Virus Maybe? Not Sure

Discussion in 'Malware Help (A Specialist Will Reply)' started by biggmoney, Apr 18, 2005.

  1. biggmoney

    biggmoney Private E-2

    Hi,

    First off I am on dialup, and use Earthlink as my provider.
    Which Earthlink is not working right now for some reason.

    I usually download around 3-5 KBPS and right now it will only download at 1 KBPS or less. This all started a few days ago. I ran my anti-virus and found 3 viruses. I use AVG Free.

    1. Trojan Horse BackDoor.Small.23.AD
    2. Trojan Horse Dropper.Small.15.AH
    3. Same as #2 but in different location

    It will also stop all downloads I do, at 50%, and won't finish the download. So some of the things I have tried downloading from this forum, such as SpyBot etc, it wont let me.


    Here are my computer details:
    Operating System: Windows XP Home Edition Service Pack 1 (build 2600)

    Processor: 2.15 gigahertz AMD Athlon XP, 128 kilobyte primary memory cache,
    512 kilobyte secondary memory cache

    Drives:
    160.02 Gigabytes Usable Hard Drive Capacity
    ASUS CD-S480/AH [CD-ROM drive]
    ELBY DVD-ROM SCSI CdRom Device [CD-ROM drive]
    HP DVD Writer 300c [CD-ROM drive]
    3.5" format removeable media [Floppy drive]
    WDC WD1600BB-22DWA0 [Hard drive] (160.04 GB) -- drive 0, s/n WD-WCAEK1079520, rev 15.05R15, SMART Status: Healthy


    I also ran HijackThis and here is its log:

    Edit by chaslang: Unrequested, inline log removed

    I would like to get a different anti-virus, but like right now I can't download anything big in size cause it won't finish the download. I have noticed it will let me download things below 1MB.

    So any help I can get would be appreciated.
     
    Last edited by a moderator: Apr 19, 2005
  2. biggmoney

    biggmoney Private E-2

    Thanks for the help lol
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really need to follow forum guidelines and read the sticky threads. No HijackThis logs should be posted without them being requested and then they must be posted as attachments to your message. You also have HJT installed incorrectly. Please try to follow the steps below. If you cannot get the downloads or run the scans due to your problems, just proceed to the section of downloading and installing and using HJT and follow those steps.

    You should uninstall SpyKiller. It is not useful and has been on a list of rogue/suspect spyware removal tools for quite some time. See: http://www.spywarewarrior.com/rogue_anti-spyware.htm

    Do you know what the next line is for?
    O4 - HKCU\..\Run: [WebWatch] C:\unzipped\SCRIPTS ETC FILES\domainalarm\Domain Alarm.exe

    What version of DAP are you running? Older versions contained malware.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus RemovalMake sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can also start working on the below after installing HijackThis properly!


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\DOCUME~1\Owner\LOCALS~1\Temp\IEXPLORE.exe <-- this is not a valid Internet Explorer

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - (no file)
    O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [Disk Keeper] C:\WINDOWS\System32\Services\{5468AC60-ED9F-49F0-B047-275985393713}\SECURITY.EXE
    O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
    O4 - Startup: PowerReg Scheduler V3.exe
    O21 - SSODL: SysTray - {E61B5E20-DE35-11CF-9C87-1579005127ED} - C:\WINDOWS\System32\msc.cpl (file missing)
    O21 - SSODL: rDcBRIvqKUbSJewL - {18A1900E-B20B-3AA4-DDDC-477C55E6CAD9} - C:\WINDOWS\System32\yjs.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\DOCUME~1\Owner\LOCALS~1\Temp\IEXPLORE.exe
    C:\Program Files\SpyKiller <--- the whole folder
    C:\WINDOWS\System32\yjs.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. biggmoney

    biggmoney Private E-2

    I did everything as you have said.

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\DOCUME~1\Owner\LOCALS~1\Temp\IEXPLORE.exe (Deleted but still shows in hijackthis)
    C:\Program Files\SpyKiller <--- the whole folder (There was no SpyKiller Folder in Program Files To Delete)
    C:\WINDOWS\System32\yjs.dll (This was deleted

    I rebooted in regular mode, and everything is still the same. I stayed up till 6am my time making sure I ran the stuff exactly as you said.

    I reboot and HijackThis automatically creates log, so here that is as well.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't understand why some of those were not fixed and some were!

    Also Spykiller is still there.
    O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup

    Look for it in Add/Remove programs. Is it there? Uninstall if it is.

    Make sure System Restore is disable!
    Make sure viewing of hidden & system files and all file extension types is enable per the READ ME FIRST step 3.


    Please answer my questions from my previous post (see message # 3).

    And why are you using so many accelerator type programs? Having more than one is probably of little use and may serve to slow you down.
     
  7. biggmoney

    biggmoney Private E-2

    Do you know what the next line is for?
    O4 - HKCU\..\Run: [WebWatch] C:\unzipped\SCRIPTS ETC FILES\domainalarm\Domain Alarm.exe
    This is a program that while I am online, watches over a website I have, and lets me know when and if the site goes down.

    What version of DAP are you running? Older versions contained malware
    I have version 5.3.9.8 with all current updates.
    Main Version 5.3.9.8
    IE Intergration Version 7.0.0.1


    Also Spykiller is still there.
    O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
    I checked, in "Add Or Remove", and in "Program Files". It is not in either. And yes I have view all files and folders. I even did a search for that file/folder and my search didn't find it. So don't understand this, cause it says its running, yet its not on my pc.

    And why are you using so many accelerator type programs? Having more than one is probably of little use and may serve to slow you down.
    That I know of I only have one running. Earthlink Accelerator
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member



    This is old and is one of the versions that I would consider containing malware. You should uninstall it. The current version is
    Download Accelerator Plus 7.4. But again, why have multiple accelerators? See below.


    No! You also have DAP!


    Which spyware protection tools like SpywareBlaster, Spybot, Ad-Aware....etc do you have installed.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
    O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\windows\system32\cm.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\windows\system32\cm.exe

    Now run Ccleaner

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  10. biggmoney

    biggmoney Private E-2

    Earthlink Accelerator is for my internet connection, by saving files in a temp folder, so it pulls the sites quicker next time I visit.
    Download Accelerator is for downloads. It speeds up downloads.

    Spyware Tools:
    Spyware Blocker (tool provided by Earthlink)
    NoAdware ver. 3.0
    (All below is stuff I downloaded from the READ ME FIRST)
    Ad-Ware
    Spyware Blaster
    CCleaner
    HsRemove
    Stinger
    CWShredder
    Kill2Me
    AboutBuster
    HijackThis



    I will get to work on your other post now.
     
  11. biggmoney

    biggmoney Private E-2

    Here is my Hijacklog
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! It looks like all the stuff we were trying to remove is gone now. Just fix the below line:

    O21 - SSODL: ShellFolder for CD Burning - {E61B5E20-DE35-11CF-9C87-1579005127ED} - (no file)

    How are things working?
     
  13. biggmoney

    biggmoney Private E-2

    Everything is working fine, except the line below. It doesn't matter how I remove it, every time I reboot it comes back. If I don't remove it, my pc doesn't work right, but if I do remove it, it does work fine.

    C:\DOCUME~1\Owner\LOCALS~1\Temp\IEXPLORE.ex
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That process was not in your last HijackThis log! Are you sure it is still happening.
     
  15. biggmoney

    biggmoney Private E-2

    Yes.

    I have to delete it first thing, or else my pc runs really slow, and sounds like its going 100% power.

    Once you told me to delete that messages ago, I was finally able to download things again, and get the downloads provided on READ ME FIRST. My pc actually acted somewhat right.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! But if you remove items like this that we need to see, it will be difficult for us to help you because we cannot see the problem.

    Please do the below (but it will be necessary for you to do this while the bad Iexplore.exe is running.

    Download ProcessExplorer from:http://www.sysinternals.com/files/procexpnt.zip

    Unzip it to a folder you can find (like c:\SysInternals) and now run ProcessExplorer and lets configure some options first:
    Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked. Now click on C:\DOCUME~1\Owner\LOCALS~1\Temp\IEXPLORE.exe. Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    Now click on File and then Save As. And save the process list. Post it back here as an attachment. Also, from now on if I say to kill a process, use ProcessExplorer instead of Task Manager. Sometimes ProcessExplorer can kill things that Task Manager cannot.
     
  17. biggmoney

    biggmoney Private E-2

    Hi,

    I am not sure whats going on. I rebooted so it would show back up, and went to download what you said too, when this time I noticed it didn't come back. I am not sure if it comes back only when I reboot into safemode then back to normal. I will test that out to see if thats what causes it to come back.

    I have now downloaded ProcessExplorer. And did your steps, but there was no IEXPLORE.exe file.

    So I am attaching both HijackThis and ProcessExplorer.
     
  18. biggmoney

    biggmoney Private E-2

    Sorry forgot the attachments
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need to see it when C:\DOCUME~1\Owner\LOCALS~1\Temp\IEXPLORE.exe
    is running not when the valid Iexplore.exe is running.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds