Got Spysheriff....

Discussion in 'Malware Help (A Specialist Will Reply)' started by F-man, Aug 24, 2005.

  1. F-man

    F-man Private E-2

    Hi there :)

    I was one of the "lucky ones" that got SpySheriff on my PC 2 days ago. After that, I've been following all the steps in the SpySheriff Removal sticky and it took quite some time.

    Now I'm wondering if something is still left, after all the "cleaning up". I just now got a pop up with some porn on it. Can someone please help? I'm attaching the last log file from hijackthis. Any help would be appriciated :)


    F-man
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are running an illegal copy of Windows on this PC.

    And yes you have a bunch of other problems. You still have SpySheriff too. Are you sure you ran all the steps and added the registry patch? I still see the below in your log from SpySheriff:

    O4 - HKCU\..\Run: [SNInstall] C:\winstall.exe
     
    Last edited: Aug 24, 2005
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have so many problems it is hard to decide where to begin. You need to be more careful with where you are surfing and buy valid software and not use cracks.

    Let's start with the HaxDoor problem.

    Please download: HSFix.zip
    Extract the files from the ZIP File to a folder that you can find (preferably in its own folder - like c:\HSFix). Now boot to Safe Mode open the HSFix Tool folder and doubleClick hsfix.bat and let it run. It will produce a log here - C:\hslog.txt

    Now reboot in normal mode and post that hslog.txt file here as an attachment.

    Now continue with the below.

    Download L2MeFix Tool

    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe.
    Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop.

    DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.

    Your computer will go crazy for a bit, but just let it run. It should eventually spit out a log in Notepad. Please also attach this log to your message.

    Please don't run any other files in the L2MFix folder.

    Now goto Add/Remove programs and uninstall: P2P Networking

    Now continue to my next message.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    H:\WINDOWS\System32\P2P Networking\P2P Networking.exe
    H:\WINDOWS\kdx\KHost.exe
    H:\WINDOWS\System32\winldra.exe
    H:\WINDOWS\System32\explorer6s4.exe

    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://195.95.218.172/index.php
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://195.95.218.172/index.php
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://195.95.218.172/index.php
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://195.95.218.172/index.php
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://195.95.218.172/index.php
    O2 - BHO: (no name) - {78364D99-A640-4ddf-B91A-67EFF8373045} - H:\WINDOWS\system32\appwiz.dll
    O4 - HKLM\..\Run: [P2P Networking] H:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
    O4 - HKLM\..\Run: [kdx] H:\WINDOWS\kdx\KHost.exe
    O4 - HKLM\..\Run: [load32] H:\WINDOWS\System32\winldra.exe
    O4 - HKLM\..\Run: [Explorer32] H:\WINDOWS\System32\explorer6s4.exe
    O4 - HKLM\..\Run: [CPU Watcher] rundll32.exe H:\WINDOWS\cpu.dll,load
    O4 - HKCU\..\Run: [SNInstall] C:\winstall.exe
    O4 - HKCU\..\Run: [aupd] H:\WINDOWS\System32\symcsvc.exe
    O4 - HKCU\..\Run: [PayTime] H:\WINDOWS\System32\paytime.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O15 - Trusted Zone: *.asdbiz.biz
    O15 - Trusted Zone: *.skoobidoo.com
    O15 - Trusted Zone: *.slotchbar.com
    O15 - Trusted Zone: *.windupdates.com
    O15 - Trusted Zone: *.asdbiz.biz (HKLM)
    O15 - Trusted Zone: *.skoobidoo.com (HKLM)
    O15 - Trusted Zone: *.slotchbar.com (HKLM)
    O15 - Trusted Zone: *.windupdates.com (HKLM)
    O15 - Trusted IP range: 67.19.178.84
    O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
    O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab
    O20 - Winlogon Notify: drct16 - H:\WINDOWS\SYSTEM32\drct16.dll
    O20 - Winlogon Notify: tcpG4T - H:\WINDOWS\SYSTEM32\tcpG4T.dll
    O21 - SSODL: SysTray.Excn - {1722ECFF-4356-4f5b-B534-E67294FE75E9} - H:\WINDOWS\System32\pigkeocl.dll (file missing)
    O21 - SSODL: SysTray.Exsh - {1768ECFC-4F5C-4f5b-B134-D67294FC78E9} - H:\WINDOWS\System32\ohjlifba.dll (file missing)
    O21 - SSODL: Internet Explorer - {F28A40D7-AD0E-034A-C651-5F0ED76232E6} - H:\WINDOWS\System32\Lbcjcf32.dll


    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    H:\WINDOWS\System32\P2P Networking <--- the whole folder
    H:\WINDOWS\kdx <--- the whole folder
    H:\WINDOWS\System32\winldra.exe
    H:\WINDOWS\System32\explorer6s4.exe
    H:\WINDOWS\System32\symcsvc.exe
    H:\WINDOWS\System32\paytime.exe
    H:\WINDOWS\system32\appwiz.dll
    H:\WINDOWS\System32\Lbcjcf32.dll
    H:\WINDOWS\cpu.dll
    C:\winstall.exe


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.


    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. F-man

    F-man Private E-2

    Thank you for replying so fast :)


    I'm on it, here is the hslog.txt. (Don't know if that is important to you, but my Windows is at H:\, so the hslog.txt file was at H:\, not C:\ )

    Now continue with the rest.....
     

    Attached Files:

  6. F-man

    F-man Private E-2

    Ok, I'm now done with the rest.

    Just a couple of coments;
    Could not find the lines;
    O4 - HKCU\..\Run: [SNInstall] C:\winstall.exe
    O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -

    Found the rest.

    When I was going to delete the files, I could not find;
    H:\WINDOWS\System32\P2P Networking <--- the whole folder
    H:\WINDOWS\System32\symcsvc.exe
    H:\WINDOWS\System32\paytime.exe
    H:\WINDOWS\system32\appwiz.dll
    H:\WINDOWS\cpu.dll
    C:\winstall.exe

    "Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder."
    I am running with windows XP, and I found this folder under h:\windows\Prefetch I deleted the files there. Id that OK?

    Ok, havn't realy got to test things that much yet. But I have to say anyway; Thank you thank you thank you. I realy do appriciate all the help you have given me. Let's just hope I won't be bothering you again ;-)


    F-man
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Well you look clean now. How are things working?
     
  8. F-man

    F-man Private E-2

    Well it all looks good. The only thing i notice now, is a error message when I start my PC. The message is; "ENGINE; Error loading driver 1060." Other than that, it's all good :)


    F-man
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That error is not a malware problem. If could be related to your Outpost Firewall (or maybe video card drivers). You may want to try uninstalling Outpost, reboot, and then reinstall. If that does not help, I would have to point you to the Software Forum.

    Other than that, you should now see the below to help keep you clean:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds