HELP!!...New here...Raze Spyware Remove;Win64.exe/Mswinb32.exe

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by CompCop, May 4, 2006.

  1. CompCop

    CompCop Private E-2

    Believe I meticulously followed all removal instructions…am running WinXP/SP2 with a fire walled DSL connection and all Win updates. Also was running the following with all updated definitions before infection:

    Norton Sys Wks 2005 w/AV (active protection enabled)
    Ad-Aware SE
    Spybot (w/resident enabled)
    E-Trust Pest patrol (active protection enabled)

    I encountered what I believe is Winfixer, but came up in E-Trust as “Raze Spyware” and Spy-bot as “Active Desktop” with constant tray icon messages of infection; credit card hacking; while the Spybot resident displays termination of Win64.exe and Mswinb32.exe (also I notice that in my Network connections folder there’s a new “Internet Gateway Connection” activated that will not allow me to delete, or disable….not to get long winded, but…

    1. Disabled Sys Restore…

    I downloaded and installed:

    Ewido Malscan Detection (clean log attached)
    MS Win Defender 1051 (BETA 2)
    MS Malicious Software Removal Tool
    CCleaner
    VundoFix V2.1
    Smitrem

    2. Rebooted in safe mode, disconnected internet, closed all running programs and scanned/cleaned the system (took 4 hours), then ran Smitrem and CCleaner before reboot to normal.

    3. Set a new Sys Restore point…rebooted..

    4. Checked and deleted all back-ups/quarantine in Norton AV…Ran all scans again, just to be safe…came up clean…was elated only to come crashing down.

    5. As soon as I rebooted again and connected to the internet, the Spybot resident kept detecting and terminating “Win64.exe” and “Mswinb32.exe” and the CE Trust Active Protection detected “Raze Spyware” again (See attached)…and the MS Messenger became active (after disabling w/plmessngerstop)..also noticed that my firewall was now disabled along with the Norton Active Protection.

    6. I’m totally lost here and would appreciate ANY and all assistance…

    7. After all of this I ran HJT and saved the log hoping that someone could help…
    :mad:
     
    Last edited: May 5, 2006
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Couple problems, heres the links to repair as well as items in question from your log. Let us know.

    Raleka is a worm-virus that spreads through the Internet by exploiting a vulnerability in the DCOM RPC service in Microsoft Windows. This vulnerability is detailed in Microsoft Security Bulletin MSO3-026 .

    http://www.microsoft.com/technet/security/bulletin/MS03-026.mspx
    http://www.sophos.com/virusinfo/analyses/trojspyrea.html

    C:\WINDOWS\System32\service.exe
    O4 - HKLM\..\Run: [Adware.Srv32] C:\WINDOWS\system32\runsrv32.exe
    O23 - Service: Windows Service Manager (WSCM) - Unknown owner - C:\WINDOWS\System32\service.exe
     
  3. CompCop

    CompCop Private E-2

    MAJ..thanks for the advice. I was able to take care of the Raleka by following your advice and the MS tech article.

    However, I can't seem to delete "O23 - Service: Windows Service Manager (WSCM) - Unknown owner - C:\WINDOWS\System32\service.exe" from HJT.

    Whenever I reboot from safe and set a new system res point, then scan again with Ewido/Ad-aware/Spy-bot...Norton AV...I get what's in the attachment...none of the others pick up on it.

    Attached is new HJT/Ewido report.

    Thanks...this is driving me nuts.
     
    Last edited: May 5, 2006
  4. CompCop

    CompCop Private E-2

    One more item...now just scanned again w/Spy-bot and had to fix active protection which was disabled again after reboot.
     
    Last edited: May 5, 2006
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please complete step 6 of the READ & RUN ME and attach the two requested logs. Also disable Spybot's Teatimer as requested in the READ & RUN ME.

    Are your copies of Ewido and Pest Patrol paid versions or free trials?

    As Major Attitude pointed out, you have a bad service running that you must stop and disable. Do the below:

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Windows Service Manager ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    WSCM

    If you receive any error messages just ignore them and continue.

    Now exit HJT and reboot

    After reboot attach the two online scanner logs and a new HJT log.
    Also delete the below file:
    C:\WINDOWS\System32\service.exe <--- only delete service.exe DO NOT delete services.exe which is valid.
     
    Last edited: May 5, 2006
  6. CompCop

    CompCop Private E-2

    Chaslang, followed instructions...success in deleting service.exe...attached Panda and HJT log. Bitdef did not detect anything and there was no tab to "view problems."

    ETRust Pest patrol is the paid/full vers. Ewido is trial.

    Two things...even after disabling Sys Restore and setting a new restore point upon cleaning/reboot...ETrust detects "NetSpy KeyLogger C:\Program Files\CA\eTrust PestPatrol\Quarantine\reg1.tmp" I quarantine, then delete it from there, but keeps coming back on reboot.

    Also task manager is disabled after every reboot "Windows Security Center. TaskManager: Settings (Registry change, fixed) by Spy-bot.

    "HKEY_USERS\S-1-5-21-507921405-1708537768-1060284298-1004\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr!=dword:0"

    Tried multiple times to attached HJT and Panda...Keep getting upload errors when trying to attach the two logs...will try again...

    Thanks for ANY assistance that you can give...I'm going nuts here.
     
  7. CompCop

    CompCop Private E-2

    Logged off and back on...was able to attach logs for you.

    Thanks..
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you editing your old messages and deleting logs? We cannot help you if you delete the history of what we have been doing! You are not supposed to be able to edit messages after 5 minutes for just this reason, however there is a bug in the vB code used by the forums.

    Start over! And run the below and attach ALL logs and do not edit them.

    Start by running this procedure: SpywareQuake Removal Procedure attach the smitfiles.txt log.

    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also since you have a paid version of Pest Patrol, you should uninstall Ewido (which you said was clean anyway) and also uninstall Windows Defender. Leaving all of these installed will waste resources, slow your PC down, and could cause conflicts. If you do re-run the READ ME as suggested, you do not need to run Windows Defender again. If fact, all I really need to see are the two logs from step 6 and then a new HJT log after the other steps have been run.

    By the way if Pest Patrol is detecting problems here:
    C:\Program Files\CA\eTrust PestPatrol\Quarantine\reg1.tmp

    Then it is detecting problems in its own Quarantine folder which would be totally stupid since it save the info there.
     
  10. CompCop

    CompCop Private E-2

    Back to the drawing board...

    Sorry to frustrate you….I didn’t intentionally delete previous logs….I tried between 20-30 times to upload what you requested and kept getting “upload error” messages. Being new here, I went to check exactly how many were “in progress” so I didn't exceed the byte max....and noticed total byte count of my posts and attachments…I assumed that the new logs wouldn’t upload because there were over 300 kb of previous logs/att., so I deleted previous and then I was able to upload the new ones. I’ll start over…
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! I now understand why you delete them, however, it was not necessary. It was not the total amount of data that you uploaded that was causing a problem. Sometimes the buttons just don't work (vB bug) and sometimes it is because the logs have the same exact data as a previous log which then gets refused. Any individual .log, .zip, or .txt file must be less than 250k and you can upload 4 logs into any single message. But there is no restriction on total size on multiple logs.

    Just attach a new BitDefender, Panda, and HijackThis log. You do not need to run ALL the other steps in the READ ME.

    Also tell me if you see the below files! And if you do, see if you can delete them. Let me know what happens.
    C:\windows\system32\keylogger32.exe
    c:\windows\system32\shellgui32.dll
    c:\windows\system32\txfdb32.dll
    c:\windows\dlmax.dll
     
  12. CompCop

    CompCop Private E-2

    As you suggested, I did find c:\windows\system32\shellgui32.dll and C:\windows\system32\txfdb32.dll and was able to delete both files. Could not find "Keylogger.exe" or "dlmax.dll."

    BTW, I ran all scans yet again in SM and re-booted to normal, re-enabled sys restore, ran HJT and attached all logs. "Adware:adware/alexa-toolbar" came up in Panda scan, but I couldn't locate it anywhere...Bitdef was clean.

    E Trust still kept coming up with the "Net Spy" keylogger in the quarantine, even though I emptied it and ran CClean...I searched in explorer and found an additional quarantine folder (2 total) in "C:\Windows\Program files\CA\Etrust Pest Patrol\Core\..." once I deleted the file from the second quarantine folder and scanned again, it hasn't come up since (crossing fingers).

    Task manager still comes up as disabled every time I reboot...Spybot catches it and I repair with the fix tab.

    RE: Tutorial...all scans worked and had no problems that I know of, besides the task manager and "keylogger" initially. I REALLY do appreciate all of your help...you guys definitely run a great site. I just can't imagine where you get the time to walk guys like me through this stuff....thanks again!
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try running the below for the Alexa Toolbar registry entry that Panda is not given any info on.

    Alexa Toolbar Removal Tool 1.0.2

    Before running the below steps with HijackThis make sure you shut down any active protection from Norton, Pest Patrol, or similar programs.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {12872A48-35BA-4A13-A5A5-B8047717564C} - (no file)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
    O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)

    After clicking Fix, exit HJT.

    Did you install any tools like the below? Sometimes restart.exe comes with tools like Look2Me Fix or others.
    C:\WINDOWS\system32\Tools\Restart.exe

    If you did not make this folder and install this file there then delete it.

    Now reboot in normal mode and post a new HJT log. Do not allow Spybot to fix the problem with Task Manager again if it shows up. In fact do not run a scan with Spybot.

    Also run the below procedure and attach the runkeys.txt log. I want to see if there is any indication of why Task Manager is getting disable.

    Using GetRunKey

    Make sure you tell me how things are working now. Itemize any remaining problems

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  14. CompCop

    CompCop Private E-2

    I ran the Alexa tool bar remover, but no detection/removal noted. I did a search for the referenced files and did find “AlxRes.dll and “AlxTb1.dll”. I deleted them both per the symantec help ctr.

    Ran HJT and fixed the referenced lines as indicated, rebooted normal ran HJT…new log and also runkeys attached.

    Task manager still is being disabled upon reboot. I did not run, nor fix w/Spybot.

    I ran Kill2me last week…I deleted the C:\WINDOWS\system32\Tools\Restart.exe.

    I’m not experiencing any other issues/problems that I know of other than the task manager issue…It may sound weird, but come to think of it, whenever I had Spybot fix the task manager issue that it detected, that’s when the E- Trust Pest Patrol would hit on the Net Spy keylogger.

    Just want to say thanks again for all of you help thus far…you have been a tremendous help…much appreciated!
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Shut down Pest Patrol and any active protection from Symantec before doing the below or they could block the changes.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Attach a new runkeys.txt log now and also tell me how things are looking! Is Task Manager okay now?
     
  16. CompCop

    CompCop Private E-2

    Chaslang, followed instructions...no problem with the tutorial...

    Should I be concerned about this? "Miscellaneous Malware Detection Report" in the runkeys log?

    Everything does seems to be working fine now as far as systems and Malware, please advise when you have time.

    Thanks again!
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing was found! All you are seeing is the section headings where info would be reported if malware was found.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  18. CompCop

    CompCop Private E-2

    Chaslang…Man I just wanted to thank you again…I know I sound like a broken record here, but before I came across your site I was about ready to format my %^&&**# hard drive…many thanks to you and the Major…thanks to you guys and the great site that you run it wasn’t necessary! And I learned a heck of a lot (although painful) too. Keep up the fantastic work! I hope that I don’t have to go through this again, but if I do, you guys will be first on my list to assist! If you ever happen to get on the "other" side of the law in southern Louisiana give me a shout and I’ll square it for ya!

    Many, many thanks!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well I don't get down that way too often. Last time was a very long time ago, but I typically keep out of trouble. ;) Thanks! And you're welcome again!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds