http://rl.webtracer.cc/-/?bayzm

Discussion in 'Malware Help (A Specialist Will Reply)' started by rfplanner, Mar 14, 2005.

  1. rfplanner

    rfplanner Private E-2

    Hi all,
    I am a new user, and whilst I was away working for 2 months my kids were playing on the computer.
    When I got back, I found a lot of spyware, luckily no viruses.
    I seem to have removed alll but the following
    http://rl.webtracer.cc/-/?bayzm
    I cannot remove this, I have tried all the best programs out there, and every time a change is made by a program or myself to remove references to this page, it seems to change back immediately.
    I am tearing my hair out (and that is REALLY difficult at my age) .
    Is there ANYONE who knows how to get rid of this thing?
    I will take ANY advise right now, as I have spent a considerable amount of time over the last week to try to kill it.
    Best regards
    Phil Daies
     
  2. tblue

    tblue Corporal

    Hi rfplanner,
    Have you followed all of the steps in the thread below??

    http://forums.majorgeeks.com/showthread.php?t=35407

    Its really helpful and gets rid of alot of problems. If you still have problems after doing all the steps...come back here and post your results.
    The pros will be happy to help you... :)
    Have a nice day,
    T.Blue
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After doing what Tblue suggested (make sure you follow all the steps), if you still have a problem:
    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENTto your next message. (Do NOT copy/paste the log into your post).
     
  4. PhilliePhan

    PhilliePhan Guest

    Hi Chas, Phil -

    This baddie is similar to the recent se.dll nasty in that it has hidden components that reinstall it. If you guys are unable to pin it down, I suggest you try the steps I outlined in Post #9 of this thread:

    Can't remove coolWWWSearch (hijacker)

    Best luck :)
    PP
     
  5. rfplanner

    rfplanner Private E-2

    Hi all,
    Thanks for all of the advice.
    I have followed all of the threads, at least twice, and still have the same problem.
    HJT does not remove any of the entries,as they appear instantaneously on the next scan. I am attaching the HJT log file, plus the files from one of the programs mentioned by Phillie, the locate file.
    Also, CWShredder finds and says it removes CWS.BOOTCNF, and CWS.SVHOST32, but they are there again on the next scan. Any more advice would really help, as this appears to be very persistent. I even deleted the entries in safe mode whilst not connected to the web, and they allcame back again.
    Best regards
    Phil Davies
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before continuing with repairs, a few up front observation, comments and questions.

    You should uninstall SpyHunter as it is a rogue/suspect spyware removal tool.

    Questions:
    1) Why are you installing software into inappropriate folders!
    - You have MailFrontier Desktop (Matador) email spam blocker software installed into a folder that belongs to ZoneAlarm. Here is the file I'm referring too:
    C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe

    2) The only trace I see of an antivirus application installed is:
    O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\System32\ZoneLabs\isafe.exe

    which is used by Zonelabs as part of their AV. But it seems like there is no antivirus application itself. Do you have it disabled or uninstalled.

    3) Aluria is a company that is associated with spyware/adware. You have the below:
    O23 - Service: Aluria Security Center Spyware Eliminator Service (ASCService) - Unknown owner - C:\Program Files\Aluria Security Center\ascserv.exe
    Is this something you purchased! It is not rated very highly either. Do you feel comfortable with this package and do you think it is actually helping you? (I don't!).
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you post the help file for locate.bat? You were supposed to post the log file it created after running it.

    You MUST remember to exit all browsers before you run HijackThis. Not doing so could make it impossible to fix problems. You had the below running:
    C:\Program Files\Internet Explorer\iexplore.exe
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixss.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixss.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Reboot into to Safe Mode and use Windows Explorer to navigate to the below folder:
    C:\WINDOWS\SYSTEM32\DRIVERS

    No look for the following file: disdna.sys
    Right click on this files and select rename. Change the name to: disdna.sss

    Now reboot back ino Normal Mode.
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rl.webtracer.cc/-/?bayzm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rl.webtracer.cc/-/?bayzm
    O1 - Hosts: 1159680172 auto.search.msn.com
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O19 - User stylesheet: C:\WINDOWS\stsheets.dat
    After clicking Fix, exit HJT.

    Reboot into safe mode and find and delete:
    C:\WINDOWS\stsheets.dat

    Reboot again into Normal Mode.

    Download this proram and follow the below steps Hoster.

    1. Unzip Hoster to a convenient folder such as C:\Hoster.
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program.
    Post a new HijackThis Log!
     
    Last edited: Mar 14, 2005
  9. rfplanner

    rfplanner Private E-2

    Hi Chas,
    The mail frontier program is part of Zone labs suite program which incudes an anti-virus, it also checks out spam as it is integrated into Outlook.
    I will take your advice and unistall the Aluria software and the Spy Hunter software before I follow the instructions below.
    I probaly got confused with the other fie I posted, my apologies for that.
    I will post the new HJT log file as soon as I have finished the instructions below.
    Best regards
    Phil Davies
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Be sure to post a copy of the log from locate.bat too.
     
  11. rfplanner

    rfplanner Private E-2

    Hi Chas,
    I have followed your instructions to the letter.
    I am attaching 2 files to this post, 1 log file for each time you asked me to run HJT.
    The final log is number 2 and was saved after all instructions were followed.
    There is still 1 reference to the webtracer problem, so I will try to go through your instructions again and clear it.
    BR
    Phil Davies
     

    Attached Files:

  12. rfplanner

    rfplanner Private E-2

    Hi Chas,
    Here is the report file from locate.bat
    BR
    Phil Davies
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Phil,

    You are not saving and attaching these files correctly. They have no carriage returns in them. You must save them directly from HijackThis as a log file which should open up notepad. Then you should directly upload that notepad file. Do not use any other tools or editors to manipulate or work with the log files.
     
  14. rfplanner

    rfplanner Private E-2

    Incidentally, disdna.sys was not anywhere on my machine
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That was the problem! I was guess since you did not post the locate log file the first time.
    Go back and repeat the process but instead of disdna.sys

    look for C:\WINDOWS\SYSTEM32\DRIVERS\CBIDF2KZ.SYS

    and rename it to CBIDF2KZ.SSS
     
  16. rfplanner

    rfplanner Private E-2

    Ok, I will send the files again, I saved them using wordpad, my confusion in my rage to get rid of this wierd bug. Sorry
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't bother right now. Just redo the process with the new .SYS file I gave you.

    Then do what was mention in the thread PP gave you with the RegSrch Tool
    We need to find other place where stsheets occurs.
     
  18. rfplanner

    rfplanner Private E-2

    Ok, will do.
    Phil
     
  19. rfplanner

    rfplanner Private E-2

    Hi Chas,
    Here are the 2 files you asked me for.
    The stsheets seems to be all over the place.
    BR
    Phil
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still posting you HJT logs incorrectly. Please stop using Wordpad!
     
  21. rfplanner

    rfplanner Private E-2

    I didn´t realise that HJT saved the file automaticaly, here is the ´raw´file without me saving it at all.
    Sorry
    Phil
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Still not correct. What are you doing differently than you did in message number 5? In that message you attached it properly. Just save the file with HJT (yes the name must be different each time but that is easy to do as HJT saves the file). When you save a log with HJT is it bringup notepad or Wordpad.
    If it is Wordpad you must have changed the file associations.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you still forgetting to exit browsers or is something else running IE?

    C:\Program Files\Internet Explorer\iexplore.exe

    And what is this below program?
    C:\Program Files\crc\crc.exe
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixsts.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixsts.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
     
  25. rfplanner

    rfplanner Private E-2

    Hi Chas,
    The file association is with wordpad, and I am unable to change it.
    Windows is refusing to allow me access to change it for some reason.
    It appears that all is ok though, as there is no reference to the bad files at all in the HJT file when it is run.
    I have also removed all references to stsheets in the registry, and cleaned and compacted the registry also.
    I removed the programs that you advised me too also
    All in all, I could not have done this without everyodys help, but especially yours. I can´t thank you enough for all of your time and advice, sorry if it has been a bit frustrating for you.
    Best regards
    Phil
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! You should make sure you have done the steps in the below thread (or the equivalent of those steps) to help avoid future problems:

    How to Protect yourself from malware!
     
  27. rfplanner

    rfplanner Private E-2

    Ok, did the reg file, CRC.exe is a registry cleaner and compactor.
    BR
    Phil
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for the info on crc. Did you see my message below? We posted at the same time.
     
  29. rfplanner

    rfplanner Private E-2

    Hi Chas,
    I will follow the instructions to the letter, beleive me.
    Thanks again for all of the time you have devoted to this problem of mine.
    I hope that someone else can also benefit from this experience in the future.
    BTW, where did you learn all of this stuff? It´s amazing, I had been at this for 1.5 weeks.
    Thanks again
    Phil
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I learned about PC's and Windows thru many years of use and programming.
    As far as spyware, just applying knowledge of the OS together with lots of daily learning myself since malware changes constantly. Most of our typical procedure work pretty well on getting quite a bit of malware problems removed. But sometimes, some extra little tweaking is required and we learn that as we go along. Since we did not create the malware, when new ones come along we have to figure out how the stubborn ones are working and how and where they hide themselves. Then we figure out when we need to do to fix the buggers.
     
  31. rfplanner

    rfplanner Private E-2

    Well it certainly seems that you learned a lot, and today, so did I.
    Thanks again, and best regards
    Phil Davies
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Happy safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds