Bad Spyware Infection at least

Discussion in 'Malware Help (A Specialist Will Reply)' started by gcpower, Mar 31, 2007.

  1. gcpower

    gcpower Private E-2

    Good morning. I would be very grateful for your help. This laptop was badly hit with popups, so much so that using a browser, or internet explorer proved impossible. I started by running spyware doctor, which identified almost 1300 This is the most I have ever seen.

    I have now followed all procedures detailed in read and run me first. CounterSpy run in safe mode will not allow me to save the log file. I enclose the first three logs. I will post the rest directly.

    I am unable to update windows, as the installation fails to instal four files. One of which is the authentication program. The update for mcafee also fails. I have just noticed that the system clock was set to 29 March but Il am certain it was correct on 29th. The windows installer keeps popping up, as well. Not surprisingly, the system is very slow with endless i/o.

    Thanks, in anticipation. Regards Graham
     

    Attached Files:

  2. gcpower

    gcpower Private E-2

    I am now posting the remaining files for the thread. I cannot find the logfile for getrunkey. The first time I ran it, it gave a blank screen. It seemed to run ok second time, but no log file. I have tried to run it again, with no success. Will try again. Thanks again.
     

    Attached Files:

  3. gcpower

    gcpower Private E-2

    I have located the original runkeys.txt file and enclose a further one from the latest execution. I do not know where it was hiding! Regards Graham
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a whole lot of malware on your PC! You will get an idea of how bad when you see the below instructions!!

    NOTES:
    1. Your OS is way out of date with updates and that is a big security risk and is a potential cause for your infections.
    2. From now on, do not run ShowNew until you have terminated (closed the windows for) GetRunKey. This way all the temp files will not show up in the ShowNew log. This advice applies to all scans. Never run multiple scans at the same time. Not only will it take longer, but some things may not work properly (especially fixes) if you do this.
    Questions:
    1. Your McAfee Antivirus may be infected. You may have to uninstall it and then reinstall & update after we finish your clean! Don't do this yet. I will tell you when it become necessary.
    2. Is your copy of Spyware Doctor a paid version?
    3. What about CounterSpy and AVG Antispyware? Free trials from the READ ME??
    Let's start some fixes now!
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Automatic Update Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • windows file explorer
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste Automatic Update into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • explorer
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [_R_`_RSIS`] C:\WINDOWS\System32\kymjlzw.exe
    O4 - HKLM\..\Run: [Windows Core Kernel Update] C:\WINDOWS\System32\win32bootcfg.exe
    O4 - HKLM\..\Run: [win32] C:\WINDOWS\System32\win32.exe
    O4 - HKLM\..\Run: [w011d550.dll] RUNDLL32.EXE w011d550.dll,I2 0004eb890011d550
    O4 - HKLM\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup
    O4 - HKLM\..\Run: [Services] C:\WINDOWS\system32\1.tmp
    O4 - HKLM\..\Run: [ppl32] C:\WINDOWS\System32\ppl32.exe
    O4 - HKLM\..\Run: [pcvp] C:\WINDOWS\System32\pcvp.exe
    O4 - HKLM\..\Run: [NAMED] C:\WINDOWS\System32\NAMED.exe
    O4 - HKLM\..\Run: [MS22] C:\WINDOWS\System32\MS22.exe
    O4 - HKLM\..\Run: [lcps] C:\WINDOWS\System32\lcps.exe
    O4 - HKLM\..\Run: [kkmc] C:\WINDOWS\System32\kkmc.exe
    O4 - HKLM\..\Run: [I`KsmztbodqeYRZnbyiz] C:\Program Files\McAfee.com\VSO\mcshield.txt:dleihscm.exe
    O4 - HKLM\..\Run: [BF4P] C:\WINDOWS\System32\bf4p.exe
    O4 - HKLM\..\RunServices: [I`KsmztbodqeYRZnbyiz] C:\Program Files\McAfee.com\VSO\mcshield.txt:dleihscm.exe
    O4 - HKCU\..\Run: [Sygate Personal Firewall] spoolvs.exe
    O4 - HKCU\..\Run: [Sjvepca] C:\DOCUME~1\EVELYN~1\APPLIC~1\DOBE~1\ANREGW~1.EXE
    O4 - HKCU\..\Run: [Aaou] "C:\DOCUME~1\EVELYN~1\APPLIC~1\CROSOF~1\tracert.exe" -vt yazr
    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\Program Files\McAfee.com\VSO\mcshield.txt:dleihscm.exe
    C:\Program Files\SpySpotter3\Defender.exe
    C:\WINDOWS\System32\kymjlzw.exe
    C:\WINDOWS\System32\win32bootcfg.exe
    C:\WINDOWS\System32\win32.exe
    C:\WINDOWS\system32\w011d550.dll
    C:\WINDOWS\system32\1.tmp
    C:\WINDOWS\System32\ppl32.exe
    C:\WINDOWS\System32\pcvp.exe
    C:\WINDOWS\System32\NAMED.exe
    C:\WINDOWS\System32\MS22.exe
    C:\WINDOWS\System32\lcps.exe
    C:\WINDOWS\System32\kkmc.exe
    C:\WINDOWS\System32\bf4p.exe
    C:\WINDOWS\system32\spoolvs.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now let's continue by running a tool to fix PurityScan problems and a some other issues.
    1. After reboot, download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2
    Mozilla Firefox (2.0)E

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  5. gcpower

    gcpower Private E-2

    Good afternoon. Thank you for responding so quickly.

    I have tried to update the OS online. Some updates have gone in, but the Microsoft Genuine Advantage install fails.

    I waited for the window to close on on Getrunkey, before running shownew. When I ran it this time, I noticed that shownew.bat was still shown as running in Task Manager. I re-ran each one and checked Task Manager, before continuing.

    1. McAfee Security Centre will not open, so i suspect it is infected. It is requesting reboot and if no improvement, reinstall. I cannot tell whether it is up to date. The update procedure starts, but that is all.

    2. Spyware Doctor is a trial version.

    3. CounterSpy and AVG Antispyware are free trials from the readme.

    I have carried out all the instructions given and posted new logs. Both Automatic Update Services and Windows file explorer were shown as stopped, already. The registry keys listed in your email were not shown in the post for some reason. This step was not carried out.

    I did not see the delete on reboot option on killbox.

    When I ran HJT for the log, CounterSpy reported a problem with grep.exe. I selected block. Notepad was displayed, but I could not find a log. I re-ran it and it was successful.

    Observations

    The dll error appearing on startup has now disappeared. It related to w011d550.dll.

    Every time I try to copy a file, using drag and drop, windows installer starts. The message is that it is installing Easy CD and DVD Creator 6.

    Internet Explorer has no url bar and the search is greyed out.

    I hope this all helps and await you further advices. Thanks again. Graham
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Once you are infected, you should not try to update while still infected. After we fix all of your malware problems, you should then try to get updated. And then always keep your system up to date.


    I suggest that you uninstall it now since there is a chance that it was infected. Do you like McAfee? Do you pay to keep it up to date? If the answer to both questions is yes, you will reinstall it later. If the answer is no to either question, a replacement should be installed (like AVG Free)

    Uninstall Spyware Doctor and CounterSpy now. Keep AVG Antispyware.

    Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Did you download from the link I gave you. It is right there on the window that shows. It should look like this:

    killbox.jpg


    I don't think you meant HJT. grep.exe is used by GetRunKey and ShowNew not by HJT. You need to allow it to run if you want the logs to be valid. Since I asked you to uninstall CounterSpy above, this should no longer be a problem


    Do you use Easy CD Creator? Sounds like it may not be installed properly. This also be related to its DirectCD function. This is not a malware problem. You may need to just unintall, reboot, and then reinstall.

    Enable the Address Bar in IE. Click View, Toolbars, and select Address Bar.


    Let's continue with your cleanup!

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now locate the below folder and delete it if found:
    C:\Program Files\Common Files\wiik

    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  7. gcpower

    gcpower Private E-2

    Good morning an thanks for your reply. Apologies for the delay in replying to you.

    1. I will not try to update windows until clean. Sorry, i thought i was helping here.
    2. McAfee deleted. Will use AVG and Zone Alarms for the firewall in future.
    3. CounterSpy and Spyware Doctor removed. No residual folders found for CounterSpy
    4. I downloaded Killbox from your link.
    5. Will deal with Easy CD later.
    6. Address bar in IE (Version 6 sp1) was enabled, but still not visible. Address and Links are shown, but no bar to type in.
    7. All other tasks carried out and no errors encountered.

    New logs posted, as requested. Nothing adverse to report.

    Regards

    Graham
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you notice the selection in the image I posted. Does yours look the same?


    Did you unlock the Toolbar first. If locked, no changes can be made. See this the below for more detail and for more to try:

    http://support.microsoft.com/kb/842903


    I had a typo in the fixME.reg patch. Please run the below to fix the one item not fixed due to the typo.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Attach a new log from GetRunKey now.

    Your logs did not show AVG and ZoneAlarm. Did you install them after getting the logs?
     
  9. gcpower

    gcpower Private E-2

    Good morning and a Happy Easter to you. Thanks for the reply to my post.

    4. Killbox does look the same as your image. I have taken an image and posted it. I did notice a folder off the root called !Killbox, though.

    6. IE now fixed.

    Registry fix now run.

    I have not installed AVG and Zonealarms. I will do this when the machine is clean.

    New getrunkey posted.
    Killbox image posted.

    I may have uploaded files twice, due to crash.

    It may be nothing, but as I was typing this reply, the machine rebooted.

    Thanks again for all the help. Hopefully, we are winning here.

    Regards

    Graham
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach any logs or images!

    Same to you! :)


    If it looks the same then why did you say and I quote:

    Install them now!!! It is too dangerous to not have them installed.
     
  11. gcpower

    gcpower Private E-2

    Good morning

    4. Killbox. I misunderstood your instructions. I was expecting a pop up box to appear during the process. My apologies for misleading you. I have now attached the image file, just in case.

    AVG and Zonealarm now installed - post running getrunkey.

    Both missing files now uploaded.

    Regards

    Graham
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. gcpower

    gcpower Private E-2

    I just wanted to thank you for all your efforts in resolving this problem. I could not have done it without you. I am now going through the very slow process of updating Windows XP. The machine still will not take the Windows Genuine Advantage update. At least I:) have a Service pack 2 disk, which i can use, then try windows update again.

    Thanks again, I am most grateful and appreciate your skill and patience.

    Regards

    Graham
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds