Please help...i believe I have an anti spy spider..how can i get rid of it??!?!

Discussion in 'Malware Help (A Specialist Will Reply)' started by maxdreamer, Apr 27, 2008.

  1. maxdreamer

    maxdreamer Private E-2

    I dont know how this happened.

    All of a sudden, my background turned all red. I get pop up stating "Your privacy settings are compromised. It is highly recommended to instal antyspyware solution".

    When I exit out of it, an internet window pops up this this anti virus site。

    On the bottom right corner, there are icons that state that my computer is running slowly due to malware activity, and it directs me to the same website。

    When i try to enter “ctrl, alt, del“ it states that it is disabled by administrator。

    How can i fix this? ANyone with any experience with this problem?!?!

    I tried running scans thru AVG, Adware, F-secure and they cant seem to get rid of it。。

    this is driving me insane:crybaby
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. maxdreamer

    maxdreamer Private E-2

    help!

    When i perform a scan with Superantispyware, during the middle of the scanning process a blue screen pops up. This screen states that a problem has been detected and windows has been shut down to prevent damage to your computer.

    PAGE_FAULT_IN_NONPAGED_AREA.

    So i restart my computer and performed the scan again. During the middle of the process, this blue screen appeared again.

    What does this mean?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please try the below doing the below.

    Run SuperAntiSpyware

    • In SUPERAntiSpyware under Configuration and Preferences, click the Preferences button.
    • Click the Scanning Control tab.
    • Under Scanner Options uncheck the below two options
      • Use Kernel Direct File Access (recommended)
      • Use Kernel Direct Registry Access (recommended)
    • Then try doing a new full scan and tell me if it still crashes. And if it does still crash, just skip SUPERAntispyware and continue with the other instructions.
     
  5. maxdreamer

    maxdreamer Private E-2

    Thanks, i was able to perform the scan after i made those changes. I saved the log, but i got to go thru the next few steps.
     
  6. maxdreamer

    maxdreamer Private E-2

    I finally finished the "Read and run me first" thread.
    I have attached the logs, but i was only able to attach 3 of the logs. I wasnt able to attach the log for MGtools. How can i attach that one?

    The background is still red. But i havent gotten any pop ups and my "ctr alt del" now works!

    Does that mean everything is fixed?

    Once again, thank you for your help!


    LOGS-
     

    Attached Files:

    Last edited by a moderator: Apr 30, 2008
  7. maxdreamer

    maxdreamer Private E-2

    Here is the log for MGTools.


    Thanks
     

    Attached Files:

    Last edited by a moderator: Apr 30, 2008
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In order for us to continue, your must go back to step 1 of the READ ME and put your system into Normal Startup mode using MSconfig. You must remain in Normal Startup. Then you need to attach a new log from MGtools.
     
  9. maxdreamer

    maxdreamer Private E-2

    Hopefully i did this correctly...

    i have attached a new MGtools log.
     

    Attached Files:

    Last edited by a moderator: Apr 30, 2008
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: StFlex IE Helper - {8334A30C-49E5-489a-B63D-5B927C1EF46E} - C:\Program Files\QdrDrive\QdrDrive15.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [Sonic RecordNow!] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
    O20 - Winlogon Notify: khfCuTJc - khfCuTJc.dll (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. maxdreamer

    maxdreamer Private E-2

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we are almost finished. Now that we got a rootkit removed, a couple of other things have to be fixed.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    After reboot, find the fixME.reg patch you made last time and double click on it again to allow it to be added to the registry.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. maxdreamer

    maxdreamer Private E-2

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you create the below files?

    2008-04-27 09:32 . 2008-04-28 17:53 29,184 --a------ C:\WINDOWS\system32\clbdll.0ll
    2008-04-27 09:32 . 2008-04-27 09:39 28,160 --a------ C:\WINDOWS\system32\clbdll.old

    Please delete them. Let me know if you have any problems getting them deleted.
     
  15. maxdreamer

    maxdreamer Private E-2

    what are those files? I didnt create anything. How do i delete those?..thanks!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use Windows Explorer to navigate to them and delete them.

    Right click Start and select Explorer to open Windows Explorer. Then work your way down to the C:\Windows\System32 folder and look for those files. When found, right click on them and select Delete. Only delete those exact file names if found. Do not delete anything else!
     
  17. maxdreamer

    maxdreamer Private E-2

    ok..i was able to delete both of those files...and i emptied the recycle bin.

    What do you think?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  19. maxdreamer

    maxdreamer Private E-2

    Everything seems to be working fine, i will install some of the recommended programs from the final step.

    I REALLLY APPRECIATE YOUR HELP!!! thanks a million!!:highfive
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    However, I would like to check something else out just to be on the safe side. Abri questioned the explorer.exe showing in your ComboFix log after I had you remove the rootkit. It showed like the below:
    From what I could tell your explorer.exe process was the valid file with the correct date and size. However now I'm wondering if something may have attached itself to your explorer.exe file in the form of an Alternate Data Stream (ADS). If you have not uninstalled SUPERAntiSpyware, run it and click the Preferences tab, and then under the Scanning Control tab make sure that Scan Alternate Data Streams is checked. Then click Close and then on the main screen select Scan your Computer . On the next form make sure that you select Perform a complete scan Then click Next and let it scan. This can take awhile. When it finishes, attach the new log.

    And if you already uninstall SUPERAntiSpyware, please redownload the new version just release today and reinstall and complete the above steps.

    Also I would like you to run the below and attach the log from GMER:

    Running GMER to detect rootkits
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds