followed instrucs and almost there

Discussion in 'Malware Help (A Specialist Will Reply)' started by helpalady, Feb 9, 2006.

  1. helpalady

    helpalady Private E-2

    I sort of followed the instructions, at first I couldn't even get online line to update anything, but as I ran and reran the different files I was making progress, in the end I did run everything in the order you perscribed. could not run bitdefender nor panda.
    I have killed spywarestriker, spyax, spy sherriff a few trojans and many others of the over 600 things that adaware and the others have found. Even ridded myself of that pesky x.
    The lasting problem is in IE, when I am online which is why I haven't been able to run bitdefender or panda and why I have typed this 3 times, I have new windows popping up most go to shopping sights and ad w a r e. they are usually one at a time but right at the end of my upload or download (ie posting my HJT file or running bitdefender) I get bogged down with the popups and I freeze.
    Any suggestions?
    On your attachment page I keep getting upload errors, it says invalid file. I will continue to read and see what I am doing wrong.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MGs!

    Use a different browser like Mozilla FireFox to attach your log. Since you cannot run either online scan I would also suggest that you run the below and attach the requested log.

    Running Spy Sweeper
     
  3. helpalady

    helpalady Private E-2

    I am on a different computer and will upload the file from here. I will get foxfire tomorrow at work as I am in the country with only dialup for access.. remember those days.
    I want to say after I sent my initial posting I was rereading it and the word windows was underlined, I was wondering why I had done that and when I moved the mouse over it a pink box poped up and disappeared faster than I could read what it said.
    Right now IE is basically unusable, everything goes to not found.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay your first problem is that your OS and IE versions are way out of date and represent a major security risk to you. Once we have fixed any existing problems on your PC, you must get updated. Some of your problems may even be due to the fact that you have not installed all the necessary security updates to protect you.

    Running with no antivirus application and no firewall is just as bad as the above. You have a bunch of problems and some are very bad as you will see below.

    You have a major problem with the below:
    You also have a second trojan that steals passwords for financial related locations. See:
    http://www.securitymob.com/my_smob/alert_info.asp?alert=29192


    You should looking into changing all of your passwords especially for financial institutions. You should call them and check to make sure tha no suspicious activities have been occurring. Do not use this PC to do any password changes or any financial related activities.


    Let's begin your cleanup!


    First download GetRunKey125b.zip to your PC someplace you can locate it. Then extract the files from the ZIP. Locate the getrunkey125b.bat file and double click on it to run it. It will create a file named runkeys.txt in the root of drive C: (C:\runkeys.txt) . This log will also popup in a notepad window which your can just close. Upload the runkeys.txt file here as an attachment. Do this before continuing to the below.

    Now look in Add/Remove programs and uninstall Crystalys_Media if found.

    Now run the procedure in the following link and attacht the two logs: Look2Me VX2 Removal

    Now continue on to my next message.
     
    Last edited: Feb 10, 2006
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After doing what I posted in message number 4, continue with the below.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\windows\batserv2.exe
    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - Default URLSearchHook is missing
    F3 - REG:win.ini: run=C:\WINDOWS\inet20003\services.exe
    O2 - BHO: CMBHO Class - {6379A99A-9102-446C-A837-0623E1810D75} - C:\Program Files\Crystalys media\cm.dll
    O3 - Toolbar: CM Band - {159C2E51-9823-11D2-8DDC-D84A1B4ACD4D} - C:\Program Files\Crystalys media\cm.dll
    O4 - HKLM\..\Run: [lihymgnA] C:\WINDOWS\lihymgnA.exe
    O4 - HKLM\..\Run: [SystemLoader] C:\WINDOWS\sysldr32.exe
    O4 - HKLM\..\Run: [Microsoft Office] C:\windows\System32\msvcp.exe
    O4 - HKLM\..\Run: [HostSrv] C:\windows\sachostx.exe
    O4 - HKLM\..\Run: [lspins] "C:\windows\System32\igps.exe"
    O4 - HKLM\..\Run: [BatSrv] C:\windows\batserv2.exe
    O4 - HKLM\..\Run: [CMLoader] rundll32.exe "c:\program files\crystalys media\cm.dll",MakeInjection
    O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
    O4 - HKCU\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe
    O4 - HKCU\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exe
    O20 - Winlogon Notify: ShellScrap - C:\WINDOWS\system32\jt2607fse.dll
    O21 - SSODL: SysTray.Exsl - {6368D5FC-6F5C-4f5b-B164-E67214F67859} - C:\windows\System32\pgpdobmp.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Crystalys media <--- the whole folder
    C:\Program Files\Common Files\VCClient <--- the whole folder
    C:\WINDOWS\inet20003 <--- the whole folder
    C:\WINDOWS\lihymgnA.exe
    C:\WINDOWS\sysldr32.exe
    C:\windows\System32\msvcp.exe
    C:\windows\sachostx.exe
    C:\windows\System32\igps.exe
    C:\WINDOWS\system32\jt2607fse.dll <--- this may have changed names by now or it may be gone due to running L2MeFix
    C:\windows\System32\pgpdobmp.dll
    C:\windows\batserv2.exe
    C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe <--- look in this folder and delete all file that begin with ibm000 . You may find some that are .exe files and some that are .dll files. They should show in the runkeys.txt log too.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. helpalady

    helpalady Private E-2

    So much for being almost there!
    I followed your instructions and here are the three logs. I will continue with your instructions.
    BTW, thankfully this is not my computer it is my niece's, but I have warned her to change all her passwords. I am a little concerned as I accessed my email (Internet not outlook)through this computer. Guess I better change that password. I also deleted norton av, I had tried to disable it but it wouldn't let me do anything I was trying to do... well I thought it was the best thing to do at the time as I was only trying to get this computer to a "workable" spot.
    OK Back to work.
    hanks for all the help.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! SpySweeper fixed a ton of problems. After you complete the rest of my instructions attach the runkeys.txt log, the L2MeFix logs (these will probably not be needed if you have not run them yet because it looks like SpySweeper fixed the Look 2 Me infection), then attach the follow up HJT log requested at the end of message # 5.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The GetRunKey125b.zip link was broken below if you tried it and had a problem I fixed it now.
     
  9. helpalady

    helpalady Private E-2

    The getrunkey125b s log is empty, I tried to upload it and it wouldn't go, so I opened it to see what I was missing and there is nothing there, When I looked at the dos window it says a ton of stuff over and over about grep no a valid file. No I did not run grep.
    I followed all the rest of the instructions
    a lot of the files you told me to delete were not there.

    oops, I missed the look2me vx2 removal. I will do that now.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It would only be empty if you did not unzip both files from the GetRunKey125b.zip file. You must make sure that both files were extracted from the ZIP file to the same folder. You cannot run the GetRunKey125b.bat from inside the zip file. If you do, it will not find the grep.exe file that it needs.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [lihymgnA] C:\WINDOWS\lihymgnA.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\lihymgnA.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  12. helpalady

    helpalady Private E-2

    You are right I only extracted getrunket, I will try again and also do the last set of instructions.
    Here are the logs of l2me
     

    Attached Files:

  13. helpalady

    helpalady Private E-2

    I am off to print your last instructions, then complete them. I am using firefox, shall I try IE and see what is happening over there?
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Now run GetRunKey125b.bat again and attach a new runkeys.txt log. Yes, give IE a run.
     
  15. helpalady

    helpalady Private E-2

    I ran HJT and "fixed" the lihymgnA line, it was not in windows under safe boot, I also did a search for it both in safe mode and regular boot, it does not show up.
    I ran IE, it seems much slower.. I think I have fallen in like with firefox.
    From what I can tell, most of the problems in this computer occured on jan 9 & 12, 2006, there are no files left from those dates. Don't know if that means anything, but thought it was worth mentioning. I can boot up and shut down without any hang ups, no error messages. I am almost afraid to think we are getting there.
    Are you tired yet?
    And that was meant to say THANK YOU
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you clicked fix on the below line:
    O4 - HKLM\..\Run: [lihymgnA] C:\WINDOWS\lihymgnA.exe

    It is still in your log!. Try again and then reboot and look for yourself at a new log to see if it is gone. If it is not gone, do the below:
    • Uninstall Spy Sweeper and MS Antispyware
    • Reboot
    • use HJT to fix that O4 line again
    • reboot to safe mode and just double check to make sure the C:\WINDOWS\lihymgnA.exe does not exist. Delete if found
    • reboot into normal mode and post a new HJT log. But look at it first yourself to see that the O4 line is gone.
     
  17. helpalady

    helpalady Private E-2

    I ran HJT and I did not find lihymgnA in the log at all, I wonder if I sent you the wrong log. I have not gone any further. Here is this mornings log.
     

    Attached Files:

  18. helpalady

    helpalady Private E-2

    While waiting I tried to run bitdefender in IE, it found 2 items it removed, originally the time was 2.5 hours to run, at 1.5 hours in with 20 mins left I got a "send to ms" error message and the program would have to shut dowm. The error report had to do with LSAShell, the auto shutdown window appeared, I opened task manager to try to stop it because bitdefender was still running. taskmanager stopped the shutdown but seconds later the entire computer froze up. I had to do a hard shutdown. Now I will not do anything more until I hear from you.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your last log was clean. What you need to do immediately is the below start from step 1 and work thru to the end. You must complete step 1 or you will keep having problems like the LSA shell message you got. Also you are very susceptable to a whole load of trojans and viruses right now. So start running the below now:

    How to Protect yourself from malware!
     
  20. helpalady

    helpalady Private E-2

    Thank you, I will get started right now.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! When you complete all the steps, post a new HJT log so I can verify you have been updated properly.
     
  22. helpalady

    helpalady Private E-2

    Life in the fast lane...
    I am trying to download the microsoft updates, the first one downloaded, then installed and said I had to restart to activate it, I restarted, then went back to start on more and the MS world pops up on my taskbar and says updates are ready to install, it is the same update, meanwhile the ms site says it cannot continue until I reboot and complete the last update. it is giving me this error message Error number:0x8DDD0007
    Do I maybe have one of the programs we used running? It is not listed in the task manager?
     
  23. helpalady

    helpalady Private E-2

    This is the update I can't seem to get anywhere with.

    Update for Background Intelligent Transfer Service (BITS) 2.0 and WinHTTP 5.1 (KB842773)
    0 KB , 0 minutes (Downloaded; ready to install)
    This software updates the Background Intelligent Transfer Service (BITS) to v2.0 and updates WinHTTP. These updates help ensure an optimal download experience with future versions of Automatic Updates, Windows Update, and other programs that rely on BITS to transfer files using idle network bandwidth
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the attached file and unzip to your harddisk (anyplace you can find it). You will see FixWinUpd.bat after unzipping. Double click on FixWinUpd.bat and in a few seconds a notepad windows will popup. This notepad file is already save at c:\winupd.txt

    Upload winupd.txt as an attachment.
     

    Attached Files:

  25. helpalady

    helpalady Private E-2

    Ok, here it is.
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  27. helpalady

    helpalady Private E-2

    well it is telling me access is denied. It did not install
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When does it say this?

    Where you able to download the file to your PC?

    Note: You must make sure you have validate your OS to Microsoft first. Did you click on the below to run genuine Microsoft Windows validation. If you have not done this at any point, you must do this first or you cannot install updates.
     
  29. helpalady

    helpalady Private E-2

    I have followed your link twice and gone through the proceedure, it does validate the software, downlaods, and seems to be just about done installing when the access denied window pops up.
    I will wonder arount the update sites help files and see what I can find. I hate to keep dragging you through this.
    As far as being a "legal" copy of xp, I honestly do not know, my neice bought this computer from her boss when he was delcaring bankrupcy about a year ago.
    WHen I looked at the update history, there were no updates for xp only windows, no version named, and the last was in 2004.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure it is actually validating? Attach a new HJT log.

    Access denied to what? What is the full message in the Window?

    It is starting to sound like the OS is not legit or that Windows was never properly activated. If this is true, I cannot help you any further. You would have to get a legitimate licensed copy of Windows installed.
     
  31. helpalady

    helpalady Private E-2

    The first time I tried through the link you sent I don't believe it validated.
    The second time it actually downloaded and ran validation software, then took me to download the update.
    The third time it would just skip the validation software and go straight to the update download

    It is a very samll window, like 1 inch x 1 inch with a red circle with an X in it to the left, to the right of the circle all it says is access denied, when you click on the upper right x to exit another box comes up saying it will have to uninstall the update in order to exit click ok, and thats it.

    If this is true, I have no problem fixing it. I did send an email to update support and it scanned the computer and they will get back to me in 24 hours. So if this is the problem at least we have a fix for that.

    I am going to stop scratching my head for 24 hours, unless you see something in this updated log.
    Again, thank you for all the help, I will let you know what they say.
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well it does not appear to me that your OS is illegal. Based on the below line in your HJT log it would appear that Microsoft has validated that your OS is genuine.

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835

    Let's try something different. This will not get you up to SP2 but at least it will be better than where you are at. Download the Windows XP Service Pack 1a (SP1a) update from the below link and then install it. Post a new HJT log after it installs successfully.

    http://www.softpedia.com/get/System/OS-Enhancements/Windows-XP-Service-Pack-SP1a.shtml
     
  33. helpalady

    helpalady Private E-2

    I am so sorry, I misread the email notifing me you had responded and thought you were waiting for me to get an answer from MS.
    Heres what has happened so far. After three trys of them trying to send me a file they did. it was Reset_subinact.zip, I was to unzip and run it, then reboot in safe mode, then try to install the first update. All went well, I went back to the update page and continued my updates. The first nine went through no problem, the tenth was service pack 2, it took 12 hours to download it (44 kbps), then when it was installing the computer froze again, just to note, nothing else was running at the time other than I was online, I had to do a hard shutdown, when I rebooted I recieved a window alert that my system was unstable and I needed to go to add/remove and remove the SP2 and redownload it. I started to do that but then a warning box came up and said I was going to mess up a lot of my installed programs and they might not work, I thought about it and decided to continue on, then another warning window came up and told me I was going to mess up a bunch of files, and the files didn't look like stuff I wanted to mess with (a bunch of dlls & serious stuff) so I stopped the uninstall and I am now wondering what to do. You and I have come so far and I am very proud that we have cleaned this thing off without losing a thing. I really don't want to mess it up now. I did turn back on restore and set a restore point prior to downloading any of the updates.
    Where to go from here??
     

    Attached Files:

  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Instead of installing it while online with MS Update. Try downloading the whole SP2 package from the below link:

    http://www.microsoft.com/downloads/details.aspx?FamilyID=049c9dbe-3b8e-4f30-8245-9e368d3cdb5a&DisplayLang=en

    Then at least you have it and can install it anytime. It will still take a long time to download with your connect speed. I'm not sure what you are referring to with programs and files getting messed up. At this point you would be better served discussing this in the Software Forum since it is really not a malware problem.

    Your alternative to SP2 is to download SP1a from the link I gave you earlier and use it instead. While it is not as secure as SP2, it is a heck of a lot better then what you are using now and it may give you fewer compatibility issues (if that is what you are having with SP2).
     
  35. helpalady

    helpalady Private E-2

    I just wanted to update and end this thread.
    I finally got all updates installed, the main ones had to be installed via safe mode, but they are all there.
    I am getting ready to install AV and tpye up a protection scedule and ship this baby back home.
    I am attaching a final HJT log just in case you want to take a peek before bidding us farwell.

    Again, Thank you, I have learned a lot and am very interested in this subject and plan on continueing to learn.
     

    Attached Files:

  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good.

    You can have HJT fix the below left over from Spy Sweeper:

    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    Is everything running okay now? Have you completed the rest of the How to protect thread?
     
  37. helpalady

    helpalady Private E-2

    All seems to be working fine, I think it is a little slow, but its not the largest system out there either.
    I cleaned up that last file you mentioned.
    I totally updated XP, and turned on auto updates
    I added AVG, and it is ON!
    I am leaving AdAware with the instructions to run at least weekly, if not more.
    I am leaving CCleaner to be run again weekly
    The only thing I haven't done yet is add Zone Alarm, I am a little confused as to what/how and should I really disable XPs firwall??? And part of me wonders is that just a little too much for my neice to handle, I will be getting calls every night about a new item popping up. I know at least it will be popping up and not loading on.
    OK, talked myself into it. I will go do that now and then I do believe that is all that is left on the list.
    Did I get it all right?
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The how to protect thread gives you a link that explains how to disable the Windows XP SP2 firewall. It is pretty easy to do.

    Note that Ad-Aware provides no blocking of malware. You need to keep Spybot install and use it's Immunize functions. You also should use the protection provided by SpywareBlaster.

    Do you still have MS Antispyware installed?
     
  39. helpalady

    helpalady Private E-2

    WOW..'Do I need to keep all four of those? And would I leave the MS on all the time? Run the Spybot weekly?
    I am looking for sort of a schedule.
    SOmebody really needs to get those "spy-guys"
    I am really thinking this little ol 256 is not going to be able to do anything other than run all this anti stuff.
    Guess I better go check and see if it is upgradeable.
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes keep Ad-Aware, Spybot S&D, SpywareBlaster, and note that you should update to Microsoft Windows Defender as now shown in the How to protect thread (MS Antispyware has been discontinued and is replaced by Windows Defender.)
    Ad-Aware uses no resource exept when scanning.
    Spybot S&D with only SDHelper enable and Immunize enabled uses very little resources accept when scanning)
    SpywareBlaster uses no resources
    Microsoft Windows Defender will use resources and provides fulltime active protection from malware.

    Based on how much surfing you do, weekly should be good.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds