Malware problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by KenB2014, May 4, 2006.

  1. KenB2014

    KenB2014 Private First Class

    I followed the "Read & Run Me First" tutorial and have the files attached. I've had problems with the IE browser freezing. Thanks.
     
    Last edited: Mar 10, 2007
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are your copies of Spyware Doctor and Spy Sweeper paid versions or free trials? Also is Spy Sweeper up to date with definitions? Have you run a full scan with it? Is it detecting Winlogonhook?

    Let's get an installed programs list from HijackThis too!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
  3. KenB2014

    KenB2014 Private First Class

    Spyware Doctor and Spy Sweeper are trial versions and Spy Sweeper has expired and won't run. I will register it if we need it for this process.

    The uninstall list is attached.
     
    Last edited: Mar 10, 2007
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by uninstalling Spyware Doctor and SpySweeper. You also really should uninstall Kazaa Lite K++ v2.4.1 It is a unauthorized illegal clone of Kazaa and Kazaa is a very dangerous P2P server to use. It is loaded with all kinds a infected and mislabled files.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to add into the registry.
    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/22efcc5f64218fd...p/RdxIE601.cab
    O16 - DPF: {84B7AC1D-9AD1-474F-B6B0-FE1641DBFDFA} (ScanFile.FileScan) - http://www.contentpurity.com/xp/ScanFilexp.CAB
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) -
    O16 - DPF: {CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_03) -
    O20 - Winlogon Notify: wineak32 - C:\WINDOWS\SYSTEM32\wineak32.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\TEMP <--- delete all file in this Temp folder
    C:\WINDOWS\system32\wineak32.dll
    c:\windows\system32\services <--- if this is a folder delete it. But DO NOT delete the services.exe file!!!
    C:\Documents and Settings\Ken\Favorites\Health
    C:\Documents and Settings\Ken\Local Settings\Temporary Internet Files\Content.IE5\AE0PN2RE\srvlkd[1].exe
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.
     
    Last edited: May 5, 2006
  5. KenB2014

    KenB2014 Private First Class

    Before I got your last posting, I decided to register Spy Sweeper and run it, based on your questions and the fact that it is a recommended program on Major Geeks. I then got your latest posting.


    Here is an update on everything I've done, following your instructions:

    Spy Sweeper detected and removed "winlogonhook" "trojan-downloader-aux" and "trojan-downloader-errlook."

    I reran the "Read and Run me First" procedure.
    BitDefender found an attachment with "Joke.Winshoot.A1" in Outlook. I deleted that message in Outlook.
    BitDefender detects "VirTool.WatchHook.A2" in a freetrial install program for System Mechanic 5 Pro, downloaded from Iolo's website. It scans clean with NAV.
    Panda Activescan detected an "emediacodec" leftover file "ldF994.tmp." I deleted this file. I don't see any other signs of "emediacodec"

    From your last post:
    I deleted Spy Doctor and Kazaa Lite, which I don't use anyway.
    I applied the registry change for "wineak32"
    I fixed the items you indicated in HJT.
    In safe mode, I deleted the files in the TEMP directory and "wineak32"
    The "services" directory is not present.
    I deleted the "Health" folder.
    "Content.IE5" folder is not found.
    Deleted the contents of "Prefetch"
    Reset web settings.

    I've attached the last bdscan, activescan and HJT files.
    Thanks.
     
    Last edited: Mar 10, 2007
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow the directions this time for obtaining a Bitdefender log. You did it correctly the first time but this time all you posted is a log summary which is not useful.

    Uninstall Windows Defender now. You no longer want or need it since you purchased Spy Sweeper.

    Delete the below folder if found:
    c:\windows\system32\services

    Do you recognize the below stuff Panda is complaining about? What are drives H: and L: ?
    H:\New Folders\Downloads\Lyrics\evillyrics\setup.exe[²ÜÇ\ExtractDLL.dll]
    H:\New Folders\Downloads\Lyrics\evillyrics.zip[setup.exe][²ÜÇ\ExtractDLL.dll]
    L:\H backup\NF\Downloads\Lyrics\evillyrics\setup.exe[²ÜÇ\ExtractDLL.dll]
    L:\H backup\NF\Downloads\Lyrics\evillyrics.zip[setup.exe][²ÜÇ\ExtractDLL.dll]


    How are things working now?
     
  7. KenB2014

    KenB2014 Private First Class

    Sorry for the error posting the log instead of the detail. It looks like Bitdefender changed their scanner. I was operating from a printed copy of the "Read and Run this first" instructions from another computer that I cleaned up earlier this year and it said "Click here to view report" which didn't match the "Click here to export the scan report" in the first window. Somehow, I got it right on the first run but went to the second window on the second run. I see your current instructions are current. I will go to your website for the most current info next time. I rescanned and attached the correct report.

    I uninstalled Windows Defender. For future reference, do you prefer Spy Sweeper or Windows Defender? Is one better than the other?

    "c:\windows\system32\services" isn't there even though Panda shows it.

    I uninstalled Evil Lyrics and deleted the downloaded program. It's a program that retrieves lyrics to songs automatically when they are played in Winamp. I tried it for one of my kids and then never used it.

    The H: and L: drives are large drives that I use for storing my digital photograpy and old video tapes that I have converted to mpgs. I also backup other drives there.

    Things seem to be working well now. Bitdefender came up clean as did most of the other scans.

    What of the (file missing) references in the last run of HJT? Should they be deleted?

    Thanks for all the help.
    Ken
     
    Last edited: Mar 10, 2007
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Spy Sweeper would be my first choice; however, it is not free like Windows Defender. In the READ & RUN ME we try to make use of free tools that can always be used by anyone. But if you already have a good malware blocker/scanner like Spy Sweeper, it is not wise to keep another real time blocker installed.

    What hardware and software do you use to convert old tapes (I assume VHS) to mpg? I need to do a bunch of this and have not been impressed by the quality of things tried thus far. Especially after making a DVD out of it.

    Do you mean the below lines?
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    HJT has some bugs where it reports things to be missing when they are not. So we typically ignore these unless they are malware related lines and none of yours are malware.


    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  9. KenB2014

    KenB2014 Private First Class

    I bought ADS DVD+DV a couple years ago. It is a hardware mpeg converter that turns out good image quality and can be set up for different resolutions. Mine is an older version, but this link should be the updated hardware.

    http://www.adstech.com/products/USBAV-709-EF/intro/USBAV-709_intro.asp?pid=USBAV-709-EF

    It comes with capture software, and then I used an older Ulead videostudio product to edit. There's a lot more current stuff out there, but the hardware did a great job.
    -----------------------------------------------
    Should I configure Spy Sweeper to run as a blocker?
    I will ignore the file missing entries from HJT.
    I flushed the restore points and will follow the guide for protecting.
    Thanks
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for the info! I had been looking at a Canopus card which gets great reviews but come without software I believe.

    Yes! The only item in it I do not recommend using is the hosts file protection. I don't believe in that and it often leads to other problems and can slow down surfing performance.
     
  11. KenB2014

    KenB2014 Private First Class

    I've heard good things about the Canopus cards too, but I saw the ADS products demonstated at the LA Computer Fair and decided to try it out. It's pretty easy to use and USB, so you could use it on multiple computers. If I remember correctly, there are different Canopus cards, with some pretty high end models. There are so many choices out there that it can be overwhelming.

    Good luck and thanks again for the help.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and thanks for the info.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds