Help with the adware/spyware removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by ONEEYEMAN, Oct 20, 2006.

  1. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi, ALL,
    I did everything that was described in the thread "Read and RUN ME FIRST".
    Here are the attached files. Please review and help.

    I couldn't upload all files, so decided to pack it in a zip file... :)

    Thank you in advance.
     

    Attached Files:

    • log.zip
      File size:
      33.8 KB
      Views:
      2
  2. ONEEYEMAN

    ONEEYEMAN Corporal

    There is also a lot of Add-Ons on my computer inside IE. And I don't know which is which....

    Thank you.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow the directions in the READ ME. You have Spybot's Teatimer running. This must be disabled.
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall!


    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. GetRunKey
    3. HJT
    Please follow the directions properly this time for getting the logs from ShowNew and GetRunKey. There are supposed to be plain text files. I'm not sure what you did last time but it looks like you pulled them into an editor like Word or similar and tried to make them into HTML. Please don't do that.
     
  4. ONEEYEMAN

    ONEEYEMAN Corporal

    Thank you for the reply, chaslang.

    So, you don't want me to run the scan at this time, right?

    I should run it in the regular mode, not "Safe Mode", correct?

    Problem is I didn't want to get connected to the web for a long time, so I just send them as an attachments, and downloaded those files from there.
    However, I won't do it anymore. I have a perfectly working Linux station on the same PC with the Web access, so this time it would be OK. I just completely forgot about it.... :eek:

    Thank you.
     
  5. matt.chugg

    matt.chugg MajorGeek

    Chaslang is away at the moment so in the interests of moving this thread along I will answer on his behalf.

    No. Just disable teatimer.

    Yes. Run it in normal mode.

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall!
     
  6. ONEEYEMAN

    ONEEYEMAN Corporal

    Thank you for picking up.
    I fixed the stuff with the SpyBot, so it does not run a TeaTimer anymore.

    I ran combofix.exe, and it did find and fixed some of the problems. It did created a log file. However, my Linux/GNOME installation is broken now. Inside GNOME, I don't have access to the console and the browser. I will try to re-boot and post the logs.

    Thank you.
     
  7. ONEEYEMAN

    ONEEYEMAN Corporal

    OK, here are the logs...

    BTW, I tried to submit them from the Linux/GNOME standard browser. Turns out, I can't see the "Manage Attachment" button. Only one one the page -and the most important one - is missing!

    Thank you.
     

    Attached Files:

  8. ONEEYEMAN

    ONEEYEMAN Corporal

    Here is the last attachment...
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of awvtr.dll once and then click the kill button. After you have killed all of the awvtr.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of awvtr.dll and kill it. (If you do not find the dll, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA} - C:\WINDOWS\system32\tscsqsvl.dll
    O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll (file missing)
    O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll (file missing)
    O2 - BHO: (no name) - {D280D201-60EB-373F-E788-606407804E9C} - C:\WINDOWS\system32\ljcrr.dll
    O2 - BHO: (no name) - {D6782724-C089-4B83-B45B-AABAB990C32F} - C:\WINDOWS\system32\awvtr.dll
    O2 - BHO: Banner Rotator - {E954DB82-1533-4714-92F2-59C98D5C18CC} - C:\WINDOWS\system32\brrotate.dll (file missing)
    O4 - HKLM\..\Run: [adstart] "iexplore.exe" "http://iesettingsupdate"
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O15 - Trusted Zone: *.imagesrvr.com (HKLM)
    O15 - Trusted Zone: *.matcash.com (HKLM)
    O15 - Trusted Zone: *.mediatickets.net (HKLM)
    O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
    O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
    O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
    O15 - Trusted Zone: *.snipernet.biz (HKLM)
    O15 - Trusted Zone: *.winantivirus.com (HKLM)
    O15 - Trusted Zone: *.winfixer.com (HKLM)
    O20 - Winlogon Notify: awvtr - C:\WINDOWS\system32\awvtr.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\asdf.txt
    C:\WINDOWS\Downloaded Program Files\Winwcd.inf
    C:\WINDOWS\Downloaded Program Files\motorsix.ocx
    C:\WINDOWS\Downloaded Program Files\USDR6_0001_D08M0404NetInstaller.exe
    C:\WINDOWS\1011_emi01.exe
    C:\WINDOWS\1011_justin.exe
    C:\WINDOWS\epi_sca6.exe
    C:\WINDOWS\hancerdoem.exe
    C:\WINDOWS\MirarSetup_876057.exe
    C:\WINDOWS\osbqehay.exe
    C:\WINDOWS\Setup90.exe
    C:\WINDOWS\srvzeuuujt.exe
    C:\WINDOWS\uni_7eh.exe
    C:\WINDOWS\unstall.exe
    C:\WINDOWS\system32\brrot-uninst.exe
    C:\WINDOWS\system32\Eim01.exe
    C:\WINDOWS\system32\justin.exe
    C:\WINDOWS\system32\ts_www.exe
    C:\WINDOWS\system32\ts_www2.exe
    C:\WINDOWS\system32\uuaidkyo.exe
    C:\WINDOWS\system32\awvtr.dll
    C:\WINDOWS\system32\BattyRun2.dll
    C:\WINDOWS\system32\ljcrr.dll
    C:\WINDOWS\system32\nsk1D.dll
    C:\WINDOWS\system32\nsmFA.dll
    C:\WINDOWS\system32\tscsqsvl.dll
    C:\WINDOWS\system32\Winwcd.dll
    C:\WINDOWS\system32\rtvwa.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Now delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Igor.FORDANWORK\Local Settings\TEMP files created within the last 90 days.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  10. ONEEYEMAN

    ONEEYEMAN Corporal

    When I ran the ProcessExplorer, I received the following message:

    ProcessExplorer Warning

    The version of Dbghelp.dll configured does not support the Microsoft Symbol Server.
    Please download and install the <a>Microsoft Debugging Tool for Windows</a> to get a
    version that does.

    After that it did run fine, and I was able to remove quite a few instances of this DLL.

    When I double clicked this file, I received following message:

    You cannot import fixme.reg: The specified file is not a registry script.
    You can only import binary registry files from within the registry editor.

    And here I am waiting for you instructions. Should I just go ahead and delete those lines in registry?


    Thank you in advance.
    Also, I already replied to this thread with this messages, but I guess somehow it was lost... :)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you did not save it properly! I have attach a ZIP file to this message that contains the fixme.reg file. Download the ZIP file, extract the fixme.reg file and double click on it. It is the same exact file that would be created by following the steps in my previous message.


    Then finish the rest of the steps and attach the new logs! Hopefully the delay in getting thru the remaining steps has not allowed things to respawn or to create new problems. We shall see.


    How is everything working?
     

    Attached Files:

  12. ONEEYEMAN

    ONEEYEMAN Corporal

    chaslang,
    Moving on, there are more problems... :)

    When I ran PocketKillBox, I was able to perform a first step: killing the temporary files. However, on the second step, right before the reboot I receive the McAfee OnAccess OnScan message:

    awvtr.dll Vuno virus found clean failed move failed.

    But that's OK, since after reboot, this file is a goner.

    Now, instead of the clean reboot, I received an error message, that lead me to the blue screen with the text "incorrect termination of logon program caused an error by the address of 0x???????"

    I hit the Power button, and then hit it again.

    Computer rebooted, but gave the following:

    winlogon.exe executed incorrect operation and will be terminated. We created the report for you convinience that will be send to Microsoft, to prevent this in the future.

    I said "Don't send", and went back to the Windows.

    Just to be absolutely sure, I checked on the file above and it was not there. Now when I hit CTRL+ALT+DEL, and selected the "Processes" tab, the winlogon.exe was running.

    Moving on.....

    Next step is to delete the files in the c:\windows\temp. It looks like I can't do that, I have 2 files left: Perflib_Perfdata_290.dat and vmware-vmount.log. The reply was:

    Can't delete the file. It is used by the other program or the disk is write-protected.

    Should I move on? Do you want an exact error message about winlogon.exe? I can post it from another computer, since I have 3 of them...
    Anything else you want me to post?

    Thank you so far...
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is a windows file and it may have been from the current date like my instructions indicated. Either way you can just skip that and continue.


    Yes exact messages should always be given but note that winlogon.exe is a valid and necessary windows process.
     
  14. ONEEYEMAN

    ONEEYEMAN Corporal

    chaslang,
    Thank you for your help. It is really great to have people like you around...
    Now back to business...

    When I rebooted my PC it didn't give me any error in regards to the winlogon.exe, which I guess is a good sign...

    Now after cleaning second directory mentioned by you last post, I produced the 3 log files again.

    And for some reason, the GNOME browser - SeaMonkey - does not show the "Attach files" button. Please look into it. All it shows is the box with the text "Attach Files" and the line "Valid file extensions:.....".

    So, hang on. I will post the logs from Windows, since I don't have an access to the button on Linux.

    Thank you again for your hard work.
     
  15. ONEEYEMAN

    ONEEYEMAN Corporal

    Here are the files.
    If you want the source code of the reply page in the SeaMoney browser I have it.
    The version is 1.0.3 under Mozilla/5.

    Thank you.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry but this is the Malware Forum for Windows based PCs. I cannot help you with problems related to Linux browsers especially in this forum. I would suggest you try two things.

    1) Uninstall, reboot, reinstall
    2) or try the Software Forum where you may find a few other people using Linux.


    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now look for the below file and delete it if found:
    C:\WINDOWS\system32\ObjSafe.tlb

    Other than that your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    7. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds