Help! @#$% popups!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by kjmarks2, Aug 3, 2006.

  1. kjmarks2

    kjmarks2 Private E-2

    My desktop somehow got a serious case of the popups. I think the main culprit is Command Service b/c I can't seem to bump it off.

    I followed the instructions in the "READ & RUN ME FIRST Before Asking for Support" thread to the best of my ability and have attached the six requested logs in a .zip file (reports.zip). I had to use CounterSpy b/c for some reason I can't get Windows Defender Beta to update (after attempting many suggested solutions).

    Spybot keeps finding Command Service and I will try some of the solutions mentioned elsewhere, but I have found that trying solutions that worked for others rarely work for me. So, I figured I'd get this onto you guys in case they don't work this time either.

    Thanks for any assistance
    kjmarks
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    It looks like CounterSpy fixed a bunch of things that I see in your current newfiles.txt log (from ShowNew.bat) Please attach a new log from ShowNew so we can work on any remaining problems.
     
  3. kjmarks2

    kjmarks2 Private E-2

    Glad to hear that COunterSPy fixed alot. I haven't noticed the popups yet, but I think that's b/c I'm paranoid and have my network unplugged until I'm sure I'm clean.

    Here is that ShowNew report you requested.

    Thanks for your help!!
    kjmarks
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you have a load of Look2 Me infections!

    Run this Look2Me VX2 Removal and attach the requested log.

    Also download the newest version of ShowNew (changed last night). And get a new log from it to attach.
     
  5. kjmarks2

    kjmarks2 Private E-2

    Look2Me_VX2 Removal procedure followed. Report is attached.

    Also, the new ShowNew log is attached.

    Additional question: Do you know anything about a false positive with SpyBot and Command Service? I get a message with TrendMicro HouseCall as well.

    Thanks again for your service!!!
    kjmarks
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not a false positive. The malware has change who owns the registry keys and thus Spybot cannot fix it for you. We will get to this later.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now download - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32bez6n4r21.exe
    C:\WINDOWS\system32n9nyb.exe
    C:\WINDOWS\system32bez6n4r21.exe
    C:\WINDOWS\system32n9nyb.exe
    C:\WINDOWS\SYSTEM32\bez6n4r21.exe
    C:\WINDOWS\SYSTEM32\mwinqpez.exe
    C:\WINDOWS\SYSTEM32\TNPI32.DLL
    C:\WINDOWS\SYSTEM32\xez6fd5b.dll
    C:\WINDOWS\Sy5KLiBhbmQgRXJpbiBNYXJrcw\mVc4M211vAk0lrLDv21hsrLOwT.vbs
    C:\WINDOWS\SYSTEM32\guard.rar
    C:\WINDOWS\SYSTEM32\guard.tmp
    C:\WINDOWS\SYSTEM32\mwinqpez.exe
    C:\WINDOWS\SYSTEM32\opdsregp.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot locat the below folder and delete it if found:
    C:\Program Files\outlook

    Now attach a new HJT log and tell me how the steps went.

    Also download the current version of ShowNew (from the same link) and attach a new ShowNew log

    Attach a log from Spybot that shows the detections of CmdService!

    Make sure you tell me how things are working now!
     
  7. kjmarks2

    kjmarks2 Private E-2

    Instructions followed. Attached are HJT log, ShowNew log and SpyBot log.

    Killbox did not give me the PendingFileRenameOperations prompt and I did delete the C:\Program Files\outlook file.

    Things seem to be working fine. I'm going to leave me computer on all night and the network connection in. Previously, this was a sure-fire way of having many, many pop-ups by morning. We'll see...

    Thanks again!
    kjmarks
     

    Attached Files:

  8. kjmarks2

    kjmarks2 Private E-2

    8+ hours later and no pop-ups. I'll take that as a positive sign! Thanks!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean other than cmdService. Let's fix it.

    Please download and install Registrar Lite

    Run Registrar Lite navigate to the following keys and take ownership of them (explained further down):

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cmdService

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService


    To take ownership of the key do the following:
    • Copy & Paste one registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the regitry key.
    • Click-on Security in the Menu
    • Select Take Ownership
    • After taking ownership, right click on the registry key and select delete. MAKE sure you are right clicking on only the above keys (the three cmdService entries).
    • Now exit RegistrarLite .
    • Tell me the results. Any errors?
    Now see if Spybot runs clean!
     
  10. kjmarks2

    kjmarks2 Private E-2

    Hooray!!

    Well, I was a bit nervous that we had another issue b/c the one registry key couldn't be found (
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService).

    However, I cleared the other two, ran SpyBot and Voila! No issues found.

    Thanks oodles for your help!!
    kjmarks
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds