Brave Sentry malware whipping me.

Discussion in 'Malware Help (A Specialist Will Reply)' started by phillik1, Sep 26, 2006.

  1. phillik1

    phillik1 Private E-2

    Ok gang - I need help. I've picked up a virus/spyware problem that is whipping my butt.

    First - I know I'm supposed to post several logs ..... however, this thing has cut off my access to the internet - so I'm on another computer for this. More in a minute.

    Second - I believe this to be a variant of the Brave Sentry/Spy Sheriff type problem.

    This is what I have done so far - and what I need.

    I was able to find help at PChell.com (before the crash) and to download and use in this order - in safe mode.

    1. SmitRem by NoahdFear
    2. CCleaner
    3. Ewido Anti-Malware
    4. HijackThis 1.99.1 and finally
    5. Killbox

    I used each one as instructed which regained my access to my desktop and my internet browser hompage (reset to msn.com).

    Before I rebooted in normal mode - I ran the Ewido one more time. It came back with a warning about this file _ which I am hand typing in

    C:\System Volume Inforation\_restore{526207BB-D2C5-4D86-B465-D6360C7E2041}

    I tried to have both Ewido and Killbox delete the file - no luck.

    I started over from scratch and noticed that CCleaner wants to add the file spoolsvv.exe (note the double v) - - which I could swear I was told to delete in the first go round - so now I'm confused and worried.

    I rebooted in normal mode. Internet will boot up and go to MSN - but if I try to go anywhere else - I just get a page not found error message - and then I can't even go back to MSN. I have both IE and Firefox - tried both.

    Here's what I need. Can anyone help me figure out just enought to get back to internet access - so that I can post my HJT logs etc?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    If you cannot attach your logs, it will be difficult to help. Why don't you just get copies of the logs onto the PC you posted your message from? And then attach them.

    I don't know where you are downloading your utilities from but if you do not download them from Majorgeeks, we cannot vouche for there authenticity. Please only download tools from Majorgeeks! CCleaner does not try to install spoolsvv.exe which is a Searchcentrix hijacker file.
     
  3. phillik1

    phillik1 Private E-2

    OK - I've done all the pre-reqs. This bug is just killing me - I've never had one this difficult to remove. I'll post my logs/reports now.
    I need all the help I can get!
     

    Attached Files:

  4. phillik1

    phillik1 Private E-2

    Here's the last two.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In the future please follow the directions for properly obtaining and posting a Bitdefender log. What you posted is not what we request and it is too difficult to read?

    Is your copy of Ewido a free trial version? If so, please uninstall it now.

    Now go back to the READ & RUN ME and properly follow the directions. You did not download HijackThis from our link. As a result you are using a version of HijackThis that has not been used in about 2 years. I need a new log from the proper version of HijackThis before we can continue. Also this time make sure you do not use MSconfig to control startups like you were doing. This is also mentioned in step 7 of the READ ME. You must be in Normal Startup mode not Selective Startup.
     
  6. phillik1

    phillik1 Private E-2

    Ok - dangit - I thought I did follow the instructions- I will do all that next.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I'm waiting for the new HJT log.
     
  8. phillik1

    phillik1 Private E-2

    OK - hope I did it right this time.

    Uninstalled ewido
    fixed boot
    used correct HJT
    used correct bitdefender save as
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2
    Kazaa Media Desktop 2.1.1
    Mozilla Firefox (1.0.4)

    Now install the current version of FireFox from: Mozilla Firefox



    The below is in your Email Sent Items folder. You should delete this:
    Local Folders\Sent Items\sc-keylog2.exe
    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    F3 - REG:win.ini: load=
    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\tttxxsp.chm
    C:\Documents and Settings\Administrator\Application Data\Lycos <--- the whole folder
    C:\WINNT\system32\cd_clint.dll
    C:\WINNT\system32\inistone.ini
    C:\WINNT\system32\ws386.ini

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach a the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  10. phillik1

    phillik1 Private E-2

    Ok- two problems to start.

    I can't get the Kazaa Media Desktop to uninstall - any suggestions?

    I also can't find the Local Folders\Sent Items\sc-keylog2.exe

    I do have the computer set to show hidden files. per the tutuorial.

    I thought I'd better see what I'm doing wrong before I go too much further.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try using this Your Uninstaller! 2006 to remove it.


    This is not a normal file. It is your part of your email application. I assume Outlook or Outlook Express???? Run it and look in your Local Folders\Sent Items folder.
     
  12. phillik1

    phillik1 Private E-2

    Uninstaller worked. But... I've looked like a pirate after hidden treasure and can't find that sc-keylog2 file. I've emptied out my MS Outlook sent file and looked in all the other files. I found an old version of outlook express -checked all of its folders - no luck. Any suggestions?

    Should I go ahead with the other steps?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes complete all the other steps!
     
  14. phillik1

    phillik1 Private E-2

    Here are the logs
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay your logs are clean! How are things working?
     
  16. phillik1

    phillik1 Private E-2

    Ok - seems to be working fine. I've got some system freezing issues now - but they seem minor and I'm going to guess they are not malware related. If anything changes, I'll check back.

    Does that mean you also don't see that SC-Keylog2.exe file anymore?

    Thank you so much for your help. I've felt lost without my functioning computer. You are the best.
     
  17. phillik1

    phillik1 Private E-2

    OK - that problem is getting a lot worse. My system will just freeze now - never did that before - even with no programs running.

    It also frequently either reboots with no warning - or goes to a blue screen with a long error message telling me I am having memory problems.

    Here is the error message

    STOP: 0x0000008E (0XC0000005, 0XF204680E, 0XF1A21A20, 0X00000000)

    Any help would be appreciated!
     
  18. phillik1

    phillik1 Private E-2

    Just FYI - it's getting worse. When I open internet explorer - it trys to open window after window and I can't get it to shut down without turning the computer off. Obviously, I'm on another computer typing this now.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! You would have to run PandaActiveScan again to see if it still finds it. You said you could not locate the related email file.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I doubt these are malware related but I will give you one more scanner to run that will look for rootkits at the end of this message.

    While a trojan named Haxdoor could cause a similar (but not exactly the same) error message, you never showed any signs of Haxdoor in your logs.

    You should take this problem to the Software (or maybe Hardware) Forum. Also take a look at the below:

    http://www.aumha.org/win5/kbestop.php


    Now let's just check for a rootkit which I don't think we will find. Download Blacklight Beta
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please post contents of the BlackLight log.
     
  21. phillik1

    phillik1 Private E-2

    OK - ran Blacklight - it found nothing. I will run Panda and keep looking for the keylogger. I read the MS memo on my error and I think I understand now. I updated my Windows XP and haven't had the error since. If it occurs again I will take the issue to the software/hardware forum.

    Again, I really appreciate the help. God Bless.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds