Malware problems! I followed the procedure. Anybody got a minute?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jim_antispy_novice, Oct 9, 2006.

  1. Jim_antispy_novice

    Jim_antispy_novice Private E-2

    Hello Spyware gurus,

    My name is Jim. I am having a few problems and followed the full instructions for malware removal and picked up a whole bunch of stuff (2 spyware, 2 trojans and 1 suspected trojan) that were parasitizing my machine. I did the panda scan and it picked up a lot of things that it couldn't remove (5 items). Has anybody got any advice or how to get them off and keep them off? I usually run Zone Alarm and AVG and also scan with spybot. I think that I must be making some fundamental mistakes somewhere because I reinstalled not long ago. The taskbar and desktop items also take quite a while to load. Anybody got an idea of why this might be? Is it another virus and how might I shake it? Previous to finding this really useful site I used spysweeper which told me that I had a couple of browser hijackers that it wouldn't remove for me and that they had exploited a hole in IE to gain some nasty control of my PC. I attached 3 files mentions in the instructional post, and will post the other 3 on a replyAnybody got some words of wisdom for me?

    Thanks

    Jim
     

    Attached Files:

  2. Jim_antispy_novice

    Jim_antispy_novice Private E-2

    Here are the hijack and panda scan logs. Thanks to anybody who might lend me a hand...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't really have too many problems!

    Bitdefender only showed items in System Restore which can be removed by flushing your restore point as indicated in step 9 of the READ ME. But we will do that after we remove the below malware.

    Panda found nothing but a few cookies and one benign/stray left over registry key. It gives no details on this key so there is nothing we can do to fix it but it is not causing you any problems anyway.

    Are the below 2 settings something you configured?
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qu123.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qu123.com

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6

    Make sure viewing of hidden files is enabled (per the tutorial).
    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://seek.yisou.com/srchasst.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://seek.yisou.com/srchcust.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\yasrde.exe
    C:\WINDOWS\system32\yasrdd.dll
    C:\WINDOWS\system32\yas.dat
    C:\Program Files\YiSou <--- the whole folder
    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Jim\Local Settings\Temp

    Now attach a the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. Jim_antispy_novice

    Jim_antispy_novice Private E-2

    Hahaha, great! Cheers for the fix!

    Hello chaslang,

    You are great! That was the nasty little piece of malware that was making me wait for my task bar and items to appear (2 or 3 minutes) at startup.


    Are the below 2 settings something you configured?
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qu123.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qu123.com

    I didnt configure them, to be honest now I never want to use explorer again so I dont really care about the home site (some reports told me that my machine's security was breached through a hole in IE).

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:

    I couldnt find any of the processes running.

    I removed the nasty.exe, .dll and .dat that you told me to but couldnt find any folder called YiSou. I even did a search for the YiSou folder with hidden files shown and still couldnt come up with anything.

    I followed all the other steps too. Here are the newfiles, runkeys and hijack files.

    Cheers

    Jim
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hahaha, great! Cheers for the fix!

    The use HJT to fix them but they may not fix now because you have run something or configured something that I did not ask for. You now have the below in your log:
    What did you run or install or change the configuration on? Spybot perhaps or SpywareBlaster??

    Also have HJT fix the below leftover from Spy Sweeper:
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    What are the below new files on your Desktop?
    Code:
    "C:\Documents and Settings\Jim\Desktop\
    bhr.exe       Oct 10 2006     2449088  "bhr.exe"
    hjbghj~1.doc  Oct 11 2006       30720  "hjbghjbhj.doc"
    Jibberish names like the .doc file are always suspected to be malware!

    The below files that I asked you to delete are still there:

    C:\WINDOWS\system32\yasrde.exe
    C:\WINDOWS\system32\yasrdd.dll
    C:\WINDOWS\system32\yas.dat

    You need to delete it. DO NOT USE WINDOWS SEARCH. Use Windows Explorer!!! That was why we had step 2 of the READ ME enable viewing of hidden files. That only enables viewing of hidden & system files in Windows Explorer not Windows Search.
     
  6. Jim_antispy_novice

    Jim_antispy_novice Private E-2

    Like rabbits out of a hat, but cant find the hat!

    Guilty! I downloaded and ran bhr.exe (browser hijack recovery) on a 15 day trial. Thats one of the items on my desktop. the other (with the gibberish name is a word file) I made of your reply to work offline with but was lazy with the name!
    I fixed this

    I found them and deleted them... then boot back into normal mode... and some undiscovered nasty makes them again. In properties of these files it says they are YAHOO but I couldnt remove my stupid YAHOO file from program files because it wont let me delete it directly and it also wont let me uninstall it. When I do this it connects to the internet... then gives me options but there are no words only question marks. The reason for this I though may be that I am a Brit living in China and sometimes get question marks where chinese characters should be on software options. Anyway, I renamed all the .exe files in the yahoo folder to .ex to make them unfunctional and was able to this so I kind of ruled this out as a suspect. Also I found a .exe next to the 3 reappearing files called yishou1.exe (very similar to the folder name you said I might find) and it looks like a setup file so I renamed this to .ex but the 3 files were still made anyway so I named it back!

    Really appreciate your help. If you ever plan a trip to Shanghai, then look me up (spareforspam@hotmail.com - I get loads of spam at this address, cos I use it for net advertising, hence the name). I would be happy to show you the sites and get you a good deal with hotels, tourist trips ect...

    Jim
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Like rabbits out of a hat, but cant find the hat!

    Then perhaps those 3 files are related to Yahoo! Assistant! Is this the application that you mean you cannot uninstall? Do you use this?

    How is your PC running right now?
     
  8. Jim_antispy_novice

    Jim_antispy_novice Private E-2

    Re: Like rabbits out of a hat, but cant find the hat!

    I dont use yahoo assistant. I never intentionally installeld it (although I dont know if it came with something else and I was careless enough not to uncheck the box in the past).

    Right now if I delete the files and restart then the computer boots up normally and the 3 files are remade but the startup is normal. If I dont delete them and they are there when I boot up I have to wait for 2 or 3 minutes with just the normal green hill backdrop but no desktop icons and no task bar at the bottom of the screen. Also sometimes it gives me the plain blue screen (another standard backdrop)for about half a second before the desktop icons and stuff appear (so in addition to making me wait). These 3 files also seem to have all priviledges! Is that normal for yahoo stuff? Is there any log that I could browse and interpret (with some online tutorial somewhere that you might know of, I know you must be pretty busy) that would tell me what file made these 3 files so I could go and delete it

    I also get a load stuff transfered to tribal fusion on every browse but the spybot and Ad-Aware-SE dont pick up the cookie for this. Any way to manually remove it or block this site (already done the spybot immunise but it hasnt made any difference to this particular data tracker)?

    Cheers

    ps. What is your view on torrents (I use a program called Azureus). Most of my friends say they are pretty safe so I used them a bit in the past but am not so sure now.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Like rabbits out of a hat, but cant find the hat!

    Then goto Add/Remove programs and uninstall Yahoo! Assistant. Then reboot your PC.

    After reboot, are those three files gone now. If not, please put all three of them into a ZIP file and upload them here as an attachment.


    I also get a load stuff transfered to tribal fusion on every browse but the spybot and Ad-Aware-SE dont pick up the cookie for this. Any way to manually remove it or block this site (already done the spybot immunise but it hasnt made any difference to this particular data tracker)?[/quote]Cookies are not problems to be concerned with and in most cases cookies are helpful and useful to you. See step 11 in this How to Protect yourself from malware!


    No P2P applications are actually safe and you cannot trust that the people you are downloading from are running clean PCs nor can you trust them to be honest. In any malware removal type forum, no one would every recommend the use of P2P applications but we obviously realize that many people use them. Some help forums will even refuse to provide you any help until ALL P2P type applications have been physically uninstalled and folders where their downloads have been saved have been deleted. I will however tell you that more than 50% of the people coming here with infections have typically picked them up by using P2P applications (some of which are bundled with malware) or by download infected files from the P2P servers. You are on your own in this area!
     
  10. Jim_antispy_novice

    Jim_antispy_novice Private E-2

    the 3 culprits

    Hello chaslang,

    I have finally got the yahoo assistant off my computer. I did it a messy way because it wouldnt uninstall so I removed deleted the Yahoo folder manually in safe mode and it let me (normally it will tell me that some .dll is write protected). I also deleted everything in the prefetch folder. However, the 3 files still reappeared so I have put them in a zip attached...
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: the 3 culprits

    Those files are definitely part of a Chinese version of Yahoo (probably something to do with a search assistant). See this:

    http://en.wikipedia.org/wiki/Yahoo!_Assistant


    Now that you remove the Yahoo folder, can these 3 files be deleted and do they stay deleted.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds