View Single Post
Old 08-22-2005, 03:27 AM   #2 (permalink)
sUBs
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,465
OS: N/A


Hello and Welcome to TSF!

Please subscribe to this thread to get immediate notification of fixes as soon as they are posted.


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =


Start HijackThis & Go to Config> Misc Tools > Open ADS Spy
  1. Checkmark/tick - "Ignore Safe System Info Streams"
  2. Click the "Scan" button
  3. When it has finished scanning, checkmark/tick all that it found
  4. Click the "remove selected" button


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =


Please download these additional files/programs. Do not run them untill instructed to do so.
Unless otherwise stated, they should be stored in same directory as the HiJackThis program.

CleanUp!.exe - Install

KillBox v2.0.0.175

About Buster.zip - Unzip to a new folder. Update About Buster & exit the program once that is completed.

CWShredder.exe
  1. Open CWShredder and click - I AGREE
  2. Click - Check For Update
  3. Close CWShredder after updating
HSFix.zip

Ewido Security Suite
  • Install Ewido Security Suite
  • When installing, under "Additional Options" uncheck..
    • Install background guard
    • Install scan via context menu
  • Double-click the icon on Desktop to launch Ewido
You will need to update Ewido to the latest definition files.
  • On the left hand side of the main screen click update.
  • Then click on Start Update.
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update Ewido
When you have finished updating, EXIT Ewido.

smitRem.exe - extract it to it's own folder.

'UNPLUG'/DISCONNECT YOUR COMPUTER FROM THE INTERNET WHEN YOU HAVE FINISHED DOWNLOADING


This webpage would not be available when you're carrying out the fix. Please save the following instructions in Notepad. I have customed my instructions on the assumption that you are using Notepad. It may lead to some confusion should you choose to do otherwise.

If there's anything that you don't understand, kindly ask your questions before proceeding with the fixes. There should not be any opened browsers when you are carrying out the procedures below.


IT IS IMPORTANT THAT YOU DON'T MISS A STEP & PERFORM EVERYTHING IN THE RIGHT ORDER.


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =


CLOSE ALL OTHER PROGRAMS & ALL OPENED WINDOWS


Run a scan with HiJackThis & select/tick the following & click "Fix checked" :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://abcsearch4u.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://abcsearch4u.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://abcsearch4u.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://abcsearch4u.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://abcsearch4u.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
F3 - REG:win.ini: run=C:\WINDOWS\inet20081\services.exe
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O4 - HKLM\..\Run: [.service] C:\WINDOWS\system\winlgon.exe
O4 - HKLM\..\Run: [jxeobpum] C:\WINDOWS\System32\jxeobpum.exe
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inet20081\services.exe
O4 - HKLM\..\Run: [Start Page] C:\WINDOWS\system32\svcnt32.exe home
O4 - HKLM\..\Run: [Microsoft standard protector] C:\WINDOWS\winsocks5.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [mroceul] c:\windows\ckbbphc.exe
O4 - HKCU\..\Run: [jxeobpum] C:\WINDOWS\System32\jxeobpum.exe
O4 - HKCU\..\Run: [jlsbttw] c:\windows\ckbbphc.exe
O4 - HKCU\..\Run: [mywsppr] c:\windows\fyntatb.exe
O4 - HKCU\..\Run: [eysikgj] c:\windows\fyntatb.exe
O4 - HKCU\..\Run: [wfrqolu] c:\windows\fyntatb.exe
O4 - HKCU\..\Run: [kkxbeao] c:\windows\fyntatb.exe
O4 - HKCU\..\Run: [sswfxiq] c:\windows\fyntatb.exe
O4 - HKCU\..\Run: [ivjbpox] c:\windows\bsebvfx.exe
O4 - HKCU\..\Run: [ybmcflj] c:\windows\bsebvfx.exe
O4 - HKCU\..\Run: [csgxbut] c:\windows\bsebvfx.exe
O4 - HKCU\..\Run: [pbpduyy] c:\windows\bsebvfx.exe
O4 - HKCU\..\Run: [vgiprip] c:\windows\bsebvfx.exe
O4 - HKCU\..\Run: [gviaugi] c:\windows\tpuebwr.exe
O4 - HKCU\..\Run: [ehhysxu] c:\windows\tpuebwr.exe
O4 - HKCU\..\Run: [wrneiht] c:\windows\pulqfcf.exe
O4 - HKCU\..\Run: [goqbiqs] c:\windows\pulqfcf.exe
O4 - HKCU\..\Run: [tcpvbdj] c:\windows\pulqfcf.exe
O4 - HKCU\..\Run: [uawfqyb] c:\windows\pulqfcf.exe
O4 - HKCU\..\Run: [cqgvavr] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [nnfftsu] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [oacauqr] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [utnbmvh] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [xcuntqm] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [lindfii] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [halqcju] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [bfodrkf] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [lfbdobv] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [mgvqqlf] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [tsginnb] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [bcoqtyp] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [qalxslp] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [mynbaqb] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [conkdcm] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [gjlsscs] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [socsayx] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [nguyxhr] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [vdidyhn] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [wofvnfj] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [ohjnykb] c:\windows\nmawyda.exe
O4 - HKCU\..\Run: [iyejvsx] c:\windows\nmawyda.e



= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =


Launch KillBox.exe & select the following options:
  • delete on Reboot
  • end Explorer shell while killing file
  • unregister dlll before deleting * if it's not grayed out
Select all the filenames below & then click on Notepad's 'Edit' menu & select Copy
  • C:\WINDOWS\system\winlgon.exe
    C:\WINDOWS\System32\jxeobpum.exe
    C:\WINDOWS\system32\svcnt32.exe
    C:\WINDOWS\winsocks5.exe
    c:\windows\ckbbphc.exe
    C:\WINDOWS\System32\jxeobpum.exe
    C:\windows\ehxwpcs.exe
    C:\windows\hjaxsbi.exe
    C:\windows\rumxygq.exe
    C:\windows\rsfofrr.exe
    C:\windows\jtbbphw.exe
    C:\windows\cctvvxs.exe
    C:\windows\frdrlrw.exe
    C:\windows\kthtjmy.exe
    C:\windows\smcclrh.exe
    C:\windows\jqptcvc.exe
    C:\windows\wxcxmeo.exe
    C:\windows\jqptcvc.exe
    C:\windows\wxcxmeo.exe
    C:\windows\cotgdqx.exe
    C:\windows\kvqfbsp.exe
    C:\windows\crvhvod.exe
    C:\windows\ryjodny.exe
    c:\windows\heshvsh.exe
    c:\windows\sfbimkg.exe
    c:\windows\iusuknl.exe
    c:\windows\xyhdwko.exe
    c:\windows\tuhdsjx.exe
    c:\windows\ertkloh.exe
    c:\windows\dyakflu.exe
    c:\windows\jyquhjm.exe
    c:\windows\cdhipuc.exe
    C:\WINDOWS\inet20081\services.exe
    c:\windows\uttfmci.exe
    c:\windows\apgcqaw.exe
    c:\windows\wtotqmx.exe
    c:\windows\gheaqxi.exe
    c:\windows\uhpejci.exe
    c:\windows\rjjgmin.exe
* Go to the File menu, and choose Paste from Clipboard
* Click the RED X button.
* Click Yes at the Delete on Reboot prompt.
* Click Yes at the 'Pending Operations prompt'.

Quote:
If you received a message such as: "PendingFileRenameOperations registry data has been removed by external process", you have to restart Windows manually .
If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, download and run missingfilesetup.exe. Then try Killbox again.
= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =


Next, reboot your computer in SafeMode :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =


If you have not done so already, please enable the viewing of Hidden files
From Windows Explorer, go to Tools>Folder Options> View tab.
  • Enable - Show hidden files and folder
  • Disable - Hide file extensions for known types
  • Disable - Hide protected operating system files
Click Yes to confirm & then click OK

Locate and delete the following folders, if present:
  • C:\WINDOWS\inet20081\

= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =


Run Cleanup! using the following configuration:

1. Click Options...
2. Set the slider to Standard CleanUp!
3. Uncheck the following:
  • Delete Newsgroup cache
  • Delete Newsgroup Subscriptions
  • Scan local drives for temporary files
4. Click OK
5. Press the CleanUp! button to start the program. Reboot/logoff when prompted.
* CleanUp! will not create any backups!!


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =


Run CWShredder & click on Fix.

Run About Buster and click - Begin Removal.
Locate 'Ab LogFile.txt' (... in the same folder as AboutBuster) and post it in your next reply.


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =


Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.

The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =


Run Ewido with it's updated definitions:(...it's important that all windows must be closed)
  • Click Scanner
  • Click Complete System Scan to begin scanning.
  • Click OK when prompted to clean files
With the first file it prompts to clean, select the option:
  • "Perform action on all infections"
  • .Choose clean and click OK.
Once finished, click the Save report button & save the report to your desktop

** Ewido scan would require at least an hour. I suggest that you go grab a cup of coffee & do something else while you wait for it to complete.


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =


REBOOT TO NORMAL MODE


Perform an online scan with Internet Explorer with Panda ActiveScan
  1. Click [Scan your PC] & a 'pop up' window shall appear. *ensure that your pop up blocker doesn't block it
  2. Click [Scan Now]
  3. Enter your e-mail address & click [Scan Now] ...begins downloading 8 MB Panda's ActiveX controls
Begin the scan by selecting My Computer
  • If it finds any malware, it will offer you a report.
  • Click on see report. Then click Save report
Post the contents of the report in your next reply

*You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
*Turn off the real time scanner of any existing antivirus program while performing the online scan



= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =


Download Trend Micro™ Anti-Spyware (by clicking the "Scan and Clean your PC" button).
  • Double-click the tmas-web-scan.exe icon
  • It will say "Loading TrendMicro definitions".
  • Click "Start Scan"
After it's done scanning, click "Scan Results"
  • Make sure all items found have a check next to them, then click "Clean Threats Now".
  • Click Exit.
Reboot your computer. I then need you to repeat the same procedure above again... using the TrendMicro tool. I need the log from the second scan/clean...NOT the first...as this will contain what’s left in the system.

In place of the TrendMicro icon will be a text file called "Antispyware.log", please double-click that log and copy the entire contents and paste them here.


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

In your next post, please include fresh logs from:
  1. HiJackThis
  2. Online scan
  3. Antispyware.log
  4. About Buster
  5. Ewido
  6. Smitfiles.txt
Please provide details of any problems you encountered whilst performing the above steps & update us on how the computer behaves now
__________________

Question - what have you done for the community today?
sUBs is offline