SY.EXE giving me trouble

Discussion in 'Malware Help (A Specialist Will Reply)' started by JimWolf, Nov 30, 2007.

  1. JimWolf

    JimWolf Private E-2

    About two or three days ago my computer started giving me low virtual memory warnings when nothing was running. Checked the task manager and it showed a new process called sy.exe. It wouldn't let me end the process, so I did a search for it on the C: drive. Found it in C:\WINNT\SYSTEM32\CONFIG.
    Ever since my last virus, I've been running an old, free copy of Sygate Personal Firewall. I checked its logs, and this program (I think) has been trying to connect to daytimelife.com. Ran a WHOIS on the name and it's a site out of China.
    I ran HijackThis to see what was going on, and also found a file called alexamw.exe on my C: drive, which I deleted.
    While searching for ways to get rid of the sy.exe, I came across this site, and ran the cleaning tools recommended in the FAQ. None of them found anything.
    Tried booting to safe mode, and that way I was able to get SY out of the system32\config directory. The virtual memory problem seems to have cleared up, but Windows is STILL trying to connect to daytimelife.com. I suspect there's a lot of stuff in the registry, but editing that scares me, so I come to you folks. Can anyone help me?
    Logs enclosed.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    First we need to remove a bunch of malware services. Make sure when you do the below that you only stop disable (and later delete) the EXACT services given. One of them in particular named Remote Procedure Call (RPC) Remote was designed to trick you. There are two similarly named services that are valid. So again I repeat, you must make sure you choose the one that match what is in my procedure exactly.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to irsriis
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • Iusr_sys
      • radsrver
      • Remote Procedure Call (RPC) Remote
      • Snake SockProxy Service
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste RpcRemote into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • SkServer
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
     
    Last edited: Nov 30, 2007
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay here is the continuation from message # 2. Make sure you complete message # 2 before doing the below.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 1
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_01
    Spybot - Search & Destroy 1.3 <-- this version is 3 years out of date and is not what we gave in the READ ME


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Startup: PowerReg SchedulerV2.exe

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot, now install the current version of Sun Java from: Sun Java Runtime
    Environment


    Now install the correct version of SpyBot - Search & Destroy and install as instructed here: Spybot S&D Installing & Running


    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  4. JimWolf

    JimWolf Private E-2

    Ok, did all that. All the services you listed in services.msc were already stopped, so I disabled them and moved on. Couldn't find TCP and UDP support in the list.
    In HJT, SkServer says it's still running and can't be deleted.

    Also, I said the memory problem was gone, but I was wrong. Still slowly filling up.
     
  5. JimWolf

    JimWolf Private E-2

    Thank you for all the help. It's going to be a while before I can give you the results. I'm on a slow rural dial-up, and having connectivity problems as well. Currently, I'm connected at 16.8. Java will take almose 3 hours to download, plus another 90+ minutes for SpyBot.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This was a mistake that I forgot to edit out. Go back and run those steps from my first message again. I edited them to change the TCP reference to Snake SockProxy Service

    After stopping and disabling it, you should be able to delete the SkServer service.

    Then continue on to my second set of steps.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can download these programs at a later time. The most important thing is to remove all the old versions and get your malware fixed. You will have to download Avenger and ATF-cleaner though as they are important in removing the malware. They are small compared to Java and Spybot.
     
  8. JimWolf

    JimWolf Private E-2

    Got all the programs listed. In ATF, the Firefox menu is greyed out. Could it be because I have it installed on a different drive than C:?

    Anyway, here are the logs. This is the second run of Avenger, so it's full of "couldn't find xxxx file" errors.

    All seems to be running well, now. The memory problem seems to be gone, but I'll wait a while before saying for certain, and my computer has stopped trying to contact China.

    On a related note, Sygate Personal Firewall has started crashing on me. Can you recomment a good, free software firewall to replace it?
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Possibly but I'm not sure.

    A link in my final instructions will give you a list of many recommended free tools including firewalls.

    Delete the below files if they still exist:
    C:\Documents and Settings\Jim\Local Settings\Temp\c8y4ef3g.exe
    C:\Documents and Settings\Jim\Local Settings\Temp\spt14.tmp
    C:\Documents and Settings\Jim\Local Settings\Temp\vllm1ccf.exe

    Then empty your Recycle Bin.


    Your logs are clean other than the above. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  10. JimWolf

    JimWolf Private E-2

    Ok, the memory problem is most certainly gone. :) But a new issue has popped up. Possibly related to the virus and all the files I deleted to get rid of it, not sure. Dialling in to my ISP used to go pretty quick, and the 'Registering your computer on the network...' message used to pass faster than I could read it, but now it's there for about 20 seconds and it seems to use 100% of the CPU.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps you need to reinstall whatever software is required to connect to your ISP.
     
  12. JimWolf

    JimWolf Private E-2

    I use the default dial-up networking software that comes with Windows 2000. Can I reinstall that without doing a whole Windows reinstall?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we defintely did not delete anything related to that so I'm not sure where your problems are at. Are you actually on dialup or are you on DSL? Did you change firewalls like you said you wanted to? Did you allow the appropriate processes to have access thru your new firewall?
     
  14. JimWolf

    JimWolf Private E-2

    I'm on actual dial-up, using the same firewall I had before. Could these problems be caused by line noise? I am having an issue with static on the line at the moment.
     
  15. JimWolf

    JimWolf Private E-2

    It also acts a little odd when hanging up. I hear the modem click as it disconnects, and the networking icon stays on the toolbar for about 15 seconds. Also seems to use a bit of CPU time.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Line noise can slow down the ability of the software to detect an actual connection and also disconnection. Thus causing the software to take longer on all operations. Not sure what effect it would have on CPU useage but the program will take longer to complete operations thus requiring more CPU time. Whether this is really total problem or not is unknown.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds