Help in spyware removal please

Discussion in 'Malware Help (A Specialist Will Reply)' started by fuzzydi, Aug 26, 2006.

  1. fuzzydi

    fuzzydi Private E-2

    I'm helping my mom clean the malware/spyware off her pc. I have followed the instructions in the "READ AND RUN ME FIRST" thread to the best of my ability. The Panda Active Scan would not run in safe mode...I kept losing the internet connection. Plus...the Panda website has changed a little in the last few days, so the scan looks a little different. Panda says it found "virtumonde" in the Windows Registry, but when I ran Vundofix, it didn't find anything.

    System Info: MS Windows XP Pro, SP2, Dell Dimension 2400, Pentium 4, 253 ghz, 256 MB ram.

    I am attaching the following files:

    runkeys.txt
    newfiles.txt
    bdscan.txt

    On my next post I will attach the HJT log file
     

    Attached Files:

  2. fuzzydi

    fuzzydi Private E-2

    Attached is the HJT logfile...

    Thanks in advance!!!

    Diane
     

    Attached Files:

  3. fuzzydi

    fuzzydi Private E-2

    Attached is an Ewido report... I selected to fix the reported issues.

    Thanks again!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run MSconfig and select Normal Startup as requested in step 7 of the READ ME. Then attach a new HJT log and a new GetRunKey log.

    The bdscan.txt log you attach is a log from PandaActiveScan. Please attach the log from Bitdefender that was requested in step 6.

    You also need to goto Add/Remove programs and uninstall this: Windows WMF Metafile Vulnerability HotFix 1.4

    You also did not really follow the instructions in the READ ME. You still have Spybot - Search & Destroy 1.3 installed. This has not been used in almost 2 years. Please uninstall this old version and install the correct version from the READ ME.

    Your FireFox and Sun Java versions are also way out of date.
     
    Last edited: Aug 26, 2006
  5. fuzzydi

    fuzzydi Private E-2

    I'm so sorry! That's what happens when I try to work on this an hour here and an hour there. I can't remember each step that I've taken. I ended up bringing her computer home with me today, so I can spend more time and attention on it. Thanks for your help!
     
  6. fuzzydi

    fuzzydi Private E-2

    OK...let's try this again. I pretty much started over with all the scans, but before that I fixed the things you mentioned in your last post.

    I'll attach files here and in my next post.

    Thanks again for any help you can give me. I really appreciate it!

    diane
     

    Attached Files:

  7. fuzzydi

    fuzzydi Private E-2

    Last post contained the runkeys.txt, newfiles.txt, and bdscan. This post contains the new Panda ActiveScan file.

    Thanks again!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are your copies of PestPatrol and ewido anti-spyware 4.0 free trial verions or paid versions?

    I also just noticed that you are also running very old versions of SpywareBlaster and Sun Java.

    Uninstall the old version of SpywareBlaster and and then update to this: SpyWare Blaster

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Then uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 3
    Java 2 Runtime Environment, SE v1.4.2


    Let's start your cleanup. Please download - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot.

    C:\documents and settings\rose\local settings\Temp\MiniBug.exe
    C:\documents and settings\rose\local settings\temp\c1.exe
    C:\documents and settings\rose\local settings\temp\bgiX.exe
    C:\WINDOWS\SYSTEM32\bUS.dll

    If Killbox does not reboot or if you get a Pending Operations type error message just click OK to continue and then just reboot your PC yourself.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\
    C:\Documents and Settings\Rose\Local Settings\Temp\

    Now attach a new HJT log and tell me how the steps went.

    Also attach a new log from ShowNew and a new log from GetRunKey.

    Make sure you tell me how things are working now!
     
  9. fuzzydi

    fuzzydi Private E-2

    Thanks in advance for all your help! To answer your questions:

    The version of Pest Patrol was old and mom no longer has a license for it. I uninstalled it. The Ewido is something I installed at the beginning of this cleaning process (2 days ago?), and is in the free trial period. I attached an Ewido report a couple posts ago, I think.

    I uninstalled the old SpywareBlaster and installed and ran the new one. I also uninstalled the old Sun Java versions and installed the new one. I thought I installed the new one yesterday, but maybe the old ones kept it from installing? Anyway, it looks like it worked now.

    I did the "fixme.reg" file and updated the registry. Then ran Pocket Killbox with no problems. The only files in the c\windows\temp folder and the c:\documents and settings\Rose\Local Settings\temp folders were dated today.

    I am attaching a new HJT log, GetRunKey and ShowNew logs. (I did see something about MiniBug still in the new HJT log)

    It seems like the pc is still taking a LONG time to boot up. It's better than it was, but still taking longer than it used to, before the spyware infestation. Part of it might have been the HP Imaging programs that loaded on startup. I removed them from the Startup folder and that may have helped some, too.

    Can I ask you a question? In this whole process, I have read that MSCONFIG should be set to normal startup. I was using it to disable the startup of certain programs, but I guess I shouldn't? I see some things in the MSCONFIG startup list that I don't recognize, and I don't know how to remove them (if needed):

    BCMSMMSG.exe
    C1.exe
    bgiX.exe

    Thanks again!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then uninstall Ewido, it is getting in our way. Do this now before continuing be my next instructions below.

    All the stuff that the registry patch was supposed to fix is still in your HJT log. To make sure that Windows Defender is also not blocking these changes first, disable Windows Defender before continuing.

    Disabling Windows Defender's realtime protection:
    • Open Windows Defender
    • Click Tools
    • Click General Settings
    • Scroll down to Real Time Protection Options
    • Uncheck Turn on Real Time Protection (recommended)
    • Close Windows Defender
    Once your log is clean you can re-enable Windows Defender Real Time Protection.



    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32\SearchBar.htm
    O4 - HKLM\..\Run: [Tray Temperature] C:\DOCUME~1\Rose\LOCALS~1\Temp\MiniBug.exe 1
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [c1.exe] C:\documents and settings\rose\local settings\temp\c1.exe
    O4 - HKLM\..\Run: [c1] C:\documents and settings\rose\local settings\temp\c1.exe
    O4 - HKLM\..\Run: [bgiX.exe] C:\documents and settings\rose\local settings\temp\bgiX.exe
    O4 - HKLM\..\Run: [bgiX] C:\documents and settings\rose\local settings\temp\bgiX.exe
    O9 - Extra button: (no name) - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - (no file)
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra button: (no name) - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O20 - Winlogon Notify: awtqr - awtqr.dll (file missing)
    O20 - Winlogon Notify: jkhhf - C:\WINDOWS\system32\jkhhf.dll (file missing)
    O20 - Winlogon Notify: jkkjj - C:\WINDOWS\system32\jkkjj.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\SearchBar.htm
    C:\Program Files\PartyGaming <--- the whole folder
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  11. fuzzydi

    fuzzydi Private E-2

    Ewido is uninstalled. Windows Defender is disabled for the time being. I fixed the items in HJT that you listed.

    After exiting HJT, I tried (in safe mode) to delete those 2 items (searchbar.htm and the Party Gaming folder), but they were already gone. :)
    I emptied the Prefetch and ran CCleaner. Reset web settings. I DID set the default page to majorgeeks.com. My mom will get a kick out of that. :)

    Attached is a new HJT log. It looks much better, to my untrained eye. It is definitely booting up quicker now. Before this, when you clicked on IE to open it, it took a long time. Now it comes up very quickly.

    Let me know how you think things look and if it's ok, I'll enable Windows Defender and do the system restore thing.

    I can't thank you enough. You are SO helpful and I really appreciate it! My mom's computer is used by all her grandkids when they are visiting and that's where most of the spyware comes from. One last question, if I may... I know from reading on this website that I should probably disable the Guest account. What I want to do is set up an account for moms grandkids to use. I would love to disable their ability to download and install. Does a limited account do that? Is that even do-able or do I need take extra steps? Perhaps that's a post for another forum...

    Again...thanks!
    Diane
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Your log is clean. Yes, enable the realtime protection of Windows Defender now.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds