Spyware: anything has failed!!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Aleph, Sep 25, 2004.

  1. Aleph

    Aleph Private E-2

    Hi to everyone,
    I'm writing 'cause I think I've done all that was in my possibility to eradicate that son of a spyware which is dwelling in my computer...

    I used the Trend Micro's online scan as you said and now it says it's clean, though I was not able to use also the Synabtec in safe mod, I think the spyware blocks it in some way...

    Than I started CCleaner, Ad Aware with plug in for VX2, Spybot, CW Shredder, Kill2me, about:Buster, HS remove, spyware Blaster, I even used the trial of Spy Sweeper, and it found even more things...

    Then I Hijacked and delete from the log things that seemed dangerous...

    Now I still get that when I open the IE, whichever in the URL I put in, it tries to go to http://a-search.biz/?wmid=1010 and sometims a little window shows up saying no modem found...

    I did everything you said, the only thing I wasn't able to do was the part of services.msc, 'cause I'm from Italy and I don't know which would be the EXACT translation for RCP or the other running object and since you said to stop only those, I preferred not to do stop anything...

    So please, give me any advice, I'm working on this since a week, some more days and I'll be flamethrowing my case...
    Thanks

    PS By the way, doing the process in safe mode again always bring ADware and Spybot finding some new spyware...
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Running About:Buster, HSremove and looking for those services (NSS, WNS, or RPC Helper) are only necessary if you have About:Blank or HSA hijack problems.

    What exactly do you delete using HijackThis? If you don't know what your doing, using HijackThis to delete items can be dangerous. You should post your HijackThis log as a .txt file attachment.
     
  3. Aleph

    Aleph Private E-2

    Here is my last Hijack Scan called "now"; the old one is "oldall" and has got all the lines before my fixing...

    Thank you for your help
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have viewing of hidden files enabled.

    When running HijackThis (scanning and espcially fixing) do not have any browsers open. You had 4 open in your now.txt log.

    Use Add/Remove Programs and uninstall SyncroAd, if that does not work then fix the line in your HJT log.

    Unless you know that the gam.exe and xss.exe processes are legitimate, follow the below steps to kill and remove them.

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below process and End it:
    gam.exe
    xss.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [golumm] C:\WINDOWS\System32\golumm\services.exe
    O4 - HKCU\..\Run: [sysinit] C:\WINDOWS\System32\golumm\services.exe
    O15 - Trusted Zone: *.windupdates.com

    Boot in safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\Donald\gam.exe
    C:\Documents and Settings\Donald\xss.exe
    C:\WINDOWS\System32\golumm\services.exe
     
  5. Aleph

    Aleph Private E-2

    Hi Chaslang,
    sorry if I didn't answer before, but yesterday has been a really hard work' day...

    I did al that you said, but my problen still seems to be there, id est when I start I.E. it's redirected from my homepage to http://a-search.biz/?wmid=1010 and then tries to load "sextracker" or something like that, but I stop it immediately...

    The name of the window is "about: blank Trusted Start Page Microsoft Explorer - Microsoft Internet Explorer": any idea?

    Thank you in advance
     
  6. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Chaslang,
    Did you see the Syncroad lines? Aleph, try removing these, I would check add\remove programs for anything you didnt install as well. I am reading from your previous Hijack This log above so also check the R0 and R1 sections for the hijack links and remove those.

    C:\Program Files\Windows SyncroAd\SyncroAd.exe
    C:\Program Files\Windows SyncroAd\WinSync.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    Collegamenti
     
  7. Aleph

    Aleph Private E-2

    Greetings Major,
    I hope not to create problems, but I'd like to attach my new Hijack log, so you can have a look about what is going on...

    It seems to me there are no more "strange" lines (apart from those 4 on svchost.exe, all the same, but repetead four times...), but the problem still lingers there...

    Now I've updated my OS to SP2, but nothing has changed, the only event is that I had to shut down Zone Alarm or I wouldn't be able to surf the net...

    Thank you again
     

    Attached Files:

    • new.txt
      File size:
      4.7 KB
      Views:
      7
  8. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Did you remove the lines I asked you to?
     
  9. Aleph

    Aleph Private E-2

    Yes Mayor,
    I used the control panel to uninstall WinAD, then the lines disappeared as well...
    The strange thing is always svchost.exe: now I have 5 files with the same name running, one more then before and two of them are of Netsystem (the better translation I could give for "Sistema di Rete")... if I HijackThis in safe mode, there would be only two of them running...
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I did MA. My previous message said,
    "Use Add/Remove Programs and uninstall SyncroAd, if that does not work then fix the line in your HJT log."

    As far as I know Add/Remove programs does remove them.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log looks fine now. Those svchost.exe processes are normal Windows processes. There are almost always 2 to 5 of them running. (My system has 5 right now.)
     
  12. Aleph

    Aleph Private E-2

    Hi Chaslang,
    I think that my log now looks fine too, but the problem's still there, I.E. is redirected to that page and I've not found a way to stop this... could it be the RCP problem?

    Thanks
     
  13. Aleph

    Aleph Private E-2

    One thing I forgot to say: if I hit the start button and click on Search, the toolbar on the bottom on the screen freeze... and nothing else happen!!!
     
  14. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Make sure its gone from add\remove programs and startup. You should always check your C:\ProgramFiles directory, directories are always left behind.
     
  15. Aleph

    Aleph Private E-2

    I manage to kill it!!!
    With today's update from Norton the antivirus recognize a Trojan start page file: I couldn't delete it even in safe mode, so I used Hijack this to kill the .dll on the next start up!

    Thank you very much for everything, finally my computer is clean!!! :) :) :)
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! I'm happy it all worked out. Do you remember the name of the DLL file?
     
  17. Aleph

    Aleph Private E-2

    I'm not very sure, it started with "ENR" and than there were Q B and some other letters, but I cannot remember the right order... sorry, I didn't think it was important...

    Later I'll look on the other computer to see if Hijack has keep some record of it, bye!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's nice to know for future reference with similar issues. HijackThis does save backups of items fixed using it, but I'm I don't think it does this file file deleted upon reboot (it would not make sense since the goal is to delete it).
     
  19. Aleph

    Aleph Private E-2

    I know that, what I wanted to say was that I was going to look for a log or something like that; I didn't find it in Hijack, but Norton has it and I was able to get the name of the DLL: enrlkqbb.dll !!!

    Well, I said "ENR" than Q and B and some other but I didn't remembre the order: not a photografic memory, but perhaps a 0.5 megapixel would do a worse job... ;)

    Bye and thanks again!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did Norton give you any other info about the problem file? Or did they just say "Trojan start page"? Nothing more specific?
     
  21. Aleph

    Aleph Private E-2

    Here I am!
    I'm sory Chaslang, but Norton didn't give any additional information, it only says "Trojan start page"...

    It also found another file the same day, which was twink64.exe, but again the description was the same.

    Bye
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Aleph,

    Thanks for coming back with that info. Just a note for you on twink64.exe. twink64.exe is not a Trojan start page. It is a Troj/Dloader-BW. Here is its description:
    Attempts to download and execute EXE files from remote websites to the Windows system folder as intron.exe, ir.exe, lpt.exe and usb.exe.
    Copies itself to the Windows system folder as twink64.exe and creates the following registry entry to run itself on system logon:
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ControlPanel = \twink64.exe internat.dll,LoadKeyboardProfile
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds