need help with VX2 / Look2Me

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by alvermin, Sep 1, 2005.

  1. alvermin

    alvermin Private E-2

    I have been experiencing a lot of pop-ups as well as stalling of surfing. I followed all steps in the "read me first before posting for help" forum. The CWShredder and Kill2me keeps finding the Look2Me, but it never goes away. My Norton anti-virus also keeps finding but can't delete all the files. My Adaware add-on says it finds a new VX2 variant but cannot clean it. I followed the other similar post and have posted my HJT log as well as my l2mfix log.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not complete the steps in the READ ME FIRST. For example, you never ran the online scanners (step 1 of the cleanup).

    Since you seem to already have L2MeFix and have already run Option 1, now run option 2 to have it run the fix. Post the log from this too.

    Your HJT log shows other problems with WinSync. FInish running the READ ME FIRST and the L2MeFix option 2 and then post a new HJT log.

    Then continue onto the steps below.



    1 - Please EXTRACT all files from Qoologic Tool to its own folder - C:\Program Files\QoologicFinder . Then, DoubleClick Find-Qoologic.bat to run the tool. It should produce a log - Please attach that with your next post!

    2 - Please EXTRACT all the files form RKFiles Tool to its own folder named C:\Program Files\RKTOOL. Then, Please boot to SAFE MODE and DoubleClick rkfiles.bat to run the tool. Let it run and then, when it finishes, look for a log at C:\Log.txt and please attach that log.

    Now come back here and post both logs as attachments. You will need to post these in a second message.
     
  3. alvermin

    alvermin Private E-2

    sorry about that. I did actually run the Bitdefender and RAVantivirus online scans, but later deleted them with HJT. I am currently running them again. then I will repost logs.

    thanks
     
  4. alvermin

    alvermin Private E-2

    ok, i have finished running:
    bitdefender
    ravantivirus
    stinger
    ccleaner
    adaware
    spybot
    cwshredder
    kill2me
    l2mfix
    HJT

    I have attached the l2mfix log that was created during the step 2 fix
    I have also attached the new HJT log

    I will now go back and follow the instructions for the Qoologic tools and RKFiles tool and then post those reports

    thanks
     

    Attached Files:

  5. alvermin

    alvermin Private E-2

    ok, i have finished the two additional steps of qoologic and rktools and i have attached the logs of each. i now have to go off to work for the rest of the day. i will check board and continue as soon as i get back home.

    thanks
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download Pocket KillBox

    Next, you will be entering items into Pocket KillBox. Please select the “Delete on Reboot” Option. Copy&Paste each of the file names listed below at the bottom of this message into the box one by one, making sure Delete on Reboot is Checked for each entry. Click the Red X for each entry, but when asked if you want to Reboot say No. Keep saying no to reboot until you enter the final file then say Yes!

    ** Note: For any of the .dll files, check the Unregister .dll Before Deleting box as well. If this option is not enabled, don't worry about it just continue.

    Also note: If you get an error message about Pending Operations after saying yes to reboot, just reboot your computer manually.

    C:\WINDOWS\ICONT.EXE
    C:\WINDOWS\SYSTEM32\bH.dll
    C:\WINDOWS\SYSTEM32\LSSSD4.EXE
    C:\WINDOWS\SYSTEM32\BDMDQRM.EXE
    C:\WINDOWS\SYSTEM32\JEAEK.DLL
    C:\WINDOWS\SYSTEM32\SFSFDKS.DLL
    C:\WINDOWS\SYSTEM32\PWKWY.DAT
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nrir.exe


    After reboot post a new HJT log and let me know how these steps went and how things are working.
     
  7. alvermin

    alvermin Private E-2

    I finished the steps with Pocket KillBox and have attached the new HJT log below. I noticed that the winsync lsssd4.exe is still listed. Will stay on and surf awhile to see how pop-ups and stalling are acting.

    thanks
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's continue.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to Command Service (or if not found look for cmdService) ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, go back to HJT and select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Command Service

    If that does not work try entering the short name: cmdService

    Now exit HJT but do not reboot if it tells you one is needed. We will be restarting HJT again in a few lines.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\lsssd4.exe reg_run
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O15 - Trusted Zone: *.musicmatch.com
    O15 - Trusted Zone: *.musicmatch.com (HKLM)
    O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\YWwA\command.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\lsssd4.exe
    C:\WINDOWS\YWwA\command.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  9. alvermin

    alvermin Private E-2

    Finished those steps and have attached HJT log. Couple things I noticed along the way:

    Command Service was already stopped (when using Services.msc)
    Command service line was not present during the first HJT fix
    neither lsssd4.exe nor command.exe were found during safe boot (i ran a file search).

    Hopefully those are good points to find.

    Not been getting many pop-ups, but have experienced some stalling while surfing. I will monitor now that I have done these last few steps.

    thanks for all your time and effort

    al
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is now clean!

    Are you really still having popup problems?

    If so, what do they say? Is there a URL? When do you get them? Is it only when connected to certain sites?
     
  11. alvermin

    alvermin Private E-2

    Haven't had pop-ups since the last fixes.

    Great to hear the log is clean!!

    Thanks for the awesome assistance
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    That's great news. Now to help keep you clean, follow the steps in the below thread:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds