How do I get rid of ADW_SE. Spyware/Malware?

Discussion in 'Malware Help (A Specialist Will Reply)' started by syrk, Apr 4, 2006.

  1. syrk

    syrk Private First Class

    Trend Micro on-line scan has picked up the following Grayware/Spyware/Malware:

    ADW_SE.123473
    ADW_SE.123475
    ADW_SE.123477
    ADW_SE.123481
    ADW_SE.123482

    Trend Micro is unable to get rid of the stuff. No other scan has picked up the stuff. Can you help? syrk
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try running TrendMicro after booting in safe mode. If that does not help, attach a log from TrendMicro that shows exactly what and where they are finding the problems.
     
  3. syrk

    syrk Private First Class

    Chaslang, my system does not allow me to run TrendMicro in safe mode. syrk
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! But you did not attach the requested log!

    I think you should work thru the below.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  5. syrk

    syrk Private First Class

    Chaslang,


    I performed the following scans in safe mode:

    Ccleaner

    MS Win MSRT negative

    Ad Aware negative

    Spybot negative

    MS Win Defender negative

    CW Shredder negative

    Ewido negative

    AVG negative

    Avast negative

    Blacklight Rootkit Eliminator negative

    a squared positive: C:\Program Files\wanadoo\ Diagnosis: Trace.Directory.WanadooToolbar
    I did NOT remove it.


    I performed the following scans in normal mode:

    Bitdefender negative BUT scan was not completed. Only 143,444 out of 143,446 files were scanned before the following IE message appeared: IE has encountered a problem with a complementary module and must close.

    I was not able to use Panda ActiveScan. The following message appeared: error on downloading ActiveScan.

    The last scan, Trend Micro on-line scan has picked up the following Grayware/Spyware/Malware:

    ADW_SE.81203
    ADW_SE.81202
    ADW_SE.106702
    ADW_SE.115414
    ADW_SE.122491
    ADW_SE.123283
    ADW_SE.123473
    ADW_SE.123475
    ADW_SE.123477
    ADW_SE.123478
    ADW_SE.123481
    ADW_SE.123482

    I attach a hjt log for your examination. syrk
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your HJT log shows no problems!

    Attach a log from a Trend Micro scan that provides more useful information. What you are giving me is not useful. I need to know what it is find and where it is finding it. What file names and in what folders.
     
  7. syrk

    syrk Private First Class

    Chaslang,

    I can't figure out how to extract a log/more information from a Trend Micro scan. syrk
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the following two files, create a folder on your desktop, call it TSC. Save these 2 files there.

    Note: They must be in the same directory for the scan to work properly!

    Sysclean Package

    Pattern.zip

    After you download the above the above, locate the file "lpt325.zip", right click to extract the contents into the same directory you created!

    Once you complete the steps above, REBOOT INTO SAFE MODE!

    Once in Safe Mode double click the file sysclean.com. When the system cleaner loads, click SCAN to start the scanner. After you complete the scan reboot and attach the Trend SysClean Log.
     
  9. syrk

    syrk Private First Class

    Chaslang,

    I ran another Trend Micro scan which again found a different group of infections. I was not able to extract an official log but I did get the following information about the infections:

    ADW_SE.81203 1 INFECTION
    HKLM\SOFTWARE\Classes\TypeLib\{232CF401-90A9-11D4-9421-005004AD29B2}

    ADW_SE.81202 1 INFECTION
    HKCR\TypeLib\{232CF40-90A9-11D4-941-005004AD29B2}

    ADW_SE.106702 1 INFECTION
    HKCU\S-1-5-21-3570486074-772453757-3757357657-1006\Software\Softwrap

    ADW_SE.115414 1 INFECTION
    HKCR\Interface\{232CF40D-90A9-11D4-9421-005004AD29B2

    PAR_SE.122491 1 infection
    HKLM\SOFTWARE\Andreas Haak

    ADW_SE.123283 1 INFECTION
    HKLM\SOFTWARE\Classes\Interface\{232CF-40D-90A9-11D4-9421-005004AD29B2}

    Cookie HTTP
    Cookie: utilisateur@revsci.net/

    Should I go on with the Trend SysClean Log scan?

    syrk
     
  10. syrk

    syrk Private First Class

    Chaslang,

    I went ahead anyway and ran the Trend Micro Sysclean Package Scan. I attach the log. Before the scan a Trend Micro Sysclean Package message came on: Pattern file "LPT $VPN.*" is missing, Please download a copy. syrk
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That error means that you did not extract the pattern file from the ZIP file you downloaded. As I indicated you must extract the pattern file from the ZIP and it MUST be in the same folder as sysclean.com

    A new pattern file has come out. Download the below file and then MAKE SURE to extract the pattern file into the proper folder. If you still get the error message, you did not do it properly.

    Trend Micro Pattern File for Windows 3.327.00

    Looks like you hand typed the detections from the Online scan. I think you have a bunch of mistakes and inconsistencies in what you reported. These are mostly registry keys and you must get the exact info or it cannot be fixed.
     
  12. syrk

    syrk Private First Class

    Chaslang,

    Sorry about that. I attach the newest Trend SysClean Log and my corrected hand typed detections from the Trend Micro Online scan.

    ADW_SE.81203 1 INFECTION
    HKLM\SOFTWARE\Classes\TypeLib\{232CF401-90A9-11D4-9421-005004AD29B2}

    ADW_SE.81202 1 INFECTION
    HKCR\TypeLib\{232CF401-90A9-11D4-9421-005004AD29B2}

    ADW_SE.106702 1 INFECTION
    HKCU\S-1-5-21-3570486074-772453757-3757357657-1006\Software\Softwrap

    ADW_SE.115414 1 INFECTION
    HKCR\Interface\{232CF40D-90A9-11D4-9421-005004AD29B2

    PAR_SE.122491 1 infection
    HKLM\SOFTWARE\Andreas Haak

    ADW_SE.123283 1 INFECTION
    HKLM\SOFTWARE\Classes\Interface\{232CF-40D-90A9-11D4-9421-005004AD29B2}

    Cookie HTTP
    Cookie: utilisateur@tacoda.net/

    Thanx for staying with me. syrk
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still are not saving the info correctly. I would suspect that all of those CLSID numbers should be the same. A CLSID is this ===> {232CF401-90A9-11D4-9421-005004AD29B2}



    Let's get an installed programs list from HijackThis!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
    Did you ever install or do you have installed the below:
    http://www.tucows.com/preview/196120
     
  14. syrk

    syrk Private First Class

    Chaslang,

    Attached find HJT uninstall_list.txt file. I neither have nor have I ever had Softwrap Tucows Wrapper installed. I have no idea what I'm doing wrong with Trend Micro. syrk
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download, install, and run: Erunt to make a backup. Let me know when you have it installed and have made a backup of your registry. Then I will make a registry patch for you to run to remove those registry keys.
     
  16. syrk

    syrk Private First Class

    Chaslang,

    I have made a backup of my registry using Erunt. syrk
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Alright below is the patch but you must realize something that I kept questioning about the results you were giving me. I kept stating the results do for what Trend Micro is reporting look incorrect because you were hand typing them and that I believe you were not typing all of them up correctly. So the patch below is only based upon what you gave me. If you gave me the wrong info, then the patch will not work. And I still feel what you gave me was not correct because the CLSID was not consistent.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  18. syrk

    syrk Private First Class

    Chaslang,

    It's true that my first attempt to hand type the Trend Micro Online scan detections was pretty shabby, to say the least, but what I gave you on my second try is correct. As to the Trend Micro Sysclean Package, I have since retried several times to get you a proper sysclean log reading, but to no avail; access to the files continues to be refused. Anyway, I will let you know how it goes and thanks for your help. I really mean it. syrk
     
  19. syrk

    syrk Private First Class

    Chaslang,

    I just ran your patch; two infections remain:

    ADW_SE.106702 1 INFECTION
    HKCU\S-1-5-21-3570486074-772453757-3757357657-1006\Software\Softwrap

    PAR_SE.122491 1 infection
    HKLM\SOFTWARE\Andreas Haak

    syrk
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try this again! I'm not sure what the Softwrap one is not going away. It could be that you do not own that registry key (this means you do not have permission to do anything with it even if you are the Administrator of the PC).

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
    Last edited: Apr 14, 2006
  21. syrk

    syrk Private First Class

    Chaslang,

    Quick question before I use your new registry patch: Shouldn't there be a bracket after "Software\Softwrap"? syrk
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! I fixed it now! Sorry about that.

    If you still have items detected, make sure that you are giving me the EXACT info being found. There has to be a way to save a log or to just copy and paste the info to a text file in notepad.
     
  23. syrk

    syrk Private First Class

    Chaslang,

    I just ran your patch; one infections remains:

    ADW_SE.106702 1 INFECTION
    HKCU\S-1-5-21-3570486074-772453757-3757357657-1006\Software\Softwrap

    syrk
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download and install Registrar Lite make sure to download it from one of the Majorgeeks links and not the Author site.

    Copy and paste the below into the Address box of registrar lit and hit the Enter key.

    HKEY_CURRENT_USER\S-1-5-21-3570486074-772453757-3757357657-1006\Software

    Then click the Security pull down on the top menu and choose Take Ownership. Click OK in the next window to approve it.

    Now copy and paste the below into the Address box of Registrar Lite and hit the Enter key.

    HKEY_CURRENT_USER\S-1-5-21-3570486074-772453757-3757357657-1006\Software\Softwrap

    Now right click on the above key and select delete.

    Now exit Registrar Lite

    Is it gone now? Did you get any error messages while doing any of the above?
     
  25. syrk

    syrk Private First Class

    Chaslang,

    It's not clear in my mind what you mean by "Now right click on the above key and select delete." syrk
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to find this key:

    HKEY_CURRENT_USER\S-1-5-21-3570486074-772453757-3757357657-1006\Software\Softwrap


    and right click on it which will present options to you. One of the options is Delete which is what we want to do.
     
  27. syrk

    syrk Private First Class

    Chaslang,

    No good. It's still there.I did not get any error messages during the process. syrk
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure that the below is 100% correct?

    HKCU\S-1-5-21-3570486074-772453757-3757357657-1006\Software\Softwrap
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the Registry Search Tool

    Unzip to your Desktop and double click on regsrch.vbs
    (if you have script protection, please allow this to run)

    In the dialog that opens enter the following:

    Softwrap

    Press 'OK'

    The search will run for a while then alert you when it is finished. Press 'OK' and copy the contents of the WordPad window and post in this thread. If it is very long, an attachment would be better.
     
  30. syrk

    syrk Private First Class

    Chaslang,

    Something must be wrong:

    RegSrch.vbs@Bill James
    Search Completed in 21 seconds
    No instances of "Softwrap" found

    I'm sure that the below is 100% correct.
    HKCU\S-1-5-21-3570486074-772453757-3757357657-1006\Software\Softwrap

    syrk
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This cannot be correct!

    First, that type or registry key (the S-1-5-21......) never is seen under HKCU (which is HKEY_CURRENT_USER). It would only be found under HKEY_USERS.

    Second RegSrch is not finding it so I doubt that it exists.

    Did you actually see this registry key when you ran the steps I gave you using Registrar Lite? If so, export just that registry key to a file and then put it in a ZIP file and upload it. Here!

    However, note I believe you we are wasting a load of time on a non-issue!!
     
  32. syrk

    syrk Private First Class

    Chaslang,

    Don't ask!

    REGEDIT4
    ; RegSrch.vbs © Bill James

    ; Registry search results for string "softwrap" 15/04/2006 23:52:30

    ; NOTE: This file will be deleted when you close WordPad.
    ; You must manually save this file to a new location if you want to refer to it again later.
    ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


    [HKEY_USERS\S-1-5-21-3570486074-772453757-3757357657-1006\Software\Softwrap]

    [HKEY_USERS\S-1-5-21-3570486074-772453757-3757357657-1006\Software\Softwrap\19C704B1AF46B15D960830D5CB198AAD461C77A6]

    [HKEY_USERS\S-1-5-21-3570486074-772453757-3757357657-1006\Software\Softwrap\Ver1.0]

    syrk
     
  33. syrk

    syrk Private First Class

    Chaslang,

    I found a fourth one:

    [HKEY_USERS\S-1-5-21-3570486074-772453757-3757357657-1006\Software\Microsoft\Search Assistant\ACMru\5604]
    "000"="softwrap"

    syrk
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So as I said from the very beginning, you were giving me the wrong information. Now that you have the correct information. Use what I gave you with Registrar Lite, but delete this key:
    HKEY_USERS\S-1-5-21-3570486074-772453757-3757357657-1006\Software\Softwrap
     
  35. syrk

    syrk Private First Class

    Chaslang,

    There are 3 entries under Softwrap:

    1. "19C704B1AF46B15D960830D5CB198AAD461C77A6" (which is identified as a key)

    2. "Ver1.0" (which is identified as a key)

    3. "ab (default) (value not set)"

    Do I delete both keys separately or do I click on and delete what appears in the address box? What about the value entry? I hope this makes sense.

    Again, I must insist about what my I eyes see: TrendMicro is reporting

    ADW_SE.106702 1 INFECTION
    HKCU\S-1-5-21-3570486074-772453757-3757357657-1006\Software\Softwrap

    I'm sorry if I'm driving you bonkers.


    syrk
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All you need to delete is the highest level key which is:

    HKEY_USERS\S-1-5-21-3570486074-772453757-3757357657-1006\Software\Softwrap

    Deleting it will delete everything under it.
     
  37. syrk

    syrk Private First Class

    Chaslang,

    You did it! Thanks for your patience. TrendMicro gave me a clean bill. As a last step I'm going to disable System Restore, reboot and then re-enable. syrk
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds