"Spyware Protect 2009" hacked me...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by billmoz, Feb 14, 2009.

  1. billmoz

    billmoz Private E-2

    I got whacked with an infection from the "Spyware Protect 2009" program when visiting a New Zealand wine website (of all places) yesterday afternoon. I had Spybot SD Tea TImer running then which stopped a lot of the crap from installing but enough got past it and so my PC got infected.
    So I was able to remove the "Spyware Protect 2009" stuff manually following the instructions from another website as well as a WINDOWS\services.exe app that kept trying to install (but was being blocked by Tea Timer) using Symantect Corporate AV, auotruns, and Spybot.
    It was after that and I was still having issues (couldn't start Windows Firewall for example and was always being redirected when using IE) that I discovered your website very late last night and so I methodically followed all your instructions for cleaning and taking logs. I now have all the logs in place and so need your advice on what is needed to get my PC perfectly clean to be 100% safe. I know that my Network Connections app is still not working correctly for example (always says that I am disconnected when I know I am not). The 3 basic logs are attached. Thank you for your help!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We still need the log from running the MGTools.exe --> C:\MGLogs.zip.
     
  3. billmoz

    billmoz Private E-2

    No worries TimW, it is now attached.
    -BillM
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs.......but I would like to know if you made some user changes:

    Code:
    "C:\WINDOWS\system32\"
    userinit.exe  Feb 13 2009       22528  "userinit.exe"
    
    And did you disable this:
     
  5. billmoz

    billmoz Private E-2

    I did not make any changes to the userinit.exe file. I did notice this file after the infection as it was modified at exactly the same time that I was attacked - Feb 13 2009 at 4:50pm. Hence, when I looked in the system32 folder and arranged the files by "date modified", i saw that userinit.exe was grouped in with all the malware files that were created at the same time (and that I have since deleted). Note that when I was first attacked, the malware did shut down my system and so I had to reboot. Is it possible the hack edited this file then? Why? If so, can I delete it and create a new one that I know is safe?

    I did turn off the hp wireless assistant - issues with the wireless connection whenever I use a wireless phone nearby - which didn't work by the way! Should I turn it back on?

    ALso note that the Wireless Network Connection and Wired Network Connection icons in the Network Connections group do not update with my connection status - they both always show that the PC is not connected and show no IP address even if I am connected (with a valid Ip address as shown by IPCONFIG). I only saw this since I was attacked so is this related to the hack?

    Thanks for your help. Good news that the logs came up essentially clean though...
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The file was actually smaller than it should be for sp3. You can go here and copy and paste it back into the system32 folder:
    C:\WINDOWS\ServicePackFiles\i386\userinit.exe

    I am not sure what the problem is with the internet icons. You are saying that ipconfig shows the proper settings, but the icons do not "work"? We may have to have you post in software for this...:confused
     
  7. billmoz

    billmoz Private E-2

    Will do on replacing the userinit.exe file in the system32 folder with the one in the i386 folder. I am guessing the other file is the right size?
    So am I 100% malware and virus free then - the hack editing my original userinit.exe file is nothing to be too concerned about?

    I will work on reinstalling the Network drivers etc to see if I can get that issue fixed separately.

    Thanks!
     
  8. billmoz

    billmoz Private E-2

    It appears that I actually have 2 userinit.exe files in my System32 folder :confused - one that was seemingly 'created' by the hack on 2/13/09 @ 4:50pm that is 22KB in size and the other which is seemingly genuine (and is an exact replica of the file in the i386 folder) that is 26KB in size, is registered to Microsoft Corp, and is version 5.1.2600.5512. So I simply renamed the hacked version and deleted it from the folder. IS that OK? I want to be sure before I reboot the system...
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry for the delay....yes, that was the right thing to do. You can get assistance if you need in the software section for your network drivers....they should be on the manufacturers website.

    Are you still having malware issues?

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  10. billmoz

    billmoz Private E-2

    Tim,

    Yes all is good now. I reinstalled the wired and wireless network connection drivers and that took care of the updating issue!

    Thanks for the help! First time being hacked like that and so a little scary on how to deal with it all...
    -Bill
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know......safe surfing. :)
     
  12. billmoz

    billmoz Private E-2

    Sorry to bother you again but I need to check quickly if I am still suffering from the hack of last week. As I told you, I have had problems with the Wired and Wireless Internet Connections which i seemingly fixed by uninstalling and reinstalling the drivers. However, the problem reappeared yesterday (ie, the icons don't update to the current connection status) and so today I decided to do a complete clean and start over (besides just uninstalling the drivers) by physically deleting the relevant SYS files in the WINDOWS\system32\DRIVERS folder. The wireless driver deletes no problem but whenever i delete the wired driver, it reappears almost immediately in the DRIVERS folder :confused. I have no experience with this but is this normal? Doesn't seem so to me so I am worried that the malware is still around doing this (for whatever reason - and I am sure it is not good!!).
    Any ideas?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  14. billmoz

    billmoz Private E-2

    Which log do I post - the sysclean.log or report.log?

    Note that the wired driver still appears after deleting even after running sysclean and that the wired and wireless connection icons still do not update. In fact the wireless connection is not working at all - i am sending this from another computer till i get the connection issue fixed.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The log from running sysclean......or both. :)

    Did you remove that file?
     
  16. billmoz

    billmoz Private E-2

    OK, I got the wireless connection working (even though i am told that it is disconnected??) and am posting the sysclean.log. Fingers crossed that it tells you what is going on here as this is very frustrating - and a little scary if indeed my connection drivers have been hacked??
     

    Attached Files:

  17. billmoz

    billmoz Private E-2

    Yes, I removed the 'stus.exe' file first. Was this linked to the bogus init.exe file that was installed by the malware?

    After deleting, I ran sysclean.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All it found was cookies...:(

    Your system is clean, so all I can think is this is a software issue. Are you using windows to configure your network? When you go to the properties for both the wired and wireless I assume they both have the check mark to show in the tray when connected?

    Yes it was connected to the fake useinit file.
     
  19. billmoz

    billmoz Private E-2

    Bummer on only finding cookies as an issue. Now what?

    OK, a search suggested using WinSockFix.exe to fix faulty network connections after cleaning up a malware infection. Is this a good idea in your opinion? I hope you know about this program...
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is only used when you can not access the internet.....which you can do. Your only problem is you are not getting an accurate icon showing when you are connected. This is something you should take up in the software forums.
     
  21. billmoz

    billmoz Private E-2

    Hi again. I just installed PC Tools Firewall Plus and found that "userinit.exe", the file that was originally hacked by the malware a week or so ago, is trying to access the internet using Symantec User Session (I have Norton AV Corporate 10 installed).
    I did a quick search and found that userinit.exe should apparently not be trying to access the internet so do i still have a problem here?
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you tell me what the file size is for that? If you have a problem with that, I will need either a new MGLogs.zip or a combo log.
     
  23. billmoz

    billmoz Private E-2

    I am guessing you are asking about the userinit.exe. file, correct? Here are the details of the file located in the system32 folder right now:
    It is 25.5KB in size, is registered to Microsoft Corp, and is version 5.1.2600.5512 (making it exactly the same when I last checked as shown in Message 8 of this thread.)
    Is the fact that it is trying to access the internet a problem then?

    Also note that when I initially installed PC Tools Firewall Plus on this PC, an error came up saying that Norton Worm Protection needed to be switched off before proceeding with the install (I ignored it and installed anyway). First, i don't have that program installed on my PC (just Symantec AV 10, Corporate Edition) and second, i did not get this message when installing the Firewall on another PC in my office here (which also has the same Symantec AV program running). This may be important...or it may be not, but I thought it could help if there is still a problem!
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well... for sp3 the file size should be :
    "C:\WINDOWS\ServicePackFiles\i386\userinit.exe" 26112

    I am not sure why you are getting this file in a reduced size or from where.

    Replace it again and disconnect from the internet and run the COmbo scan and a new MGlogs.
     
  25. billmoz

    billmoz Private E-2

    Oh, I just can't read the Property details properly. Right clicking on the userinit.exe file and selecting "Properties" gave the following data:
    Size: 25.5 KB (26,112bytes)
    Size on disk: 28.0 KB (28,672bytes)

    So it has the size that I quoted originally (25.5KB) as well as the size you expected (26,112bytes). So no problems there after all, right? :-D However, the "dates" are not the same for the 2 files...in the i386 folder, userinit.exe was created on July 18, 2008 and modified on April 13, 2008 (before it was created??) whereas in the system32 folder, it was created on August 4, 2004 and modified on April 13, 2008. Is this strange?

    And is it a problem that userinit.exe is trying to access the internet?

    I will go ahead and remove the system32 file anyways and replace with the i386 file and see what happens after rebooting (ie, does it try to access the internet again)....
     
  26. billmoz

    billmoz Private E-2

    OK then Tim. It appears that the system32/userinit.exe file is a problem as it reappears in the system32 folder as soon as I delete it. So I cannot install the i386 file in the system32 folder (even when i say overwrite the original when copying, it is still the file created in 2004 that is there!)...:confused
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then it is the right size.....and yes it should be allowed to access the internet.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds