Unknown Problem.

Discussion in 'Malware Help (A Specialist Will Reply)' started by soulvaki, Dec 20, 2008.

  1. soulvaki

    soulvaki Private E-2

    It all started when I needed Adobe Dreamweaver for a school project. I first went to the reccomended Adobe site and couldn't get the download manager to work on any browser. So I went and found it through other means. I ran it and my computer was infected. Errors of certain .tmp files come up on startup. There was viewpoint.exe errors too until I uninstalled viewpoint. I've noticed there's a whole lot of svchost.exe's in my processes. It loads internet explorer multiple times in the background. Also when I right click in firefox I get a pop up that says "test 4". I have AVG Free 8 and it's fully updated. I ran it and it found 12 trojans. It said it got rid of them, but the problem is still about. I ran CCleaner and ATFcleaner. I've read the initial post and the only thing that worked was MGTools and I've attached the log. None of the other programs will even start. The mouse shows an hourglass for one second, then nothing happens. Any help would be gladly appreciated.
     

    Attached Files:

  2. soulvaki

    soulvaki Private E-2

    Oh, I don't mean to bump or anything. I ran another scan in AVG while in safe mode today. I've attached the log that produced.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    First we need to cleanup from Norton being installed since you now have AVG.

    Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)

    Now you need to uninstall the below as requested in step 1 of the READ & RUN ME:
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 4
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 2
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6 Update 1
    Messenger Plus! 3 <-- this program is the source of tens of thousands of infected PCs due to malware sponsor programs
    Messenger Plus! Live <-- this program is the source of tens of thousands of infected PCs due to malware sponsor programs
    Spybot - Search & Destroy 1.3 <-- 4 years out of date

    You need to cleanup your Desktop immediately. Remove everything except lnk icons and ComboFix.exe which we asked you to save there. And the below should be deleted:
    Code:
    C:\Documents and Settings\Compaq_Owner\Desktop\
    bcro.exe      Dec 18 2008     3074552  "bcro.exe"
    taskmgr.exe   Aug  4 2004      135680  "taskmgr.exe"
    _CRACK_       Dec 17 2008              "_crack_"
    

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\tmr\WinTmr.exe,
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [WinSvr] C:\WINDOWS\system32\tmr\WinTmr.exe
    O18 - Filter hijack: text/html - {DFAA31C8-A356-4313-9D95-5EDAB46C5070} - (no file)
    O20 - AppInit_DLLs: wbsys.dll,slarse.dll,avgrsstx.dll
    O20 - Winlogon Notify: rwachyx - C:\WINDOWS\SYSTEM32\rwachyx.dll
    O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
    O23 - Service: FCI - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe
    O23 - Service: ICF - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.
    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Compaq_Owner\Local Settings\Temp

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    See if you can run the other scans from the READ & RUN ME now. Try all of the below:
    • SUPERAntiSpyware
    • Malwarebytes
    • Spybot
    • ComboFix
    Attach logs from any of the above that run.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds