Need help SpySheriff virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by chase8937, Jan 13, 2006.

  1. chase8937

    chase8937 Private E-2

    The other day I went online and down in the corner it say my computer is infected. The home page wants me to download spysheriff. I have tried doing everything you guys ask. My Ad ware stops at 219 process modules. Spyboat take hours and still does not finish. i could not run microsoft antispy in safe mode.
     

    Attached Files:

    Last edited by a moderator: Jan 13, 2006
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download the attach GetRunKey120.zip to your PC someplace you can locate it. Then extract the files from the ZIP. Locate the getrunkey.bat file and double click on it to run it. It will create a file named runkeys.txt in the root of drive C: (C:\runkeys.txt) . This log will also popup in a notepad window which your can just close. Upload the runkeys.txt file here as an attachment.

    Please upload the above runkeys.txt file now before continuing with below and then continue. If you do not do this, you will overwrite the runkeys.txt later thus losing this info.

    Now follow the steps in the below and then attach the requested smitfiles.txt log:

    SpywareStrike, Smitfraud, SpySheriff, SpyAxe & PSGuard Removal

    After doing the above, run GetRunkey.bat a second time and upload the new runkeys.txt file. You may need to rename it to runkeys2.txt (maybe not if you are posting in a second message than the first upload).
     
  3. chase8937

    chase8937 Private E-2

    Here is the runkey.txt, and smitfiles
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have viewing of hidden and system files enabled per the READ ME.

    Use Windows Explorer and look for the below file:
    C:\WINDOWS\system32\wiatwain.dll.dll

    Does it exist? If so, please delete it. Let me know what you find.

    How are things working now?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also on more cleanup and recheck step.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    No attach a new log from GetRunKey.bat
     
  6. chase8937

    chase8937 Private E-2

    I have a quick question. I have found a file named C:\WINDOWS\system32\wiatwain.dll.
    Is this the same file as C:\WINDOWS\system32\wiatwain.dll.dll. Also did you say not to do more clean up are to do more.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's the same file. Delete it.

    My previous message had a typo in the first line. It said:
    But it should have said:
    I wanted you to do one more thing ( the registry patch).

    Also at the end:
    should be
     
  8. chase8937

    chase8937 Private E-2

    I have tried to delete the file C:\WINDOWS\system32\wiatwain.dll. But it will not let me.

    Thanks

    Matt
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run the SpywareStrike, Smitfraud, SpySheriff, SpyAxe & PSGuard Removal steps again but while in safe mode try to delete the file after running SmitRem (you will see that file list with many others after the HJT fix step).

    Save and attach the smitfiles.txt log again. Also run the Panda scan as indicated and attach the log.
     
  10. chase8937

    chase8937 Private E-2

    Went I run the Runthis.bat. It scans, then it will clean disk. But then the icon for the cleaning disk disappears. And the is no txt file to save.
     
  11. chase8937

    chase8937 Private E-2

    I found the new smit,txt sorry about that post
     
  12. chase8937

    chase8937 Private E-2

    My viewing of hidden and system files are enabled per the READ ME.

    I could not find this file in my HJT log.
    C:\WINDOWS\system32\wiatwain.dll.dll

    Now when I turn on my computer the home page is back to yahoo.com, but it still says Your computer is infected in the corner of the screen. I did do all the cleaning step. The adware stops everytime at 253 process. Spybot seem to run very slow.
     

    Attached Files:

    Last edited by a moderator: Jan 31, 2006
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The file is named C:\WINDOWS\system32\wiatwain.dll not C:\WINDOWS\system32\wiatwain.dll.dll (that was a typo on my part and in the original GetRunKeys program you ran). The file you need to delete does still show in your PandaScan. So you must not have enabled viewing of hidden files, system files, and extensions enabled, otherwise you would see it. Or you just did not notice it because you were looking for wiatwain.dll.dll

    Are you using manually procedures in Windows Explorer to find it. Or are you using search? Search will not work because you did not enable options in search to look for hidden and system files. You only enable them for Windows Explorer when you manually click to expand folders and navigate by hand to the proper location.

    Do the procedure in the below again (delete the old version of GetRunKeys that you have first):

    Using GetRunKey

    Attach the runkeys.txt log but also look at it yourself and see if down toward the bottom you see the below line:

    Spyware Strike file C:\WINDOWS\system32\wiatwain.dll found

    If you do, the file is there and you are not looking for it properly.

    You also have other items (some of which you should have removed when following the thread for SpywareStrike etc removel. Delete all of the below
    C:\WINDOWS\SYSTEM32\cd_clint.dll
    C:\WINDOWS\SYSTEM32\search.html
    C:\WINDOWS\dict.dat
    C:\PROGRAM FILES\MyWay <---- the whole folder
    C:\PROGRAM FILES\SpywareStrike <---- the whole folder
    C:\WINDOWS\system32\P2P Networking v123.cpl
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds