Virus/Spyware attack

Discussion in 'Malware Help (A Specialist Will Reply)' started by arkanshimas, Jun 14, 2007.

  1. arkanshimas

    arkanshimas Private E-2

    Hi,
    I downloaded at patch for a game some time ago. I did not get the patch, but an abdundance of trojans, viruses, malware etc. instead. Internet explorer opens without me telling it to(I only use firefox and opera) then internet explorer go wild and open a lot of different pages. I also get a lot of messages from my firewall telling me that so and so program want to start. (Winlogon was one of them)
    I found something called outer(something) in the add/remove program section of the control panel. I removed it. I also found vinmoundo with search and destroy. I removed it, at least I tried to, by using the tool you supplied in the special removal section. I followed the steps in the read and run me first section. Note that I could not run AVG in safe mode. Got a connection failed message. (Tried both with and without the network option) I ran it in normal mode and it worked. I think I went throught the other steps as I was supposed to.
    I use avast as my virus scanner and comodo as my firewall.
    When I ran the different scanners they found several things. I have attached all of them below as per your request. Hopefully someone can look at them and tell me what I should do next.

    Thank you
     

    Attached Files:

  2. arkanshimas

    arkanshimas Private E-2

    Here are the rest of the files.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to run AVGAntispyware and have it fix all that it finds!!

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 6
    Reboot and install:
    Java Runtime 6
    You should also uninstall all the poker programs...at least until we are done.

    Do you know what this is?
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
    Or this:
    C:\WINDOWS\system32\nb-no?

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT

    Be sure to tell us how things are running.
     
  4. arkanshimas

    arkanshimas Private E-2

    I ran the AVGAntispyware software and, this time, fixed the problems;)
    I have unistalled the J2SE Runtime Environment 5.0 Update 6 and installed the newest version.
    All poker programs removed.

    Do you know what this is?
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
    Or this:
    C:\WINDOWS\system32\nb-no?


    I don't, but the word koblinger is a norwegian word meaning something like connections.
    For the last one "no" is the... I don't remember the word, but I'll try to explain: When you go to a norwegian web page you type no as the last part of the address. Same as co.uk for britain. I think it is just a short version for Norway. It might be something else,but that is my guess anyway.

    I merged what you wanted me to merge with the registry.

    I could not find any of the files you wanted me to fix with the hijack this application. Could it be because I removed all poker software and merged the file you wanted me to merge?

    I have attached the logs.

    Only problem I notice now is that my firewall asks about the same connetions time and time again even if I ask it to remember. It might be a problem with the firewall. I might just change it as I have been thinking about it anyway. Do you have any recommendations?

    I really appreciate your help. Thank you!
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    My Norwegian must be rusty.....

    I am not that familiar with Comodo ....you could try uninstalling and using Zone Alarm....

    Your logs look clean. You may uninstall any programs we had you download (including CounterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds