PC has downed tools and gone to lunch

Discussion in 'Malware Help (A Specialist Will Reply)' started by Anon-885913a7aa, Dec 5, 2006.

  1. Anon-885913a7aa

    Anon-885913a7aa Anonymized

    Hi chaps, and chapettes(!)

    New user so be gentle with me hey.

    I'm working with Windows XP Professional OS.

    Please please help me out on this one. I've gone through and completed the 'read me before asking for help section' and have cleaned up some problems on my pc - but some still remain. Spybot and Counterspy were clean.

    The scans were clean except for: Bitdefender found a 'Trojan.SrchSpy.D' virus, and Panda found a spyware and 2 suspicious files.

    I've attached the newfiles and runkey.txt files and the activetxt one also.

    I'll send up the HJT log in a new mail.

    In anticipation of any assistantce I am eternally grateful!
     

    Attached Files:

  2. Anon-885913a7aa

    Anon-885913a7aa Anonymized

    And here's the HJT log.

    Trust it's all as it should be.......thanks again.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You Windows OS is way out of date with updates and represents a major security risk. After we fix your malware problem, you MUST get updated.

    Where is your log from Bitdefender? Based on your HJT log, it was never run!

    Are your copies of Ewido and Spyware Doctor paid versions or free trial versions?

    Did you buy the below or are they trials?
    Easy SpyRemover
    MacroVirus
    CyberDefender


    Please run the below procedure and attach the requested log:

    WareOut Removal


    Then Run HijackThis and select the following lines (some may be gone after running the above WareOut fix. Just ignore and continue.) but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R3 - URLSearchHook: (no name) - {B5677C5C-3806-B339-8274-0A1035900340} - scanSYS.dll (file missing)
    F3 - REG:win.ini: run=,
    O1 - Hosts: localhost 127.0.0.1
    O4 - HKLM\..\Run: [TRPT] newbreed.exe
    O4 - HKLM\..\Run: [dialer423] msag.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [UserSp1] MSTCPDLL.exe
    O4 - HKCU\..\Run: [iesetupdll] StatusCheck.exe
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.155 85.255.112.77
    O17 - HKLM\System\CS1\Services\Tcpip\..\{71EBFDF3-21D6-4734-8ECE-14F4971FFA92}: NameServer = 85.255.115.155,85.255.112.77
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.155 85.255.112.77
    O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.115.155 85.255.112.77
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.155 85.255.112.77

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode and attach a new HJT log along with the log from FixWareOut.
     
  4. Anon-885913a7aa

    Anon-885913a7aa Anonymized

    Thanks for that reponse,

    On the pc we run free copies of a-squared anti-dialer, a-squared free, and trial versions of avg and ewido.

    The copy of CyberDefender has already been removed, should I uninstall EasySpyRemover and Macrovirus? I've also got a trial version of Spyware Doctor that I've tried to uninstall to free up some space but it just won't budge. It just starts, then tries to direct me to their website to buy a 6 month trial version. When I refuse it stops completely.

    What updates to the MS OS do you recommend?

    I've run the WareOut removal and attach the log, BUT when going into the Network Connections area on the Control Panel, I cannot bring up anything to do with the TCP/IP - the properties page has only a tab saying 'General' and says I can connect to the internet using an Internet Connection.

    Therefore I've gone no further with the HJT etc until you can impart some more wisdom!!

    :confused:
     

    Attached Files:

  5. Anon-885913a7aa

    Anon-885913a7aa Anonymized

    Well that's that sorted - the internet connection had shaken loose - but you all knew that and didn't tell me...... :)

    I've now managed to complete the Wareout process and the log has been attached previously - I've re-run HJT and attach the log as requested.

    Thanks again chaslang for your assistance so far, really appreciated.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you follow the directions and ran HijackThis AFTER you ran FixWareOut??? You logs still show all of the same problems; however this could also be due to the fact that you have WAY too many antispware protection tools installed and they are all fighting against each other and they are all blocking the fixes.

    Try the fix I gave to you again and look at a new log yourself afterwards. If all the items I'm asking you to fix are still there, then UNINSTALL all your free trial antispyware applications (including CounterSpy from the READ ME) and then run the fix again. If you still have problems uninstall Spyware Doctor, try using this to uninstall it: Your Uninstaller! 2006

    Attach a new HJT log afterwards.

    Are you using a dialup, cable, or DSL connection?
     
  7. Anon-885913a7aa

    Anon-885913a7aa Anonymized

    I used Uninstaller 2006 - and it claimed to have removed the Spyware Doctor files - but they remain in my local drive.....

    I have removed the MacroVirus files also. oh great my applications are being hijacked as I type - or the firewall is attempting to block it anyhow. :mad:

    I've re-run FixWareOut and attach the log - I'll re-run HJT now and attach a new log later. Should I now uninstall CounterSpy?

    We run on a broadband connection, wired up.
     

    Attached Files:

  8. Anon-885913a7aa

    Anon-885913a7aa Anonymized

    I have now run HJT and checked it as you asked - all the dodgy files seem to have gone. :) Log attached.

    I didn't have to remove any of the anti-spyware programs but my pc is still slow, therefore will have a clear-out of some of them once the whole problem has cleared up in readiness for any updates required.

    Your advice so far has been clear and therefore, to a technophobe, superb. Thank you. I await further instructions chief.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still see the below on your PC:
    a-squared Anti-Dialer
    CounterSpy
    CyberDefender
    Ewido
    MacroVirus
    SpyRemover
    Spyware Doctor

    Based on previous messages I expected that the below should already be uninstall:
    CounterSpy
    CyberDefender
    MacroVirus
    SpyRemover
    Spyware Doctor

    Please goto Add/Remove programs and try again to uninstall each of these again. I know you have a problem with SpyWare Doctor uninstalling and my next steps below will give manual steps to remove it. I will also be including manual steps to remove other items, but you must first try uninstalls. CounterSpy should easily uninstall.

    Start by downloading a tools we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\WINDOWS\System32\Service.exe <<--- BE CAREFUL. DO NOT TRY TO kill services.exe which is valid. Notice the 's' after service.
    C:\Program Files\Spyware Doctor\swdoctor.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [Easy SpyRemover] C:\Program Files\Easy SpyRemover\EasySpyRemover.exe /smart
    O4 - HKLM\..\Run: [MacroVirus] C:\Program Files\MacroVirus\MacroVirus.exe -boot
    O4 - HKCU\..\Run: [CyberDefender Early Detection Center] "C:\Program Files\CyberDefender\cdinstx.exe" -cfgwizard
    O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\System32\Service.exe
    C:\Program Files\Spyware Doctor\swdoctor.exe
    C:\Program Files\Easy SpyRemover\EasySpyRemover.exe
    C:\Program Files\MacroVirus\MacroVirus.exe
    C:\Program Files\CyberDefender\cdinstx.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\Spyware Doctor
    C:\Program Files\Easy SpyRemover
    C:\Program Files\MacroVirus
    C:\Program Files\CyberDefender

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Dec 7, 2006
  10. Anon-885913a7aa

    Anon-885913a7aa Anonymized

    OK done all that.

    Ran HJT but could not kill off C:\Windows.....service.exe - message I gained was "may be closed or protected by Windows, could not kill."
    C:\Program Files.....swdoctor.exe had gone.

    Ran a scan but could not find any of the files mentioned, exited HJT.

    Ran Pocket Killbox, all fine, rebooted.

    Managed to paste C:\Windows\System32\Service.exe but could not paste in the other four .exe files. Completed rest of actions on Killbox. Rebooted pc. Then found and deleted the C:\Program Files\Spyware Doctor file - all the others had scarpered.

    Ran the requested logs and attach below - the HJT log was run last.

    The pc is running much faster or seems to be and things are loading at a better speed.

    What's next mon captain?
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are running HijackThis improperly now. You had it correct in your previous log. Delete the below file folder which is the wrong location. That way you cannot run this one anymore.

    C:\Documents and Settings\Andy\My Documents\hijackthis\analyse.exe


    Only run the one you have here:

    C:\Program Files\HJT2\hijackthis\analyse.exe

    The below bad service is now showing and we need to remove it:
    O23 - Service: Service - Unknown owner - C:\WINDOWS\System32\Service.exe (file missing)
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteService into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.
    After reboot, delete this file: C:\WINDOWS\system32\mtwuuaaa.exe

    Now attach a new logs from HJT and ShowNew.
     
  12. Anon-885913a7aa

    Anon-885913a7aa Anonymized

    Thanks,

    done all of that, and the bar-coded file has gone.

    Files attached as requested.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps (don't delay of following these. You need to get to step 9 below and run thru that link ASAP).
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  14. Anon-885913a7aa

    Anon-885913a7aa Anonymized

    Brilliant, massive thanks to you for all your help, and also your colleagues, the service given is superb.

    Have a top notch Christmas. :)
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and thanks! ;)

    Enjoy the holidays malware free! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds