Pesky Spyware won't go away, XP

Discussion in 'Malware Help (A Specialist Will Reply)' started by Blade897, Jan 5, 2013.

  1. Blade897

    Blade897 Private First Class

    Hi all I am having some difficulty getting rid of some spyware that has been infecting my computer. I have MalwareBytes and that has been blocking many of the popups that have came with this software to various and strange websites. Also concerning is that sometimes I get emails disguised as people I regularly contact directing me to random links to buy products. I am attaching log files of all the spyware programs I have run. Hopefully this elucidates the problem. Thanks very much for taking the time to help.
     

    Attached Files:

  2. Blade897

    Blade897 Private First Class

    Also, I have done these scans.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please click Start, Run and copy and paste the below into the run box and click OK:

    C:\DOCUME~1\ALLUSE~1\APPLIC~1\TARMAI~1\{889DF~1\Setup.exe /remove /q

    Then do the same thing with the below string:

    MsiExec.exe /X{86D4B82A-ABED-442A-BE86-96357B70F4FE}

    Now rerun a scan with Hitman Pro and attach the new log.
     
  4. Blade897

    Blade897 Private First Class

    Thanks for the reply Chaslang as usual.

    The first file you wanted me to remove, wouldn't work using the specified path, but I was able to locate that file and delete it myself, I also cleared the recycle bin.

    Attached is the new log
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wrong thing to do! I did not ask you to do this. This is the uninstaller program. Now you deleted it and we cannot uninstall it.

    From the READ & RUN ME instructions
     
  6. Blade897

    Blade897 Private First Class

    Apologies, I thought /remove did the same thing as any kind of delete, but now I know.

    In an effort not to go out on a limb again, what steps should I take from now? I am currently running a scan to see if I can retrieve the deleted file using ParetoLogic Data Recovery. But If I cannot find it, I can also try restoring the file via periodical backups I create. Is this something I should be doing, or is there perhaps another way to uninstall the malicious software?

    Thanks.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Deleting does not equal uninstalling. ;) And all you did was delete the uninstaller program and nothing else.

    Only do what I ask you to as stated.

    Again! You are doing something not requested. Please don't. I will post follow up manual instructions when I can work them up.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I also just noticed that you are using a version of MGtools that is more than 1 year out of date! Why? Old versions should be removed when you finish cleanup and you are always supposed to be downloading what we ask you to download in the READ & RUN ME. Don't change it now. Just follow my instructions and we will take care of this too. For our procedures to work reliably (including final instructions) you need to follow our instructions properly. Note, putting things we have you download in folders like below:

    C:\Documents and Settings\Daniel\My Documents\Downloads\HitmanPro.exe
    C:\Documents and Settings\Daniel\My Documents\Downloads\MGtools.exe

    Is not what we requested and will cause our procedures not to work
     
  9. Blade897

    Blade897 Private First Class

    I have all ceased activity on that machine! Your wish is now my command. Thanks very much for your time and help.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    :-D

    Uninstall the below old versions of software:
    Java(TM) 6 Update 33

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    After clicking Fix, exit HJT.

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\Program Files\Ask.com
    C:\Program Files\Yontoo
    C:\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
    C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\cvv9puxh.default-1355528890578\extensions\plugin@yontoo.com
    C:\Documents and Settings\All Users\Application Data\Tarma Installer
    C:\WINDOWS\Temp\*.*
    C:\Documents and Settings\Daniel\Local Settings\temp\*.*
    
    :Reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Software\Microsoft\Windows\CurrentVersion\Run]
    "ApnUpdater"=-
     
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Tarma Installer\Components\{8D8654CD-7FBC-4C7E-84E9-371BFA8DB04E}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Tarma Installer\Components\{9307081B-7444-494C-8CF6-2FA7C0E92BFB}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Tarma Installer\Components\{9D9785E5-3424-40B6-A287-BA143AD53109}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Tarma Installer\Components\{A8F0AD53-1AEE-447E-89CD-71C325796F84}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Tarma Installer\Components\{B6783DFA-B8C8-4CB6-AB9F-EF1A1F7F7AE8}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Tarma Installer\Components\{F5F971A9-DBF8-4EEC-81E3-5F1660573E6C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Tarma Installer\Products\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}]
    [-HKEY_USERS\S-1-5-21-1409082233-299502267-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}]
    [-HKEY_USERS\S-1-5-21-1409082233-299502267-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
    [-HKEY_CLASSES_ROOT\CLSID\{FE9271F2-6EFD-44b0-A826-84C829536E93}]
    [-HKEY_CLASSES_ROOT\CLSID\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}]
    [-HKEY_CLASSES_ROOT\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}]
    [-HKEY_CLASSES_ROOT\AppID\YontooIEClient.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\YontooIEClient.Layers]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\YontooIEClient.Layers.1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
    [-HKEY_CLASSES_ROOT\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}]
    [-HKEY_CLASSES_ROOT\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}]
    [-HKEY_CLASSES_ROOT\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\YontooIEClient.Api]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\YontooIEClient.Api.1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}]
    :Commands
    [purity]
     
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:

    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. Blade897

    Blade897 Private First Class

    Hi Chaslang,

    I have completed all the steps up to OTM. I can't get passed the OTM step because when I copy the code into the left side panel and press "Move It," the computer freezes. I have waited over 5 hours without a response. The only thing I can note is that the format of the code is much more condensed then the way you have it here, but I am not sure that that would be the cause. Any ideas? Thanks.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you mean. Does it contain all the information exactly as shown or not? Did you disable protection software before trying this? You can also try safe boot mode.
     
  13. Blade897

    Blade897 Private First Class

    Safe mode did the trick. When I meant condensed, I meant the structure of the code was condensed as if they were all on one line, but the actual amount of code was not abbreviated.

    I forgot to mention that I was not able to remove R3 - UrlSearchHook because it doesn't appear when I run HijackThis. I downloaded MGTools and saved the .exe file to the C drive. R3 not showing up is strange because I see that it shows up in the MGlogs, but as you can see in the hijackthisstandalone.log, R3-UrlSearchHook does not show. I generated the hijackthisstandalone.log with Analyze.exe which is the same file the MGlogs program used to produce one of the MGlogs correct?

    Attached are the log files. So far, I have not noticed any redirections, but I imagine that search hook needs to be fully removed before I can start being less worried.

    Thanks!
     

    Attached Files:

  14. Blade897

    Blade897 Private First Class

    I couldn't edit my earlier post I guess, but it turns out I just got a redirection blocked, so it looks like it is still there.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    With which browser? Firefox I assume based on your logs?

    Run this >> Reset Firefox to Defaults
     
  16. Blade897

    Blade897 Private First Class

    Sorry, by redirection blocked I was referring to what had caused me to post here in the first place. Ever since I have gotten this malware, MalwareBytes has had to keep blocking redirection requests for my browser (firefox), without MalwareBytes blocking them firefox takes me to sites with random advertisements. So it looks like the original bug is still there.

    Do I still proceed with your firefox suggestion?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also since OTM apppears to have not worked exactly as we wanted, do the below.

    Delete the below files
    Code:
    "C:\WINDOWS\Tasks\"
    at1.job       Jan  6 2013         470  "At1.job"
    at2.job       Jan  6 2013         470  "At2.job"
    at3.job       Jan  5 2013         470  "At3.job"
    at4.job       Jan  6 2013         470  "At4.job"
    at5.job       Jan  6 2013         452  "At5.job"
    at6.job       Jan  6 2013         452  "At6.job"
    at7.job       Jan  6 2013         452  "At7.job"
    at8.job       Jan  6 2013         452  "At8.job"
    
    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  18. Blade897

    Blade897 Private First Class

    Okay done. Adding to registry was successful.

    I will be watching closely to see if any more redirection blockages happen.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, the logs look fine. The only suggestion left ( which is not related to the redirection ) is that I would not allow the below to be loading at startup.

    O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
     
  20. Blade897

    Blade897 Private First Class

    Done. I will be monitoring the computer, and repost here if I notice anything.

    Just have to thank you for your time and support as usual, you have helped throughout the years and I can't tell you enough how much I appreciate it.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds