OuterInfo Removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by Benny666, Nov 23, 2006.

  1. Benny666

    Benny666 Private E-2

    Hello,
    I have been having issues with OuterInfo pop-ups!! I followed your instructions and so far, so good!! I am attaching the first section of required documentation of scans. Please let me know if there are any other preventative measures I should be taking to make sure this nasty adware doesn't return.

    Thanks,
    Ben
     

    Attached Files:

  2. Benny666

    Benny666 Private E-2

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You have a lot more problems than just OuterInfo. You have PurityScan, WinAd Client, Trojan.Hacktool.Prockill.A, Virtumonde and more.

    But first you need to follow the directions in the READ & RUN ME and install the proper version of HijackThis. You are using v1.97.7 which has not been used in over two years and this means you did not download from the link in the READ ME.

    Get the proper version but do not attach a new HJT log yet. I will ask for one later.

    You also did not install the recommened Sun Java version as requested in the READ ME. You are also using a very outdate version of Sun Java.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2

    Now install the current version of Sun Java from: Sun Java Runtime Environment


    Now Continue with the below!
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the below new logs and tell me how the above steps went.

    1. ComboFix.txt
    2. GetRunKey
    3. ShowNew
    4. HJT
    Make sure you tell me how things are working now!
     
    Last edited: Nov 24, 2006
  4. Benny666

    Benny666 Private E-2

    Thanks for your help! I downloaded the version of these files that you recommended. I didn't have any problems running these programs and my computer appears to be free of pop-ups although I guess it isn't completely virus-free yet. Attached are the most recent log files. Please let me know if I need to do anything else to get rid of these files.
     

    Attached Files:

  5. Benny666

    Benny666 Private E-2

    And here's the Hijack this log from the second scan.

    Thanks,
    Ben
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member



    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Becibwninda
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below Service (if you do not find it or get any errors, just continue):
      • Ilpatwt

    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste Becibwninda into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • Ilpatwt
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Continue by downloading a tools we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    R3 - URLSearchHook: (no name) - {30940B30-C884-B55E-8088-C66942DE8A90} - C:\WINDOWS\System32\gdalw.dll
    O2 - BHO: (no name) - {30940B30-C884-B55E-8088-C66942DE8A90} - C:\WINDOWS\System32\gdalw.dll
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Umraqqae] C:\Documents and Settings\Ben\Application Data\W?nSxS\s?chost.exe
    O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
    O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
    O23 - Service: Becibwninda - GRISOFT, s.r.o. - (no file)
    O23 - Service: Ilpatwt - Macrovision Corporation - (no file)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\WINDOWS\SYSTEM32\wintsvcc.exe
    C:\WINDOWS\SYSTEM32\gdalw.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  7. Benny666

    Benny666 Private E-2

    OK, I've followed the steps you have given me. However, I wasn't able to fix the following files in Hijack This because they weren't listed:

    O23 - Service: Becibwninda - GRISOFT, s.r.o. - (no file)
    O23 - Service: Ilpatwt - Macrovision Corporation - (no file)

    Attached is a log from three programs that you have asked me to run.

    Thanks again for your help,
    Ben
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's okay! The first steps with stop and deleting the service removed them. The other HJT step was just a backup step.

    You did not delete C:\WINDOWS\SYSTEM32\wintsvcc.exe with PocketKillBox. You need to delete it manually or with Killbox.


    Other than the above, your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds