freeprodtb and look2me (i think)

Discussion in 'Malware Help (A Specialist Will Reply)' started by arsoisaen, May 13, 2006.

  1. arsoisaen

    arsoisaen Private E-2

    so was dling off shareaza (p2p) and got this virus, once i smelled something fishy i immediately hit the power button, but it was too late.

    freeprodtb is now on my desktop, tagasaurus was there (got rid of it somehow)

    what i've done is run look2me-destroyer (didn't find any), symantec l2m fix, and general adware/spybot, and brute force uninstaller

    i also already uninstalled something called toolbar888 from add/remove programs


    here is my hjt log:


    Edit by chaslang: Inline HJT log removed!

    and here is my l2mfix log:

    Edit by chaslang: Inline L2MeFix log removed. This procedure is no longer even used as it does not work.

    thanks for any help
     
    Last edited by a moderator: May 13, 2006
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read and follow the sticky thread procedures. ALL logs must be posted as attachments and no HijackThis should be posted with having run standard cleaning procedures.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. arsoisaen

    arsoisaen Private E-2

    sorry bout before, been a year or so since i've posted

    anyways ran all the things before, windows malware found TONS in like directories i didn't know existed (not sure if i made them or they were there befroe)

    in my add/remove theres toolbar888 which i cant remove

    attacked is hjt and bdscan, the panda scan wont work for me, everytime it initializes it then redirects my browser
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to empty your Trend Micro\Internet Security 2005\Quarantine folder as indicated in step 0 of the READ ME. You should check to make sure it is empty now even though Bitdefender may have gotten much of it.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\PROGRA~1\ipwins\ipwins.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll
    O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll
    O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe

    It's your decision on the PartyPoker stuff, but we highly recommend against this stuff!
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\PartyGaming\PartyPoker\RunApp.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\PartyGaming\PartyPoker\RunApp.exe


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\ipwins <--- the whole folder
    C:\WINDOWS\cfg32r.dll
    C:\WINDOWS\cfg32o.dll
    C:\WINDOWS\system32\csrrs.exe <--- may be gone already

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  5. arsoisaen

    arsoisaen Private E-2

    everything seems to be working now (task manager, regedit), i think what killed it was actually adaware, once i ran that the freeprodtb disappeared.

    i haven't reinstalled shareaza yet so im not sure if it'll constantly appear such as last time

    also i couldn't find the program files\ipwins\ipwins.exe you told me to delete, but other than that it seems to be running fine.
     

    Attached Files:

  6. arsoisaen

    arsoisaen Private E-2

    err im not sure how to edit post so sorry for the double but i just noticed that the toolbar888 is still on my add/remove, and i can't get rid of it. also there are random folders around my computer that i've been deleting, but the placement seems completely random and all the folders are empty
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis may have deleted it when fixing the O4 line.

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  8. arsoisaen

    arsoisaen Private E-2

    just want to be sure before i do the system restore but should i just leave the toolbar888 alone? its in add/remove that i cant get rid of and also has a folder in my program files.

    thanks again
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you cannot uninstall it using Add/Remove programs, use HijackThis to uninstall it.

    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Choose the program you wish to uninstall by selecting it in the window.
    • Now Click Delete this entry

    Then delete the c:\Program Files\toolbar888 folder!

    Now continue with the System Restore toggle and the How to protect thread.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds