abetterinternet is getting the better of me

Discussion in 'Malware Help (A Specialist Will Reply)' started by Giantmundo, Apr 11, 2005.

  1. Giantmundo

    Giantmundo Private E-2

    I have the abetterinternet spyware on my machine and try as i will I cannot get rid of the thing. I ran my tools alot of times and got rid of some things but abtterinternet re-occurs via ZoneAlarm warning. I checked your suggestions at generic removal and found I already had most of the tools. I downloaded the one's I didn't have and followed your instructions to the letter.

    In safe mode I have run these with the following results:
    CCleaner (I seem to empty the bin endlessly these days)
    Trend Micro (found one that it couldn't clean - file specified is:
    c:/windows/system32/vcybbiw.exe)
    Symantec (nothing)
    CCleaner (I can't help myself)
    AdAware (nothing)
    Spybot (nothing)
    CWShredder, Kill2Me, about:buster (nothing)
    HSRemover (8 items removed)

    Once back in normal mode it wasn't long before ZoneAlarm revealed to hits. As follows:
    docs and settings/local settings/temp/OWT/aurareco.exe
    and c:windows/prefetch had files as well
    thnall1ac.exe in prefetch and docs and settings somewhere.

    I have downloaded Hijackthis and placed it in a program files folder.

    I think I am ready for your treatment doctors.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Giantmundo

    Giantmundo Private E-2

    Here is the HJT file as requested.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    c:\windows\system32\pimgihq.exe
    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\PCHealth\HelpCtr\System\panels\blank.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - (no file)

    Is this iibar.dll some toolbar you knowingly installed? I would guess not. If not, make sure you fix this next line too.
    O3 - Toolbar: iiBar - {8AA99D86-978D-4963-A845-24AF39FB0CF2} - C:\Program Files\iiBar\iiBar.dll

    O4 - HKLM\..\Run: [wekbnp] c:\windows\system32\pimgihq.exe

    O15 - Trusted Zone: *.musicmatch.com
    O15 - Trusted Zone: *.musicmatch.com (HKLM)


    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    c:\windows\system32\pimgihq.exe

    Also delete the below folder if iibar is not something you wanted on your system:
    C:\Program Files\iiBar


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. Giantmundo

    Giantmundo Private E-2

    Firstly, thanks alot Chaslang for your advice.

    I examined your suggestions and did most of it and everything now seems fine.

    Let me explain what I did do and what I didn't do.

    I killed the three R0's - i understand they are registry changes that need to be removed but not why - any suggestions as to where I can learn more.

    Killed the 02 which I understand is a browser hook and I assume that since it didn't have any meaningful reference then it can only be bad - am I right at least a bit

    The 03 iiBar is a useful DSL usage counter related to my ISP hence I kept it.

    I kept the 015 as they referred to musicmatch which I have and it also seemed to imply that it had access to my trusted zone via zonealarm - I took the risk that they are OK - don't get cross ... pls

    Now the fun part - i suspected (or hoped) that you would suggest that I kill the 04 and its related file - so I used HJT to 'fix' it and then I couldn't help myself to have a quick look to see if the file existed (via windows explorer) before I went over to safe mode and found that it was gone.

    I suspected that it had regenerated itself. So since I had already broken the rules I started to play around with this. I got another HJT log and noted that it had in fact regenerated itself in the system32 folder under another name. I noted that the file in both cases was 75k in size and that the random name was always 6 chars in length. I repeated the HJT fix and look process and found that when i perform the HJT fix the file regenerates and hence I could not delete the file as it did not exist. Therefore i decided to reverse your instructions (sort of). I renamed the file first (in safe mode) and then in normal mode used HJT to fix the 04 record. Generated a new HJT log and noted that the little buggar had not regenerated. Decided then to delete the renamed file and do a CCleaner. Restore is now back on and I have played with the machine for a number of hours and all seems quite OK.

    Here's the latest HJT log. How does it look to you Chas?

    By the way this has been a most illuminating experience and I'd say even fun. I have learnt a few new things and got a good result. Tempted to get infected again with something to see if I can fix it myself - on second thoughts I don't think I'll push it.

    Anyway I am interested in learning more - any suggestions?

    Thanks again.http://forums.majorgeeks.com/newreply.php?do=newreply&noquote=1&p=559407#
    Big Grin
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is no reason for MusicMatch to be in your Trusted Zone. In fact, I have not had one case yet where something really needed to be in the TZ. Adding items to the TZ makes it too easy for bad stuff to hide itself among the good stuff. So it is a practice I recommend against. MusicMatch should not be adding themselves to your TZ when you install their software. Does it break anything? No! But it is not a good thing to do and it is not necessary.

    Hang around and read thru some of the thousands of threads. You will learn a lot.

    Quite often malware does a good job at regenerating itself and we take a variety of different steps (including ones like you did) to fix/remove the problems.

    At anyrate your log is clean. Check out the below thread:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds