp\iP.exe
    C:\documents and settings\owner\local settings\temp\BECN9.exe
    C:\documents and settings\owner\local settings\temp\dzfQZJo.exe
    C:\documents and settings\owner\local settings\temp\C14o.exe
    C:\documents and settings\owner\local settings\temp\58UTiJRxt.exe
    C:\documents and settings\owner\local settings\temp\E47ecHL6.exe
    C:\documents and settings\owner\local settings\temp\3nD.exe
    C:\documents and settings\owner\local settings\temp\lV.exe
    C:\documents and settings\owner\local settings\temp\1n8r7SLvH.exe
    C:\documents and settings\owner\local settings\temp\jc.exe
    C:\documents and settings\owner\local settings\temp\BECN9.exe
    C:\documents and settings\owner\local settings\temp\dzfQZJo.exe
    C:\documents and settings\owner\local settings\temp\iP.exe
    C:\documents and settings\owner\local settings\temp\SrprcGyy.exe
    C:\documents and settings\owner\local settings\temp\MfD6mo.exe
    C:\Documents and Settings\Owner\Application Data\roba.exe
     
  17. ppreheim

    ppreheim Private First Class

    The previous log was from safe mode. I also ran those programs initially in safe mode. Reran them today in normal mode. Peper ran completely and didn't find anything. uninst.exe ran to abou 45% of its progress bar, stallled for a few seconds, and then quit. I don't know if it worked or not.

    Deleted everything in C:\documents and settings\owner\local settings\temp

    Went to "Kill Processes" in HJT only found C:\WINNT\System32\cabview4.exe running

    Fixed all with Browser closed except:
    O2 - BHO: (no name) - {F8AF9487-063A-27C8-1953-5CF07ECC6F9F} - C:\WINNT\system32\mddc.dll
    O4 - HKLM\..\Run: [46W9ZTR4PK2DPL] C:\WINNT\System32\LgnJ8V3.exe
    O4 - HKCU\..\Run: [Ewzrpg] C:\WINNT\system32\?hkdsk.exe

    I could not locate those lines

    Deleted all programs except:
    C:\WINNT\system32\mddc.dll
    C:\WINNT\System32\LgnJ8V3.exe
    C:\WINNT\System32\automove.exe
    C:\WINNT\aqadcup.exe - (found a aqadcup.rcf file and moved that to the recycle bin)
    C:\WINNT\jawa32.exe (Found jawa32e.bin, jawa32vs.bin, java32.bat and trashed them
    C:\WINNT\System32\erspolcy.exe
    C:\WINNT\System32\seremgmt.exe
    C:\WINNT\System32\serwvdrv.exe (found a dll by this name, could not delete.Access denied)
    C:\WINNT\system32\?hkdsk.exe (found a dll by this name, could not delete.Access denied)
    c:\counter.cab


    Deleted C:\Documents and Settings\Owner\Application Data\roba.exe

    Rebooted into normal mode and ran HJT - Log attached

    No pop-ups so far will reboot and try some more. Things look pretty good though, at least from my non-genious mind. Thanks again for all the help.. I would never have been able to solve this without you.
     
  18. ppreheim

    ppreheim Private First Class

    Rebooted and things look great. Should I delete those similar files I found, or put them back?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    I would delete them. You never posted the follow up HJT log.
     
  20. ppreheim

    ppreheim Private First Class

    Oops, sorry about that, here it is.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side.
    Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINNT\system32\r?gsvr32.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {E17A4A49-D1F9-A858-823A-8A4DF5A77D92} - C:\WINNT\system32\qjcricr.dll
    O4 - HKCU\..\Run: [Aabq] C:\WINNT\system32\r?gsvr32.exe
    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINNT\system32\qjcricr.dll

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  22. ppreheim

    ppreheim Private First Class

    Was able to do all the instructions except the deletion of qjcricr.dll as it could not be found. HJT is posted....... Thanks
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  24. ppreheim

    ppreheim Private First Class

    Thanks again for everything. So nice to have a computer I can navigate the internet with again.

    Will do the pretection thread now!!

    Thanks again!!
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Happy safe-surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds