Need help!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by phm, Jan 2, 2005.

  1. phm

    phm Private E-2

    Hi there, and happy newyear!
    I've been spending days trying to remove all kinds of malware (SurfSideKick, about:blank and others) from my daughters notebook, but I dont seem to succeed. Every time I hit the internet something bad start bilding up. :mad:
    After following your read-me-first-tutorial I thought to be clean and installed Windows XP servicepack 2 in order to give more security, but when I went for updates, I still got pop-ups. So I followed your toturial once again all the way! Did all the downloads, the safemode-scans and fix'es and at last I ran HijackThis, using the toturial. Now Spybot and all other scans told me that I was clean, but not. :confused:
    After having connected to the internet I've got all this again:
    CoolWWWSearch.Bootconf
    coolWWWSearch.Loadbat
    coolWWWSearce.Oslogo
    cool.WWWSearch.Tapicfg
    coolWWWSearch.Xmlmimefilter
    IGetnet
    Common Hijacker
    wich Spybot seems unable to remove (even though it says so)
    The only thing HijackThis found and could not fix is some 015 Trusted zones:
    *.frame.crazywinnings.com
    *.static.topconverting.com
    *.frame.crazywinnings.com (HKLM)
    *.static.topconverting.com (HKLM)
    So someone please - what do I do now?
     
  2. phm

    phm Private E-2

    Still need help. svchost.exe identified

    Hi again!
    I cryed out for help yesterday, but got no reply. Have done everything (se thread posted ysterday) but is still infected.
    Read your answer to Yousai, who got a simular problem and tryed out your advice to him. Found svchost.exe and rundl32.exe by using HijackThis, but is not able to kill it. Tryed manually but same result. Tryed ctrl-alt-delete, still no result :mad:
    So pleece HELP ME!!!!
    p.s. when chasing svchost.exe manually I found spoolsrv.exe and spoolsrv.dll and kicked them out
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Still need help. svchost.exe identified

    I merged you back with your originally thread. Things have been very busy around here and we just were not able to get to you yet.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Still need help. svchost.exe identified

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  5. phm

    phm Private E-2

    Re: Still need help. svchost.exe identified

    Hi!
    I understand perfectly that you're busy - no hard feelings, I'm just glad for the oppotunity of getting help. :)
    Log-file attached.
    I'll bee at the computer all evening hoping to get the magic words from you!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Still need help. svchost.exe identified

    This looks like a safe mode boot log. Please post one from Normal boot mode.
    You do have a few things I can see that must be fixed. I'll get back to you in a little while.

    What is your expected home page?
    Do you use iFinger?
     
    Last edited: Jan 4, 2005
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Still need help. svchost.exe identified

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O15 - Trusted Zone: *.frame.crazywinnings.com
    O15 - Trusted Zone: *.static.topconverting.com
    O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
    O15 - Trusted Zone: *.static.topconverting.com (HKLM)


    After clicking Fix, run another scan with HJT.

    I'm guessing that the crazywinnings.com stuff may come back. Let me know if they do. I have another step to fix that.
     
  8. phm

    phm Private E-2

    Re: Still need help. svchost.exe identified

    You're quite right - it was a safe mode boot log. Here is another one.
    Also you're right about the Trusted Zone things keep comming back. Eventhough I let HijackThis fix them they're back next time I scan. I also tryed to remove them via my browser-settings, but without result.
    The startpage is allright and, iFinger is also OK (it is a dictionary).
    Sorry I didn't answer you yesterday, but I have to get up early in the morning, so I have to hit the bed around 23 oclock, but I'll be online every day from 17 - 23
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Still need help. svchost.exe identified

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file move.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.)

    Double-click on the move.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes.
     
  10. phm

    phm Private E-2

    Re: Still need help. svchost.exe identified

    Ok done that
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Still need help. svchost.exe identified

    But did it work. Check you HJT log now. Are the O15 lines gone?
     
  12. phm

    phm Private E-2

    Re: Still need help. svchost.exe identified

    Yes they are gone.
    What about the svchoast.exe is that a bad thing to, and will I be able to kill it with HijackThis?
     
  13. phm

    phm Private E-2

    Re: Still need help. svchost.exe identified

    And can I try to hit the internet?
    I just realised, that I didn't tell you, that I didn't write you from the infected comp. but from a clean one.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Still need help. svchost.exe identified

    What svchoast.exe thing? You don't have any files like that running. You do have:
    C:\WINDOWS\system32\svchost.exe

    but that is a valid process.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Still need help. svchost.exe identified

    If the O15 lines are gone you should be able to use the PC but I would look into having the stuff from here installed first: How to Protect yourself from malware!

    Especially a firewall, but you may have the WinXP SP2 firewall already enable since that is the default.
     
  16. phm

    phm Private E-2

    Re: Still need help. svchost.exe identified

    Ok that was what I ment.
    Tryed to hit the internet - there still seems to be problems. Pop-up occured while visiting Symantec.
    Spybot - Search & Destroy still detected the earlier listed entries, but doesn't seem to be able to fix them.
    Also ran HijackThis - new log attached. As you can see I have got some new 01 - Hosts :(
     

    Attached Files:

  17. phm

    phm Private E-2

    Re: Still need help. svchost.exe identified

    Checked the Open hosts file manager in HijackThis. Result:
    127.0.0.1 www.igetnet.com
    127.0.0.1 code.ignphrases.com
    127.0.0.1 clear-search.com
    127.0.0.1 sds.clrsch.com
    127.0.0.1 status.clrsch.com
    127.0.0.1 www.clrsch.com
    127.0.0.1 clr-sch.com
    127.0.0.1 sds-qckads.com
    127.0.0.1 status.qckads.com
    #Start of entries insert by Spybot - Search & Destroy
    #End of entries insert by Spybot - Search & Destroy
     
  18. phm

    phm Private E-2

    Re: Still need help. svchost.exe identified

    I'm of to bed now, but will be back tomorrow.
    Thanks a lot for your help so far.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Still need help. svchost.exe identified

    This problem occurred because it was lying dormant in the background while you were not connecting to the internet. Now that you connected, we can see it and fix it.

    Download the below tools:

    http://www.downloads.subratam.org/DllCompare.exe

    Pocket KillBox


    VX2.BetterInternet Finder XP/2k - Version Msg126

    Generic Find It Tool - NT/2000/XP


    Extract all the files from the Generic Tool into its own folder.
    Then run find.bat. Post the log it creates back here as an attachment.
     
  20. phm

    phm Private E-2

    Re: Still need help. svchost.exe identified

    I'm back from work and have done the downloads.
    You didn't tell if I should connect to the internet while running the find.bat so I didn't connect the bad comp. as odd sites keep popping up even my browser is closed.
    Made the downloads on the cleen comp. and lifted them to the infected one, extracted to separate folder C:\findit, ran find.bat. After 5 min. this message occured:
    the given path was not found ??
     
  21. phm

    phm Private E-2

    Re: Still need help. svchost.exe identified

    Well - a litle more patience was needed :eek: . After 15 min. this log was shown.
    I also post a log from the VX2Finder.
    Hope it will help you (and thereby me ;) )
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Still need help. svchost.exe identified

    Please be careful! Only run what I ask. I did not want you to run anything but the find.bat program. I will tell when we will use the others.

    Here is a list of files that we need to delete using Killbox.

    C:\WINDOWS\System32\mvtscax.dll
    C:\WINDOWS\System32\l66olgj316o.dll
    C:\WINDOWS\System32\splwapi.dll
    C:\WINDOWS\System32\f62mlgf1162.dll
    C:\WINDOWS\System32\kkdlt1.dll
    C:\WINDOWS\System32\mwpbde40.dll
    C:\WINDOWS\System32\MUC70.dll
    C:\WINDOWS\System32\oweaut32.dll
    C:\WINDOWS\System32\rHsdlg.dll
    C:\WINDOWS\System32\dg32gt.dll
    C:\WINDOWS\System32\stnike.dll
    C:\WINDOWS\System32\cmrpol.dll
    C:\WINDOWS\System32\micms.dll
    C:\WINDOWS\System32\myctf.dll
    C:\WINDOWS\System32\mcdemui.dll
    C:\WINDOWS\System32\ote2disp.dll
    C:\WINDOWS\System32\crc.dll
    C:\WINDOWS\System32\mxdart.dll
    C:\WINDOWS\System32\wbi.dll
    C:\WINDOWS\System32\iordbg32.dll
    C:\WINDOWS\System32\mbxml2.dll
    C:\WINDOWS\System32\woavideo.dll

    and C:\WINDOWS\System32\guard.tmp

    And here is how you need to do it.

    Here is the procedure to use to delete them. Run Pocket Killbox. Select the option to Replace on Reboot.

    Now you are going to repeat the below steps for every file except C:\WINDOWS\System32\guard.tmp (we will add it separately at the end). Replace the the word fullpathfile with the actual full file name path from above (one file at a time). For example, the first time you paste in C:\WINDOWS\System32\mvtscax.dll

    1) Now, Copy and Paste fullpathfile into the box
    2) Check the option to Use Dummy.
    3) Now, Click the Red X and Yes to the confirmation message.
    4) A message will ask if you want to reboot now – Click NO.
    5) Repeat for all files except the last one

    For the last file, we will be rebooting when prompted. Here is the final step of the file deletions:

    Now, Copy and Paste C:\WINDOWS\System32\guard.tmp into the box. Check the option to Use Dummy and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your machine to reboot Normally. Tell me if you get any error messages on reboot and tell me the exact messages.

    After it reboots get another find.bat log and post it. Also run DLL Compare – Click Run Locate.com then click the Compare button. Follow the prompts and allow time for it to complete and make a log. Please attach that Log.

    Also post a new HijackThis log.

    Important:
    Also run Windows Explorer and look in C:\WINDOWS\System32 for the file guard.tmp. Tell me if you see it or not.
     
  23. phm

    phm Private E-2

    Re: Still need help. svchost.exe identified

    Thank you very mush for a quick reply! Are you online and working 24 hours a day?
    OK, sorry about the impations with the VX2 finder. I'll try to take one step at a time.
    Did the reboot - no error-messages were shown.
    No sign of C:\WINDOWS\System32\guard.tmp.
    Find.bat and DLL Compare logs attached.
    HijackThis log follows.
     

    Attached Files:

  24. phm

    phm Private E-2

    Re: Still need help. svchost.exe identified

    Here follows the HijackThis-log
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Still need help. svchost.exe identified

    No I'm not here 24 hrs a day, though it seems like that sometimes.

    Run Pocket KillBox and Copy and Paste the Following into the box: C:\RECYCLER\Desktop.ini - Click Red X to delete it using Standard File Kill.

    NOW:

    Open VX2Finder and Click on the "Find Vx2.Betterinternet" button.

    Then click on these buttons in the right pane unless they are "greyed" out:

    - UserAgent$ Button to remove the UserAgent from the registry
    - Guardian.reg
    - Restore Policy

    Exit and reboot.

    Using START > RUN > regedit, please open the registry editor and navigate to the following:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Dynamic Directory

    Backup this key by clicking File, Export and then enter a File name and save it somewhere you can find it (if needed). Do the Export before doing the following:
    RightClick on the above registry key (the Dynamic Directory one - make sure the bottom of the regedit window shows the full reg key as shown above in bold) and select DELETE.

    NEXT: Run find.bat (Generic Detection Tool) and attach that Log and a fresh HJT Log

    We may be finished if everything checks out.
     
  26. phm

    phm Private E-2

    Re: Still need help. svchost.exe identified

    Wow! Sounds good finaly to get rid of this crap. :)
    Did as requested. Using VX2 only "UserAgent$" and "Restore Policy" showed up.
    Files attached.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Still need help. svchost.exe identified

    You forgot to attach the files.
     
  28. phm

    phm Private E-2

    Re: Still need help. svchost.exe identified

    Don't understand what happend. Actualy I did attach the files, and also I looked for your answer all night, but it didn't show up until this morning althoug it says that you posted it yesterday???
    But we try again.
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Still need help. svchost.exe identified

    Okay! The problem is all cleaned up now. However I see this in your HJT log:

    O23 - Service: Print Spooler - Unknown - C:\WINDOWS\system32\spoolsv.exe (file missing)

    That file should not be missing. Check in C:\WINDOWS\system32 to see if it is really missing. If so, you need to get a copy back there. Look for a c:\i386 or a c:\windows\i386 folder on your hard disk. If you find it, check for a spoolsv.exe file there and copy it to the system32 folder. If you find it but it is named spoolsv.ex_ , you will have to uncompress the file from a command prompt. I'll explain that later if it becomes necessary.
     
  30. phm

    phm Private E-2

    Re: Still need help. svchost.exe identified

    Well thanks a lot for your help so far, both to you Chaslang for your personal assistans and Major Geeks for running this fantastic site. How do you do it, when everything is free and the site dosen't seem to be overloaded with adds? Are you all volunteers?
    I haven't been online since yesterday because of a general black-out here due to a hurricane, that ran acros the contry yesterday. The pover is back now, but our internet is stil not running, so I write you from my work.
    In regard to the spoolsv.exe file I might have deleted it by mistake during the batle. However I did find it in the Windows\i386 folder but as you say as aspoolsv.ex_ so what to do now?
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Still need help. svchost.exe identified

    Yes, the helpers here are all volunteers!

    For the spoolsv.exe
    Open a command prompt by click Start, Run and enter cmd in the box and click OK.
    Now enter the following commands each followed by the enter key:
    cd c:\windows\system32
    expand c:\windows\i386\spoolsv.ex_ spoolsv.exe
    exit

    Now open Windows Explorer and make sure the file c:\windows\i386\spoolsv.exe is present and that you HJT log does not show it to be missing.
     
  32. phm

    phm Private E-2

    Re: Still need help. svchost.exe identified

    Trying to uncompres the spoolsv.ex_ file by doing what you told me to do, but haven't succeded.
    Getting the message: ther were not given any destination for c:\windows\i86\spoolsv.ex_spoolsv.exe ???
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Still need help. svchost.exe identified


    Did you enter the command properly?

    There is a space after expand and another space after spoolsv.ex_

    The way you wrote it above looks like you left out the space.

    And it is not i86. It is i386.
     
  34. phm

    phm Private E-2

    Re: Still need help. svchost.exe identified

    Ofcause you were right again! I didn't notice the space after spoolsv.ex_. Using that everything worked out as you told me. Also the internet works perfect without pop-up's.
    So I won't ask you anything more this time, I only want to thank you once again for your great help, and if you ever feel like spending a couple of days in the contryside in Denmark, please feel free to come and visit us. Just send me a mail to let me know the date of arrival.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Still need help. svchost.exe identified

    You're welcome! Now that's a nice offer. I would love to visit Denmark some day. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds