Virus Help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Shaniqua007, Jan 3, 2007.

  1. Shaniqua007

    Shaniqua007 Private E-2

    Hey guys. I need help! I seem to have downloaded a super smart virus. I read the malware removal post and did steps 0-5, but then i hit a few snags in step 6. I'm in safe mode and was able to run Ccleaner and spybot and counterspy, but I am not able to run the online scanner at bitdefender. When I click on the link it tells me that this page is not available. I think it's the virus doing it because I know I'm online as I am posting this right now. It also did this before when I tried to download my symantec antivirus updates, and go to a few other antivirus pages so it looks like this virus is blocking certain antivirus pages, even after steps 1-5. I didn't know if I should try to run PandaActive scan, because I haven't run bitdefender yet, and the post said to run bitdefender first. So, what should I do next? I'm posting the logs I have thus far.
    Thanks!
     

    Attached Files:

  2. Shaniqua007

    Shaniqua007 Private E-2

    oh ya, I should also add that this virus keeps turning off my system restore, so I'm really hesitant to not follow the posted instructions EXACTLY because I don't have any system restore points to fall back on. HELP!
     
  3. Shaniqua007

    Shaniqua007 Private E-2

    Me again! Ok, so I've continued with what the "read and run first" post said and I think I may be virus free, but I'm not sure! I did steps 0-7, but I was unable to run ditdefender so I skipped that step.

    Now when my computer starts up the only thing that seems out of place is that it displays a message that says it can't find c:\WINDOWS\system32\dstpdmmtdp\winlogon.exe and I just click ok and my comp starts up and everythng seems fine. So, was that a virused file that I deleted that is still listed in the registry? should I delete it from the resgistry? Also, I'm just wondering if I'm really in the clear because counterspy also detects a program trying to add itself to the startup registry, and so I just click block, but I'm wondering what's going to happen in 14 days when my free trial of Cspy runs out. Anyways, enough jabber, here are my logs! Thanks in advance for any advice!
     

    Attached Files:

  4. Shaniqua007

    Shaniqua007 Private E-2

    here is the last logfile
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    No! You still have a load of problems!

    Is the below ProxyServer setting something you configured?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = webproxy.queensu.ca:80

    Also did you disable RemoteAdministration and did you install this?
    https://secure.logmein.com/activex/RACtrl.cab

    Now download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Now Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_04
    Mozilla Firefox (1.0.4)

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\Program Files\Common Files\{288D813E-0AF0-1033-0701-040405130002}\Update.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F3 - REG:win.ini: load=C:\WINDOWS\system32\dstpdmmtdp\winlogon.exe
    F3 - REG:win.ini: run=C:\WINDOWS\system32\dstpdmmtdp\winlogon.exe
    O4 - HKLM\..\Run: [Microsoft Wind Protection Subsystems] windxp.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Wxtdfial] C:\Program Files\Aksptvb\Hksmpj.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [{288D813E-0AF0-1033-0701-040405130002}] "C:\Program Files\Common Files\{288D813E-0AF0-1033-0701-040405130002}\Update.exe" te-110-12-0000282
    O4 - HKLM\..\RunServices: [Microsoft Wind Protection Subsystems] windxp.exe

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\AT2M1GL0\loud[1].htm
    C:\temp\salmau.dat
    C:\Program Files\Aksptvb\Hksmpj.exe
    C:\Program Files\Common Files\{288D813E-0AF0-1033-0701-040405130002}\system.dll
    C:\Program Files\Common Files\{288D813E-0AF0-1033-0701-040405130002}\Update.exe
    C:\WINDOWS\system32\dstpdmmtdp\winlogon.exe
    C:\WINDOWS\system32\windxp.exe
    C:\WINDOWS\system32\svchosts.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folders and delete if found:
    C:\WINDOWS\system32\dstpdmmtdp
    C:\Program Files\Aksptvb
    C:\Program Files\InetGet2
    C:\Program Files\Network Monitor
    C:\Program Files\Common Files\{288D813E-0AF0-1033-0701-040405130002}
    C:\Program Files\Common Files\{288D813E-0AF1-1033-0701-040405130002}
    C:\Program Files\Common Files\{388D813E-0AF0-1033-0701-040405130002}

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\Enobong\Local Settings\Temp\

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Jan 8, 2007
  6. Shaniqua007

    Shaniqua007 Private E-2

    Hey Chaslang!

    Thanks so much for the help! I've run into a snag though... I ran hjt but when it came time for me to paste that bolded text into notepad and rename it fixME.reg, when I clicked on it, a msg said this this was not a valid Win32 application. What's wrong? What do I do now?
     
  7. Shaniqua007

    Shaniqua007 Private E-2

    Oh, and yes the proxyserver is something I configured, but I don't recall disabling RemoteAdministration or installing https://secure.logmein.com/activex/RACtrl.cab The name doesn't ring a bell, and when I clicked on it it said that it can't verify the publisher so I decided to not run it to see what it was! Thanks! Waiting for more instructions!
     
  8. Shaniqua007

    Shaniqua007 Private E-2

    Ok, so I never was able to get fixME.reg to merge with the system registry files by clicking on it, but my brother helped me out and edited the registry files manually, so that got done. Everything else went smoothly EXCEPT at one point you asked me to go into my computer and manually delete a bunch of files. I did that, except there were no files named C:\Program Files\Aksptvb or C:\Program Files\Network Monitor for me to delete. The rest were there though, and I deleted them.

    Here are my latest logs. Am I in the clear yet?
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is LogMeIn! A remote desktop application that you probably installed an used at some point. If you don't use this, then have HJT fix the below line:
    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100

    You did not save the registry patch file correctly and that is why you had a problem with it. The edits you did manually were not all completed correctly. Let's do this differently. Download the attach fixIT.zip file and extract the contents to your Desktop. That will put a fixIt.reg file on your Desktop. Double click on fixIt.reg and say yes to add it to the registy.


    Also delete the below file:
    C:\Documents and Settings\Enobong\Start Menu\Programs\Startup\winlogon.lnk

    You did not tell me how things are working!
     

    Attached Files:

  10. Shaniqua007

    Shaniqua007 Private E-2

    Ok, still having a few problems. I deleted logmein cuz I don't use it anymore. I also deleted winlogon like you said. I still can't get the registry file to merge. I downloaded fixIT.reg like you said, unzipped it, put it on the desktop and double clicked it. It says "this is not a valid Win32 application". I tried right clicking it and selecting "merge" same thing. Not working. Can I just go in and make the changes manually again? You'll have to walk me thru how to do that though, cuz my brother did it for me the 1st time. Other than not being able to get the registry thing to merge, my comp seems to be working fine, but then again it pretty much always was. It looks like my Symantec antivirus files are updating again, but I have no way to be sure. CounterSpy isn't blocking a bunch of programs at startup anymore, so it looks like those are gone. And I can visit the Symantec website again, whereas before it was being blocked, so again, I'm wondering if I'm in the clear. What now? I'm dying to be virus free! I feel like I'm so close! Thanks!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you click Start, Run, and enter regedit and click OK! Does the Windows Registry Editor open up?

    If so click File, Import and navigate to the fixIt.reg file on your Desktop and select it.

    You are basically clean, we just need to finalize the registry fixes and find out why you are having a problem with registry patches. Typically that is a sign of one of two things:

    1) either directions are not followed exactly (and I assume since I gave you a ZIP file and you extracted it to the Desktop, that this is not the problem)
    2) a problem within the operating system exists. Either a configuration error, a policy restriction, or missing/corrupted files.
     
  12. Shaniqua007

    Shaniqua007 Private E-2

    Yay! So I got the registry file to merge by going to it thru the start menu. So that's all done. I think maybe CounterSpy was blocking the changes I was trying to make before, because this time when I went to it via the start menu and got the reg editor to come up and I clicked open fixIT.reg, then CS poped up a window that said "a program is trying to add itself to the regisrty files" and I had to click "allow". So maybe that was the problem, although that message didn't pop up before. Just an idea. Anyways, we appear to be in the clear now. Is it time for a system restore toggle now? And did you want to see any more logfiles to make sure the changes went thru correctly? Thanks for all the help!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You'te welcome and yes attach another log from GetRunKey!

    And then immediately continue with the below, if you are not having any other malware problems:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  14. Shaniqua007

    Shaniqua007 Private E-2

    Yes! It feels so good to be virus free again! Thank you SOO MUCH Chaslang! See these? :cry They're tears of joy. Here's the last log.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your clean but I want you to do two more things!

    First uninstall the CounterSpy trial which is of no use after the trial period.

    Then run this new registry patch.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now we are done (that is assuming you completed the How to protect thread).
     
  16. Shaniqua007

    Shaniqua007 Private E-2

    Yay! Done and done. Much love to you Chaslang. You must get all the women doing this... :heart
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Women???? Who has time for women when I cannot get a free minute with all this malware! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds