AZE... Help me!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by punkaholicgravy, Jun 7, 2005.

  1. punkaholicgravy

    punkaholicgravy Private E-2

    Hello all... i am in desperate need of some help. i was recently infected with that stupid AZEsearch thing. I have followed all the intructions in the tutorial and i am still screwed. . i did everything it told me to do, used every antivirus program etc etc. and it's still on my computer!! i deleted it from the registry and it's still not gone. i have tried everything i know. i've gone in through safe mode and deleted the corresponding files and its still there. any help would be greatly appreciated!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. punkaholicgravy

    punkaholicgravy Private E-2

    i ran hijackthis...here is the log file
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please install HijackThis as requested. You are running it directly from the ZIP file and will not get any backups. FIx this before you continue.

    Now goto Add/Remove programs (in Control Panel) and look for the below and uninstall:
    Media Access
    Toolbar

    Do you know what the below two items are:

    O4 - HKLM\..\Run: [StopSignSsTsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus
    O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe"

    Spybot has a bug that causes it to ignore a few baddies, one of which is newdot.net.

    Fixing SpyBot's Ignore Products Bug:
    I want you to run SpyBot and get into the Advanced mode by selecting Mode and then
    Advanced mode. Then select Settings and the in the left column select Ignore Products.
    In the right window pane make sure the All products tab is selected. Then in that
    window, right click your mouse and choose "Deselect all". Now in the left pane click
    at the top on SpyBot S&D and then choose Search for Updates. Download any updates
    required. Now click Check for Problems. Fix any that are found.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\Program Files\Media Access\MediaAccK.exe
    C:\Program Files\Media Access\MediaAccess.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.top20results.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O1 - Hosts: 213.219.251.78 www.google.com
    O1 - Hosts: 213.219.251.78 google.com
    O1 - Hosts: 213.219.251.78 www.google.co.uk
    O1 - Hosts: 213.219.251.78 google.co.uk
    O1 - Hosts: 213.219.251.78 www.google.ca
    O1 - Hosts: 213.219.251.78 google.ca
    O1 - Hosts: 213.219.251.78 www.google.es
    O1 - Hosts: 213.219.251.78 google.es
    O1 - Hosts: 213.219.251.78 www.google.de
    O1 - Hosts: 213.219.251.78 google.de
    O1 - Hosts: 213.219.251.78 www.google.fr
    O1 - Hosts: 213.219.251.78 google.fr
    O1 - Hosts: 213.219.251.78 www.google.com.au
    O1 - Hosts: 213.219.251.78 google.com.au
    O1 - Hosts: 213.219.251.79 www.yahoo.com
    O1 - Hosts: 213.219.251.79 yahoo.com
    O1 - Hosts: 66.218.75.184 mail.yahoo.com
    O1 - Hosts: 213.219.251.81 astalavista.com
    O1 - Hosts: 213.219.251.81 www.astalavista.com
    O1 - Hosts: 213.219.251.81 astalavista.box.sk
    O1 - Hosts: 213.219.251.81 www.astalavista.box.sk
    O1 - Hosts: 213.219.251.81 cracks.com
    O1 - Hosts: 213.219.251.81 www.cracks.com
    O1 - Hosts: 213.219.251.80 www.msn.com
    O1 - Hosts: 213.219.251.80 msn.com
    O1 - Hosts: 213.219.251.80 search.msn.com
    O1 - Hosts: 213.219.251.80 www.search.msn.com
    O1 - Hosts: 213.219.251.80 go.com
    O1 - Hosts: 213.219.251.80 www.go.com
    O2 - BHO: AzEntretien Class - {0d2def3a-f4f1-42ec-ac4f-132e7ba6e292} - %SystemRoot%\azentretien.dll (file missing)
    O2 - BHO: ZToolbar Activator Class - {da7ff3f8-08be-4cac-bc00-94d91c6ae7f4} - C:\WINDOWS\azesearch4.dll
    O2 - BHO: AddressBar Class - {f65b197f-8260-4d52-909a-f70118e646eb} - C:\WINDOWS\system32\iasada.dll
    O3 - Toolbar: AZE Search - {a19ef336-01d4-48e6-926a-fe7e1c747aed} - C:\WINDOWS\azesearch4.dll
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
    O4 - HKCU\..\Run: [Intel system tool] C:\WINDOWS\system32\hookdump.exe
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAccess/ie/bridge-c5.cab
    O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
    O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} - http://www.spywarestormer.com/files2/Install.cab
    O16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} - http://www.azebar.com/install/azesearch.cab


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Media Access <--- the whole folder
    C:\Program Files\Toolbar <--- the whole folder
    C:\WINDOWS\system32\iasada.dll
    C:\WINDOWS\azesearch4.dll
    C:\Program Files\NEWDOT~1
    C:\WINDOWS\system32\hookdump.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. punkaholicgravy

    punkaholicgravy Private E-2

    ok... i did everything that you told me to do. however certain things couldn't be done:
    couldn't delete C:\Program Files\Toolbar <--- the whole folder
    C:\WINDOWS\azesearch4.dll
    C:\WINDOWS\system32\hookdump.exe
    because they weren't there.

    couldn't kill :C:\Program Files\Media Access\MediaAccK.exe
    C:\Program Files\Media Access\MediaAccess.exe

    because they weren't there.

    coudn't fix:O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    because they weren't there.

    however, it seems that it has disappeared. but i still have this stupid background on my desktop (see attatchment 2) that i can't get rid of. and the windows security alert thing won't go away. other than that, everything is back to normal. thank you sooooooooo much.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those items were not there to delete because earlier steps had fixed them. My other steps were just backups in case the others did not work.

    I did not address your Desktop issue yet. The other items needed to be fixed first.

    You did not answer a question I need an answer too:

    Also it looks like you forgot to have HJT fix the below:

    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s

    Fix it now and then delete the folder associated with Newdotnet.

    For you Desktop problem, try the below.

    Right click on your Desktop and select Properties. Then click the Desktop tab and then the Customize Desktop button. Now in the next window that comes up click the Web tab. Make sure at the bottom that Lock desktop items is unchecked. Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too. Then click OK. Apply. OK.

    If you cannot right click on your Desktop, bring up Control Panel and select Display. Then select Desktop and continue with the above steps.

    Post a new HJT log and tell me how things look.
     
  7. punkaholicgravy

    punkaholicgravy Private E-2

    ok, everything else has been fixed, once again, thank you so much. sorry about forgetting to answer your question... i'll do that now...

    O4 - HKLM\..\Run: [StopSignSsTsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus

    when i first got the virus, i downloaded an anti-virus program called stop sign, it said it was free, but when i finished scanning with it, it told me i couldn't heal anything unless i bought it... so naturally, i uninstalled it... but i guess something about it must be still lingering around...

    as for:
    O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe"

    no idea...
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! What is the current status with your Desktop?

    Do the below appear in add remove programs:
    Acceleration Software <--- definitely uninstall if it does
    SP2 Connection Patcher <--- this one we need more info on what it is but it appears like it may be a crack for using WinXP SP2 illegally?


    If you cannot uninstall Acceleration Software then just have HJT fix the below line:

    O4 - HKLM\..\Run: [StopSignSsTsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus


    Then reboot into safe mode and delete the below folder if it exists.
    C:\Program Files\Acceleration Software
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds