Help."Detected SPYware! System error #384" Problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by valesspot, May 31, 2006.

  1. valesspot

    valesspot Private E-2

    hello i will appreciate all posible support to all admins

    my desktop can not access the internet after my lil brother was playing with it. it gives me an blue screen message when i open internet explorer this message comes up" detected spyware! System error # 384.........your ip is 68.72.85.25. is using.............................................................................
    " i have tried all the 6 steps to remove malware and it did no help . on the bottom right side of the screen , a red icon appeares and tell me that ive been infected.
    Please take a look at my hijackthis LOg and let me know if this issue can be solved..
    i appreciate all Possible help that i can possibly get.
     

    Attached Files:

    • HJT.txt
      File size:
      6.9 KB
      Views:
      2
    Last edited by a moderator: May 31, 2006
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Your OS and IE versions are way out of date and represent a major security risk. After we fix your current problems, you must get updated or you will constantly be running into malware problems.

    Since you have no internet access, we will bypass normal procedures for the moment until we get internet access back. However, it is important that you pay close attention to the below warning!

    Serious Note: You have files like ibm000x.exe or dll on your PC which means you have a serious problem to deal with. This is a password stealing trojan. Your financial accounts (passwords etc) may have been compromised. See this link:

    http://www.liutilities.com/products/wintaskspro/processlibrary/ibm00001/
    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\System32\intell321.exe
    C:\Program Files\paytime.exe
    C:\WINDOWS\System32\422cc696.exe
    C:\WINDOWS\System32\0mcamcap.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
    O2 - BHO: (no name) - {196B9CB5-4C83-46F7-9B06-9672ECD9D99B} - C:\WINDOWS\system32\winbrume.dll
    O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
    O4 - HKLM\..\Run: [intell321.exe] C:\WINDOWS\System32\intell321.exe
    O4 - HKLM\..\Run: [SysTray] C:\Program Files\paytime.exe
    O4 - HKLM\..\Run: [422cc696.exe] C:\WINDOWS\System32\422cc696.exe
    O4 - HKLM\..\Run: [0mcamcap] C:\WINDOWS\System32\0mcamcap.exe
    O4 - HKLM\..\Run: [win32hp] C:\WINDOWS\System32\win32hlp.exe
    O4 - HKLM\..\RunServices: [0mcamcap] C:\WINDOWS\System32\0mcamcap.exe
    O4 - HKCU\..\Run: [shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe"
    O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
    O4 - HKCU\..\Run: [422cc696.exe] C:\Documents and Settings\JORGE CASTELLANOS\Local Settings\Application Data\422cc696.exe
    O4 - HKCU\..\Run: [0mcamcap] C:\WINDOWS\System32\0mcamcap.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\winstall.exe
    C:\Documents and Settings\JORGE CASTELLANOS\Local Settings\Application Data\422cc696.exe
    C:\Program Files\paytime.exe
    C:\WINDOWS\System32\intell321.exe
    C:\WINDOWS\System32\422cc696.exe
    C:\WINDOWS\System32\0mcamcap.exe
    C:\WINDOWS\System32\win32hlp.exe
    C:\WINDOWS\system32\winbrume.dll
    C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe <--- actually, look for any files here that begin with ibm00 and end with anything else and delete them (like ibm00001.exe, ibm00001.dll, ibm00002.exe, ibm00002.dll ..... etc).
    C:\Program Files\Common Files\Microsoft Shared\Web Folders\tmp.tmp


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now. If you have internet access now, you MUST start running the below to make sure we found everything:

    READ & RUN ME FIRST Before Asking for Support
     
    Last edited: May 31, 2006
  3. valesspot

    valesspot Private E-2

    i thank you very much. i was now able to access the internet and everything looks great.
    Some of the files that were on the Windows Explorer to delete were not listed to be deleted. here are the ones that i was not able to find in the list...
    C:\winstall.exe

    C:\Documents and Settings\JORGE CASTELLANOS\Local Settings\Application Data\422cc696.exe (the local settings file was never there.)

    C:\Program Files\Common Files\Microsoft Shared\Web Folders\tmp.tmp

    This files were not found.
    Here is my new Hijacthis log below..

    Edit by chaslang: Inline log attached
     

    Attached Files:

    Last edited by a moderator: Jun 1, 2006
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please remember that logs must ALWAYS be attachments.

    You need to start running ALL steps in the READ & RUN ME now. The infections you had were serious and it is important that you run all of those steps so we can make sure nothing else is hiding. HijackThis logs do not show everything. So run the READ ME and attach the two logs from step 6.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds