Tried but dont work :(

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by xjennzennx, Jan 28, 2005.

  1. xjennzennx

    xjennzennx Private E-2

    Hello there i been here before and you guys do wonders...
    but sad to say got more crap on comp , well tried to clean it with your guys post and not working,, so let me know if i should show you guys my hijack log.
    and not sure what the prob is ..thanks for any help you can give...
     
  2. TheOldThug

    TheOldThug First Sergeant

    Hi

    This site has alot of good tools for cleaning up your computer. It's very important that the first thing you do is the following:

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal.
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    Try this... you may find it's all you need. If not post your results and I am sure one of the PROS can help you. These guys are quite busy, as you can see by the number of posts, so hang in there. Good Luck!! :)

    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, INCLUDING YOUR WEB BROWSER, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder for example C:\Program Files\HJT

    TheOldThug
     
  3. TheOldThug

    TheOldThug First Sergeant

  4. xjennzennx

    xjennzennx Private E-2

    Ok Tried Those And It Seems To Not Work There Are 2 This It Cant Delet, Both Are Trojans ...here Is My Hi-jack Log ..thanks Again For Anyhelp
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Read the instructions again for HJT.

    No browsers should be running. You had Internet Explorer running. You need to extract HJT from the ZIP file and put it in the directory indicated and run it from there. Also you need to post HJT logs from normal boot mode not safe mode.

    You have more problems then what you mentioned.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After fixing what I mentioned in my previous message continue with the below. Note, if you do not fix what I indicated first, you will not get any backups from HJT and thus if you make a mistake you will be unable to fix it.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).
    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\VINCE\LOCALS~1\Temp\sp.dll/sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
    O2 - BHO: IE Search Toolbar Helper - {2C5175A2-ADF3-4F57-AB70-BA90FD60A383} - C:\Program Files\IESearchToolbar\IESearchToolbar.dll
    O2 - BHO: (no name) - {D714A94F-123A-45CC-8F03-040BCAF82AD6} - C:\WINDOWS\Downloaded Program Files\SbCIe028.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O3 - Toolbar: IE Search Toolbar - {EB381422-F797-4A98-A266-9DC490821907} - C:\Program Files\IESearchToolbar\IESearchToolbar.dll
    O4 - HKLM\..\Run: [kiudwrnfobvf] C:\WINDOWS\System32\oysxth.exe
    O4 - HKLM\..\Run: [Software] C:\WINDOWS\System32\Software\software.exe
    I have to question this Bouncer entry. Do you know what it is? If not, fix it too. I wonder if it is a renamed Virtual Bouncer.
    O4 - HKLM\..\Run: [Bouncer RunStartup] C:\Program Files\Bouncer\LiveUpdate.exe 110
    O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
    O4 - HKCU\..\Run: [iyaaqgd] c:\windows\bwjuejo.exe
    O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
    O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - C:\WINDOWS\Downloaded Program Files\SbCIe028.dll
    O15 - Trusted Zone: *.awmdabest.com
    O15 - Trusted Zone: *.c4tdownload.com
    O15 - Trusted Zone: *.clickspring.net
    O15 - Trusted Zone: *.finefind.net
    O15 - Trusted Zone: *.frame.crazywinnings.com
    O15 - Trusted Zone: *.iframe.biz
    O15 - Trusted Zone: *.megapornix.com
    O15 - Trusted Zone: *.mt-download.com
    O15 - Trusted Zone: *.newiframe.biz
    O15 - Trusted Zone: *.overpro.com
    O15 - Trusted Zone: http://www.paypal.com
    O15 - Trusted Zone: *.pizdato.biz
    O15 - Trusted Zone: *.slotch.com
    O15 - Trusted Zone: *.sp2admin.biz
    O15 - Trusted Zone: *.sp2****ed.biz
    O15 - Trusted Zone: *.vse-moe.biz
    O15 - Trusted Zone: *.windupdates.com
    O15 - Trusted Zone: *.ysbweb.com
    O15 - Trusted Zone: *.awmdabest.com (HKLM)
    O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
    O15 - Trusted IP range: 206.161.125.149
    O15 - Trusted IP range: 206.161.125.149 (HKLM)
    O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://c:\nosuch.mht!http://spy-ware-soft.com/freecounter.chm::/test.exe
    O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://www.sidestep.com/get/k42037/sb028.cab
    O16 - DPF: {666DDE35-E955-11D0-A707-000000521958} - http://69.56.176.227/webplugin.cab
    O23 - Service: ISEXEng - Unknown - C:\WINDOWS\System32\angelex.exe (file missing)

    After clicking Fix, exit HJT. Some of the above O15 entries will probably come back. We get them on the next pass with another procedure.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\IESearchToolbar <--- delete the whole folder
    C:\WINDOWS\System32\Software <--- delete the whole folder
    C:\Program Files\Bouncer <--- if you fixed the entry above them delete the whole folder.
    C:\WINDOWS\System32\oysxth.exe
    c:\windows\bwjuejo.exe
    C:\WINDOWS\System32\spoolsrv32.exe
    This next file (C:\WINDOWS\Downloaded Program Files\SbCIe028.dll) cannot be found using Windows Explorer because of where it is located. So we need to use a special procedure to delete SbCIe028.dll:
    - Click Start, Run, and enter cmd in the box and click OK. This opens a commend prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s SbCIe028.dll
    del SbCIe028.dll
    exit

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  7. xjennzennx

    xjennzennx Private E-2

    yea things seem to be better just want to know i still keep getting a po up on the desk top seems to be from windows . saying it detects spayware and there is no spyware protection on my pc.. also a icon on my toolbar on the bottom sasys the same thing , when playing online games it some time drops my screen to the desktop . other than that i think its fine ...
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you forget to shut Internet Explorer down again?
    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    You must always exit browsers before using HijackThis. Not doing so can affect the ability to fix items properly.

    Did you forget to fix the below items last time or did you have a problem with finding the files and deleting them:

    O4 - HKLM\..\Run: [Bouncer RunStartup] C:\Program Files\Bouncer\liveupdate.exe 110
    O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
    O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe

    They are still in your HJT log now.

    If order to help me help you, you must provide feedback on the instructions and you must answer questions. Remember I cannot see what happens at your end. You need to tell me if things work or if they do not work.

    I had asked about the Bouncer stuff. Do you know what it is? I'm still assuming it is bad.
     
    Last edited: Jan 30, 2005
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First let's fix the crazywinnings problem:

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file move.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.)
    Double-click on the move.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes.


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).

    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search21.thesearchs.com/search.html
    O4 - HKLM\..\Run: [Bouncer RunStartup] C:\Program Files\Bouncer\liveupdate.exe 110
    O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
    O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\Bouncer <--- if you fixed the entry above them delete the whole folder.
    C:\WINDOWS\System32\spoolsrv32.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
    Last edited: Jan 30, 2005
  10. xjennzennx

    xjennzennx Private E-2

    Yea those bouncer file i could not remove ...not sure how to stop running explorer am dont see it running ..i wil try to remove the crazy winning thing now.. i let you know thx for the help again..
     
  11. xjennzennx

    xjennzennx Private E-2

    also my notepad is not responding..i got wordpad but not sure if that will work..
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, you can use Wordpad. But when you save it, you must change the Save as type to Text Document. And then change the filename to move.reg.

    You will get another prompt about saving a text document. Just say yes.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    SO I guess that means you do not know what it is for?

    Can you right click on the liveupdate.exe file and get Properties, Version info?
     
  14. xjennzennx

    xjennzennx Private E-2

    ok did all that you said to do think all worked but the Bouncer one thats not going away..
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Exactly what are you doing! This log is from

    Logfile of HijackThis v1.98.2
    Scan saved at 6:47:10 PM, on 8/25/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)



    So what is it that you are trying to do here.
     
  16. xjennzennx

    xjennzennx Private E-2

    not sure what happened ..sorry dont know a whole lot about computers just very basic stuff.. i think this is newest log..
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now you are running HJT from the ZIP file again. We had this all fixed by even back in message # 7. What did you do to the proper HJT that was:

    C:\Program Files\hijackthis\HijackThis.exe
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why is savedump.exe running now? This was not running earlier. Exactly what have you been doing.
    C:\WINDOWS\system32\savedump.exe

    You need to do the following because I think they are conflicting with each other and blocking some changes.
    Goto Add/Remove programs and uninstall all of the below (if installed - some I can see are)
    - SpywareGuard
    - SpyBlocker
    - Spybot S&D
    - SpywareBlaster
    - Spykiller <--- this is junk anyway
    - BestPopUpKill <--- this is junk anyway
    - Bouncer <--- see if there is anything like this in add/remove programs. It may be called VIrtualBouncer

    Then reboot and post a new HJT log that is properly installed.

    Please look on your system for C:\Program Files\Bouncer\liveupdate.exe
    Can you see this folder and file?
     
  19. xjennzennx

    xjennzennx Private E-2

    ok i removed what i could ...here the log
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are these still in your log:

    O4 - HKLM\..\Run: [SpyBlocker] C:\Program Files\SpyBlocker Software\spyblocker.exe
    O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
    O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup

    Is it because there was no uninstall in Add/Remove programs? If so, exit all browsers and have HJT fix those entries. Then reboot in to safe mode and delete:

    C:\Program Files\SpyBlocker Software <--- the whole folder
    C:\Program Files\SpyKiller <--- the whole folder
    C:\Program Files\BestPopUpKiller <--- the whole folder

    Then reboot in normal mode and post a new HJT log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds