This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

thecoolpics.net - pllss.. help me...

11 min read

This thread's last reply is from August 7, 2007, 2:57 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Hi sundara. :)

Welcome to Malware Removal Forum. My name is mayi and I will be helping you. As I am still an undergraduate, I will need my fixes checked before posting back to you. Thank you for your patience.
Hi sundara,

Step 1

I don't see an antivirus program running in your log. It could be that you disabled it, or you don't have an antivirus at all.

If you have disabled it, please re-enable it back.

If you have no antivirus, please download ONE antivirus from one of the links below:

AVG Antivirus Free
AntiVir for Windows 2000 and Windows XP
avast! 4 Home Edition
Clamwin

Please print out or save this set instructions as you will be working in Safe Mode without internet connections.

Step 2

  1. Download SDFix by AndyManchesta and save it to your desktop.
  2. Double click on SDFix.exe. By default, it will install to C:\.
  3. Click on Install.


Step 3

Boot into Safe Mode.

  1. When you see BIOS screen, start pressing F8.
  2. A boot menu will appear shortly.
  3. Using the up down arrows, select Safe Mode and press the Enter key.
  4. Windows will now load.
  5. Log in to your usual account.


Step 4

  1. Navigate to E:\SDfix (if you installed it to the default location, otherwise, locate where you installed it)
  2. Double click on RunThis.bat
  3. Type Y to begin the cleanup process.
  4. It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  5. Press any key to reboot.
  6. When the PC restarts the tool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  7. Once the desktop icons load, the SDFix report will open on screen. You can also find the report in SDFix folder, named Report.txt.


Step 5

  1. Open My Computer.
  2. Double click on your E drive.
  3. Right click on an empty space and select New > Folder. Type in BFU as the name of the folder and press Enter.


Step 6

Please download Brute Full Uninstaller by Merijn from one of these links:

From Castlecops
From DKnoppix
From Merijn
From Major Geeks

  1. Locate the bfu.zip that you've downloaded earlier.
  2. Right click on bfu.zip and select Extract All....
  3. Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
  4. In the Files will be extracted to this directory: box, copy and paste in E:\BFU. Then click OK.
  5. Check (tick) the Show extracted files box.
  6. Right click here and select Save Link As... (In Internet Explorer it is Save Target As...). Save it to E:\BFU folder.
  7. Navigate to E:\BFU and double click on BFU.exe.
  8. In the Scriptfile to execute field, copy and paste this in: E:\BFU\coolpics.bfu
  9. Click on Execute.
  10. Once done, click OK and click on Exit.


In your next reply, please post:

  1. SDFix report
  2. A new HijackThis log
Hi sundara,

Please re-run Steps 2, 3, 4 and 6 in my previous post to you.

In addition, please do the following:

Please rename HijackThis.exe to dumb.exe by following the instructions below:

  1. Navigate to E:\Program Files\Trend Micro\HijackThis
  2. Right click on HijackThis.exe and select Rename.
  3. Type in dumb and press Enter.
  4. Double click on dumb to run it. Select Do a system scan and save a logfile. Please post back this log in your next reply.
Do not close HijackThis yet.

  1. Click on the Config... button at the bottom right hand corner.
  2. At the top, click on the Misc Tools button.
  3. Look under System tools.
  4. Click on the Open Uninstall Manager... button.
  5. Click on the Save list... button.
  6. It will prompt you to save. Save this log in a convenient location. By default it's named uninstall_list.txt.
  7. Notepad will open. Please post back this list in your next reply.


In your next reply, please post:

  1. SDFix report
  2. A new HijackThis log
  3. The uninstall list
Hi sundara,

Please set your system to show hidden files and extensions.

Step 1

Show hidden files and folders
  1. Open My Computer.
  2. Go to Tools > Folder Options.
  3. Select the View tab.
  4. Scroll down to Hidden files and folders.
  5. Select Show hidden files and folders.
  6. Uncheck (untick) Hide extensions of known file types.
  7. Uncheck (untick) Hide protected operating system files (Recommended).
  8. Click Yes when prompted.
  9. Click OK.
  10. Close My Computer.

There is auto created "New Folder (Microsoft Corp.) found in my PC. Whenever i hitting that Coolpics.net comes again.

Select this folder icon, do not open it: New Folder. Does it have any extensions behind? Such as .exe or .dll ?

Step 2

  1. Please download VundoFix.exe by Atribune from Atribune and save it to your desktop.
  2. Double click VundoFix.exe to run it.
  3. Click the Scan for Vundo button.
  4. Once it's done scanning, click the Remove Vundo button.
  5. You will receive a prompt asking if you want to remove the files, click YES
  6. Once you click yes, your desktop will go blank as it starts removing Vundo.
  7. When completed, it will prompt that it will reboot your computer, click OK.
  8. Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

In your next reply, please post:

  1. VundoFix report (C:\VundoFix.txt)
  2. A new HijackThis log
  3. Whether there is a file extension for the new folder found on your PC
Hi sundara, please post the VundoFix log (E:\VundoFix.txt)

Please also download Flash Disinfector by sUBs and save it to your desktop.

Plug in your external disk and hold down the Shift key so it doesn't auto run.

Double click on Flash_Disinfector.exe to run it. Your desktop will disappear for a while. Once the cleaning is done, click OK and your desktop will return.

If it doesn't appear, press Ctrl + Shift + Esc to bring up Task Manager.

Click on File > New Task (Run...). Copy and paste in explorer.exe and click OK.

Please uninstall Flashget as it's infected with spyware.

For a list of clean download managers, please see this article or here.
Hi sundara,

  1. Please open VundoFix.
  2. In the blank white space above the Scan For Vundo and Remove Vundo buttons, right click and select Add more files?.
  3. Add in the following files:
    • E:\WINDOWS\system32\ipnydgh.dll
    • E:\WINDOWS\system32\sruusxm.dll
  4. Click Add Files, then Close Window.
  5. Click on Remove Vundo.
  6. You will receive a prompt asking if you want to remove the files, click YES.
  7. Once you click yes, your desktop will go blank as it starts removing Vundo.
  8. When completed, it will prompt that it will reboot your computer, click OK.
  9. Please post the contents of E:\vundofix.txt and a new HijackThis log.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

In your next reply, please post:

  1. VundoFix log (E:\VundoFix.txt)
  2. A new HijackThis log
Please download Combofix from Tech Support Forum or Bleeping Computer. Save it to your desktop.

Double click to run it. Follow the prompts. Once done, it will reboot and a log will be produced. Please post that log and a new HijackThis log in your next reply.

Note: Do not mouse click on Combofix while it is running. That may cause it to crash.
Hello sundara,

Are you still there?

If you have problems following the instructions, please let me know.
Hello sundara,

Please delete your current copy of Combofix and download the latest copy of Combofix from Tech Support Forum or Bleeping Computer and save it to your desktop.

Please copy and paste the following in the Code box into Notepad. Do not use any text editors as it will not work.

Folder::
E:\Temp\ClnExtor

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrkp32]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{347867a2-8fe1-11db-99da-0011119f8d04}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{448a3dc0-39d5-11dc-914a-0011119f8d04}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c39d12f-2473-11dc-910a-0011119f8d04}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c4dd525-ec9e-11db-908a-0011119f8d04}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4fd5f5e1-88e3-11db-99c6-0011119f8d04}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{547a3917-869e-11db-99c2-0011119f8d04}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5cac29d4-9243-11db-99e1-0011119f8d04}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{647f1e61-416f-11dc-915b-0011119f8d04}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f654f64-e0d7-11db-9073-0011119f8d04}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7cca81ae-3c50-11dc-9151-0011119f8d04}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7e6d27ca-6d72-11db-9994-0011119f8d04}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{deeebc6e-d37b-11db-9a7f-0011119f8d04}]


Click on File > Save As.

In the File Name field, copy and paste in CFScript.txt

Click Save.

Note: Do not change the file name.

Drag CFScript.txt into Combofix. Please see the picture below:



Once done, a Combofix log will be produced. Please post this Combofix log as well as a new HijackThis log in your next reply.
Hello sundara. :)

Step 1

Please copy and paste the following in the Code box into Notepad.

attrib -r -s -h C:\Autorun.inf
del /q C:\Autorun.inf
attrib -r -s -h D:\Autorun.inf
del /q D:\Autorun.inf


Click on File > Save As....

In the File Name box, copy and paste in fix.bat
In the Save as type box, select All Files from the drop-down list.

Click Save.

Step 2

  1. Please download AVG Anti-Spyware and save it to your desktop.
  2. Double click on avgas-setup-7.5.0.50.exe to install AVG Anti-Spyware. Install it in the default location.
  3. Once installed, start AVG Anti-Spyware by going to Start > All Programs > AVG Anti-Spyware 7.5 > AVG Anti-Spyware.
  4. In the main screen, you should see Your Computer's Security.
    • Next to Resident Shield, click on Change state. It should now be Inactive.
    • Next to Automatic Updates, click on Change state. It should now be Inactive.
    • Next to Last Update, click on Update now. If your firewall prompts you, tell your firewall to allow it. Should you be unable to update it, download the updates from here. Save it to your desktop. Double click to run the installation and the updates will be installed. Make sure AVG Anti-Spyware is closed during the installation.
    • Right-click the AVG Anti-Spyware icon near the clock and uncheck (untick) Start with Windows. Confirm by clicking Yes.
  5. Now click on the Scanner button at the top.
  6. Select the Settings tab.
  7. Under How to act?, click on Recommended actions and select Quarantine.
  8. Under How to scan?, check (tick) all the boxes.
  9. Under Possibly unwanted software:, check (tick) all the boxes.
  10. Under Reports:, uncheck (untick) the Only if threats were found box and select Do not automatically generate report.
  11. Under What to scan?, select Scan every file.
Do not run a scan yet. You will run a scan later.

Step 3

Please download ATF Cleaner by Atribune.

  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All.
  • Click the Empty Selected button.


If you use Firefox browser

  • Click Firefox at the top and choose: Select All.
  • Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.


If you use Opera browser

  • Click Opera at the top and choose: Select All.
  • Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.


Step 4

  1. Start AVG Anti-Spyware by going to Start > All Programs > AVG Anti-Spyware 7.5 > AVG Anti-Spyware.
  2. Click on the Scanner button at the top.
  3. Select the Scan tab.
  4. Click on Complete System Scan to start the scan.
  5. When the scan has finished, follow the instructions below.
    IMPORTANT: Don't click on the Save Scan Report button before you did hit the Apply all Actions button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
  6. When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  7. Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.


Step 5

Please go to Kaspersky website and perform an online antivirus scan.
Please use Internet Explorer as it uses ActiveX.

  1. Click on Kaspersky Online Scanner button.
  2. Read through the requirements and privacy statement and click on Accept button.
  3. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an ActiveX from Kaspersky. Click Yes.
  4. When the downloads have finished, click on Next button.
  5. Click on Scan Settings button.
  6. Select extended under Scan using the following antivirus database:
  7. Check (tick) these boxes under Scan options:
    • Scan Archives
    • Scan Mail Bases
  8. Click OK
  9. Click on My Computer under Please select a target to scan:
  10. Once the scan is complete it will display if your system has been infected. Click on Save as text button and save it to your desktop.
  11. Copy and paste this log in your next reply.


Step 6

Can you please help me check if these files are still present on your system:

1. C:\Autorun.inf
2. D:\Autorun.inf

In your next reply, please post:

  1. AVG Antispyware scan report
  2. Kaspersky Antivirus scan report
  3. A new HijackThis log
  4. Whether or not the 2 files are present
Hello sundara,

Your Kaspersky log is bad news.

A backdoor has been detected, as well as several cracked softwares. It's our policy not to help victims if they use cracked softwares.

My standard warning if a backdoor has been detected.

Your computer has multiple infections, including a backdoor. A backdoor gives intruders complete control of your computer, logs your keystrokes, steal personal information, etc.

You are strongly advised to do the following:

  • Disconnect the computer from the Internet and from any networked computers until it is cleaned.
  • Back up all your important data except programs. The programs can be reinstalled back from the original disc or from the Net.
  • Call all your banks, financial institutions, credit card companies and inform them that you may be a victim of identity theft and put a watch on your accounts. If you don't mind the hassle, change all your account numbers.
  • From a clean computer, change all your passwords (ISP login password, your email address(es) passwords, financial accounts, PayPal, eBay, Amazon, online groups and forums and any other online activities you carry out which require a username and password).
Do NOT change your passwords from this computer as the attacker will be able to get all the new passwords and transaction records.

Due to its backdoor functionality, your computer is very likely to have been compromised and there is no way that it can be trusted again. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be to do a reformat and reinstallation of the operating system (OS). However, if you do not have the resources to reinstall your OS and would like me to attempt to clean your machine, I will be happy to do so.

To help you understand more, please take some time to read the follwing articles:

What are Remote Access Trojans and why are they dangerous
How do I respond to a possible identity theft and how do I prevent it
When should do a reformat and reinstallation of my OS
Where to backup your files
How to backup your files in Windows XP
Restoring your backups