Spyware.AproposMedia

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by geoman, Nov 17, 2005.

  1. geoman

    geoman Private E-2

    hi - I've been trying to help a friend clean up their laptop .... when I got it, it was barely useable ... slow boot, multiple error messages, and non-stop, crippling pop ups.... after much work, and with the help of your instructions (THANK YOU!!!), it's now in pretty good shape.

    I still get the following at boot, from Ewido:

    file: AutoUpdate.exe
    Path: C:\Program Files\AutoUpdate
    Infection: Spyware.AproposMedia

    and I select Block/Clean and everything seems to be working ok, but I get the same warning everytime I reboot...

    so, I thought this would be a good time to see if you can spot something in my HJT log to get rid of this, and any other lurking problems ...

    I have followed all the steps in your clean up instructions and read and followed the steps for downloading, installing, and running HJT.

    My HJT log is attached ...

    thanks for your help!
    paul
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Command Service (or if not found look for cmdService) ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Command Service

    If that does not work try entering the short name: cmdService

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Windows Overlay Components ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Windows Overlay Components

    Now exit HJT but do not reboot if told it need to do so. We will do that later after restarting HJT to fix other problems. We will also double check in HJT to fix the above.

    Did you want the below two R1 lines set to about:blank? If not, add them to the list for HJT to fix.
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\Q2hhcnVjaw\command.exe (file missing) <--- may be gone already
    O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\kvvbhay.exe (file missing) <--- may be gone already


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (if found):
    C:\Program Files\AutoUpdate <--- the whole folder
    C:\WINDOWS\Q2hhcnVjaw <--- the whole folder
    C:\WINDOWS\kvvbhay.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.


    .
     
  3. geoman

    geoman Private E-2

    Thanks!!! You guys are amazing! After following the instructions you provided, I did NOT get any ewido,etc. warnings after rebooting ... and no pop ups so far!

    I've attached another HJT log as requested ...

    please let me know if there is any other tweaking you think I should do!

    thanks again and again!
    paul
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. geoman

    geoman Private E-2

    hi again .... I'm glad my log looks clean, and everything is running smoothly ... BUT ....

    I just downloaded and installed updates for MS AntiSpyware, Ad-Aware, and Ewido, and they all found various "threats":

    MS Antispyware: removed 2 items:

    BookedSpace Browser Plug-In
    Adware.cmdService Adware

    Ad-Aware SE:

    Tracking cookie: charuk@tribalfusion.com
    Cmd Services: c:\windows\system32\atmtd.dll
    and c:\windows\system32\atmtd.dll_

    Ewido:

    Spyware.Cookie.2o7 ... charuk@msnportal.112.207[1].txt



    anything to worry about...?

    thanks,
    paul
     
  6. geoman

    geoman Private E-2

    oh! and when I just went to the link in your message about disabling Messenger, and I click on the Download link there, I see it points to something with "tribalfusion" in the URL and it takes me to a Napster page! Nothing about disabling Messenger there!??

    am I doing something wrong...?

    thanks,
    paul
     
  7. geoman

    geoman Private E-2

    ooops ... please disregard last post re Messenger ... I was clicking on the "Download" link in the text description below, and I see now that it is really just an ad link for "downloading" something .... in this case, Napster ...

    I did the Messenger Disable download by using the proper download link at the top of the page ...

    sorry ....
    and thanks again,
    paul
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have already had MS Antispyware installed and run! It is part of the READ & RUN ME which you said you ran.

    The more tools you run the more stuff you can find. Quite often, the additional things found like this are either dormant or harmless. As long as they were fixed, there is nothing to worry about.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! So is everything running OK now?
     
  10. geoman

    geoman Private E-2


    um, no .... ewido just found the "tribalfusion" threat, etc., again ... Even though MS etc said they "cleaned" these, it looks like they're coming back .... disabling Messenger didn't seem to make any difference (although I'm glad to have it gone, anyway...)

    I'm just concerned that if these couple of things are finding their way in, that others may follow ....?

    thanks,
    paul
     
  11. geoman

    geoman Private E-2

    sorry, yes, I promise, I DID have ALL those things installed and run, rebooted in safe mode etc etc - every step in the read me, before I uploaded the HJT post ...

    I just thought it would be good to check for updates and run them one more time after things looked clean ... and they keep finding stuff ...!

    paul
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's just a tracking cookie! You will get them on many sites including Majorgeeks. Most tracking cookies are not problems. They are just used to determine which advertisements on each web page to show you. They will keep coming back each time you do any surfing anywhere.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A friend of mine (PhilliePhan) has pointed out that it may be worth running the below procedure to be sure we have gotten all of AproposMedia. Run the steps in the below link. Make sure they are run from safe mode boot.

    AproposMedia Fix
     
  14. geoman

    geoman Private E-2

    Thanks! I downloaded and ran it in safe mode and have attached the new HJT log and the other log ...

    things are really working well now ... THANKS AGAIN!!!
    paul
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Your clean. Just make sure you complete the steps in How to Protect yourself from malware! as I mentioned before. You need a real firewall which is covered there too.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds