And Another....

Discussion in 'Malware Help (A Specialist Will Reply)' started by Goodier, Jan 6, 2006.

  1. Goodier

    Goodier Private E-2

    have done my best to follow the Read & run me first, I seem to be experiencing a lot of what I read on here. I ran all the cleaning software and my own AVG on safe boot, but the online stuff had to be done on normal boot. I am on XP.

    The Bitdefender fell over after about 5 hours, but had cleaned a clicker trojan by then. Here are the Panda log (after Bitdefender fell over) and Hijack this run last of all.

    Please let me know what to do next.
     

    Attached Files:

    Last edited by a moderator: Jan 6, 2006
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not use the paper clip to make attachments go inline. Just attach them without selecting inline.

    Notice how I changed your attachments now.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Smitfraud, SpySheriff, SpyAxe & PSGuard Removal

    And attach the smitfiles.txt log.

    Why did you put the below in your hosts file:
    O1 - Hosts: 194.130.106.133 lilthas01
    O1 - Hosts: 194.130.106.134 qa.gb-en.music36.ioko.com
    O1 - Hosts: 194.130.106.134 qa.ca-en.music36.ioko.com
    O1 - Hosts: 194.130.106.134 qa.ca-fr.music36.ioko.com
    O1 - Hosts: 194.130.106.134 qa.mx-es.music36.ioko.com
    O1 - Hosts: 194.130.106.134 qa.sv-se.music36.ioko.com
    O1 - Hosts: 194.130.106.135 gb-en.music36.ioko.com
    O1 - Hosts: 194.130.106.135 ca-en.music36.ioko.com
    O1 - Hosts: 194.130.106.135 ca-fr.music36.ioko.com
    O1 - Hosts: 194.130.106.135 mx-es.music36.ioko.com

    If still having problems afterwards, please describe them.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look in Add/Remove programs and uninstall SpywareStrike . It is a rogue tool the will hijack your desktop.
     
  5. Goodier

    Goodier Private E-2

    Spyware Strike I have been removing all day. It just keep coming back. But its not in add/remove at the moment to remove - it was earlier.
    No idea why that stuff is in the host files. Doesn't ring any bells.

    Will do as you suggest and get back.

    Thanks
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
     
  7. Goodier

    Goodier Private E-2

    Thanks for the help so far, I have my homepage back, but I still have the clicking pop-up saying System Instrusion detected. Spyware Strike came back again (I uninstalled it again).

    Ran Host.exe and smtrem.exe

    Here is the lastest Panada and Smt files
    Can you help again?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know what the below is:
    C:\Documents and Settings\Ciro Paradiso\Desktop\Access Members Area.exe


    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\Program Files\SpywareStrike\SpywareStrike.exe
    C:\Program Files\SpywareStrike\SpywareStrike.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: HomepageBHO - {27150f81-0877-42e9-af13-55e5a3439a26} - C:\WINDOWS\system32\hp897E.tmp
    O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} - http://66.117.37.13/dba2218.exe

    After clicking Fix, exit HJT.
    Run Windows Explorer and try to delete:
    C:\Program Files\SpywareStrike <--- the whole folder


    If it cannot be delete, boot in safe mode and kill the process again with HJT (if it is running) and then delete the C:\Program Files\SpywareStrike folder.

    Also look for and delete the below:
    C:\Documents and Settings\Ciro Paradiso\Cookies\ciro paradiso@www.spysheriff[1].txt
    C:\Documents and Settings\Ciro Paradiso\Cookies\ciro paradiso@xmts[2].txt
    C:\Documents and Settings\Ciro Paradiso\Cookies\ciro paradiso@112.2o7[1].txt
    C:\Documents and Settings\Ciro Paradiso\Cookies\ciro paradiso@ad.yieldmanager[2].txt
    C:\Documents and Settings\Ciro Paradiso\Cookies\ciro paradiso@burstnet[1].txt
    C:\Documents and Settings\Ciro Paradiso\Cookies\ciro paradiso@com[2].txt
    C:\Documents and Settings\Ciro Paradiso\Cookies\ciro paradiso@i.screensavers[1].txt
    C:\Documents and Settings\Ciro Paradiso\Cookies\ciro paradiso@microsofteup.112.2o7[1].txt
    C:\Documents and Settings\Ciro Paradiso\Cookies\ciro paradiso@tribalfusion[1].txt
    C:\Documents and Settings\Ciro Paradiso\Cookies\ciro paradiso@www.burstbeacon[1].txt
    C:\Documents and Settings\Ciro Paradiso\Cookies\ciro paradiso@xmts[2].txt

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Reminder Note: Once we have determine you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  9. Goodier

    Goodier Private E-2

    Will go and do those things.

    The Access Members has appeared on the desktop and is unwanted, can you help?
     
  10. Goodier

    Goodier Private E-2

    I looked at what you asked, and SpywareStrike isn't a process or a folder (I did a search too). I found all but one of the cookies you mentioned.

    Should I still delete the prefetch folder?

    Thanks
     
  11. Goodier

    Goodier Private E-2

    Went away came back and the spywarestrike folder was back, so have followed the instructions completely and here is the log file.

    Although the line C:\Program Files\SpywareStrike\SpywareStrike.exe was there twice in HJT once I fixed one, the other one vanished. The icons are still around in the program menu.

    Would appreciate advice on the "access members" as it isn't something I want...

    Thanks again
     

    Attached Files:

  12. Goodier

    Goodier Private E-2

    Re: And Another....(Problems with SpywareStrike)

    I had followed the instructions earlier, but after watching other posts felt I might have used CCleaner properly. So I did it again following the notes.

    Here is the HJT log.

    I still have icons for Spywarestrike (can't find evidence of a directory), I have the baloon on the bottom bar and also I still have the Access Members mentioned above.

    What now?

    Thanks
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [SpywareStrike] C:\Program Files\SpywareStrike\SpywareStrike.exe /h

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\SpywareStrike
    C:\Documents and Settings\Ciro Paradiso\Desktop\Access Members Area.exe

    Also delete and icons on your Desktop for SpywareStrike. If you cannot see the above in safe mode, delete them in normal boot mode.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  14. Goodier

    Goodier Private E-2

    Hello and again and thanks

    Followed the instructions, there wasn't a SpywareStrike folder in program file (not the first time its not where you expected). I did remove it using add/remove programmes. And yes I did have the view files set as recommended.

    I am left with this pop-up (which even appears in safe mode) saying "System Instrusion detected!"

    HJT log attached

    Thanks
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download WinPFind
    • Extract it to the root folder of drive C ( C:\ ). This will create a folder called WinPFind in the C:\ folder. Inside C:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program.
    • Now click Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.
    • When it is done, it will show the results of the scan. Right Click in the window and choose Select All. Then Right Click again and select Copy which will copy to the contents of the log to your clipboard. Then open a notepad window and paste in the log by pressing CTRL-V. Save it to a file and upload the text file here as an attachment.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  17. Goodier

    Goodier Private E-2

    Hello again

    Well Spyware Strike 2.5 is back - again, will nothing tell it to go away!

    The pop-up is still present, trying to look genuine (a yellow triangle with an !) appearing from a red circle with a cross which flips back and forth from a Microsft looking icon.

    Followed instructions from both other messages and attached the log file.

    Thanks
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay post a new HJT log. Also note, if things are coming back. Do not do anything on your own to work trying to fix them. I need to be able to see everything in order to help you work on this. If you work off line, I may not see what I need to see.

    This is a new form of the Smitfraud, SpyAxe, Spysheriff family and there may be some new hidden procedures we need to locate in order to fix.
     
  19. Goodier

    Goodier Private E-2

    Ok, quite happy to do that. Thought it was me....

    Here is the HJT log.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Then get a new WinPfind log and attach it. Also let me know if there is any change in status.
     
  21. Goodier

    Goodier Private E-2

    As requested, nothing has changed the popup is still there and SpyStrike is still on my programs list.

    here is the wpfind log

    Thanks again
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    On what list?
     
  23. Goodier

    Goodier Private E-2

    Sorry

    In the start up menu and on the desktop .

    Also in c:\program files\

    I say this because sometimes it hasn't been in c:\program files\ but has been on the desktop/start up menu when you have asked me to delete the folder.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can't you just delete them? If it is in the Start Menu, just right click on it and select delete. If it is in C:\Program Files\SpywareStrike just delete the folder.

    You should also run the below and post the Ewido log:

    Running Ewido Security Suite
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please also check to see if the below file exists:

    c:\windows\system32\newwrap.dll

    Make sure you have viewing of hidden & system files enable per the READ ME.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  27. Goodier

    Goodier Private E-2

    Hi again

    After running Ewido (log below) the pop up is currently absent and spywarestrike isn't in the program file directory.

    The dll file isn't there.

    I'll go and look at the new instructions now.

    Thanks
     
  28. Goodier

    Goodier Private E-2

    And here is the file
     

    Attached Files:

  29. Goodier

    Goodier Private E-2

    Here is the pandascan and smitfile.

    The pop-up has gone. The only thing I am still aware of it the prefetch folder (mentioned in an earlier post) is still present.

    Hope this means its all sorted. If you think it is I have remembered the restore point. Do let me know if I should do that now?
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't delete the prefetch folder? Just either delete the files in it.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  31. Goodier

    Goodier Private E-2

    Thanks for your help, seem to be back to "normal".

    Hope I don't need your help again in a hurry, but thanks its been invaluable.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds