Ummmm...OK now what???

Discussion in 'Malware Help (A Specialist Will Reply)' started by Petite_Blonde, Jan 2, 2006.

  1. Petite_Blonde

    Petite_Blonde Private E-2

    :( I have read the initial procedure and downloaded, installed the programs asked...went into safe mode etc to find/fix problems. I still seem to have quite a few issues according to bitdefender.

    I don't want to post unwanted information so I will ask....now what???

    Any help will be greatly appreciated.

    PB
     
  2. Petite_Blonde

    Petite_Blonde Private E-2

    Here is my bitdefender text...please if anyone can help!!
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have run the READ & RUN ME, you need to attach 3 logs per the directions in steps 6 and 7 of the READ ME.

    BitDefender
    PandaActiveScan
    HijackThis

    You have not attach anything yet. Also do you notice any malware problems. I mean visibly (this does not mean what BitDefender says).
     
  4. Petite_Blonde

    Petite_Blonde Private E-2

    Thank you for the response...Hopefully I have done this correctly. I am not sure what malware is. I hate not being more educated here. My computer seems to run ok, the only reason I knew I had a problem was because my microsoft beta and Norton both gave me warnings at the same time from visiting a site. So now this!!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What about the PandaActiveScan log?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note you did not follow the directions in step 7 for installing HijackThis and you are running it twice from two different and both incorrect locations. You must fix this now.

    C:\DOCUME~1\Liisa\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
    C:\Documents and Settings\Liisa\My Documents\HJT\HijackThis.exe
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have an infection that is hiding some files on your system. I need the Panda log to help find some of them. Also you will need to run the below two tools so we can look for some additional problem files.

    1 - Please EXTRACT all files from Qoologic Tool to its own folder - C:\Program Files\QoologicFinder . Then, DoubleClick Find-Qoologic.bat to run the tool. It should produce a log - Please attach that with your next post!

    2 - Please EXTRACT all the files form RKFiles Tool to its own folder named C:\Program Files\RKTOOL. Then, Please boot to SAFE MODE and DoubleClick rkfiles.bat to run the tool. Let it run and then, when it finishes, look for a log at C:\Log.txt and please attach that log.


    Now come back here and post all three logs as attachments.
     
  8. Petite_Blonde

    Petite_Blonde Private E-2

    ok first...when I tried to run HJT and a window came up to make a new folder so I did...where is the best place for me to have this/these folders? Sorry I forgot to post the panda log...here it is.

    Should I do another HJT scan once I have the folder in its proper place? I'm sorry to be so clued out...thats why I'm here!!! I appreciate your patience.
     

    Attached Files:

  9. Petite_Blonde

    Petite_Blonde Private E-2

    ok I read how to re-save HJT in program files....should I uninstall it and reinstall to the correct place?
     
  10. Petite_Blonde

    Petite_Blonde Private E-2

    when I double click on Find.Qoologic.bat a window pops up saying

    This application may depend on other compressed files in this folder. For this application to run properly. It is recommended that you first extract all files...Do I ignore that??
     
  11. Petite_Blonde

    Petite_Blonde Private E-2

    ok hopefully I fixed the HJT thing so here is the new log. I read to change my msconfig so I did that to boot normal.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you follow the directions given? They say
    The same for RKfiles.

    I need these two logs before we can continue.
     
  13. Petite_Blonde

    Petite_Blonde Private E-2

    ok I extracted the files from Qoologic tool...clicked on the setup...hit run and Norton has halted my computer saying the setup has malicious content.
     
  14. Petite_Blonde

    Petite_Blonde Private E-2

    ok it did a scan even though I got the warning from norton..will post both after I do the rkfiles...be right back
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Norton is wrong! It is just a script to help detect malware. Rather poor reflection on Norton to detect a simple batch file that is just searching you PC for file information and not the real trojan files that we know you have.
     
  16. Petite_Blonde

    Petite_Blonde Private E-2

    Here are the two logs
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Now attach a current HJT log and make sure you do not reboot or power down afterwards or the malware file could rename itself. Wait until I give you a fix.
     
  18. Petite_Blonde

    Petite_Blonde Private E-2

    Latest HJT...
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay download Pocket KillBox and extract it to its own folder somewhere that you will be able to locate it later later. Do not run it yet. Just get it extracted. I will post a fix that will need it in a few minutes. So I getting you started while I write something up.
     
  20. Petite_Blonde

    Petite_Blonde Private E-2

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet. And do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\sms_msn.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {279A1B41-6CAC-4ABF-B39C-72C8E489F685} - (no file)
    O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\pkqaww.exe reg_run
    O4 - HKLM\..\Run: [elitemedia] C:\WINDOWS\elitemediapop.exe
    O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\qwinrsap.exe FI002
    O4 - HKLM\..\Run: [sms_msn] C:\WINDOWS\system32\sms_msn.exe
    O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\qwinrsap.exe
    O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
    O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
    O15 - Trusted Zone: *.elitemediagroup.net
    O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)

    After clicking Fix, exit HJT.


    Below you will find a list of files that we need to delete using PocketKillbox. Read thru the below instructions so you understand them before starting. You do not want to reboot with Killbox until all filenames have been entered.

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\OIWZ.EXE
    C:\WINDOWS\system32\iaspeen.dll
    C:\WINDOWS\system32pkqaww.exe
    C:\WINDOWS\system32\sms_msn.exe
    C:\WINDOWS\elitemediapop.exe


    and C:\WINDOWS\system32\qwinrsap.exe


    Here is the procedure to use to delete them. Run Pocket Killbox. Select the option to Delete on Reboot.

    Now you are going to repeat the below steps for every file except C:\WINDOWS\system32\qwinrsap.exe (we will add it separately at the end). Replace the the word fullpathfile with the actual full file name path from above (one file at a time). For example, the first time you paste in C:\WINDOWS\system32\iaspeen.dll

    1) Now, Copy and Paste fullpathfile into the box
    2) Now, Click the Red X and Yes to the confirmation message.
    3) A message will ask if you want to reboot now – Click NO.
    4) Repeat for all files except the last one

    For the last file, we will be rebooting when prompted. Here is the final step of the file deletions:

    Now, Copy and Paste C:\WINDOWS\system32\qwinrsap.exe into the box. Make sure you still have Delete on Reboot selected. Then click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your machine to reboot Normally. If you get an error message about "Pending operations", just reboot manually but tell me if you are getting this message.

    After reboot, attach a new HJT log and tell me how these steps went. Also tell me how things are working now. Again DO NOT REBOOT after posting.

    I will check back in later tonight. I'll be offline for awhile now.
     
  22. Petite_Blonde

    Petite_Blonde Private E-2

    Well that seemed to go smoothly..feels like I just performed an operation or something..haha.

    I can't believe the process to go through to get rid of this stuff. I have Norton and the MS anti-spyware beta..I thought I was protected well enough.

    Now I have another question. I had read I need to make changes to my system restore. I won't do anything about that yet until you say everything is OK, but I am not sure what I need to do to clean all that up too.

    Here is my current HJT log.

    Thank you for all of your time and patience with me. I truly appreciate this help and would also like to know where I can make a donation to YOU.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you miss fixing this line?
    O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)

    Try again.

    Other than that, you are clean. How are things working? If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  24. Petite_Blonde

    Petite_Blonde Private E-2

    ok I deleted that line again and did another HJT log just to be certain I am OK to go ahead with the restore.

    A few questions. the file I made on my desktop that I called fixme.reg can I delete that or move it off my desktop?

    Now on my computer and wonder what they are for example...where I store my photos there is faint coloured icons that say thumb.db that weren't there before in each file folder. is that normal?

    My windows media player didn't seem to be as loud as it was previously but I fluffed it off but after the stuff we did my volume is so much better...I notice a file folder called system volume information that is faint as well and when I go to open it to see whats inside it says it's not accessable.

    One more thing..I had a friend here who was on my computer and I notice there is a file called nethood thats also faint. When I open it, it says its password protected to a ftp server. When I hover over the file it shows my friends addy to his company. Is it possible he just signed onto his work email or something? Is there a place to remove this junk if thats what it is.

    Now I feel very paranoid about my privacy after yesterday.
     

    Attached Files:

  25. Petite_Blonde

    Petite_Blonde Private E-2

    OK forget my last post...Looks like I have problems still. I went into safe mode and did all the scans again just to see what they said....that volume file I was talking about seems to be an issue and I haven't gotten rid of the Qoologic.

    Maybe I should have mentioned this previously or possibly it doesn't matter but...my two youngest kids have their own log in for windows...do I need to scan with these programs in their usernames too?

    Posting my latest panda, bitdefender and HJT.
     

    Attached Files:

  26. Petite_Blonde

    Petite_Blonde Private E-2

    one quick thing...I tried to update the immunize on spybot and it doesn't do anything but tell me Im not protected by 1600 and something issues. I kept clicking immunize and tried updating but I still get the same thing
     
  27. Petite_Blonde

    Petite_Blonde Private E-2

    I also just did a log for the Qoologic tool and this is that file. Im afraid to restart my computer till I hear from you.
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can delete fixme.reg.

    thumb.db is normal.

    system volume information is system restore.

    Nethood is a normal folder too. Although for most people it is probably empty. Is is normally in C:\Documents and Settings\username\NetHood where username is the user account name. But it sounds to me like you may be talking about something different. Where is the NetHood you are referring to? And what did you open or run that asked for a password? Perhaps you need to uninstall whatever your friend put on your PC. Ask them what they did.

    You are only just seeing these now because you now have enable viewing of hidden and system files whereas you had this disabled before.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tell me what version of Spybot is running and what the Last Detecion Update indicates (this is a date). Click on Help About while Spybot is running.

    Also to add items to Immunize you first click Immunize on the left of the screen but then you need to click the green plus sign at the top to actually Immunize.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you running all the scans again? Your logs show no problems. You need to do what I said in message number 23 (not the HJT part, the other parts).
     
  31. Petite_Blonde

    Petite_Blonde Private E-2

    I deleted the file from message #23 when you asked.. The version of spybot latest detection update is 2005-12-30

    Your the expert so if you say my scans are clean I trust that.

    I guess when I scanned and they said stuff was there I assumed it was something to be concerned about. I will check and see where that button is for the immunize...thanks very much.

    I will now continue to protect from malware as you posted above.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

     
  33. Petite_Blonde

    Petite_Blonde Private E-2

    When I did the spyware scans they would show that some stuff was cleaned after scan and some not or maybe me being a complete amateur was misunderstanding how to read the logs.

    I did my system restore and now want to hide my files again. I liked it better that way. That made complete sense when you said thats why I was seeing new files...DUH..sheesh I guess my username here is very fitting!

    I thank you very much for all of your help. I really appreciate your time. I would like to know if there is somewhere I can make a donation either to you or this site. I looked around and don't see anywhere to contribute to the help I have received.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you see something again, provide me with specifics. Which program and exactly what did it find and where (attach a log) and ask your questions.

    No we do not take donations but you can buy some a MG's Tee-shirt or sweatshirt etc.
    Click the Geek Wear button on the right side of the main page.

    And also send your friends here!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds