Big problems --- PLEASE help

Discussion in 'Malware Help (A Specialist Will Reply)' started by hogbone, May 21, 2007.

  1. hogbone

    hogbone Private E-2

    I have done everything in the "READ AND RUN ME FIRST" sticky thread, but I
    I suspect that most (or all) of my efforts were thwarted and/or counterfeited by the malware at issue.

    Creation of a log file was not an option when I ran CounterSpy in Safe Mode. I abandoned the BitDefender scan after about 48 hours (hardware interrupts were hogging about 99% of CPU) while the BD scan was running. The other log files will be attached to this post and my next one.

    I have been suffering a variety of problems for the last two weeks or so.

    My Trend Micro AV and firewall has been replaced by a bogus version, so I have just stopped it for the moment. Windows Update has been prevented from working properly. All online AV/spyware/malware scanners are disabled in various nefarious ways. Navigation to various security-related websites (including MajorGeeks.com) via IE6 often results in crash of ALL open IE windows.

    Etc.

    I am at my wit's end.

    PLEASE help.

    ...
     

    Attached Files:

  2. hogbone

    hogbone Private E-2

    Other log files attached.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Before we get started, I have to refer you back to step 3 of the READ ME. You have both TrendMicro and Avira AntiVir installed. You must uninstall one of these now.

    I also see signs that you had NOD32 installed but appear to have uninstalled it. Delete the below folder from it:
    C:\Program Files\ESET

    Also uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Delete the below folder too:
    C:\Program Files\Easy SpyRemover

    Is your copy of Spyware Doctor a free trial version or a paid version?


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to LFWSDWHZ
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • RA
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste LFWSDWHZ into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • RA
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down.


    Uninstall the below old versions of software as requested in step 6 of the READ ME:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 8
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment Standard Edition v1.3.1_18

    Make sure you reboot after uninstalling the above!

    After reboot attach new logs from ShowNew and GetRunKey!

    Are you having anymore malware problems?
     
  4. hogbone

    hogbone Private E-2

    Thank you very much, chaslang, for trying to help me.

    Unfortunately, I did everything you recommended, but all my malware problems still remain.

    I have attached new log files.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Exactly what malware problems are you referring too?

    Also please answer any questions I ask? You did not answer my quesion about Spyware Doctor.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What application were included in "SBC Yahoo! Applications" that you have installed? I thought this included an antivirus, antispyware, firewall....etc?

    Please put a copy of the below file into a ZIP file and attach it here:

    C:\WINNT\ua2.dll


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  7. hogbone

    hogbone Private E-2

    I am referring to exactly the same "malware problems" that I referenced (in admittedly somewhat general terms) in my original post:

    AND ...

    Last, but absolutely, positively NOT least ...

    ... which was a shorthand way of trying to communicate that I have problems that are so numerous, widespread, and constantly attacking that I am physically and mentally unable to provide a detailed and comprehensive catalog for your review. Like I said before:


    Moving right along ...

    I apologize for my omission.

    I think my copy of Spyware Doctor was a freebie, which may or may not be a moot point because I uninstalled Spyware Doctor yesterday (at the same time I uninstalled the Avira AntiVir, which was completely inactive anyway).


    SBC Yahoo (now AT&T) is my DSL provider. If I recall correctly, I installed the bare minimum to set up my Internet connection, specifically EXCLUDING ALL "antivirus, antispyware, firewall....etc" offered by SBC Yahoo.


    Now, I have a few questions for you:

    1. What is crypt32chain?

    [As in ... HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]

    2. What is daas_s.dll?

    3. What are all the files of the form is-XXXXX.tmp (where "XXXXX" is a seemingly random sequence of five alphanumeric characters, e.g., is-PQ5DI.tmp)?

    4. Why do I get the following error message whenever I try to access System Volume Information on ANY of my logical drives:

    "System Volume Information is not accessible. Access is denied."?

    5. Why does Registry Booster sometimes (but NOT always) give me the following error message:

    "The Key HijackThis.exe under SOFTWARE\Microsoft\Windows\CurrentVersion\AppPaths contains a bad path for the value"?

    6. Why did Windows Update "successfully" install Hotfix KB832894 over and over and over (six times, to be exact), yet it does not show up in my Control Panel's Add/Remove Programs list?

    7. Why does Windows Update sometimes (but NOT always) give me the following error message:

    "Files required to use Windows Update are no longer registered or installed on your computer," ... invariably followed by ...

    "The website has encountered a problem and cannot display the page you are trying to view"?

    8. How is my Trend Micro PC-cillin Internet Security 2007 (8.320.1004/4.481.00) being replaced by a malicious imposter EVERY time I attempt to do a manual update, and at various other seemingly random times?

    [These occasions are fairly obvious because of both (a) the bogus "update" pop-up window and (b) the change of text from "Trend Micro PC-cillin Internet Security 2007 (8.320.1004/4.481.00)" to "Trend Micro PC-cillin Internet Security 2007 (7./)" when I move the mouse over the icon in my system tray.]

    9. Why does the Symantec Online Virus Scan refuse to run, informing me that I do not have Active X properly enabled in IE6, when I know good and well that all relevant settings are just as they should be (and other sites with the same "requirements" confirm my belief)?

    10. Why do all the other online virus scanners listed at http://wiki.castlecops.com/Malware_Removal:_Online_Anti-Virus_Scans cause a complete crash not only of their own Internet Explorer window, but also ALL other open IE windows?

    11. Why do I sometimes (rarely, so far) get a screwball, NON-MICROSOFT error message (something like, "If you close this window, bad things may happen") whenever I try to close certain Internet Explorer windows?

    12. Why do ALL open IE windows crash at least 15% of the time that I attempt to navigate to any security-related website, but this problem NEVER happens when I go to Yahoo Sports, IMDb.com, or any of a zillion other NON-security-related websites?

    13. Am I correct in assuming you are aware that the services you instructed me to remove in your original post were all remnants left behind by Sysinternals RootkitRevealer?

    14. I could go on (and on ... and on ... and on ...), but as I said (or at least implied) before ...

    This situation has me broke-down, busted, worn out, and nearly witless. The weird occurrences on my computer that have been increasingly frequent over the last two weeks are too much (in both quantity and "quality") for me to relate as well as I wish I could. Nevertheless, ... ANY help you can provide will be GREATLY APPRECIATED.



    OK, I have done this.



    This step is not working. Double-clicking on fixME.reg merely reopens the file in Notepad.


    Now what?
     

    Attached Files:

    • ua2.zip
      File size:
      45.3 KB
      Views:
      3
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are no signs anywhere that your Trend Micro firewall has been replace by a "bogus" one. Why do you say this? If you still believe this is true, uninstall your Trend software, reboot, and then reinstall.

    Your logs are clean! Without facts and descriptions of what your problems are, I cannot help you with them. And in this forum, we only address malware issues.


    Normal part of Win XP. Don't believe everything you read in links tellling you it is a trojan. What you are referring to is a registry key not a file.

    Unknown! But not known to be malware. Right click on it and select Properties and select the version tab. Work you way thru the Item names and see who it belongs too. There could also be an associated daas_s.log file.


    Exactly what files and where are you seeing these? If in your Temp folder, then that is what they are ..... temp files used by applications and given random names to avoid possible conflicts with other temp files from other applications.

    Because it is System Restore which is a protected part of your OS and you should not be accessing it. Even antivirus program and other scanners cannot access it.

    Because you probably initially had HijackThis installed someplace other than where it is located now and the original path to it would therefore not exist if you deleted it. Or if you rename it as we requested, it will also not see the hijackthis.exe file since it does not exist anymore. This is not a problem!

    Not malware! This is a Software Forum topic! General comment: Windows Update is and has always been flaky.

    Not malware! This is a Software Forum topic! Some of your files are missing or not registered. General comment: Windows Update is and has always been flaky.

    I still don't see why you think this is bogus. They sound valid to me.

    Thousands of people every week have problems running all kinds of online scanners just like Symantec's. The reasons are not always obvious. It could just be a minor setting change on your system from the defaults or it could even be due to protection software (like Trend Micro) getting in your way.

    Unknown but based on your issues with Windows Update and Symantec Online, perhaps you have some windows system files missing or unregistered. Also you could still have some security settings or Trend Micro complicating the matter.

    Unknown and you are not being specific enough as to exactly when it happens and what you were doing in that window. Also I seriously doubt it has anything to do with malware.

    Unknown but again sounds more like a Windows system problem. If it were malware, you would never get to the security site to begin with.

    Yes and they should not be there after you finish running the program.

    Nothing that you mention sounds like malware. Perhaps you should try the software forum or you should look into a repair install or a totally reinstall.

    Another problems that points towards problems within your Windows OS not malware. This means you have an incorrect fileassociation for registry files (.reg files). It also could mean you have othe file associations wrong.


    Save the below quote box to a file name fixRA.reg (save it the same way as you did the fixME.reg file. Once saved, click Start, Run, and enter regedit and click OK. This will open the Registry Editor. Click File and Select Import. Navigate to the fixRA.reg file and double click it to import it.
    After doing the above, reboot your PC. Now see if you can double click the fixME.reg patch to import it automatically.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds