Major Spyware Problem...Please Help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by HasSanK, Jan 20, 2005.

  1. HasSanK

    HasSanK Specialist

    I have just been told to put my Hijackthis log on here along with my original post shown below.

    "I have a very big problem concerning some spyware, trojan, virus or something else on my PC... I'm not quite sure what it is. I will describe the problem below:

    A couple of days ago I let a friend use my PC so he could get some information off the internet but it appears that he went on more than just an information web site if you know what I mean

    After returning to my PC I realised that there was a new dialer in my 'network connections' folder named GBdialer... I managed to get rid of this via manually deleting it but I think it may have left some things behind as I have also been left with an icon on the desktop named 'Access Members Area' which cannot be deleted. I have tried many removal processes such as Mcafee, Norton, Spybot, Spysweeper & Ad-Aware!

    These have not managed to find anything whatsoever on my PC as I perform regular sweeps with these programs. Although they did not manage to find anything I have still been left with this icon on my desktop. I have tried manually deleting this but just come up with an error message which reads 'Cannot Delete Access Members Area: It is being used by another person or program. Close any programs that might be using the file and try again'

    Because of this message I tried doing exacly what it suggested by opening task manager and going to the processes section. When I got to this section I realised there was a new process which I had never seen before called 'services.exe'... I checked up on this with Google and found out that it was a trojan. So i tried to cancel the process so that I could delete the desktop icon but an error message came up which read 'This is a critical system process. Task manager cannot end this process'

    I would be extremely grateful if I could receive any help on this matter as this is my last resort due to searching the internet for 5 days now for ways to remove this threat... Thanks in advance for any help I may receive!"
     
  2. jms493

    jms493 Private E-2

  3. HasSanK

    HasSanK Specialist

    Thanks for your help but unfortunately it hasn't helped me... Like I said before, I have tried many of these spyware removal programs and none of them seem to work! Maybe I will get a better result from manually removing some registry item or something like that but I don't know how to do it... If anyone else has any more ideas please could you help me!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Didn't you already have a thread started with this problem in it:

    http://forums.majorgeeks.com/showthread.php?t=52525

    Why did you start a new one? You just need to be patient? It's been very busy here and you just drifted down the stack a little. A friendly "bump" to remind us would be better.

    I don't see where anyone asked you to post a HijackThis log.

    You need to first follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way 'services.exe' is not necessarily a trojan. If it is running from the correct location it is a valid windows process. You need to be careful what you read and how you interprete it.
     
  6. HasSanK

    HasSanK Specialist

    OK, I'm sorry about starting a new thread, I'm new to this forum thing and didn't know. Anyway, what if my thread just drifts down to page 10 for example and then never gets seen again.. How am I suppose to give you a 'bump' as you say?

    Anyway, about services.exe... I am pretty confident it is the trojan version as the memory usage is 5000 K whereas the non trojan version is only around 124... Also, I never had this process until i received the dialer and the 'Access Members Area' icon.

    And finally, about the person who asked me to post the Hijackthis log... I made a mistake...nobody asked me to post the Hijackthis log on this forum, it was on 'forums.thetechguys.com' as I have posted the same thread on there.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Adding a message to your thread would bring it back to the top. So something like:

    Can anyone please help me with this I'm still having a problem and it looks like I slipped way down to page x and no one is seeing my message anymore?


    The sooner you run all the steps of the READ ME FIRST the sooner we will get you fixed up.

    After doing ALL of the READ ME, if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not always a good thing to do. You really should only work your problem at one place or the other. Working both at the same time can confuse the people helping you because we know nothing about what is going on elsewhere.


    Also your services.exe is still probably okay.

    The bad one is typically called service.exe.


    It is asociated with the W32.Randex.R trojan and when executed, it copies itself to one of the following locations:

    %System%\service.exe
    %System%\svhost.exe
    %System%\pointer32.exe

     
  9. HasSanK

    HasSanK Specialist

    Ok, from now on I will just work with the help I get from this forum so as not to cause any confusion... I have not received any help from the other forum so far so nothing has changed. Maybe the services.exe is the proper one but I still don't know why it only appeared when I got the dialer and the desktop icon... Also I don't know how to get rid of the icon from the desktop, it just wont budge!

    Also, I have run all the steps of the 'READ ME' but this has not helped.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you the dialers are running services, then services.exe would have to run.

    If you ran all the steps post the HJT log as requested. Make sure you follow those directions though!
     
  11. HasSanK

    HasSanK Specialist

    HIJACKTHIS Log: Major Spyware Problem...Please Help!

    I have just been told to put my Hijackthis log on here by 'Chaslang' along with my original post shown below as he has instructed me on a lot of ways to get rid of the problem but none has helped... I appreciate your help anyway Chas.


    EDIT by chaslang: Delete problem description! It's already been given.
     

    Attached Files:

    Last edited by a moderator: Jan 20, 2005
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: HIJACKTHIS Log: Major Spyware Problem...Please Help!

    Please stop creating new threads! Stay in one thread until the problems are resolved.
    I'm merging you back to the other thread!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: HIJACKTHIS Log: Major Spyware Problem...Please Help!

    You did not follow the directions on where to install HJT too. You have it here:
    C:\Documents and Settings\Owner\Desktop\hijackthis\HijackThis.exe

    Please install it correctly before continuing!

    You should not be installing programs there! You also put SpySweeper there:
    O4 - HKCU\..\Run: [SpySweeper] "C:\Documents and Settings\Owner\Desktop\Hassan's Folder\Spy Sweeper\SpySweeper.exe" /0

    That folder should be used for Documents and or Settings for each user. Programs really should be installed in most cases to their default folders which is normally under C:\Program Files

    Will the run elsewhere? Yes? But this is a bad practice and can lead to problems?
     
  14. HasSanK

    HasSanK Specialist

    Ok I Didnt Realise That I Had To Also Put The Hijackthis Log Into The Same Thread As The Problem Description! I Mean, Give Me A Break Here... I've Only Just Started Using Forums, Everyone Makes Mistakes, You Cant Expect Me To Understand Everything From Day 1!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Stop complaining! All I did was tell you how to do it properly. You have open at least 3 threads on this problem already. Look at message #4.

    If you want help, all we ask is for you to follow directions. That I can and do expect. If you don't understand a direction or a procedure. Then ask questions but in the same thread.

    If you READ the FAQs and the stickies in the forums which they clearly tell you to do, all of this would be apparent.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you right click on the Desktop icon what information do you get about it. Like Target, Start in information.

    You need to download LSP - Fix

    NOW:
    Unzip it and run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the xfire_lsp_10650.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move xfire_lsp_10650.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.


    Now run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O13 - DefaultPrefix:
    O16 - DPF: {F0BC061F-DAF9-4533-8011-53BCB4C10307} (Installations Assistent) - http://install.mp3bereich.de/InstallationsAssistent.ocx
    O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} - http://66.117.37.13/dba842.exe
    O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
    O23 - Service: kavsvc - Unknown - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe (file missing)

    Do you know what this below item is for? If not, fix it too.
    O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://sib1.od2.com/common/Member/ClientInstall/10.01.0004/OCI/setup.exe


    After clicking Fix, exit HJT.

    Now reboot and post a new HJT log. Are you still having a problem?
     
  17. HasSanK

    HasSanK Specialist

    Thanks for your help Chaslang, my problem is sorted now! I appreciate it.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. But you really should post the follow up HJT log to make sure!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds