Various malware and now other probs

Discussion in 'Malware Help (A Specialist Will Reply)' started by loopytait, Dec 8, 2006.

  1. loopytait

    loopytait Private E-2

    I have done everything that Read and Run says to do! (phew) - Which took me 2 days. Poop. Initially we had a horribly infected laptop with malware etc abundant. I think there is still stuff there. I also now have a hardware (I think) problem. Let me know if you want the error number (not sure if I will have to take that to the hardware forum later?? ALso a rundll error has appeared w02f5743.dll - I think it's to do with the clean-up/downloads etc. Anyway here are all my attachments. Thank-you for being here.
     

    Attached Files:

  2. loopytait

    loopytait Private E-2

    Arggh! - I sent you a AVG spyware scan by accident. Please find attached the Counterspy one I should have sent plus others.

    More to come
     

    Attached Files:

  3. loopytait

    loopytait Private E-2

    And finally - The Hyjack This scan. From the Analyse.exe as requested - I hope I've completed all correctly! X
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log from AVG Antispyware shows that you did not fix any of the many problems that it found. Please run a new scan and make sure you fix everything this time. Then attach a this new log from showing what was found and fixed.

    Your CounterSpy also show something you need to take very serious. It found the below file:
    c:\program files\common files\microsoft shared\web folders\ibm00001.dll


    This is a Password Stealing Trojans: Trojan.W32.Torpig

    See this for what you have: http://www.liutilities.com/products/wintaskspro/processlibrary/ibm00001/

    If you use this PC for any financial related matters, you must take this possible threat seriously.

    You are strongly advised to do the following immediately:
    1. Disconnect infected computer from the internet and from any networked computers until the computer can be cleaned. If you have network compters, start checking them for problems too.
    2. Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
    3. From a clean computer, change *all* your online passwords -- for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
    Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passords and transaction information.
     
    Last edited: Dec 9, 2006
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay after you take care of what I gave in message number 4, let's start the cleanup!

    Uninstall the below software:
    Command
    Companion wizard
    Java 2 Runtime Environment, SE v1.4.2_03

    Now install the current version of Sun Java from: Sun Java Runtime Environment
    • Now Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Microsoft authenticate service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteMsaSvc into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Continue by downloading a tool we will need - Pocket KillBox


    Save it to its own folder somewhere that you will be able to locate it later.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\Program Files\Common Files\dc6_startupmon.exe
    C:\Program Files\Common Files\ers_startupmon.exe
    C:\Program Files\Common Files\dc6_startupmon.exe
    C:\Program Files\Common Files\ers_startupmon.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you
    are reading in right now
    :

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forums.majorgeeks.com/showthread.php?t=35407
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
    R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
    O2 - BHO: (no name) - {34BE2630-9E4A-4556-B104-BE245AE6194A} - C:\Program Files\Internet Explorer\nihyvigeb.dll (file missing)
    O4 - HKLM\..\Run: [ssjf0e14] RUNDLL32.EXE w02f5743.dll,n 006f0e0e0000000a02f5743
    O4 - HKLM\..\Run: [DC6] "C:\Program Files\Common Files\dc6_startupmon.exe" /min
    O4 - HKLM\..\Run: [ERS] "C:\Program Files\Common Files\ers_startupmon.exe" /min
    O4 - HKLM\..\Run: [DC6_check] "C:\Program Files\Common Files\dc6_startupmon.exe"
    O4 - HKLM\..\Run: [ERS_check] "C:\Program Files\Common Files\ers_startupmon.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/installdrivecleanerstart.cab
    O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://locator1.cdn.imagesrvr.com/s.../pages/scanner/ErrorSafeNewReleaseInstall.cab
    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.21.10/ttinst.cab

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have
    saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the
    list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-
      click and choose copy):

    C:\Documents and Settings\dave\mc.exe
    C:\Documents and Settings\dave\Application Data\Dxcknwrd.dll
    C:\Documents and Settings\katie\cc.exe
    C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.dll
    C:\Program Files\Common Files\{10F06556-084F-1033-0302-05041124002c}\Update.exe
    C:\Program Files\Common Files\dc6_startupmon.exe
    C:\Program Files\Common Files\ers_startupmon.exe
    C:\Program Files\Common Files\err.log
    C:\WINDOWS\system32\atmtd.dll
    C:\WINDOWS\system32\sporder.dll
    C:\WINDOWS\system32\ssjf0e14.dll
    C:\windows\system32\w02f5743.dll
    c:\windows\keyboard1.dat
    C:\WINDOWS\NDNuninstall6_38.ex
    C:\WINDOWS\NDNuninstall7_22.exe
    C:\deskbar_e55.exe
    C:\deskbar_e58.exe
    C:\deskbar_e90.exe
    C:\dfndrff_e56.ex0
    C:\keyxk.exe"
    C:\kybrdff_e56.exe
    C:\RDFX4.exe
    C:\uniq
    C:\WA6P
    C:\yz02.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a
    PendingFileRenameOperations
    prompt, just click OK to continue (But please let me know if you receive this message!).[/
    COLOR]

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Documents and Settings\dave\Application Data\WinAntiVirus Pro 2006
    C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2006
    C:\Program Files\Common Files\Companion Wizard
    C:\Program Files\Common Files\WinAntiVirus Pro 2006
    C:\Program Files\Common Files\{10F06556-084F-1033-0302-05041124002c}
    C:\Program Files\Deskbar
    C:\Program Files\Network Monitor

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1
    of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. loopytait

    loopytait Private E-2

    Thak for your response - I have beenoffline for a couple of days due to a family bereavement - but I'm back on it now... so starting with the password stealer- . I do have a second PC networked to the infected one. This is my "work" PC. It has Norton Internet security - up to date etc. Should I run the "free scan" that is on the link that you sent to me on my work PC??? - Or would it be better to run Counterspy? Thanks.
    PS: I dodn't "fix" the AVG stuff, because I realised that I should have been using Counterspy (as per the Read and Run instructions)... so I ran and "fixed" using that instead. WOuld you still like me to run and Fix the AVG one as well??
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry to hear this!

    Are you talking about scanning your 2nd PC for malware? If so, no don't run the performance scan from the LIUtilities site. You would be better served by running the READ & RUN ME on it to make sure it is not infected. But I don't suggest putting any logs from it in this thread. It would be better to post them in a second thread and just reference this thread as the reason for doing the scans.

    You only needed to install one. If you still have AVG Antispyware installed, yes, run a new scan and let it fix anything found. Attach the new log. It found many things not shown in the CounterSpy log.


    /
     
  8. loopytait

    loopytait Private E-2

    OK.. Thanks so far!! - I have followed all the instructions. I am definitely not getting all the pop-ups adware etc that I had been seeing and I am now not getting the rundll error either. Attached are the 3 logs as requested. I will also send the AVG log in a second message. Thank-you.
     

    Attached Files:

  9. loopytait

    loopytait Private E-2

    As promised... the AVG scan and fix from today.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay have one folder to delete and then you are clean. Delete the below folder:
    C:\WA6P

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  11. loopytait

    loopytait Private E-2

    Yippeeeee! - Clean, at last! - I feel like I've had a week long shower! - I'm ready for the How to protect yourself bit now... so I'll go to that next.
    Just 2 last questions.... When I did the System restore thing my PC didn't ask if I wanted to reboot (I did reboot anyway), but is there any way I can check what the restore points actually are??

    Also - On my "work" PC (the one that is networked to this one that we have been working on) I have Norton... I've noticed that people here aren't that impressed with it. Is there something better I should use?? - Many Many Many Thanks!! - Happy Holidays! from the UK.:)
     
  12. loopytait

    loopytait Private E-2

    Hmmm - Help - new prob? or part of fix?? - I was trying to download updates to Windows (as per How to protect yourself instructions). It wanted to download about 7... part of the way through the laptop crashed! - Stop Error: 0x0000608E (0xC0000005, 0xF1A23BAA, 0xF0132A20,0x00000000) - On restart it suggested a driver error from recent installation of either hardware (none installed) or software..... any ideas? - Do you want me to start this as a new thread? Thanks, Loopy
     
  13. loopytait

    loopytait Private E-2

    OK -Went back and did the Windows update thing again... but refused the Explorer 7 update - all went fine. Could it be that update?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what the problem is with Internet Explorer 7. You would be better off asking this question in the Software Forum since it is not a topic we would cover in the Malware Forum. Sorry we just don't have the time to cover non-malware problems here.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds