Keystoke logger/spam

Discussion in 'Malware Help (A Specialist Will Reply)' started by Woden20, Sep 11, 2008.

  1. Woden20

    Woden20 Private E-2

    Hi everyone
    I was hoping someone might help me out. I'd be really grateful as I've tried and failed to sort this. I'm stuck now.
    I'm very worried as I think I've got either a keystroke logger downloading screen snapshots and emailing them to a hacker so my passwords are compromised or someone is using my computer to forward on spam emails I receive from them

    What happens is
    When I log on first the Norton Symantec box comes up highlighting the letter symbol showing me an email/message is being sent out (I think)
    Then roughly every 1 or 2 minutes ever after (seems random) Symantec tells me its scanning another outgoing message. I've no idea what they are (I think it must be emails though as I always get that scanning message when I send an email). Some messages do seem to be bigger than others.

    I've got Norton firewall & antivirus set up as standard.
    I've also tried running Spybot, Spyware Doctor, NoAdware, Pestpatrol & Rubotted with no luck
    I think maybe whatever I've got is hidden well within one of my normal programmes in the registry and can't be detected easily

    As well as these messages (emails?) the Norton antivirus keeps on saying it has detected and removed this virus
    http://www.symantec.com/security_response/writeup.jsp?docid=2002-101518-4323-99
    even though I have successfully removed it already using the SAFE mode. It seems to be continually trying to reinstall I think.
    Whether the two problems are linked I 'm not sure but they both started around the same time.

    I've attached a HIJACKTHIS log of my programmes
    I've also attached a screenshot of a programme called ActivePorts as well. It shows what ports are open. It might help hopefully to try and see anything unusual

    Many thanks for any help anyone can give



    Logfile of HijackThis v1.99.1
    Scan saved at 18:09:08, on 11/09/2008
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.



    PROCESS PID LOCAL IP LOCAL PORT REMOTE IP REMOTE PORT STATE PROTOCOL PATH
    Unknown 0 127.0.0.1 1054 127.0.0.1 1027 TIME_WAIT TCP
    Unknown 0 127.0.0.1 1100 127.0.0.1 1032 TIME_WAIT TCP
    Unknown 0 127.0.0.1 1098 127.0.0.1 1032 TIME_WAIT TCP
    Unknown 0 127.0.0.1 1096 127.0.0.1 1027 TIME_WAIT TCP
    Unknown 0 127.0.0.1 1032 127.0.0.1 1104 TIME_WAIT TCP
    Unknown 0 77.99.214.25 1101 216.32.90.186 80 TIME_WAIT TCP
    Unknown 0 77.99.214.25 1089 62.25.101.100 80 TIME_WAIT TCP
    Unknown 0 77.99.214.25 1087 62.25.101.100 80 TIME_WAIT TCP
    Unknown 0 77.99.214.25 1068 203.23.213.115 80 TIME_WAIT TCP
    Unknown 0 77.99.214.25 1061 83.231.138.8 80 TIME_WAIT TCP
    Unknown 0 77.99.214.25 1060 83.231.138.8 80 TIME_WAIT TCP
    System 4 77.99.214.25 138 LISTEN UDP
    System 4 77.99.214.25 137 LISTEN UDP
    System 4 0.0.0.0 445 LISTEN UDP
    System 4 77.99.214.25 139 LISTEN TCP
    System 4 0.0.0.0 1047 LISTEN TCP
    System 4 0.0.0.0 445 LISTEN TCP
    lsass.exe 620 0.0.0.0 500 LISTEN UDP C:\WINDOWS\system32\lsass.exe
    svchost.exe 776 0.0.0.0 135 LISTEN TCP C:\WINDOWS\system32\svchost.exe
    svchost.exe 828 127.0.0.1 123 LISTEN UDP C:\WINDOWS\System32\svchost.exe
    svchost.exe 828 0.0.0.0 1025 LISTEN TCP C:\WINDOWS\System32\svchost.exe
    svchost.exe 904 0.0.0.0 1063 LISTEN UDP C:\WINDOWS\System32\svchost.exe
    svchost.exe 904 0.0.0.0 1028 LISTEN UDP C:\WINDOWS\System32\svchost.exe
    svchost.exe 960 127.0.0.1 1900 LISTEN UDP C:\WINDOWS\System32\svchost.exe
    svchost.exe 960 0.0.0.0 5000 LISTEN TCP C:\WINDOWS\System32\svchost.exe
    ccApp.exe 1892 127.0.0.1 1027 LISTEN TCP C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    svchost.exe 2148 0.0.0.0 1030 LISTEN UDP C:\WINDOWS\System32\svchost.exe
    svchost.exe 2732 0.0.0.0 1041 LISTEN UDP C:\WINDOWS\System32\svchost.exe
     
    Last edited by a moderator: Sep 12, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:


    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. Woden20

    Woden20 Private E-2

    Hi, thanks for replying

    Just got in and started working through your post
    I'm trying to download the cccleaner but I get this error message

    C:Windows\system32\msvbvm60.dll
    An error occurred while trying to replace the existing file
    Deletefile failed code 5
    Access is denied

    Should I press the ignore option and skip this file or is it important

    Thanks
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure that you get this message when you are downloading CCleaner? Or did you mean you got it when you tried to install CCleaner.

    Either way just skip CCleaner.
     
  5. Woden20

    Woden20 Private E-2

    Hi,

    1) I've now managed to download & install & run Ccleaner to clean hard drive & check registry
    2) Have defragmented hard drive using Smart Defrag
    3) Nothing is quaranteened under Norton Antivirus
    4) I've downloaded Superantisypware but couldn't get it to install to run it
    Kept getting message ''the windows installer could not be accessed. Could be running in safe mode or the windows installer is not correctly installed''
    I don't think I'm in safe mode as the safeboot box under msconfig/system configuration utility/boot.ini is unchecked
    Under the general tab it is normal set up - load all device drivers and set ups. Is this wrong maybe?
    In fact I'm getting a lot of windows installer messages when I first switch on now which I never used to get
    5) Ran spybot - only a NoAdware programme showed which I deleted
    6) Ran Malwarebytes - one entry I've deleted, log is underneath
    Interestingly after I deleted that the Downloader virus I mentioned above flashed up as well with Norton saying it has deleted it
    7) I was going to delete all the various Java's I've got that are on your list but not sure about these other two
    Is it safe to delete these - ''Java webstart'' & ''Jfreechart 0.9.21 demo''
    Sorry for being a bit dense but which is the right Java option to download to replace them from
    java.sun.com/javase/downloads/index.jsp
    Is it Java SE 6 Update 10?
    8) Looked at Combofix and downloaded the file ''winxpsp1'' but got stuck after that.
    I tried dragging it over the combofix symbol and the red bars going accross seemed to show it had worked but then nothing seemed to happen after that
    I thought maybe I had to install the winxpsp1 first maybe but it asked for a floppy drive to copy images to, so I wasn't sure
    I am doing it right?

    Printer problem
    For some reason I now seem to have two printers installed
    HP PSC 2170 and a HP PSC 2170 (copy 1). I have to manually click on the copy 1 before I can print anything off now

    Many thanks
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Just click the link we gave you. You don't need to unstall Webstart or the Jfreechart which has nothng to do with Sun Java.

    Just skip the Recovery Console and double click the ComboFix.exe icon on your Desktop to run it.

    Not related to malware. I suggest you delete the second printer and post any further questions on this in the Software Forum.

    Will SUPERAntiSpyware install now after running Malwarebytes? Also try renaming the SUPERAntiSpyware.exe installer file to SAS.exe and see if it will install.

    Either way you still need to continue on and complete all steps as requested.
     
  7. Woden20

    Woden20 Private E-2

    Hi,
    All the logs ran nice and smoothly.

    1) I've attached the Mgtools log
    I've got XP 2002 Home edition SP1 but I've no idea whether its 32 or 62 bit. Just tell me where to check if you need it
    2) Attached the Combofix log as well
    3) Managed to run Superantispyware but only once I'd run these first two logs, changed it to SAS.exe as well
    Attached the log, nothing on it

    Good news is that the outgoing email I was sending when I first booted up seems to have stopped, or at least I don't see it now.
    The flow of apparent emails that Norton was scanning every few minutes has also stopped.
    If I blocked internet access, the Pc after a while would restart itself, and that's stopped as well

    I sometimes still get an incoming UDP message that I don't recall seeing before that Norton asks me if I wish to permit it
    'remote system attempting to access C\windows\sysyem32\lsass.exe.
    Is that OK?

    I'd be grateful if you'd check there isn't anything else nasty to worry about in the logs, for peace of mind

    I tried to remove these old Java's but couldn't. I keep getting that error installer message I mentioned above.
    Would you prefer me to raise that on the software forum?

    Will I need to do a toggle system restore now?

    Many thanks
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have your Windows XP SP1 bootable CD? You may need it during this next step.

    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System Rile Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.

    Do you use any P2P or torrent downloading programs? Exactly when does this message from Norton occur and how often.


    You need to stop downloading things to your C:\Program Files folder. This folder should only be used for installed programs. If you need the below files, I suggest that you move them somewhere else, otherwise delete them:
    Code:
    2007-08-29 16:52 20,256,064 ----a-w C:\Program Files\QuickTimeInstaller.exe
    2007-04-05 19:21 49,152 ----a-w C:\Program Files\Fee calculator.exe
    2007-04-05 19:06 486,912 ----a-w C:\Program Files\CalcPlus.msi
    2007-03-28 15:09 14,994,152 ----a-w C:\Program Files\GoogleEarthWin_EARD.exe
    2006-04-05 16:52 7,984,736 ----a-w C:\Program Files\ewido-setup.exe
    2006-04-02 11:02 212,984 ----a-w C:\Program Files\RootkitRevealer.zip
    2006-04-01 17:08 22,719 ----a-w C:\Program Files\Startup Programs (YOUR-U2KZFIB7P8) 2006-04-01 17.34.18.txt
    2006-04-01 16:36 293,545 ----a-w C:\Program Files\Silent Runners.vbs
    2006-04-01 16:24 13,273 ----a-w C:\Program Files\Startup Programs (YOUR-U2KZFIB7P8) 2006-04-01 17.13.22.txt
    2006-02-17 01:55 79,944 ----a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
    2005-11-20 19:52 667,344 ----a-w C:\Program Files\MP3gain-win-1_2_5.exe
    2005-02-16 11:06 218,112 ----a-w C:\Program Files\HijackThis.exe
    2004-07-13 17:14 445 ----a-w C:\Program Files\FILE_ID.DIZ
    2004-07-13 17:14 444 ----a-w C:\Program Files\whatsnew.txt
    2004-07-13 17:14 2,823 ----a-w C:\Program Files\README.TXT
    2004-07-13 15:12 1,663,509 ----a-w C:\Program Files\ak_setup.exe
    2004-04-30 21:07 3,704 ----a-w C:\Program Files\LICENSE.TXT
    2004-04-30 17:54 1,317 ----a-w C:\Program Files\ORDER.TXT
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    See if you can use the below to get all the old Sun Java versions uninstalled:

    Your Uninstaller! 2008


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
    O3 - Toolbar: (no name) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    After clicking Fix, exit HJT.




    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Malwarebytes and make sure you check for updates first and then run a new scan
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).




    Then attach the below logs:
    • C:\ComboFix.txt
    • new Malwarebytes log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Sep 17, 2008
  9. Woden20

    Woden20 Private E-2

    Hi,

    1) Deleted all the files you listed, they all looked superfluous
    2) Windows Messenger removal seemed to work OK, but I had to press OK to ignore this message that came up ''error registering the OCX16422''
    Is that important?
    3) Got rid off all the old Java's Ok and successfully installed the new one
    4) Ran the Mgtools\analyse.exe.
    Got the message saying fixme was added to the registry
    5) Ran malwarebytes and then the Ccleaner
    7) I've attached all the logs again

    The Pc is definitely running much quicker and smoother now and these emails seem to have stopped. Hopefully the logs back that up.
    Thanks a bunch for that, there's no way I would have managed all that on my own

    About that incoming lsass.exe message trying to connect inwards to me - it was just occasionally, but at random times, it seems to have stopped now.
    I don't think I have any P2P or torrent programs. Only thing I can think of is a financial website I use that provides constantly updating prices
    but I think that uses Java.

    Can you reassure me that all these things below are safe and I needn't worry about them
    When I log on first Norton Firewall tells me all these programmes under system 32 are accessing the internet in this order
    C\windows/system32/lsass.exe - just at start up, don't see it again after that
    This is a first though - /alg.exe - never seen it before until start up today
    Then 2 at same time of /svchost - again just at start up
    Then /hkcmd connects up
    Shortly after I am asked if I wish to permit /hkcmd to send an outgoing message
    Should I allow it?

    Many thanks again
     

    Attached Files:

  10. Woden20

    Woden20 Private E-2

    I just noticed the 1st part you asked
    Do you have your Windows XP SP1 bootable CD? You may need it during this next step.

    I bought the Pc preinstalled from HP store about 3 years ago but there was no disc. I remember running off 7 CD's then for some reason. I think it was to copy all the settings on the computer. Is that any use?

    Thanks
     
  11. Woden20

    Woden20 Private E-2

    Back again,
    Bit disorganised today. Just ran that scan. The blue bar gradually went right along to the end. I was expecting a finished message but one never came up. Does that just mean the scan found no problems?

    Hopefully me doing this bit out of order won't matter ?

    Thanks
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the ComboFix log that was requested in my last fix. Also you need to run C:\MGtools\GetLogs.bat again and make sure you allow it to finished running and that you do not allow any protection software to terminate it. You last log shows that it did not run properly.

    Do you see both Pest Patrol and Spyware Doctor in Add/Remove programs?
    Are both of these programs paid versions or are they trial versions?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All but hkcmd.exe are all valid Windows Operating System processes. hkcmd.exe is just a process for your multimedia keyboard.

    alg.exe does not need network or internet access.
    hkcmd.exe more than like requires no access.
    lsass.exe requires access
    svchost.exe requires access


    It only means that it did not need your CD to fix anything that it may have found. It really was more important to run this first but based on the MBAM log, I don't think it matters anyway.
     
  14. Woden20

    Woden20 Private E-2

    Hi,
    Sorry, I thought I'd attached that ComboFix log
    I've tried a few times and it won't attach although its only seems to be 14.3kb & a txt file. Is there a way round this?

    I closed Pestpatrol, SAS & Spware Doctor and disabled Norton antivirus before I clicked on Getlogs.bats
    Hopefully this new Mglog zip file has updated OK now

    Spyware Doctor 4.0 is in the add/remove bit of the C drive but Pest Patrol isn't
    Both are paid versions I've had for 2 or 3 years now and renew each year

    Thanks
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run the fix I gave you with ComboFix. You did not follow those instructions and are therefore trying to attach the same log as last time. I bet the log you are trying to attach has the below as the first line:
    ComboFix 08-09-13.01 - Owner 2008-09-15 18:02:22.1 - NTFSx86


    Since you use Pest Patrol, I have updated that CFScript.txt file to not delete the Startups. So you should recreate this file before running the fix again.

    But something is wrong if Pest Patrol does not appear in Add/Remove programs.

    It is not recommended to have more than one of this installed. Also if you have been updating Spyware Doctor, why do you have version 4.0 when they are currently selling version 6?
     
  16. Woden20

    Woden20 Private E-2

    Hi,
    You were right, that log was still dated 13/9
    Hopefully the attached log is OK now, its got todays date on it at least!!

    Will I wait till after I'm fixed to remove Pestpatrol and get an updated version of Spyware Doctor. No idea why I'm still on 4 as its on auto daily updates.
    Or do you think SAS might be the best one to keep?

    Pestpatrol is definitely not in Add/remove but I assume I can just use the uninstaller tool you gave me to do it.
    Its on the

    Thanks
     

    Attached Files:

  17. Woden20

    Woden20 Private E-2

    I have noticed something strange about Outlook though
    As I said above all these messages every few minutes saying Symantec is scanning something going out have stopped.

    But now when I send an email, even if just a test with nothing in it it takes a good 30 seconds to go. It goes to the outbox and then the scanning message comes up for a good 15 seconds. Is it possible something is still attaching itself to any emails I send out?
    It was always much much quicker before.

    Thanks
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You were not supposed to simply run ComboFix. You need to drag the CFScript.txt file on top of the ComboFix.exe icon otherwise the fix will not work. Try again. After you run ComboFix properly you have to attach the new log and you also have to attach a new MGlogs.zip file obtained by running the GetLogs.bat file again.
     
  19. Woden20

    Woden20 Private E-2

    Hi,

    Dragged that .txt file onto the .exe file
    But the file won't upload
    Ran the .bat file again, attached log
    I think your going to have to guide me through exactly what I need to do
    I'm not that good on computers and I'm getting a bit confused

    Thanks
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it looks like you are still having a problem getting the ComboFix procedure to work properly so let's try fixing this using another tool. It is possible that all your protection programs (Norton, Spyware Doctor, and Pest Patrol) are actually getting in the way of fixing your PC. Too bad they did not do as good a job in keeping the malware off to begin with. Shut down as much of these programs as you can before trying to do the below.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Sep 19, 2008
  21. Woden20

    Woden20 Private E-2

    Hi again,

    I've ran and attached these 2 logs
    Fingers crossed I've done it right this time

    Re how the Pc is working now -
    Those dodgy outgoing email scan messages I was getting are still gone which is great.
    Any time I send an email though it now takes forever to exit system as I mentioned above and every time I log on I still get loads of installers messages, makes logging on really slow. Both these issues never used to happen before I started the fixes.
    Could it be something I've done unintentionally to cause them?

    Thanks
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.

    I'm not sure if you are referring to shutting down your PC ( i.e., system) or exiting your email program. However this does not sound like a malware problem. It just sounds like your PC trying to terminate all running processes and you will have alot due to the duplicate antispyware programs.

    You should get the exact information and also a report from Event Viewer and post them in the Software Forum with as much information about this as possible. Windows installer issues occur all the time for many reasons. Yes the act of removing malware can sometimes instigate the problem but the actual reason for it happening now is unknown. I would guess you may have already had some kind of Windows Installer issue anyway since you have Pest Patrol installed but it does not even show in Add/Remove Programs. This could even be part of the problem.

    Not based on what was showing as removed in your logs. Before we perform final cleanup instructions which would also remove System Restore points, you have the option of trying to use System Restore to go back to a point before you began the malware cleaning steps. This may or may not fix your remaining issues, and it may restore some of the malware too (which could be cleaned again. Perhaps by using different steps.).
     
  23. Woden20

    Woden20 Private E-2

    Hi,
    Sorry, my poor use of English. I'm not refering to either shutting down the Pc or closing down Outlook.
    I really meant that every time I send an email now Outlook says 'sending' in bottom right of computer for about 20 seconds and the email sits in the outbox, then Symantec scans it for about a further 20 seconds.

    I think to keep things simpler for me since we've just about finished cleaning the malware off I'd prefer not to reinstate the old restore points if we don't know it will definitely sort the installer problem.
    I've not heard of event viewer before. If you can you give me a link to it I'll run it prior to posting this installer problem on the Software Forum once
    I've done this final clean up.
    Since I'm going to remove PestPatrol anyway would it be best if I did it now before we do this final clean up, if it might fix the installer problem?

    Thanks
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This could just be an issue with Symantec or with Outlook not sending emails immediately. You could try shutting down Symantec to see if it changes anything.

    First a note! Final instructions would remove ALL restore points which means then you would not have the option available to try and resolve this problem via System Restore. We are actually finished with malware removal. So perhaps we should not go to final steps anyway until you investigate further on the Windows Installer issues in the Software Forum.

    You can read about Event Viewer in the below link:

    http://support.microsoft.com/kb/308427

    How are you going to remove it when there is nothing in Add/Remove Programs? Are you going to reinstall it and then use the uninstaller?
     
  25. Woden20

    Woden20 Private E-2

    Hi,
    For whatever reason, without doing anything, sending emails are bank to normal speed today. Very strange, so I'll see what happens over the next few days.

    On the desktop I can right click on the Pestpatrol icon, it brings up that new uninstaller (you gave me) option.
    Its giving me the option to delete file PestPatrol.exe on path C\program files\Pest Patrol
    Once I saw that I went into the program files folder and all the files are there. There is a Pest Patrol uninstall option called UnPP.exe.
    Worry is under the quarantine file its got three zipped files 1) Hacker Eliminator zip file, 2) two files called wer5d.temp.dir00, and another called 5e,
    3) Some kind of registry entry file I think
    Will these quaranteened files reinfect the computer if I uninstall it?
    So as I seem to have got two possible ways to uninstall which would be the best/safest one to try first?

    I'll get a software query opened next up and come back to you once they've had a look at it.

    Looking at the event manager security log every day when I log on there is an entry ''event 540'', ''anonymous logon''.
    Other details when I go into it are NT authority/anonymous logon, category logon/logoff, logon ID 0x0, 0X3B18D, logon type 3,
    logon process NtLmSsp, authentication package NTLM
    Clicking on the option to send to Microsoft - file name MsAuditE.dll, type success audit
    It’s the anonymous got me wondering. Is there anything to worry about?

    Thanks
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No they will not reinfect you. You can simply delete anything in the quarantines too. You can also delete the quarantine folders after uninstalling. That is if the uninstall does not remove them. Use PestPatrol's uninstaller if it works.

    These are more than likely not problems. They may be related to ASPNET. Are these old logs or are they new items still occurring? Is this company owned PC and is it used to logon to a Domain.
     
  27. Woden20

    Woden20 Private E-2

    Hi,

    I removed Pest Patrol with its own uninstaller

    I was looking at the security log history of the last few days in time order. The anonymous one is still there today. It appeared after I switched on the Pc first today, I later used Turn of computer - restart to reboot and it appeared again.

    Its a home PC, personally owned, I don't logon to any domain that I'm aware of.

    Thanks
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still expect that it is related to ASPNET that is installed.
     
  29. Woden20

    Woden20 Private E-2

    Hi Chasling
    Hope you had a good holiday.

    I had major problems when I tried to download SP2 as part of my fix on the sofware forum. The PC crashed just as it was installing the SP2 information.
    Message was ''Missing or corrupt Ntfs.sys'' when I tried rebooting. I had to use the F10 option for system recovery to reinstate the original factory settings.
    It cleared up the uninstaller problem though so I hoped SP2 would work now and it did thankfully.
    I also got the new Java installed no problem and its working well.
    I defragged it all again and the PC overall is much faster which is a big help.
    So I think we should be able to go ahead now.

    I had been thinking of getting rid of my Norton & Spyware Doctor for a while now. They were nearly expired so I've uninstalled them and replaced them
    with the 2009 Kaspersky Firewall/Antinvirus/Malware package.

    Will the rollback to factory setting have undone a lot of what we had already done?
    Some of the programs like Spybot/SAS/Malwarebytes/Avenger seem to have disappeared. I think combo fix is still there.
    Is that QOOBOX in C\programe related to Malwarebytes?, I've noticed there seems to be virus files in the quarantine folder.
    I did the windows messenger removal again and re-ran Ccleaner.
    I haven't done the sfc /scannow as yet.

    I ran the full Scan for Kaspersky. Hopefully these details might help.
    It found 2 copies of a high risk one called Trojan.Downloader.Win32.Delf.gcy which are now deleted.
    Its stopped 4 inbound attempts so far by a worm called Intrusion.Win.MSSQL.worm.Helkern to get into port 1434.
    It says my system is clear. Is it likely though?

    Will we need to do anything again just to make sure everything is OK before the final clean up?

    Thanks
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes thanks! :)

    Do you mean go ahead with final instructions? Are you having any remaining malware problems?


    A rollback to factory settings effectively removes everything you have ever installed after the factory shipped the PC to you. All registry entries will be removed although all files and folders may not be removed. It also reinstalls everything that you may have uninstalled from the original ship date.

    No! It is ComboFix's quarantine folder.

    If it is blocking incoming attempts to access your PC then it is just doing what it is supposed to be doing.

    If you reset to factory installation, you can just do the final instructions below since it is unlikely that you have malware to be concerned with.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  31. Woden20

    Woden20 Private E-2

    Hi,

    I think all the malwares gone now, can't see any problems at all now.
    Before I do the final instructions can I just check something first.
    Will uninstalling Combo fix automatically delete the viruses in the quarantine folder at the same time?
    If not, can I safely delete them manually?

    Thanks
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is supposed to delete all of the files and folders from ComboFix. However affter uninstalling it, if you still see the C:\QooBox or a C:\ComboFix folder then just delete them and empty your Recycle Bin afterwards.
     
  33. Woden20

    Woden20 Private E-2

    Hi Chaslang.
    Been away a few days. I've just done all the final tidying up and the Pc is behaving itself once again, its much much quicker as well.

    So thanks again for all the time & help you've given me
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds