Win32:Dialer-407

Discussion in 'Malware Help (A Specialist Will Reply)' started by Kwalters6016, Feb 20, 2008.

  1. Kwalters6016

    Kwalters6016 Private E-2

    Went thru Read and Run (I believe I did it all correctly). Thought all was good but while using IE had a pop-up. Any help is appreciated.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Next look for and delete these two : (note the date as the ? marks could be anything)
    Code:
    C:\Program Files\Common Files\"
    CROSOF~1      Feb 19 2008              "??crosoft
    SEMBLY~1      Feb 19 2008              "??sembly"
    
    * Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    * On the page that opens, scroll down to Network DDE NetDDEPACSPTISVR
    * then right click the entry, select Properties and press Stop Service.
    * When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    NOw do the same for Protected Storage ProtectedStorageAppMgmt
    * Click OK until you get back to Windows.

    * Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste NetDDEPACSPTISVR andProtectedStorageAppMgmt into the box that opens, and press OK
    * If you receive any error messages just ignore them and continue.
    * Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  3. Kwalters6016

    Kwalters6016 Private E-2

    Ok I did as you listed below, couple things:

    When I did this:

    Run C:\MGtools\analyse.exe by double clicking on it.

    I did not find these files:

    O23 - Service: Network DDE NetDDEPACSPTISVR (NetDDEPACSPTISVR) - Unknown owner - C:\WINDOWS\system32\accessi.exe
    O23 - Service: Protected Storage ProtectedStorageAppMgmt (ProtectedStorageAppMgmt) - Unknown owner -

    Also - when I ran Avenger and clicked the traffic light I got the following error message (so no log attached here):

    Error: could not open Run Key to register cleanup batch

    Here's where I kick myself in the head - this has taken me so long to do that I now realized my AV and firewall are on and your first instruct. said to have them off. Hopefully the files here still mean something?

    Thanks
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then I guess I won't kick you as well .....:)

    Just disable the anti-virus and spyware programs and re-do the fix. Then get me another MGLogs.zip.
     
  5. Kwalters6016

    Kwalters6016 Private E-2

    99% sure I did it right this time. Logs attached.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok....let's see if we can't finish up:

    * Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    * On the page that opens, scroll down to:
    MSCSPTISRV MSCSPTISRVSwPrv
    * then right click the entry, select Properties and press Stop Service.
    * When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    * Click OK until you get back to Windows.


    * Next, run C:\MGtools\analyse.exe, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste:
    MSCSPTISRVSwPrv
    into the box that opens, and press OK
    * If you receive any error messages just ignore them and continue.
    * Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Now re-Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    Quote:
    Files to delete:
    C:\hrqxpxrv.bat
    C:\pcuklpck.bat
    C:\WINDOWS\system32\CDDBU.dll
    C:\WINDOWS\SYSTEM32\DRIVERS\chmucikc.dat
    C:\WINDOWS\SYSTEM32\DRIVERS\luoomlcu.sys
    C:\WINDOWS\SYSTEM32\DRIVERS\pjykybin.sys
    C:\\WINDOWS\\ss245sd.exe
    [/quote]
    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  7. Kwalters6016

    Kwalters6016 Private E-2

    I didn't get very far - I cannot run C:\MGtools\analyse.exe

    I get an error from c:\MGTools\analyse.exe that says "windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item."
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Make sure you have your security software disabled while we do this:

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Uninstall Avenger .....then download The Avenger by Swandog469, and save it to your Desktop. (This is a newer version).

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

     
  9. Kwalters6016

    Kwalters6016 Private E-2

    Ok - when I ran Avenger, copied the text in the quote box and clicked Execute got this error message:

    Error: Could not open Run Once key to register cleanup. Aborting execution! (error 0: the operation completed successfully.)

    I stopped at this point - thank you so much for all your help so far.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It may have actually ran..did it ask to reboot? Do you have a log?
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    File::
    C:\hrqxpxrv.bat
    C:\pcuklpck.bat
    C:\WINDOWS\system32\CDDBU.dll
    C:\WINDOWS\SYSTEM32\DRIVERS\chmucikc.dat
    C:\WINDOWS\SYSTEM32\DRIVERS\luoomlcu.sys
    C:\WINDOWS\SYSTEM32\DRIVERS\pjykybin.sys
    C:\\WINDOWS\\ss245sd.exe
    
    Registry::
    [[B]HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E07F9A0D-3736-4AC7-ADA8-E30B8B9DB2B0}][/B]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Get me the log from that.
     
  12. Kwalters6016

    Kwalters6016 Private E-2

    Answer to your first post : Avenger did not ask for a reboot and I don't have a log- seems to have just closed.

    I got an error running Combofix and then it rebooted. Log is attached.

    Thx again
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try both avenger as well as COmboFix in safe mode ....do the avenger first and see if it removes the items and if not, try combo.....those files need to go!
     
  14. Kwalters6016

    Kwalters6016 Private E-2

    Ok - ran in safe mode. MGLogs attached
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run thisDisable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds