Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed

Outline · [ Standard ] · Linear+

 Task Manager Has Been By your Administrator, Sempurna plz help me check

views
     
Sempurna
post Jun 24 2007, 01:11 PM

Look at all my stars!!
Group Icon
VIP
3,022 posts

Joined: Jul 2006
From: KL


Hi IrishCoffee,

Please run HijackThis and click "Scan". Place a check (tick) next to the following entries (if present):

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: IeMonitorBho Class - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - (no file)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1



Close ALL programs and browsers (including this one), leaving ONLY HijackThis open, then click "Fix checked".

Then please exit HijackThis.


NEXT:

Please download ComboFix by sUBs:

NOTE: In the event you already have ComboFix, this is a new version that I need you to download.
  • Save it to your desktop.
  • Double-click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Please do NOT mouse-click ComboFix's window while it is running. That may cause it to stall. Also, please do NOT adjust your time format while ComboFix is running.


NEXT:

Please reboot your computer normally into Windows, and then please post the ComboFix log and a new HijackThis log.

~~~
Sempurna
post Jun 24 2007, 03:48 PM

Look at all my stars!!
Group Icon
VIP
3,022 posts

Joined: Jul 2006
From: KL


Hi IrishCoffee,

OK, let's pick up the leftovers.

Before fixing anything, please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
(start copying from "@echo off")

CODE
@echo off
For %%g in (
C:\WINDOWS\system32\RVHIOST.exe
) do catchme -l nul -k %%g >nul
echo.Please submit the file, catchme.zip located on Desktop
pause
exit


Save this as submit.bat. Choose to "Save as type - All Files" and place it on your desktop.

It should look like this: user posted image

Double-click on submit.bat and allow it to generate a zipped file on your desktop called catchme.zip.

Please submit catchme.zip to this site -> http://www.bleepingcomputer.com/submit-malware.php?channel=4

Please include a link to this topic in the message.

NOTE: The file must be uploaded before proceeding to the next step.


NEXT:

Please go to Start -> Control Panel -> Software -> Add or Remove Programs and remove any of the following that are listed:

BitDownload
BitGrabber
BitLord
BitRoll
CiD Manager
CiD Help
Download Plugin for Internet Explorer
Messenger Plus!
Messenger Plus! 2
Messenger Plus! 3
Messenger Plus! 3 & Sponsor
Messenger Plus! Live
Messenger Plus! Live & Sponsor
Messenger Plus! Live & Sponsor (CiD)
Netpumper
Search Plugin
WinZix
Zone Media



NEXT:

For this next step, please ensure that ComboFix.exe is on your desktop:
  • Then, please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    (start copying from "File::")


    CODE
    File::
    C:\WINDOWS\system32\RVHIOST.exe
    C:\WINDOWS\system32\cid_store.dat
    C:\WINDOWS\mppds.exe
    C:\Documents and Settings\Sora ilX\Local Settings\Temp\wz6555\socksfarm.exe

    Folder::
    C:\Program Files\Messenger Plus! Live
    C:\Documents and Settings\Sora ilX\Local Settings\Temp\wz6555

    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mppds]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SocksFarm]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{632f9bd6-b36a-11db-9577-00095be3cde9}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a987e1a0-af38-11db-88a9-00095be3cde9}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b664299c-84c7-11db-be4c-806d6172696f}]


  • Save this as ComboFix-Do.txt and change the "Save as type" to "All Files" and place it on your desktop.


    user posted image


  • Referring to the screenshot above, drag ComboFix-Do.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Please do NOT mouse-click ComboFix's window while it is running. That may cause it to stall. Also, please do NOT adjust your time format while ComboFix is running.


NEXT:

Please run HijackThis and click "Scan". Place a check (tick) next to the following entries (if present):

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: IeMonitorBho Class - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - (no file)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k



Close ALL programs and browsers (including this one), leaving ONLY HijackThis open, then click "Fix checked".

Then please exit HijackThis.


NEXT:

Please download Flash_Disinfector.exe by sUBs and save it to your desktop:

NOTE: In the event you already have Flash_Disinfector, this is a new version that I need you to download.
  • Double-click Flash_Disinfector.exe to run it.
  • Follow any prompts that may appear.
  • Your desktop will vanish for a while, and then reappear. This is normal.
  • Wait until the program has finished scanning, then please exit the program.


NEXT:

Please go to: VirusTotal
  • At the top of the page you'll find a "Browse" button. Click the "Browse" button and browse to next file:

    C:\WINDOWS\system32\muzapp.dll

  • Click "Open".
  • Then click the "Send" button at the top of the VirusTotal page.
  • This will scan the file. Please be patient.
  • Once scanned, copy and paste the results in your next reply.

Then please do the same as above for the following files:

C:\WINDOWS\system32\muzapp.exe
C:\WINDOWS\system32\TG_VIEW0607.DLL
C:\WINDOWS\system32\TG_SYNC.DLL
C:\WINDOWS\system32\TG_DUMP0611.DLL
C:\WINDOWS\system32\RadLightTTAUninstall.exe
C:\WINDOWS\system32\TTACodecs-uninstall.exe


NEXT:

Please download CCleaner (freeware) and save it to your desktop:
  1. Run the CCleaner installer.
  2. During installation process, please UNCHECK "Add CCleaner Yahoo! Toolbar".
  3. Once installed, run CCleaner and click the "Windows" tab.
  4. Select the following:
    • Check everything under the "Internet Explorer" section.
    • Check everything under the "Windows Explorer" section.
    • Check everything under the "System" section.
    • Check ONLY "Old Prefetch data" under the "Advanced" section.
  5. Then, click the "Applications" tab:
    • CHECK everything there.
  6. Next, click the "Options" button in the left pane, then click the "Advanced" button:
    • UNCHECK : "Only delete files in Windows Temp folders older than 48 hours".
  7. Next, click the "Cleaner" button in the left pane, then click the "Run Cleaner" button (bottom right), click "OK" at the prompt.
  8. When done, please exit CCleaner.

CAUTION: Please do NOT use the "Issues" button in the left pane. This is a built-in registry cleaner. If you don't know how to use it, you may cause irreparable damage to your system.


NEXT:

Let's run an online scan to make sure we're not leaving anything behind.

Please do an online scan with Kaspersky Online Scanner using Internet Explorer (this online scanner only works with IE):
  1. Click on "Kaspersky Online Scanner".
  2. You will be prompted to install an ActiveX component from Kaspersky, click "Yes".
  3. The program will launch and then begin downloading the latest definition files.
  4. Once the files have been downloaded click on "Next".
  5. Now click on "Scan Settings".
  6. In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:
      Extended
    • Scan Options:
      Scan Archives
      Scan Mail Bases
  7. Click "OK".
  8. Now under select a target to scan:
    • Select "My Computer".
  9. This program will start and scan your system.
  10. The scan will take a while so be patient and let it run.
  11. Once the scan is complete it will display if your system has been infected.
    • Now click on the "Save Report As" button.
    • In the "File name:" field, type kavscan.
    • In the "Save as type:" field, select "Text file (*.txt)".
  12. Save the file to your desktop.
  13. Copy and paste that information in your next post.

Note for Internet Explorer 7 users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.


NEXT:

Please REBOOT your computer normally into Windows and post these logs in your next reply:
  1. The log from the ComboFix scan located at C:\ComboFix.txt.
  2. The reports from VirusTotal.
  3. The log from the Kaspersky scan.
  4. A new HijackThis log.

(You might have to paste the logs in multiple posts in the event they are too long and breach the post length restrictions of the forum software).

How are things running now?

~~~

Sempurna
post Jun 27 2007, 01:13 PM

Look at all my stars!!
Group Icon
VIP
3,022 posts

Joined: Jul 2006
From: KL


You didn't run Flash_Disinfector, and I don't have the other logs. smile.gif
Sempurna
post Jun 27 2007, 04:20 PM

Look at all my stars!!
Group Icon
VIP
3,022 posts

Joined: Jul 2006
From: KL


QUOTE(cpteoh @ Jun 27 2007, 03:44 PM)
is it brontok?
*
If it was, HijackThis won't even run. smile.gif

And, don't you think that I would recognize Brontok when I see it? smile.gif
Sempurna
post Jun 27 2007, 06:56 PM

Look at all my stars!!
Group Icon
VIP
3,022 posts

Joined: Jul 2006
From: KL


Hi IrishCoffee,

The above VirusTotal reports are incomplete. There should be more scanners telling us the results of the scans. smile.gif
Sempurna
post Jun 27 2007, 07:29 PM

Look at all my stars!!
Group Icon
VIP
3,022 posts

Joined: Jul 2006
From: KL


You are still not doing the complete scans at VirusTotal. Is your Internet connection laggy or disconnecting?
Sempurna
post Jun 28 2007, 01:15 AM

Look at all my stars!!
Group Icon
VIP
3,022 posts

Joined: Jul 2006
From: KL


Show me a new ComboFix log after running Flash_Disinfector, please.

Also, please let me see a fresh HijackThis log, please.
Sempurna
post Jun 29 2007, 04:11 PM

Look at all my stars!!
Group Icon
VIP
3,022 posts

Joined: Jul 2006
From: KL


Hi IrishCoffee,

The logs appear to be clean. smile.gif

How are things running now?
Sempurna
post Jun 29 2007, 05:19 PM

Look at all my stars!!
Group Icon
VIP
3,022 posts

Joined: Jul 2006
From: KL


You're most welcome, IrishCoffee. smile.gif

Yep, your system appears to be clean. smile.gif

Uninstall and reinstall Photoshop. Probably got corrupted by the malware and the cleaning process.

~~~

Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0222sec    0.29    7 queries    GZIP Disabled
Time is now: 16th December 2025 - 05:59 AM