Author Topic: Resolved: Can someone help me or try?  (Read 22063 times)

0 Members and 1 Guest are viewing this topic.

SafeSurf

  • Guest
Re: Can someone help me or try?
« Reply #15 on: August 02, 2010, 09:47:54 AM »
As for the one program you told me to download does it give me an option not to run the registry cleaner or download it and wait to run the entire thing until essexboy has looked at it?
You can download it and use the "Cleaner" button; don't use the "Registry" button until Essexboy works with you.  But if you are finding that you having a hard time downloading and installing things while you are having this malware problem, wait until Essexboy works with you.

Re: the use of the usb flash drive, I would not use that again unless Essexboy says it's OK.  You had malware that was found by MBAM, it is possible for that malware to have also gotten into the flash drive as well after you used it from the other machine into this one.  So for now, isolate the stick and don't use it.

Essexboy...she's ready for you.  See OTL logs on page 1.  Thanks.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89110
  • No support PMs thanks
Re: Can someone help me or try?
« Reply #16 on: August 02, 2010, 04:12:38 PM »
@ Nariamathstes,
Please start a New Topic of your own as this will just confuse the current thread and we will help you there. 
<snip>

I believe you have just responded to a spammer posting for the first time in a totally unrelated topic, the Afganistan flag doesn't relate to their location and email address is listed in a spammers listing.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

SafeSurf

  • Guest
Re: Can someone help me or try?
« Reply #17 on: August 03, 2010, 12:41:49 AM »
@ DavidR.

I realized that after the fact and reported him...bye, bye.  ;D

artisticmind

  • Guest
Re: Can someone help me or try?
« Reply #18 on: August 03, 2010, 05:00:45 AM »
My avast! full system scan picked up a virus today, "HTML:Downloader-F" a trojan. MBAM has not picked up anything and both systems are updated.

ETA: i did get the CCleaner downloaded and installed. I guess i'm confused on what it should actually be "deleting." I did the "analyze" search first and it pulled up a bunch of my word documents for school but i think it's just the links where I had to post them to an online site for online classes. It won't actually touch the documents themselves, will it?
« Last Edit: August 03, 2010, 05:25:14 AM by artisticmind »

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89110
  • No support PMs thanks
Re: Can someone help me or try?
« Reply #19 on: August 03, 2010, 05:42:43 AM »
What is the infected file name, where was it found e.g. (C:\windows\system32\infected-file-name.xxx) ?

If it was moved to the chest (a protected area), which presumably is the action you took then MBAM wouldn't find anything.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Can someone help me or try?
« Reply #20 on: August 03, 2010, 07:41:17 AM »
Hi artisticmind

Firstly follow DavidR's advise and see if we can identify the infection so to get some idea of what is the current state of play with malware threat. This will give us a bit of time to assess the next course of action. In the meantime what follows is an optional course of action, which you could undertake - or perhaps consider while other forum members might like to contribute second opinion on the situation.

If you want we can tidy up a bit to make things easier for removal work that may need to be done later. It would appear that the virus  on yr system was originally identified as follows - and some of the removal work has since been underway, initially by Malwarebytes --

Malware by name exe.exe  - http://www.threatexpert.com/report.aspx?md5=dbd276f428069d37532f9697eb864ca9

1. You should run Norton /Symantec uninstaller tool(s) just so avast has a bit more freedom to perform to its best without false positives
- you had Norton Internet Security 2009, plus a Symantec Endpoint Protection product, I guess as trial that you did not activate
- so I dont think it would hurt to run the uninstaller tool(s)

Quote
It possible if i go back through my paperwork there was a trial of norton or something that came with the netbook that i never activated, not a fan of norton...
Here is the trace in yr OTL log --

= Win32 Services (Safelist) =
SRV - File not found [Auto | Stopped] -- C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe -- (Norton Internet Security)

= Driver Services (SafeList) =
DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\NIS\1000000.07D\SRTSPX.SYS -- (SRTSPX)
DRV - File not found [File_System | System | Stopped] -- C:\WINDOWS\System32\drivers\NIS\1000000.07D\SRTSP.SYS -- (SRTSP)

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVEX15.SYS -- (NAVEX15)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVENG.SYS -- (NAVENG)

To sort these out, go to this page http://uninstallers.blogspot.com and download both Norton / Symantec uninstaller tools.
Or (a bit harder) Symantec product - http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007080209280848?Open&seg=ent
(Likewise) http://www.symantec.com/norton/support/kb/web_view.jsp?wv_type=public_web&docurl=20080710133834EN&ln=en_US

You will be wanting to boot into Safe Mode and run these uninstaller tools, but before you do that you can download HijackThis as well (if not done so already) so that you can also run an overview scan while you are in Safe Mode and do a bit of tidying up in preparation for any more serious removal work that needs to be done. Ultimately, you can run OTL again and just see how much damage still remains on yr system.


2. When you run the HijackThis scan, there are the entries you will look to fix. Click here – (will take direct to HjT download)
http://www.filehippo.com/download_hijackthis/download/8571e06e5eb8ab03c649f3b5d647c599/

Run in Safe Mode. To fix an entry put a check in the box next to the entry and then click Fix checked tab down left corner of screen
Or you can post the log to the forum first, before taking action, if that is what you prefer

Fix the following --

O4 - HKLM..\Run: [Psurogaje] C:\WINDOWS\eqesabam.DLL File not found
O4 - HKCU..\Run: [Predujehoko] C:\WINDOWS\otalibc.DLL File not found

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

The Java program on yr system looks a bit mess about - may pay to check for any damaged entries in Downloaded Program Files
Start -> Control Panel -> Internet Options -> General -> (Browsing history) Settings -> Objects, and check for anything with (damaged)
Reply post if any damage

Back to Java entries in HjT - this Plug-in is out of date
O16 - DPF: {CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_17-windows-i586.cab (Java Plug-in 1.5.0_17)
and this Plug-in is a double entry
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
this Plug-in is a good entry
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)

However java has only now just been updated
- rather than use Fix checked just now, may pay to uninstall all existing java and re-install latest version (can do now or later)

Likewise some mess about with Adobe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
Check what you have for Adobe in Control Panel - would not hurt to uninstall all existing, then go to Adobe download page  http://www.adobe.com/downloads/  and only install Flash Player and Shockwave, for the time being while the malware issues are being attended to (And as with Java, dont have to do this now if dont want - can do now or later)

3. Run the OTL scan again to bring us up to date.
« Last Edit: August 03, 2010, 10:05:30 AM by mkis »
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

SafeSurf

  • Guest
Re: Can someone help me or try?
« Reply #21 on: August 03, 2010, 09:02:10 AM »
artisticmind,

I had PM'd Essexboy a while ago, and just PM'd him again.  I believe he was away when I first PM'd him, but he should be contacting you shortly.  In the meantime, follow the instructions given to you above.  Thanks.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Can someone help me or try?
« Reply #22 on: August 03, 2010, 09:06:08 PM »
Here I be  ;D sorry for the delay
Quote
One or more of the identified infections is a backdoor Trojan and a key logger.

If this computer is ever used for on-line banking, I suggest you do the following immediately:

1. Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.

2. From a clean computer, change ALL your on-line passwords for email, for banks, financial accounts, PayPal, eBay, on-line companies, any on-line forums or groups you belong to.

Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.


Once this fix has run could you let me know what your current problems are please

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

Code: [Select]
:OTL
SRV - File not found [Auto | Stopped] -- C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe -- (Norton Internet Security)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVEX15.SYS -- (NAVEX15)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVENG.SYS -- (NAVENG)
O4 - HKLM..\Run: [Psurogaje] C:\WINDOWS\eqesabam.DLL File not found
O4 - HKCU..\Run: [Predujehoko] C:\WINDOWS\otalibc.DLL File not found
[2010/07/28 23:02:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\gntjpgixe
[2010/07/23 21:26:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ansara\Local Settings\Application Data\xbfgeluhk
[2010/07/25 14:25:46 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Eferewohi.dat
[2010/07/25 12:07:24 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Gkijozececisuwa.bin

:Commands
[purity]
[resethosts]
[emptytemp]
[EMPTYFLASH]
[CREATERESTOREPOINT]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

artisticmind

  • Guest
Re: Can someone help me or try?
« Reply #23 on: August 03, 2010, 09:51:48 PM »
DavidR~ the virus was found in C:\docs and settings\networkservice\localsettings\temp int. files\content.ie5\qx9bxrpo\exemple[1].htm

i'm going to print the above instructions and work on getting that stuff accomplished for you and i'll report back later...hopefully i can get most of it done during my little one's nap time  ;D

ETA: i deleted my cookies and temp internet files last night as well, i've been doing that about every 3 days if that helps for your research purposes.

and this is a dumb question, how do i set the correct time on this forum? i've went into my profile and can not see any tools to set the time in there. this form shows my current time as 8pm when it's acutally 3pm
« Last Edit: August 03, 2010, 10:04:17 PM by artisticmind »

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89110
  • No support PMs thanks
Re: Can someone help me or try?
« Reply #24 on: August 03, 2010, 10:40:06 PM »
I'm not sure if you can change that but it comes under the Look and Layout Preferences section of the Profile.

There are restrictions on what you are allowed to change in your profile (after you have registered) until you have 20 posts.

- The problem comes from drive by spammers, who having registered put objectionable or commercial links in their profile signature to try and gain link promotion, etc.

There have also been cases of the PM function being abused to spam forum members, so you will notice that you can't use the PM function either.

Unfortunately because of the actions of others legitimate members suffer by the actions to prevent this spamming.

I see essexboy is back and he is targeting the areas that I was asking about.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

artisticmind

  • Guest
Re: Can someone help me or try?
« Reply #25 on: August 03, 2010, 11:20:38 PM »
1. You should run Norton /Symantec uninstaller tool(s) just so avast has a bit more freedom to perform to its best without false positives

To sort these out, go to this page http://uninstallers.blogspot.com and download both Norton / Symantec uninstaller tools.

okay that site has tools for norton/symantec, a corporate norton/symantech which i know i don't need, and a symantec active x tool. i need both the regular norton and the symantec active x uninstall tools, correct?

Thanks david regarding the time. not a big issue just a little on the annoying side, i'll live with it LOL

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Can someone help me or try?
« Reply #26 on: August 03, 2010, 11:44:10 PM »
Thats okay, just run OTL with the script and direction that essexboy has provided above.

the next scan / log should show that the issue has been sorted.
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

artisticmind

  • Guest
Re: Can someone help me or try?
« Reply #27 on: August 04, 2010, 01:00:24 AM »
logs are attatched.

the rundll errors went away, Thanks! the popup window that i get after opening my IE seems to have went away, usually comes up within 30seconds or so of opening it. The only thing that i can see remains is my searches from google are being redirected. Example i searched for cars.com, came up with a match for cars.com and clicked on it and this is the link i'm redirected to "affordableendo.com/result.php?Keywords=cars.com&r=494934328b7147af81b885c683737a4d368ac647123151aa40218ca5b889724bbb344f15e838afab84ec5d59af55e081&Submit=Go" with an http:// on the front of it.

I've went to my add/remove programs list and removed all adobe items. I have "acrobat.com" listed in my program list, do i need to remove that as well? I've also removed the java update 6 from my program list but have a JSRE upate 5 (or something similar to that- it has the little "java" cup icon on it) do i need to take that out as well?

artisticmind

  • Guest
Re: Can someone help me or try?
« Reply #28 on: August 04, 2010, 03:39:18 AM »
okay i lied, the pop up came up this time after i connected to the internet, some random spam full page popup. the only other thing i have yet to see is the Win32 error message report that i mentioned in my first post. It *usually* comes up about 45mins to an hour after i've connected to the 'net and once it comes up it breaks my internet connection and i have to shut down my VZAccess connection and window and restart my internet.

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Can someone help me or try?
« Reply #29 on: August 04, 2010, 06:55:21 AM »
Okay this is better. I'm going to leave this for the moment in case essexboy wants to post comments.

The only thing is the log files you have attached - could you run a standard OTL scan as you did very first time and attach the logs please.
The desktop is still a bit cluttered but dont worry too about that right now. Best post OTL logs first.

Also could you tell us a bit about yr network service as it appears to me that you have Java, Sun, Adobe active on network.

Are you able to work the computer with only small irritations, no major problems?
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.