Dameware + other none deletable files

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by miamidice, Aug 21, 2006.

  1. miamidice

    miamidice Private E-2

    Hey there i hope someone can help me.

    Someone messed with my internet options "restricted sites" level and set it to medium-low. I connected to the internet and downloaded a file from azeurus, and now I have things like Dameware and many other spyware type programs connected to the internet with me which are making my computer very slow. I am currently using windows 2000 and am having to use a dial-up connection if that makes any difference, I've attached the hijackthis log and any help removing these pests would be greatly appreciated,

    yours sincerely

    Eleanor

    xxx
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Did you look in Add/Remove programs for an uninstall to DameWare?
    What is all the Oracle stuff shown in your HJT log? Do you use Oracle?

    Why are you running a non-updated Windows 2000 system, without an antivirus, with no antispyware blocking, and with no firewall? This is very dangeous and is the reason that you are so badly infected.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:

      • [*]runkeys.txt - the log from GetRunKey.bat
        [*]newfiles.txt - the log from ShowNew.bat
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. miamidice

    miamidice Private E-2

    Hey, I've attempted everything in the "READ AND RUN ME FIRST" post, I couldn't run the Bitdefender and Panda Scan because my internet connection is running too slowly (thats another thing thats happened since the spyware.) I also cant do the disable system restore on my windows version. I THINK i've managed to get rid of dameware, i dont have it in the sys tray anymore.

    The main problem now seems to be my comp running really slow when connected to the net, when i try and play online poker it disconnects from the poker server about every 30 seconds, but my net connection remains. Also I have a RUNDLL error message saying:
    " error loading w0127744.dll "

    I've posted some attachments for u to have a look at,

    please help if u can!

    thanks ellie

    xxx
     

    Attached Files:

  4. miamidice

    miamidice Private E-2

    Also here is my analyse (HJT) log.

    All that oracle stuff on my comp u asked about, I dont use it. I got my comp 2nd hand off a business and I think they used it but i've never deleted it because not sure if it would mess up my computer,

    thanks

    ellie

    xxxx
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you do not have System Restore on Windows 2000 but you were not supposed to disable it yet anyway.

    You do need to install HJT properly though. You have it here:

    C:\Documents and Settings\Administrator\Desktop\hjt\analyse.exe

    That is exactly where the READ ME specified not to install it. Please fix this now.

    Also you appear to have two PandaActiveScans still running:
    C:\WINNT\System32\ActiveScan.exe
    C:\WINNT\System32\ActiveScan.exe

    Please make sure they are no longer running. Then attach a new HJT log.

    Is the below valid? Is this really Oracle?
    c:\orant\bin\oracle80.exe

    Is the below ProxyOverride something you setup?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = intranite.aniteps.com
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about this! I just noticed that you were not running PandaActiveScan. You have a trojan that is named activescan.exe that is running. We will get to it soon, but first I need you to run the below and attach the requested log:

    Look2Me VX2 Removal
     
  7. miamidice

    miamidice Private E-2

    Hey thanks for this. I didn't set up any proxy override, maybe the person who had the laptop before me did. Is it something to be concerned about? Will the computer still function fine without it?

    As for Oracle all i know is that there was a bunch of oracle files on the system when i was given the laptop, and i wasn't sure if deleting it would cause any harm so i left it.

    I've posted the proper hjt log and the look2me txt for u to have a look at,

    thanks!

    ellie

    xx
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you still use Oracle? I tend to doubt it since I did not see it in your installed programs list in the ShowNew log. That means it was never uninstalled properly.
    Do you have any idea what the below two files are for?
    C:\MSCIOTL.SYS
    C:\ICSYSINF.log

    First goto Add/Remove Programs and uninstall TargetSaver.

    Now Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to DameWare Mini Remote Control (if that is not found, look for the short name: aswUpdSv)... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now repeat the above stop and disable for the following services:
    PE Sytray Manager
    Windows PE Debugger

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    DWMRCS

    Now repeat the Delete NT Service steps for:
    PE Sytray Manager
    Windows PE Debugger

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of gebcy.dll once and then click the kill button. After you have killed all of the gebcy.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    iifefge.dll

    Next double click on explorer.exe and again click once on each instance of gebcy.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    iifefge.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = intranite.aniteps.com
    R3 - URLSearchHook: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll
    O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINNT\system32\iifefge.dll
    O2 - BHO: (no name) - {753AD400-99F9-46F7-9CF7-86BBC9DC8107} - C:\WINNT\System32\gebcy.dll
    O4 - HKLM\..\Run: [Windows Management] stmb32.exe
    O4 - HKLM\..\Run: [Local Security Authority Service] C:\WINNT\System32\lssas.exe
    O4 - HKLM\..\Run: [qzm1c3f9] RUNDLL32.EXE w0127744.dll,n 0031c3f60000000a0127744
    O4 - HKLM\..\Run: [ActiveScan Antivirus] ActiveScan.exe
    O4 - HKLM\..\RunServices: [Windows Management] stmb32.exe
    O4 - HKLM\..\RunServices: [ActiveScan Antivirus] ActiveScan.exe
    O4 - HKCU\..\Run: [Windows Management] stmb32.exe
    O4 - HKCU\..\Run: [ActiveScan Antivirus] ActiveScan.exe
    O4 - HKCU\..\RunServices: [ActiveScan Antivirus] ActiveScan.exe
    O15 - Trusted Zone: http://www.toucansurf.com
    O15 - Trusted Zone: http://www.toucantele.com
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
    O20 - Winlogon Notify: AdminDebug - C:\WINNT\system32\jt8s07l7e.dll
    O20 - Winlogon Notify: gebcy - C:\WINNT\System32\gebcy.dll
    O20 - Winlogon Notify: iifefge - C:\WINNT\SYSTEM32\iifefge.dll
    O20 - Winlogon Notify: MS-DOSOptions - C:\WINNT\system32\f22mlcf11f2.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.
    C:\dfndrfh_10.exe
    C:\kybrdfh_10.exe
    C:\WINNT\system32\iifefge.dll
    C:\WINNT\System32\gebcy.dll
    C:\WINNT\SYSTEM32\ycbeg.tmp
    C:\WINNT\SYSTEM32\ycbeg.ini
    C:\WINNT\system32\stmb32.exe
    C:\WINNT\system32\ssmc.exe
    C:\WINNT\System32\lssas.exe
    C:\WINNT\system32\w0127744.dll
    C:\WINNT\system32\ActiveScan.exe
    C:\WINNT\System32\gebcy.dll
    C:\WINNT\SYSTEM32\iifefge.dll
    C:\WINNT\system32\f22mlcf11f2.dll
    C:\WINNT\SYSTEM32\MSmedia.exe
    C:\WINNT\SYSTEM32\icont.exe
    C:\WINNT\SYSTEM32\v1201.exe
    C:\WINNT\SYSTEM32\host.exe
    C:\WINNT\SYSTEM32\eraseme_35745.exe
    C:\WINNT\SYSTEM32\hoxhiujp.exe
    C:\WINNT\SYSTEM32\tsuninst.exe
    C:\WINNT\SYSTEM32\hggdefe.dll
    C:\WINNT\SYSTEM32\GEKCSP.DLL
    C:\WINNT\SYSTEM32\GNKCSP.DLL
    C:\WINNT\SYSTEM32\DOSETUP.DLL
    C:\WINNT\SYSTEM32\byxurrq.dll
    C:\WINNT\SYSTEM32\qopon.dll
    C:\WINNT\SYSTEM32\gebcy.dll
    C:\WINNT\SYSTEM32\STARDDLG.DLL
    C:\WINNT\SYSTEM32\SIELL.DLL
    C:\WINNT\SYSTEM32\r26u0cj9efo.dll
    C:\WINNT\SYSTEM32\w0127744.dll
    C:\WINNT\SYSTEM32\qzm1c3f9.dll
    C:\WINNT\SYSTEM32\VXAR332.DLL
    C:\WINNT\SYSTEM32\qxap.dll
    C:\WINNT\SYSTEM32\qbdit.dll
    C:\WINNT\SYSTEM32\CDDIAL32.DLL
    C:\WINNT\SYSTEM32\c000ladm1d0a.dll
    C:\WINNT\SYSTEM32\h8l20i3oe8.dll
    C:\WINNT\SYSTEM32\fpnm0351e.dll
    C:\WINNT\SYSTEM32\CEYPTDLG.DLL
    C:\WINNT\SYSTEM32\dkcompos.dll
    C:\WINNT\SYSTEM32\iifefge.dll
    C:\WINNT\SYSTEM32\MBL_MTF.DLL
    C:\WINNT\SYSTEM32\p48q0el5ehq.dll

    If Killbox does not reboot or if you get a Pending Operations type error message just click OK to continue and then just reboot your PC yourself.
    After reboot locate the below folder and delete it if found:
    C:\Program Files\Deskbar <--- the whole folder

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINNT\Temp
    C:\Documents and Settings\Administrator\Local Settings\Temp

    Now attach a new HJT log and tell me how the steps went.
    Also attach a new log from ShowNew and a new log from GetRunKey.
    Make sure you tell me how things are working now!
     
  9. miamidice

    miamidice Private E-2

    Ok well I followed all the steps you asked me to do, and now the spyware and viruses have ALL come back and infected the computer like it was at the very beginning even before i followed the "READ THIS FIRST!!!"

    I did the steps of going into service.msc but the pe sytray manager and windows debugger didnt give me the option of stopping the service so i just disabled the start up.

    WHat am I to do now?!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are all the system files (files in your C:\winnt\system32 folder for Windows) all having their dates changed? Nothing we did should be touching these. Did you do anything other than the steps I gave to you in message # 8?

    Also are you sure you did the steps with Pocket Killbox correctly? I still see many the files it was supposed to delete. Did you get any error messages while running the procedures? Somethings did get fixed like the bad O23 Services and Look2Me and also Virtumonde but many remain and new ones appeared.

    I think part of your problems with why you are so infected and why they are comming back is because your OS is so out of date and also the fact that you do not have proper protection installed. Let's get you a little better protected before we continue and this may help block things from returning. Please download, install and run the below antivirus and firewall.

    AVG Free Edition - run a full scan after installing and updating to current definitions


    ZoneAlarmFree - after installing, do not allow anything to access the internet that you do not recognize as a valid program. Obviously any process name I'm asking you to delete should be blocked.


    Now goto Add/Remove programs and uninstall the below:
    Command
    Network Monitor
    Search Bar

    Now attach new logs from HJT and ShowNew.


    You did not answer my questions about Oracly and those other two files.


    Another question, what are the below and did you install them:

    Terminal Services Client MSI
    Terminal Services Client
    ToucanSurf Connection Manager
     
    Last edited: Aug 31, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds