ABetterInternet my a#!

Discussion in 'Malware Help (A Specialist Will Reply)' started by MrNerd, Jul 30, 2006.

  1. MrNerd

    MrNerd Private E-2

    I am having a very rough bit of malware that I can't get rid of. I followed all the instructions in you FAQ, including running Spybot, Ad-Aware, Microsoft Windows Malicious Software Removal Tool, Ccleaner, CounterSpy, CWShredder, Kill2Me, BitDefender, and PandaScan. All in the proper order and proper recomended safe modes.

    Bassically they all manage to find quite a bit of malware, and remove it all, but not really because it is all back in time for the next scan, even if it is 1 second later. Specifically this ABetterInternet.nail thing pops up on every scan of Ad-Aware, and is sucessfully cleaned, and back again right away. So I think maybe this is the guy downloading the rest of the bugs, but it's just a guess.

    I've attached some of my log files as requested. I have a hijackthis log also, but since the max attachments is 3 I used the first 3 requested in the FAQ for this post. I would be grateful for any help. Given the many hours I've already spent on this, I can't help but think if the terrorists had attacked a maker of spyware, we wouldn't have bothered going to war over it.
     

    Attached Files:

  2. MrNerd

    MrNerd Private E-2

    Oh well, just thought I'd reply with the Hijackthis log to save time.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You have a few problems with malware and another in that you Windows Version is way out of date which is a major security risk to you.

    Let's start with the below procedure:

    Qoologic Removal Procedure

    Then attach a new HJT log.
     
  4. MrNerd

    MrNerd Private E-2

    Thanks, I ran QooFix both in and out of Safe mode. It found some stuff both times and removed it (the same stuff actually). But it doesn't seem to have made any lasting effect. Adware is still finding Betterinternet.nail in the registry. (and other things keep popping up and installing themselves in startup according to Counterspy).

    And yeah, I can't update this copy of Windows anymore. You can probably guess why. Yes, I'm a terrible person. :rolleyes:
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are going to continue to have big problems then! This unpatch version of Windows is full of security holes!!!!

    Try the latest version of QooFix available here: http://www.malwarebytes.org/qoofix.php

    Post a new log from it and a new HJT log. Don't worry about the other stuff (BetterInternet etc) we will get to it. I first want to work on Qoologic.
     
  6. MrNerd

    MrNerd Private E-2

    Ran the newest version of Qoofix in safe mode and it removed some stuff. Ran it again and it registered clean. Subsequent scans by Ad-Aware, Spybot, and CounterSpy also register clean (inclusing the destruction of ABetterInterNet.nail). Holy crap, I think it's a clean system. Major Geek, as far as I'm concerned you should be a Colonel.

    You know the irony is that I got this spyware on my computer while trying to update my system. Since I couldn't get the normal Service Pack 2 to work, I downloaded a "cracked" one which was in fact Spyware. I'm a sucker for sure, and Bill Gates would be laughing. All to get the stupid Call Of Cthulhu game working......

    Thanks Chaslang.

    P.S. I attached a Hijackthis log, just for good measure.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We have a little more to do!

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to SymWMI Service ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    SymWSC

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
    O16 - DPF: {127CE7BA-AD89-4108-A913-C52EFC037C36} -
    O16 - DPF: {2776DDE9-D4B2-4BF7-9F98-ADC1A1B80AF5} -

    After clicking Fix, exit HJT.

    Now if you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  8. MrNerd

    MrNerd Private E-2

    Ok I did those things. Everything worked except I couldn't get it to delete SymWSC, even after I disabled SymWMI it still kept saying it couldn't delete it because it was system critical.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not system critical! It may have done it anyway. Attach a new HJT log so I can see. While waiting for me to respond, make sure you get started on the toggling System Restore and the How to protect thread steps.
     
  10. MrNerd

    MrNerd Private E-2

    Ok here is the new log. I managed to find a way to install Service Pack 2, and also got a bigger hard drive (not really connected, just in case something wierd shows up on there). Working on the preventive measures.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it looks good other than the below which is still present.

    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

    This is probably coming back because you have the registry locked for editing. See the below in your HJT log:
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    That toolbar is just a leftover from McAfee but you should be able to fix it. You will just have to remove those O6 restrictions lines first (use HJT or remove the restrictions in program you are doing this with - like Spybot or SpywareBlaster or similar). Then fix the O3 line again.

    Other than that you are all done (after you finish the How to protect thread)!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds