Help with spyware (followed directions)

Discussion in 'Malware Help (A Specialist Will Reply)' started by arrchangel, Dec 28, 2005.

  1. arrchangel

    arrchangel Private E-2

    I have been having an awful time removing some spyware from my pc. Attached are the logs I recieved after following the advice of http://forums.majorgeeks.com/showthread.php?t=35407. I have followed the directions and still have some spywares on here :(

    Any help regarding this would be very appreciated. Thanks in advance for your time.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MG's

    Let's beging by emptying your recyle bin and any quarantine folders.

    And if you use Norton N-Protect, empty it too.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you run L2MFix?

    You did not follow the steps in the READ & RUN ME for disabling the below:
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    You also seem to have skipped step 3 of the READ ME. I see AVG and Symantec.

    Were you running multiple notepad sessions when running HJT? And also WinZip? Why?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After fixing what was mentioned in messages 2 & 3, continue with below. If you do not take care of those first, these steps may not work.

    Look in Add/Remove programs and uninstall Limeshop if found.
    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
    R3 - URLSearchHook: (no name) - _{49A25301-7CAC-A4FA-B638-457843BA4CE2} - (no file)
    R3 - URLSearchHook: (no name) - _{EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\SYSTEM\Userinit.exer.dll
    O2 - BHO: (no name) - {3BFF1355-B140-58C2-8753-60550DF3724E} - C:\WINDOWS\SYSTEM\LCXDHI.DLL (file missing)
    O2 - BHO: (no name) - {69AF480D-E344-0D94-8753-60550DA6271C} - C:\WINDOWS\SYSTEM\DLJZ.DLL (file missing)
    O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
    O2 - BHO: (no name) - {CE61D270-DB62-F508-1353-4BEEC18131B8} - C:\WINDOWS\Wlwdqxku.dll (file missing)
    O3 - Toolbar: Search - {44C7C79E-4DBD-4E1A-FD19-A424734AC5B9} - C:\WINDOWS\Wlwdqxku.dll (file missing)
    O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
    O3 - Toolbar: (no name) - {12EE7A5E-0674-42f9-A76B-000000004D00} - (no file)
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
    O16 - DPF: {2119776A-F1AD-4FCD-9548-F1E1C615350C} -

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (if found):

    C:\Program Files\LimeShop <--- the whole folder
    C:\WINDOWS\SYSTEM\LCXDHI.DLL
    C:\WINDOWS\SYSTEM\DLJZ.DLL
    C:\WINDOWS\Wlwdqxku.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).


    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Reminder Note: Once we have determine you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  5. arrchangel

    arrchangel Private E-2

    Thank you for welcoming me :)

    Okay I will do this as soon as I get back to work. As for the notepads, they were opened when the logs were created, out of curiousity.

    I actually uninstalled symantec from the get-go, I found that software to be more of a problem than a solution. I ended up just deleting the symantec folder while in safe mode since an uninstall didn't stop the startup's from re-registering themselves.

    I ran L2MFix because I saw in one of the logs that it was present, maybe I was wrong?

    I really appreciate the help with this!

    edit: by Limeshop are you referring to LimeWire?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Deleting folders is not the correct way to uninstall. Using Add/Remove programs is. Did you use Add/Remove programs first? We will need to do some work later to remove the items still showing up.

    The Look2Me infection that L2MeFix works on does not appear to be present. But yes Panda showed an EXE file and flagged it as Look2Me.

    I only saw Limeshop in your log not Limewire. Do you also have Limewire? If so, what version is it?
     
  7. arrchangel

    arrchangel Private E-2

    I uninstalled the Norton programs using add/remove, of course. I even ran a Norton Removal Tool, yet the startup processes kept coming back. After seeing the BitDefender see the Norton virus defintions, I decided to delete the folder containing the items out of desperation.

    I ran the scan (BitDefender) the first and second time with Norton un-installed, the second time with the Symantec folder deleted. I did not want to have the Panda scan see the same definitions.

    I do have LimeWire; its the PRO version of the software.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Version number???

    And do you use whatever Limeshop is supposed to be?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After doing all the other steps! Run HJT and Fix the below lines:
    O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
    O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
    O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg

    Then reboot and delete the below folder if found (unless you own other symantec software):
    C:\Program Files\Common Files\Symantec Shared

    If you do own other Symantec Software that you still use, then you should not delete the Symantec Shared folder. But instead just delete the below files that are in the folder:
    symlcsvc.exe
    ccApp.exe
    ccEvtMgr.exe
    ccSetMgr.exe
    SBServ.exe
     
  10. arrchangel

    arrchangel Private E-2

    Ah, its ver. 1.0.0.2, I don't know what Limeshop is so I'm gonna go with a big "No" on that one.

    All these problems began when my buddies got on my computer for a night. The rest is history :mad:
     
  11. arrchangel

    arrchangel Private E-2

    Ok, attached is the HJT log. It was created after following your instructions. See anything out of the ordinary?
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! Isn't that the first version of Limewire which is very old. I thought they were on LimeWire current version: 4.10.0 now.

    Older versions (before the latest ones) all contained malware.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! I never noticed that you did not follow step 7 of the READ AND RUN ME properly. HJT is still installed incorrectly.
    C:\Documents and Settings\Laur\Desktop\Comp Info\HijackThis.exe

    The below process is not valid for a WinXP system. Did you upgrade from WinMe to WinXP?
    O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\SYSTEM\Restore\StateMgr.exe

    Fix these next O9 lines with HJT:
    O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
    Unless you know for sure the below is clean, fix it.
    O16 - DPF: {A1B09066-C95C-4EF6-8DFD-3DD0AFE610B6} - http://pak02.pictures.aol.com/ygp/aol/plugin/screensaver/YGPPicScreensaver.en-US.9.1.6.20.cab
     
  14. arrchangel

    arrchangel Private E-2

    My bad! :rolleyes:

    LimeWire Pro v4.9.41.1

    edit:

    Yes, the computer was upgraded to XP from Me as part of this process of fixing the computer. I removed the ebate earlier, I ran a search on it and seen what kind of junk it was.

    Well, the computer is now out of my hands and is hopefully all better. I just found some malware on my pc at home, so thats next. Good times.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So you were working on a PC that was not yours?
     
  16. arrchangel

    arrchangel Private E-2

    The PC is mine, but is used by my family. Is there a problem with that?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! It just that you said
    And we always have finishing things to do.

    1) follow step 1 of the READ ME now to remove possible infected restore points

    2) follow the steps in the below link to help keep the PC clean:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds