Hi, need help with a frustrating SpyQuake

Discussion in 'Malware Help (A Specialist Will Reply)' started by rshapner, Sep 18, 2006.

  1. rshapner

    rshapner Private E-2

    Howdy, A couple of days ago I was infected with a vicious spyware messing up my computer, constantly having ishost.exe,ismini.exe,issearch.exe, and isnotify.exe running and unable to kill them.

    I followed the steps I found here on the forum, and it pretty much cleaned the pc but ishost and ismini are still here, and the spyware seems to be rebuilding itself, keeps popping up notices of so called viruses.

    I have attached the smitfiles log and HJT log as asked in the sticky.
    Thanks in advance for any help you might offer.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You have a bunch more problems than just SmitFraud/SpyQuake.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.



    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. rshapner

    rshapner Private E-2

    Hey, I'm back after finally completing the checks.
    I would sure appreciate your help with removing all my problems!
    Thanks, Roi.
     

    Attached Files:

  4. rshapner

    rshapner Private E-2

    Continuing.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow the directions in the READ & RUN ME properly! You are using a Spybot version that is two years out of date. Uninstall the old version of Spybot, then reboot, then after reboot delete the C:\Program Files\Spybot - Search & Destroy folder.

    Now uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_01
    Java 2 Runtime Environment, SE v1.4.2_04
    Mozilla Firefox (1.0.7)

    Then install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Do you know what the below jibberish Excel spreadsheet on your Desktop it?
    Code:
    C:\Documents and Settings\Administrator\Desktop\
    2be6~1.xls    21 Sep 2006       20992  "‚Œ‰… ’…ƒ„ .xls"

    Your Windows OS version is way out of date and represents a major security risk. You MUST get updated afer we fix all malware problems!

    Per step 7 of the READ ME, you must be in Normal Startup mode and not use MSconfig to control any startups. Please run MSconfig now, and select Normal Startup. The click Apply and OK to close MSconfig. Do not reboot at this point if it tells you to do so.

    Now please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to the following key and take ownership of it (explained further down):

    HKEY_LOCAL_MACHINE\software\microsoft\mssmgr

    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the Menu
    • Select Take Ownership
    • Now leave RegistrarLite running and continue
    • Now run the REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate to HKEY_LOCAL_MACHINE\software\microsoft\mssmgr
    • Does the above mssmgr key still exist! If so, right click on it and select Delete.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    After completing ALL of the above instructions, continue here!

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winfon32.dll once and then click the kill button. After you have killed all of the winfon32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of winfon32.dll and kill it. (If you do not find the dll, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {D500DE29-067F-41AB-93C0-EA0137E0DCF0} - (no file)
    O4 - HKLM\..\Run: [WinServices] "netconfig{5}.bpq"
    O4 - HKLM\..\Run: [mediadriver{5}] "msc0nfig.dli"
    O4 - HKLM\..\Run: [COM Services] "msc0nfig.dli"
    O4 - HKLM\..\Run: [Microsoft Update Machine] "xvshost.exe"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\RunServices: [NT Guard] "iexplore.exe"
    O4 - HKLM\..\RunServices: [Microsoft Update Machine] "xvshost.exe"
    O4 - HKCU\..\Run: [Microsoft Update Machine] "xvshost.exe"
    O16 - DPF: {1E8E209A-6120-4EF1-B0B6-A65191D905B9} (CInstallManager Class) - http://fun.012fun.net/Installs/InstallManager.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://antu.popcap.com/games/popcaploader_v5.cab
    O20 - Winlogon Notify: winfon32 - C:\WINDOWS\SYSTEM32\winfon32.dll

    After clicking Fix, exit HJT.


    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    c:\windows\mwsvm.dat
    c:\windows\smdat32m.sys
    C:\WINDOWS\SYSTEM32\netconfig{5}.bpq
    C:\WINDOWS\SYSTEM32\msc0nfig.dli
    C:\WINDOWS\SYSTEM32\xvshost.exe
    C:\WINDOWS\SYSTEM32\iexplore.exe
    C:\WINDOWS\SYSTEM32\winfon32.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folders and delete if found:
    C:\Program Files\Power Scan
    C:\Program Files\ClockSync

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Administrator\Local Settings\Temp

    Now attach a the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!
     
  6. rshapner

    rshapner Private E-2

    Wow thanks alot for the comprehensive reply!
    I'll make all the needed steps and get back here.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Make sure you give me feedback on the steps and also attach the requested logs!
     
  8. rshapner

    rshapner Private E-2

    Uninstalled old programs and installed the new ones.
    The excel file is fine, just in hebrew :p
    Norton keeps bugging me about an ishost.exe file (part of the SpywareQuake, which have been supposedly fixed last week), and about a winfon32.dll (a trojan.nebuler, which I can't seem to remove), so I downloaded CounterSpy and ran a scan, cleaned anything it found, for now these 2 things don't popup, but I doubt it cleaned them (didn't mention either).
    I still have open connection on netstat when there should'nt be, which really annoys me.
    I also get BSOD and a crash once in a while, could be after 20 mins or after 7 hours, but I always get it 2 minutes after I start a run with the new Spybot.
    Should I go on with your instructions? I think that I still have some threats that I need removed before those steps, right now I'm gonna start a Norton scan and report back.
    I'm attaching the HJT log I did in normal mode.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to do ALL of what I requested in message number 5.
     
  10. rshapner

    rshapner Private E-2

    Continuing:

    Ran registrar and made the reg file, everything went fine, the mssmgr key no longer exists!

    Ran process explorer, did as requested, Fixed the entries in HJT.

    Ran the fixme.reg, used killbox as described.

    No folders with the given names we're found.

    Deleted all temp files.

    The forum won't let me to attach the getrunkey, and shownew logs for some reason, it tells me I already posted them in this thread, even if I change their names or suffix to .log, but I added the HJT log.

    Unfortunately I'm still getting an occasional popup of "anti-spyware", and a crash when I try to scan with Spybot or Norton, I'll have to wait for a while to see if anything else occurs.
    Thanks for the help so far!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That would mean the contents are still the same as what you already uploaded which would probably mean you did not get new logs. However, since both tools have been updated since you downloaded them, you need to download the new versions of GetRunKey and ShowNew. Then get new logs from them and attach them.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some new stuff showed up in your log! This is probably occuring because of what I said about your OS being so out of date. This is a big security hole.

    Is your copy of Window legit and licensed to you?

    Does your Symantec software include a firewall????
     
  13. rshapner

    rshapner Private E-2

    Got the new versions, here are the logs:

    I think my Windows is legit, I got it with the computer.
    My Norton has a firewall, it blocks connections many times.
    Thanks!
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That does not always mean it is legit. Depends on who you bought the PC from. Why haven't you ever allowed the OS to update?

    Is your Norton stuff as old and out of date as your copy of Windows is?

    WHY are you using MSconfig to control startups? Please run msconfig and select Normal Startup and remain in that mode and do not use msconfig to control anything!

    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions
    including the one you are reading in right now
    :
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {4C79F750-9B1B-F1B3-9E4A-05E62F244B1E} - C:\WINDOWS\System32\nexmldg.dll
    O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINDOWS\System32\ixt0.dll (file missing)
    O4 - HKLM\..\Run: [egqbdyj.dll] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\egqbdyj.dll,roclbsd
    O20 - Winlogon Notify: winfon32 - winfon32.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\nexmldg.dll
    C:\WINDOWS\System32\egqbdyj.dll

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then
      click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like
      www.majorgeeks.com. Click Apply. Click Delete
      Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip
      step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be
      Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the
      General tab and set your home page address to something useful like [COLOR=purple[/URL]
      ]www.majorgeeks.com[/color]
      . Click Apply. Click Delete Cookies, Click Delete Files and select Delete all
      Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer
    Settings!

    Now reboot in normal mode and post a new HJT log and a new log from GetRunKey!

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and
    re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Oct 1, 2006
  15. rshapner

    rshapner Private E-2

    I never trusted all those Windows updates, and their anti-spyware stuff, and I got along fine for a good few years until now.
    My Norton is the 2006 version, updated as it can be, but it annoys me when it didn't find this threat.

    Sorry about that MSconfig, it got a little slow so I went back to control start-ups and forgot to put it in normal mode again.

    Files and folders are not hidden.

    I fixed all of the HJT keys,
    these files we're not present already:
    C:\WINDOWS\System32\nexmldg.dll
    C:\WINDOWS\System32\egqbdyj.dll


    I reset Web settings and added the new logs.
    Thanks.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is a very bad practice. You need the updates for Windows. If you don't trust Microsoft then you should not use Windows at all. You should place a lot less trust Norton! It is slowing your PC down and as you have seen, it not only did not prevent or detect these problems, it could not remove them. You can get free applications that will work better.

    It's slow because of a few things.

    1. Norton as already stated
    2. CounterSpy and Ewido and SpySweeper all being installed. Are any of these paid versions? I see Spy Sweeper is a trial so you should definitely uninstall it now since it will not work at all after the 15 day trial ends.
    MSconfig should only be used for temporary debugging. Microsoft did not design for how you and thousands of others are using it. If you don't want or need certain programs, you shoud uninstall them. If you need them but don't want them to run at startup, configure the program to not load the applications at startup. For things that you cannot control because of poorly designed software forcing you to live with them loading when you don't want them to, you can either have HijackThis fix the load command permanently or you can use a program designed to be a startup manager (see Startup CPL )

    Your logs are clean! Are you having any other malware problems!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds