gomyron/DriveCleaner/PrivacyProtector

Discussion in 'Malware Help (A Specialist Will Reply)' started by danikat411, Jul 6, 2007.

  1. danikat411

    danikat411 Private E-2

    Help! My boyfriend's little brother got a little click happy and 'accidentally' installed some serious trouble on my PC.

    Now my home page is constantly switched to gomyron.com and my desktop is a webpage that's red and ominous looking and says My Privacy is in Danger (it installs a folder in C:\Windows that holds the images and such for the desktop) A flashing red triangle appears periodically in my system tray indicating that I need to install anti-spyware because my computer is compromised. And there are pop ups galor related to installing anti-spyware and warnign that my computer is infected. Always referencing Privacy Protector, Drive Cleaner and such. Links are also added to My Favorites for these 'products'.

    Attaching logs now.....
     

    Attached Files:

  2. danikat411

    danikat411 Private E-2

    Posting more logs....

    Also, I was not able to run much while in Safe Mode.....and the pop ups have dissipated considerably.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please re-run Counterspy and have it fix everything that it finds!!

    Now use add/remove programs to uninstall your old Java:
    J2SE Runtime Environment 5.0 Update 3
    J2SE Runtime Environment 5.0 Update 6


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    Remove all of your browser toolbars and extensions.

    Download and install Registrar Lite

    Then run Registrar Lite.

    Copy and paste the below into the Address box of registrar lit and hit the Enter key.

    HKEY_LOCAL_MACHINE\SYSTEM

    Then click the Security pull down ont the top menu and choose Take Ownership. Click OK in the next window to approve it. Now exit Registrar Lite and continue.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Please attach new logs for:
    Counterspy
    ShowNew
    GetRun
    HJT
    Avenger
     
  4. danikat411

    danikat411 Private E-2

    My PC is already acting SO much better!! It's really eery how quickly it's gone back to normal. But I'll take it!!

    Here are the logs...
     

    Attached Files:

  5. danikat411

    danikat411 Private E-2

    and the last two logs.....

    Thanks again for all of your help!! I appreciate it!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to have Counterspy fix/delete/quarantine what it finds!
    Please download DelCmdService, and save it to your Desktop.

    * Unzip the content to your Desktop (a folder named delcmdservice)
    * Double-click on the delcmdservice folder
    * Double-click on delreg.bat to launch the tool
    * When the tool has finished, please reboot your computer

    Attach a new RunKeys and HJT log.
     
  7. danikat411

    danikat411 Private E-2

    I have been letting CounterSpy fix/remove/quarantine everything it finds. However, a PurityScan file continues to be encountered.

    Here are the latest logs

    Thanks, again for your help.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is the log from counterspy:
    Status: Ignored
    Files detected
    C:\WINDOWS\Οracle\sеrvices.exe
    Will it not allow you to quarantine it?

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now:
    Run Registrar Lite navigate to each of the following keys (one at a time) and take ownership of them (I explained how to do that further down).

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETWORK_MONITOR]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_NETWORK_MONITOR]


    To take ownership of the key do the following:

    * Copy & Paste the registry key from above into the Address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    * Click-on Security in the top Menu
    * Select Take Ownership
    * Repeat these steps for all of the registry keys given above before continue to the next steps below.
    * Now leave RegistrarLite running and continue
    * Now run the fixME.reg REGISTRY PATCH below in this message.
    * Tell me the results. Any error messages?
    * Now in RegistrarLite click View and then Refresh
    * Now navigate one at a time to each of the above keys we took ownership of to make sure they were deleted.
    * If any of the keys still exist, move on down to PART 2 - Setting Permissions for Everyone below!.


    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    PART 2 - Setting Permissions for Everyone

    Run the below if some of the registry keys still exist after running the above steps.

    Now I want you to use Registar Lite again to navigate to each of the below keys (one at a time) by pasting them into the Address Bar and hitting return. But this time click the Security menu item and select Edit Permissions so we can change permissions to everyone ( I describe this down below the list of registry keys).
    After click Edit Permissions , here is what I expect you to see in the Group or user names area of the form:

    Everyone
    SYSTEM

    Select Everyone by clicking on it. Now at the bottom in the Permissions box click the check box for Full Control. The click Apply and then OK to get back to the main Registrar Lite screen. Nowright click on the registry key and select Delete. The click View and Refresh. Check to see if the registry key just deleted truly deleted. If so, move on to the next to work thru the whole list. If it does not delete, I want you to boot into safe mode and repeat these exact same steps to see if we can do it from safe mode.

    Then reboot your PC!

    Now run GetRunKey again and attach a new log as well as the avenger log.
     
  9. danikat411

    danikat411 Private E-2

    I don't even know if its possible....but I think its back. Can this thing just come back?!?!?

    It's crazy, but last night all of a sudden the same types of pop ups started up again...I've begun to go back and do the same cleanup as before but thought I should get this post resurrected while I get started again. :eek:
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem ...just be sure to attach new logs.
     
  11. danikat411

    danikat411 Private E-2

    Ok, this is MUCH worse than the first time around. I couldn't complete the BitDefender Scan because when I ran it and went to find the window amongst the pop ups; it would end up closing with the extra windows and I was never able to capture a log. I was attempting to re-run when I discovered that I can no longer connect to the internet.

    Lovely.

    I've tried renewing my IP address several times but I don't have a default gateway anymore for some reason. At first I blamed my modem but when the renew didn't work via ipconfig...I was at my wits end.

    So I started to do a System Restore.......went back through two weeks worth of Restore Points....and none would complete.

    I ran these logs this morning....though I'm almost certain that I'll have to wipe out my OS and start over. Recommendations?
     

    Attached Files:

  12. danikat411

    danikat411 Private E-2

    And my CounterSpy trial has expired but I ran it anyway, here's the log
     

    Attached Files:

    • cspy.txt
      File size:
      535 bytes
      Views:
      1
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since the trial use is over with Counterspy....uninstall it.
    Now disable all anti-virus and anti-spyware programs.
    Find and delete these!:
    C:\Documents and Settings\Edna\Favorites\Error Cleaner.url
    C:\Documents and Settings\Edna\Favorites\Privacy Protector.url
    C:\Documents and Settings\Edna\Favorites\Spyware&Malware Protection.url


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now after reboot, please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT
    * Avenger
     
  14. danikat411

    danikat411 Private E-2

    Ok, still having issues with renewing my IP address so I can't connect to the internet at home. Posting this from work.

    The pop ups are already slowed (if not gone) so I'm hopeful we're making progress. THANK YOU!!!

    I couldn't download that application but I ran CLEAN UP! which similarly wipes out cookies and temp files.

    Here are the logs.
     

    Attached Files:

  15. danikat411

    danikat411 Private E-2

    One more log and a screen shot of my connectivity issue....I have no DNS Server entry or Default Gateway

    Tested my router and it's fine.....so I'm going to try another cable and see if that does the trick....
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Go to start / run / type "cmd" without quotes and at the prompt type:
    "ipconfig /all" --- without the quotes.

    Tell me what it shows.
     
  17. danikat411

    danikat411 Private E-2


    I'll make sure to run Hijack This tonight....just to let you know....the screen shot from my earlier post is pretty much what I see in my ipconfig...but I'll screen shot that for you as well.

    I tried a different ethernet cable last night and that didn't work. So then I tried to connect my laptop (borrowed from work) to my modem and it had the same Low Connectivity/cannot renew IP address issue. So I may end up calling Verizon out for a service call. Because now I suspect the router even though they tested it and they said everything was working correctly. Because why wouldn't an entirely different computer work? :confused

    Thanks so much for your help!
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you tried a computer that you know does not have issues connecting to the web ...then I would suspect a problem in the modem.....
    Do the HJT and then lets see if there is any malware left ...to rule that out.
     
  19. danikat411

    danikat411 Private E-2

    My sincerest apologies!! I had to travel and was unable to keep up the effort to restore my PC until now. I got Verizon to send me a new router and even after that worked for ONE DAY....we had to get a repair guy out here today.

    But so far so good! YAY!!

    Here's my latest log. Hopefully I've gotten everything and won't have to worry about and more malware!
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem.

    Run HJT and have it fix these two items:
    O21 - SSODL: wmpconf - {14E41FCE-532A-42F9-A122-86A6BA6DF4C1} - C:\WINDOWS\wmpconf.dll (file missing)
    O21 - SSODL: wmpenv - {250B7257-9D5F-496D-AE8C-D31B4A2A0941} - C:\WINDOWS\wmpenv.dll (file missing)

    Were you not able to do this from earlier? You may have to disable all of your anti-virus and anti-spyware to do it!

    Otherwise, I take it that things are running well?
     
  21. danikat411

    danikat411 Private E-2

    Ok, so now I think I might have something related to lsass.exe

    Here is my bitdefender log.
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach new logs for:
    ShowNew
    GetRun
    HJT
     
  23. danikat411

    danikat411 Private E-2

    I appreciate your help.
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach new logs for:
    ShowNew
    GetRun
    HJT
    Avenger
     
  25. danikat411

    danikat411 Private E-2

    Thank you!! Attached are the logs
     

    Attached Files:

  26. danikat411

    danikat411 Private E-2

    here's the other
     

    Attached Files:

  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean. You may uninstall any programs we had you download (including CounterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds