Help with Spyware.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Fireball420, Sep 27, 2004.

  1. Fireball420

    Fireball420 Private E-2

    Hi,
    I was told that if I downloaded HijackThis and posted the log someone could help me get rid of some unusually annoying spyware. Can someone take a look and help?
    Thanks,
    Aaron.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to follow guidelines! HijackThis is the last step and we have rules about how and when to post a log. Please do the below first.

    Please follow all the steps in this Sticky thread < READ ME FIRST: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    And please indicate your exact problems.
     
  3. PhilliePhan

    PhilliePhan Guest

    Hi Aaron,
    Well, you are somewhat correct. ;) We are happy to help, but you need to start here:

    http://forums.majorgeeks.com/showthread.php?t=35407

    You also need to move HijackThis to its own folder - C:\Program Files\HijackThis. This will allow for the preservation of backups.

    Befor you get started on the tutorial, see if you are able to remove the following via Add or Remove Programs:

    Web Rebates
    SyncroAd
    Bullseye Network


    Your HijackThis log is a mess. Once you have moved HJT to a safe place, have it fix the following:

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://rev0lt.net/index.html

    O2 - BHO: (no name) - {68DB3170-B06C-0ECC-D256-6C557C84244A} - C:\WINDOWS\System32\espkffc.dll

    O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" –atboottime

    O4 - HKLM\..\Run: [Windows SyncroAd] C:\Program Files\Windows SyncroAd\SyncroAd.exe

    O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"

    O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe

    O4 - HKLM\..\Run: [cbzzcl] C:\WINDOWS\System32\atyrvy.exe

    O4 - HKLM\..\Run: [conscorr] C:\WINDOWS\conscorr.exe

    O4 - HKLM\..\Run: [Sysino] lsess.exe

    O4 - HKLM\..\RunServices: [Sysino] lsess.exe

    O4 - HKLM\..\RunServices: [Sysino] lsess.exe

    O4 - HKLM\..\RunOnce: [Sysino] lsess.exe

    O4 - HKCU\..\Run: [Sysino] lsess.exe

    O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm

    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_f...166f16089431:81b1e337486498d88431998986b85d10

    O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab

    You will need to track down and try to DELETE:

    C:\WINDOWS\System32\lsess.exe
    C:\Program Files\Windows SyncroAd
    C:\Program Files\Web_Rebates\


    NOTE:
    I’m sure I missed a few entries and there will probably be a couple that reappear. Also, if you recognize any that you know you want or need, leave them alone. There are a few in your log with which I am not familiar.

    Now, begin the tutorial. Note the steps that you are able to complete and the ones that give you trouble. This will help us fix you up more quickly. Post back with any questions. I’ll be away for a bit, but there are many here who are much more qualified to help you than I. So, no worries! :)

    Best luck,

    PP

    *** Looks like Chaslang got here at same time. You are better off in his able hands.
     
    Last edited by a moderator: Sep 27, 2004
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hi PP! Yeah I guess you were typing while I was giving the canned speech to get things started.

    Fireball,
    You need to follow the tutorial steps first, then go to Add/Remove programs as PP suggested and uninstall those items. Then you should proceed on to anything remaining from the list PP has given to you. You will need to delete all the bad .exe files. You may need to boot in safe mode to do that.
     
  5. PhilliePhan

    PhilliePhan Guest

    Hi Chas,

    There are A LOT of nasty looking things on Aaron's log. I listed only the ones that jumped out at me. I'm heading out the door and don't have time to look up the ones I don't know.

    Best :)

    PP
     
  6. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    No biggie, I do the same thing sometimes :)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's okay! Let's wait for the tutorial and the steps given thus far to be executed. Then we will see where we are at.
     
  8. Fireball420

    Fireball420 Private E-2

    Hey Guys,

    Thanks so much for your help! I'm sorry I didn't follow the normal protocols in the beginning, but I have now. :) I did everything in that post (The 'Do this before asking for help' post), and everything seemed to work fine (IE I had not problems installing, configuring, and cleaning). I then followed every instruction that PhilliePhan wrote with the following results:

    -VIA the Add/Remove programs I was able to remove Web Rebates and SyncroAd, but not Bullseye Network (As I didn't see it there).

    -I had HijackThis fix most of the items that were mentioned to tick off, although some of them weren't there (I'm assuming they were fixed by the other spy/adware programs).

    -I tried to track down and delete the following:

    C:\WINDOWS\System32\lsess.exe
    C:\Program Files\Windows SyncroAd
    C:\Program Files\Web_Rebates\

    -lsess.exe didn't exist, although lsass.exe did. Was that a typo or is it just a very similar name?
    -Windows SyncroAd got deleted.
    -Web_Rebates didn't exist (Again assuming it was already dealt with)

    So everything seems to be working fine now, except for one last thing that perhaps someone can shed some light on. Every time I login with any user on the computer, an IE window pops up with the following URL:

    http://gen0cide.net/page1/index.html

    I doubt it's doing anything really bad, it's just totally annoying.

    I have attached my latest HijackThis log file as well.

    Thanks so much!

    Aaron.
     

    Attached Files:

  9. PhilliePhan

    PhilliePhan Guest

    Hi Aaron,

    Welcome to the world of Malware! lsess is made to look like the legitimate and needed lsass in order to try to fool you. Really, it sticks out like a sore thumb! ;)

    Your log is better.
    You should have HijackThis fix the following:

    O4 - HKLM\..\Run: [REEGRUN] C:\index.exe

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)


    Find and delete: C:\index.exe - Note that you may have to shut down the running process via Task Manager.


    I AM UNSURE ABOUT THE FOLLOWING, SO DO NOT FIX THEM FOR NOW:

    O4 - HKLM\..\Run: [WIN3S2SNDS] C:\windows\system32\winiprtx.exe

    C:\windows\system32\winiprtx.exe

    O4 - HKCU\..\Run: [Mahr] C:\Documents and Settings\Lanny\Application Data\eog?.exe


    Do you recognize any of those? Let us know.

    Best,

    PP
     
    Last edited by a moderator: Oct 2, 2004
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your suspicions are correct PP.

    Fireball,
    Fix the item PP gave but also end these processes with Task Manager:
    C:\windows\system32\winiprtx.exe
    C:\WINDOWS\SoftwareDistribution\Download\6ca7b3a8efd5a9b6f87fff395a2eb989\update\update.exe

    And have HJT fix the below lines (make sure no browsers are open when fixing):
    O4 - HKLM\..\Run: [WIN3S2SNDS] C:\windows\system32\winiprtx.exe
    O4 - HKCU\..\Run: [Mahr] C:\Documents and Settings\Lanny\Application Data\eog?.exe

    Then reboot in safe mode and delete the below (along with the index.exe file PP gave you):
    C:\windows\system32\winiprtx.exe
    C:\Documents and Settings\Lanny\Application Data\eog?.exe
     
  11. Fireball420

    Fireball420 Private E-2

    Hey guys!

    Thanks so much!! This has fixed all my problems!

    Fireball.
     
  12. PhilliePhan

    PhilliePhan Guest

    Glad to hear it, Aaron! :) I imagine Chas will agree that you are quite welcome!

    Best,

    PP
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cool! Another one bites the dust!

    You're right PP! Fireball is most welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds