[DONE]Malware, Spyware, trojans... oh my!!!! HELP!

CastleCops -> AntiSpyware

Author: gracie_girlLocation: USA PostPosted: Wed May 21, 2008 7:57 pm    Post subject: Malware, Spyware, trojans... oh my!!!! HELP!

My computer is doing really strange things lately!! When it goes into hibernation and I come back to turn it on, instead of a screen saver there is a blue screen with black bugs crawling all over it and then when i touch the mouse pad it will go back to normal...

also, getting really weird pop-ups: some are pornographic and some are like "debt saver" pages - never seen any of them before!

When i attempt to press ctrl-alt-del i get a message that says i cannot access the task manager because the administrator blocked it?? I'm pretty sure i'm the administrator on my computer and i didn't change this!

I think there is malware or spyware on here so I scanned my computer twice with SUPERAntiSpyware but the problems still persist.

WHAT CAN I DO?!?! HELP PLEASE!!! Thank you sooo much

Author: MauriceNLocation: USA PostPosted: Thu May 22, 2008 3:00 pm    Post subject:

Hello gracie_girl,

Your system does have malware infections. You need to do some preparation work and then after, make a New post in the HijackThis forum.

The main page for Trend Micro HijackThis Logs forum is
CastleCops Link/f67-Trend_Micro_HijackThis_Logs.html

Read this first CastleCops Link/t102301-Hijackthis_Guidelines_Read_Before_Posting.html

If you have peer-to-peer filesharing programs on this system, remove them first.
See CastleCops Link/t204179-P2P_programs_we_ask_that_you_remove_first.html

Next, see http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Overview

Get the HijackThis utility, run it as suggested, and only then, post a new thread by going to this forum
CastleCops Link/f67-Trend_Micro_HijackThis_Logs.html

and pressing "New Topic" button, put your HJT log in there, along with all pertinent details.

NOTE: As you get this popups from rogues & malware, do not click the X button at upper right to clode the window(s).
Instead, press and HOLD the ALT key, then tap the F4 function key.
ALT+F4 is the key sequence to close a window.
Some of these rogues will get further into your system when you press the X (close) button {for 'their' message window}.

Don't do free-whelling web surfing and minimize your internet activity to basically just this forum, or the sites you are guided to by CC forum staff.

This is my standard 1st reply to malware issues, consisting of doing some cleanup and getting basic reports.

If your system is running Vista, you likely need to run the programs as Administrator. If so, you Right-click on the program icon or shortcut, select "Run As Administrator".

1. Set Windows to show all files and all folders.
Bring up Windows Explorer / Tools / Folder Options/ select VIEW Tab and look at all of settings listed.

"CHECK" (turn on) Display the contents of system folders.

Under column, Hidden files and folders----choose ( *select* ) Show hidden files and folders.
Next, un-check Hide extensions for known file types.
Next un-check Hide protected operating system files.

2. Take out the trash (temporary files & temporary internet files)
Please download ATF Cleaner by Atribune, saving it to your desktop. It is used to cleanout temporary files & temp areas used by internet browsers.
Arrow ATF-Cleaner should be run per the above in every user-login account {User Profile}

For Technical Support, double-click the e-mail address located at the bottom of each menu.
=
3. Important! => Open Notepad > Click on Format > Uncheck Word wrap, if checked. Exit Notepad.

4. Please download & save Malwarebytes Anti-Malware from Here or Here
Double Click mbam-setup.exe to install the application.Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

5. Download Deckard's System Scanner: http://www.techsupportforum.com/sectools/Deckard/dss.exeNote: Your firewall may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so.
>
In a post to the CC HJT forum, , and NOT here ......please post (in order):

Be sure to do a Preview prior to pressing reply because all reports may not fit into 1 single reply. You'll likely have to do more than 1 reply.

Make one and only 1 post into the HJT forum. And do NOT reply to your own post, until after 1 of the CC moderators or staff has responded. ok?

Cheers.

Author: gracie_girlLocation: USA PostPosted: Sat May 24, 2008 7:28 am    Post subject: MBAM

Malwarebytes' Anti-Malware 1.12
Database version: 783

Scan type: Full Scan (C:\|)
Objects scanned: 96605
Time elapsed: 56 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 5
Registry Keys Infected: 11
Registry Values Infected: 6
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 17

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\chfvqagi.dll (Trojan.Vundo) -> Unloaded module successfully.
C:\WINDOWS\system32\ddcBRlif.dll (Trojan.Vundo) -> Unloaded module successfully.
C:\WINDOWS\system32\odmvfstw.dll (Trojan.Vundo) -> Unloaded module successfully.
C:\WINDOWS\system32\tkyuygob.dll (Trojan.Vundo) -> Unloaded module successfully.
C:\WINDOWS\system32\iprjrjxf.dll (Trojan.Vundo) -> Unloaded module successfully.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fc25fe12-39d7-4625-a95a-e895774356aa} (Trojan.Vundo) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{fc25fe12-39d7-4625-a95a-e895774356aa} (Trojan.Vundo) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{240a2128-acd4-4124-87af-527124caac38} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{240a2128-acd4-4124-87af-527124caac38} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\b4bda793 (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{240a2128-acd4-4124-87af-527124caac38} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\OriginalWallpaper (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\ConvertedWallpaper (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\SCRNSAVE.EXE (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ttool (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\ddcbrlif -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\ddcbrlif -> Delete on reboot.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\chfvqagi.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\igaqvfhc.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ddcBRlif.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\filRBcdd.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\filRBcdd.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\odmvfstw.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\wtsfvmdo.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tkyuygob.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\bogyuykt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Gracie\Local Settings\Temporary Internet Files\Content.IE5\HAMLT3TV\hctp[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Gracie\Local Settings\Temporary Internet Files\Content.IE5\HAMLT3TV\kb456456[1] (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Gracie\Local Settings\Temporary Internet Files\Content.IE5\HAMLT3TV\kb456456[2] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{145A78D9-30F3-4441-A76F-9F54405CDEA6}\RP726\A0091612.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{145A78D9-30F3-4441-A76F-9F54405CDEA6}\RP731\A0092647.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{145A78D9-30F3-4441-A76F-9F54405CDEA6}\RP731\A0092667.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\blackster.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\iprjrjxf.dll (Trojan.Vundo) -> Delete on reboot.

Author: MauriceNLocation: USA PostPosted: Sat May 24, 2008 12:40 pm    Post subject:

MBAM shows that you have Vundo infections. Please, right away, do as requested by Prince Serendip.
De-install BitComet and Ares.
Run a new HijackThis Scan and Save.

Reply ONLY on your thread at the HIJACKTHIS forum and not anywhere else. The link to that thread is

CastleCops Link/t222425-New_Log.html

Do NOT reply here.

I will endeavor to catch your updated HijackThis post after you have done as requested by Prince Serendip.
Cheers.



CastleCops -> AntiSpyware

All times are GMT

Page 1 of 1


Powered by phpBB © 2001 phpBB Group