Can't get rid of this spyware!!! Help!!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lackis, Sep 7, 2004.

  1. lackis

    lackis Private E-2

    I am having so many problems with spyware. Somehow, someone downloaded Kazza Lite Accelerator on my computer, and now i'm stuck with all this spyware!

    I have run the following programs to try to get rid of the files: Trend Micro virus scan (found 4 trojans that were unopened), I have Zone Alarm running in "Stealth Mode" so no programs can gain internet access without me knowing, Spyware Doctor, Spyware Blaster, Lava Soft Adaware SE, Spybot search and destroy and probably two or three more. Oh and Registry Mechanic.

    Major Issue #1:
    When I'm in Zone Alarm, I see some new programs that have tried to access the internet. When I do a google search on them, I gather that they are spyware. I have deleted them from wherever they have made their home as well as from the registry (if i can find them) BUT they keep coming back. These programs are: Edow.exe, inetfuel.exe, & is-QCJ1V.tmp. I have run adware and the other program and they do not find these files. The Edow.exe program is located in my C:/WINNT/system32 folder, as well as "WrapperOuter.exe" and some other suspicious looking items! Please help me to get rid of them. I have HiJack This and did not post my log because you requested it. Please let me know if I should post it. I also recently got rid of something called "WoModule". When it was installed, everytime I would delete out of my programs menu a program called "Earn" and when I deleted it and all then restarted it came right back. I finally got rid of it...I think (i haven't seen it for a few days).

    Major Issue #2:
    This really isn't that big a deal, but some of the address of the pop-ups I get are as follows:
    http://www.ad-w-a-r-e.com, http://adv1.eblocs.com, http://69.20.56.3, http://www.xzoomy.com, http://ads1.revenue.net/r?site_id=12324&pplacement_id=1&r

    A lot of the other pop ups I was getting were casino related. Please help me!
    This is my work computer and my dad (I work for him) and I are both at our wits end! We are not computer illiterate so please feel free to command us around and suggest different things! I can post my hijack this log if it helps!

    Thanks so much for your consideration and any help is appreciated!
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Have you tried running these programs in safe mode. They are hard to delete because they are running. Did you check add\remove programs for anything to remove that you did not install?

    Personally, sounds like you have done quite a bit and know enough to use Google, etc., so I would like to see your Hijack This log. Please attach it as a text file.
     
  3. lackis

    lackis Private E-2

    StartupList report, 9/7/2004, 8:39:30 AM
    StartupList version: 1.52
    Started from : C:\Documents and Settings\Terry Lowry\My Documents\Downloads\HijackThis.EXE
    Detected: Windows 2000 SP4 (WinNT 5.00.2195)
    Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    * Using default options
    ==================================================

    Running processes:

    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\PROGRA~1\APC\POWERC~1\agent\pbeagent.exe
    C:\WINNT\system32\ZoneLabs\isafe.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\System32\nvsvc32.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\ZoneLabs\vsmon.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    C:\WINNT\system32\CTHELPER.EXE
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Spybot\TeaTimer.exe
    C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    C:\Program Files\BPFTP Server\G6FTPSrv.exe
    C:\Program Files\Spyware Doctor\spydoctor.exe
    C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
    C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe
    C:\Program Files\Trend Micro\Internet Security\PCClient.EXE
    C:\Program Files\Trend Micro\Internet Security\PCCGUIDE.EXE
    C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe
    C:\Documents and Settings\Terry Lowry\My Documents\Downloads\HijackThis.exe
    C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
    C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
    C:\Program Files\Opera\opera.exe

    --------------------------------------------------

    Listing of startup folders:

    Shell folders Startup:
    [C:\Documents and Settings\Terry Lowry\Start Menu\Programs\Startup]
    BPFTP Server.lnk = C:\Program Files\BPFTP Server\G6FTPSrv.exe

    Shell folders Common Startup:
    [C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
    Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    --------------------------------------------------

    Checking Windows NT UserInit:

    [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    UserInit = C:\WINNT\system32\userinit.exe,

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    Synchronization Manager = mobsync.exe /logon
    NvCplDaemon = RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
    nwiz = nwiz.exe /install
    NvMediaCenter = RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
    NeroFilterCheck = C:\WINNT\system32\NeroCheck.exe
    HPDJ Taskbar Utility = C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe
    HPHmon03 = C:\WINNT\system32\hphmon03.exe
    SunJavaUpdateSched = C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    WINDVDPatch = CTHELPER.EXE
    UpdReg = C:\WINNT\UpdReg.EXE
    Jet Detection = "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
    Zone Labs Client = "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    pccguide.exe = "C:\Program Files\Trend Micro\Internet Security\pccguide.exe"
    PCClient.exe = "C:\Program Files\Trend Micro\Internet Security\PCClient.exe"
    TM Outbreak Agent = "C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe" /run
    VBundleOuterDL = C:\Program Files\VBouncer\BundleOuter.EXE

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    SpybotSD TeaTimer = C:\Program Files\Spybot\TeaTimer.exe

    --------------------------------------------------

    Shell & screensaver key from C:\WINNT\SYSTEM.INI:

    Shell=*INI section not found*
    SCRNSAVE.EXE=*INI section not found*
    drivers=*INI section not found*

    Shell & screensaver key from Registry:

    Shell=Explorer.exe
    SCRNSAVE.EXE=C:\WINNT\PENGUIN.SCR
    drivers=*Registry value not found*

    Policies Shell key:

    HKCU\..\Policies: Shell=*Registry key not found*
    HKLM\..\Policies: Shell=*Registry value not found*

    --------------------------------------------------


    Enumerating Download Program Files:

    [{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}]
    CODEBASE = http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab

    [HouseCall Control]
    InProcServer32 = C:\WINNT\DOWNLO~1\xscan53.ocx
    CODEBASE = http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab

    [Update Class]
    InProcServer32 = C:\WINNT\System32\iuctl.dll
    CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38201.5935416667

    [{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}]
    CODEBASE = http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab

    --------------------------------------------------

    Enumerating Winsock LSP files:

    Protocol #1: C:\WINNT\system32\ZoneLabs\vetredir.dll
    Protocol #20: C:\WINNT\system32\ZoneLabs\vetredir.dll

    --------------------------------------------------

    Enumerating ShellServiceObjectDelayLoad items:

    Network.ConnectionTray: C:\WINNT\system32\NETSHELL.dll
    WebCheck: C:\WINNT\system32\webcheck.dll
    SysTray: stobject.dll

    --------------------------------------------------
    End of report, 6,125 bytes
    Report generated in 0.110 seconds

    Command line options:
    /verbose - to add additional info on each section
    /complete - to include empty sections and unsuspicious data
    /full - to include several rarely-important sections
    /force9x - to include Win9x-only startups even if running on WinNT
    /forcent - to include WinNT-only startups even if running on Win9x
    /forceall - to include all Win9x and WinNT startups, regardless of platform
    /history - to list version history only
     
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Thats not a Hijack This log file. Run Hijack This, hit scan. Choose the save log button, select all files at the bottom and name it hijackthis.txt or similar, then attach. Thanks!
     
  5. lackis

    lackis Private E-2

    My Bad! Sorry about that!

    [log removed and uploaded by Kodo]
     

    Attached Files:

    • hjt.txt
      File size:
      4.5 KB
      Views:
      2
    Last edited by a moderator: Sep 7, 2004
  6. Kodo

    Kodo SNATCHSQUATCH

    the only thing I can see in there is this

    O4 - HKLM\..\Run: [VBundleOuterDL] C:\Program Files\VBouncer\BundleOuter.EXE
     
  7. lackis

    lackis Private E-2

    Now the only problem is I can't find that file. I get an error message saying " 'C:\Program Files\VBouncer' is not a valid folder". Anything anyone can suggest to help?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds