Apparent SHeur2 or gadmon issue

Discussion in 'Malware Help (A Specialist Will Reply)' started by BlueMax, Dec 21, 2008.

  1. BlueMax

    BlueMax Private E-2

    Hello, and thanks in advance for any help you can provide. This takes a little exposition since I only have one file to attach. Friday I got a spontaneous IE popup, which is odd since I don't use IE on the machine. I updated spybot S&D which had been installed, and ran - no issues. I did a full AVG scan - 3 instances of what was called SHeur2.GAS indicated as removed. Windows had updates ready to install but not yet installed. I hit install for those. Then things got weird. Couldn't get back to windows update page, AVG stopped updating and said it couldn't find the server. Couldn't get to majorgeeks.com, and we're off. A friend tried some stuff, but to no avail. I did some checking here and at other sites on a different computer, and it appears that the files that may be causing the problems are gadcom.exe and csrssc.exe, which I can't get rid of.

    Next, I got to here and went through the steps in read and run me first. Everything completed that could be completed, with explanations for things not completed:
    1. sun java 1.6 v7 won't uninstall, sun java 1.6 v11 won't install
    2. SUPERAntispyware won't install
    3. spybot was already installed - now it won't run or reinstall
    4. malwarebytes was installed in safemode - won't install in regular and won't run in regular
    5. combofix won't install - tried the error correction stuff to no avail

    Good news (if there is any) is that MGTools installed and ran, resulting in the attached log. During running it, a note does pop up that registry editing has been disabled by the administrator - but the account I'm using is an admin account with all rights and privileges. I ran it a few times. Posting all from a different computer, as the other one won't go to any site that might appear to offer help.

    Thanks in advance for any help you can offer.
     

    Attached Files:

  2. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    Run c:\mgtools\analyse.exe

    remove theese lines:

    O2 - BHO: C:\WINDOWS\system32\tyshb36rfjdf.dll - {D5BF49A2-94F1-42BD-F434-3604812C807D} - C:\WINDOWS\system32\tyshb36rfjdf.dll

    O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)

    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

    See if the programs will install for you then.
     
  3. BlueMax

    BlueMax Private E-2

    Thanks for the response. I had been browsing the forum for similar issues on installing the software, and I apologize for going off the program, but I followed these instructions in an earlier attempt to get the apps installed:
    After reboot, AVG immediately popped up with the resident shield - after I turned that off, I attempted to install the programs. All installed correctly except SuperAntiSpyware. The various scans (and Spybot S&D) appear to have caught and fixed Simtfraud-c, gadmon, SHeur2, and some others. I have those logs and will attach if you want, but here are the latest logs from all but SuperAntiSpyware.

    Tonight, I followed your analyse.exe instructions - only finding the O3 toolbar entry - the other two were not there. SAS still doesn't install. The attached logs are run after the removal of that. Computer appears otherwise to be running well.

    One more note - still cannot uninstall JRE 1.6 v 7 - get the transform failure and have been unable to take care of it. Also, JRE 1.6 v 11 still won't install - get error 25099.

    Thanks again. You guys are computer savers.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You appear to be in pretty good shape now. We have a few minor things to do.

    See if you can uninstall the old version with the below:

    Your Uninstaller! 2008


    Now reboot your PC.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. BlueMax

    BlueMax Private E-2

    Thanks again.

    Have successfully uninstalled Java old version and successfully installed v11.

    Ran the fixme.reg and got a note that it had been successfully performed.

    Ran ccleaner.

    Ran the wrong MGtools (ran MGtools.exe - sorry, had closed browser and messed that up). Re-ran mgtools\getlogs.bat.

    Computer appears to be running well with no issues.

    Log attached.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  7. BlueMax

    BlueMax Private E-2

    Big thanks to Corporal Punishment, who deserves a promotion, and to chaslang.

    No further problems evident. Will follow final steps.
     
  8. BlueMax

    BlueMax Private E-2

    In following the final steps, I cannot seem to find any way to get to system restore. It's not where the clean guide says it should be, and it's not where Windows XP says it will be. Any thoughts?

    Thanks
     
  9. BlueMax

    BlueMax Private E-2

    All is now taken care of - after a reboot into safe mode, then a regular reboot, I was able to disable and reenable system restore.

    Thanks again!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Glad to hear you go it worked out.

    You're welcome. Surf safely!
     
  11. BlueMax

    BlueMax Private E-2

    Sorry to be back, but I'm having another issue. I had Adobe Acrobat Reader installed on the system before all this and I could view pdf files. Now, I can't. The Adobe folder is gone. I downloaded the Adobe Reader 9.0 installer, and when I attempt to install, I get Windows error 1303.

    System is Windows XP Home Edition SP3

    I tried booting into safe mode to install, logged in as Administrator, and get the message that the Administrator has set privileges that do not allow installation.

    Could something done in the removal of malware, or by the malware itself, broken the installation privileges? The user account is also listed as an Adminstrator.

    Any suggestions? Thanks in advance.
     
  12. BlueMax

    BlueMax Private E-2

    Also, Windows critical updates labeled Microsoft .NET Framework 2.0 Service Pack 1 and Microsoft .NET Framework 3.0 Service Pack 1 will not install.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry but this has nothing to do with malware and nothing to do with the cleaning procedure. Your first logs showed that you did not even have Acrobat Reader installed when you came here.

    Also they showed you already had the .NET Framework software installed. Notice there were only two Adobe Flash Player items and no Adobe Reader and also notice all of the .NET Framework software listed.

    The below were all in your MGlogs.zip file in the newfiles.txt log.

    "DisplayName"="Adobe Flash Player 10 Plugin"
    "DisplayName"="Adobe Flash Player ActiveX"
    "DisplayName"="Microsoft .NET Framework 1.1 Hotfix (KB928366)"
    "DisplayName"="Microsoft .NET Framework 1.1"
    "DisplayName"="Microsoft .NET Framework 2.0"
    "DisplayName"="Microsoft .NET Framework 3.0"

    If you are having problems with installing software and getting a 1303 error, it may relate to a permissions error. You could try running the below, but any additional questions/support for these problems is better suited for the Software Forum:

    Run this Resetting Registry and File Permissions and then reboot and see if you can install your programs.
     
  14. BlueMax

    BlueMax Private E-2

    Thanks. I must have had a browser plug-in that allowed me to look at pdf files. Couldn't install the subinacl file but rooted around the software forum and found steps for taking ownership of folders, then assigning permissions. Turns out the administrators account didn't have ownership of the Program Files folder - tough to install without that. Took ownership and re-applied permissions, and all works.

    Thanks, and I'll quit bugging you.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds