PC Keeps Getting Invaded by SPYWARE

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by soupdogg, Mar 11, 2005.

  1. soupdogg

    soupdogg Private E-2

    I ran a spyboy search and destroy and ad aware se last night and had 0 problems. I wake up this morning and immediately upon start up some pop up for amatuer gay pictures or some garbage comes on my screen. after just about puking i closed it. Then when I opened up internet explorer I found I had been hijacked by about 15 different spy ware progs. I ended up cleaning everything 0 threats and when ir estarted my computer that little popup came up again and same story only more spyware this time. So i did a more thourough clean to make sure I got rid of everything and had disconnected my internet. everything seemed to be fine and almost as soon as i plugged my internet back in boom up comes that popup. I cleaned everything almost the same a hectically went through regedit deleting things that looked suspicious. I removed everything. Plugged back in to the internet and no pop up. I was working on my ocmputer for about 4 hours when suddenly it started working really hard. I had installed Microsoft anti spyware which is suposed to block all malicious code from affecting your computer. It gave me a message saying xact bargain buddy was trying to install blah blah so i get rid of it and do a scan and all of a sudden I have 30 diff syware progs. Everything from 180solutions to coolserach to webrebates. It's a bloody mess. I had all this spyware come up about a week ago. I ended up backing up all important files and doing a total system restore to all original settings. I am at my witts end with this bloody spyware. If anyone can help me please please help me. My only guess is I have some sort of trojan or something somewhere that nothign I have in recognizing and it lays dormat untill I connect to the internet. I hope one of you guys can help me. I'm a newbie member so please be nice.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To help us to best help you, please follow the steps below closely and in the order given and do not skip anything. If you have any difficulty, please post back letting us know what steps you have completed, what you found while doing the scans if anything along with details about any problems you may have encountered in completing the steps. The more details you can provide the better. Don't be afraid to ask for additional help if you don't understand something!

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus RemovalMake sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENTto your next message. (Do NOT copy/paste the log into your post).
     
  3. soupdogg

    soupdogg Private E-2

    Well I did everything on your list.
    I was unable to do a Trend Micro scan.
    Symantec Came back clean
    Stinger came back clean
    ran ccleaner
    446 items on ad aware im not typing them all
    spybot had 44
    ran sybot again on startup because some couldnt be removed
    ie Elitum.Elitebar
    DyFuCa.Internet Optimizer
    IsearchTech.SideFind
    n-Case
    I removed all the registry keys manually that spybot said it could remove
    I still have a pile of crap in my add remove programs
    I pretty much have this Hijackthis log file memorized and coudl clean it myself but am posting it for suggestions.
    I'm making sure I have all windows updates right now.
    If someone can help me that would be great.


    Edit by chaslang: Inline log attached
     

    Attached Files:

    Last edited by a moderator: Mar 12, 2005
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think you forgot one step:

    Is this your complete log? No editing?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run thes additional steps:

    Give this a run: http://securityresponse.symantec.com/avcenter/FxIstbar.exe

    Read about the removal tool here:
    http://securityresponse.symantec.com/avcenter/venc/data/adware.istbar.html


    - Please download and install Microsoft® Windows AntiSpyware
    - Make sure you upgrade it to the lastest definitions. Do not run the scan when asked!
    - Then boot into safe mode and run a full system scan.
    - Then reboot in normal and report back what it finds and fixes and does not fix too.
    - Post a new HJT log (as an attachment this time please)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well in order to keep you moving along, I'm not going to wait for the results of my previous message. After complete my previous message, it is possible that some of the below may alread be fixed and will no longer appear in your log.

    Goto to Add/Remove Programs and look for uninstalls for the below and uninstall if found:
    Media Access
    Delfin Media Viewer Adware


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\slserver.exe
    C:\WINDOWS\System32\mikejones.exe
    C:\WINDOWS\sixtypopsix.exe
    C:\Program Files\Media Access\MediaAccK.exe
    C:\WINDOWS\jiusjwv.exe
    C:\WINDOWS\System32\50cent.exe
    C:\WINDOWS\System32\abasa5jrp.exe
    C:\Program Files\Media Access\MediaAccess.exe
    C:\DOCUME~1\Owner\LOCALS~1\Temp\Z8dFiW.exe
    C:\Program Files\ISTsvc\istsvc.exe

    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [NAV Auto Updates] slserver.exe
    O4 - HKLM\..\Run: [start extracting] mikejones.exe
    O4 - HKLM\..\Run: [sixtysix] C:\WINDOWS\sixtypopsix.exe
    O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
    O4 - HKLM\..\Run: [4VZWsdBN] C:\WINDOWS\jiusjwv.exe
    O4 - HKLM\..\Run: [Windows Media Player] 50cent.exe
    O4 - HKLM\..\Run: [lldhita] c:\windows\system32\lldhita.exe
    O4 - HKLM\..\Run: [Dvx] C:\WINDOWS\System32\wsxsvc\wsxsvc.exe
    O4 - HKLM\..\Run: [abasa5jrp] C:\WINDOWS\System32\abasa5jrp.exe
    O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
    O4 - HKLM\..\RunServices: [NAV Auto Updates] slserver.exe
    O4 - HKLM\..\RunServices: [Windows Media Player] 50cent.exe
    O4 - HKLM\..\RunServices: [start extracting] mikejones.exe
    O4 - HKCU\..\Run: [NAV Auto Updates] slserver.exe
    O4 - HKCU\..\Run: [start extracting] mikejones.exe
    O4 - HKCU\..\Run: [Windows Media Player] 50cent.exe
    O4 - HKCU\..\RunServices: [start extracting] mikejones.exe
    O15 - Trusted Zone: *.media-motor.net
    O15 - Trusted Zone: *.popuppers.com

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\wsxsvc <--- the whole folder
    C:\Program Files\ISTsvc <--- the whole folder
    C:\Program Files\Media Access <--- the whole folder
    C:\WINDOWS\System32\slserver.exe
    C:\WINDOWS\System32\mikejones.exe
    C:\WINDOWS\sixtypopsix.exe
    C:\WINDOWS\jiusjwv.exe
    C:\WINDOWS\System32\50cent.exe
    c:\windows\system32\lldhita.exe
    C:\WINDOWS\System32\abasa5jrp.exe
    C:\Documents and Settings\Owner\Local Settings\Temp\Z8dFiW.exe <--- delete all file and subfolders in this Temp folder that is allows you to delete.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now run Ccleaner that you installed while running the READ ME. And on the Windows tab leave the default settings and select Run Cleaner. Do not run any other options.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  7. soupdogg

    soupdogg Private E-2

    Sorry about the dealy in reply takes a long time to do these dam scans.

    Microsoft AntiSpyware found and removed
    Windupdates
    Ist.lstbar
    ist.xxxtoolbar

    it ignored a bunch of files labelled () and woudlnt remove them
    mostly files found in system32 folder
    furoa.exe furol.exe.furom.exe.furop.exe buddy.exe. elitfbr32.exe elitexij32.exe
    gegmgg.exe hockkeod3.exe qun4mkbu9.dll and a few i can't read my notes for.

    Also I can't figure out how to attach my log file.

    I see you have uploaded a step for me to do so i will do that.

    Also as I started typign this my microsoft anitspyware is telling me that ist.istbar browser modifier is trying to install i hit remove and 5 seconds later it happens again.

    Let me know how to attach that file and I will go on with your steps.

    thanks
     
  8. soupdogg

    soupdogg Private E-2

    Ok I followed your last steps

    C:\WINDOWS\System32\wsxsvc <--- the whole folder (not there)
    C:\Program Files\ISTsvc <--- the whole folder (not there)
    C:\Program Files\Media Access <--- the whole folder(not there)
    C:\WINDOWS\System32\slserver.exe (deleted)
    C:\WINDOWS\System32\mikejones.exe (deleted)
    C:\WINDOWS\sixtypopsix.exe(deleted)
    C:\WINDOWS\jiusjwv.exe(deleted)
    C:\WINDOWS\System32\50cent.exe(deleted)
    c:\windows\system32\lldhita.exe(not there)
    C:\WINDOWS\System32\abasa5jrp.exe(deleted)
    C:\Documents and Settings\Owner\Local Settings\Temp\Z8dFiW.exe <--- delete all file and subfolders in this Temp folder that is allows you to delete. (deleted folder)

    I have attached my hjthis log.

    Everything seems to be ok for now.

    How do I make sure this never happens again it feels like i got raped or something.

    Do I need to download windows service pack 2?

    If i run adaware spybot and microsoft antivirus shoudl that keep me safe.

    Let me know what you think of this and how you think this shat happened.

    Once again thanks. Nice to know theres good people out there to fight this fight against the idiots who invented this spyware shat.

    peas
     

    Attached Files:

  9. soupdogg

    soupdogg Private E-2

    I know i'm probably annoying the hell out of you but I attached a screen shot with the listing of those files Microsoft Antivirus Chose to ignore and won't do anything else with them. How can I remove these? Just by deleting them in safe mode?

    Let me know please.

    Peas
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! You HJT log is clean. You should try running MS Antispyware after booting in safe mode. See if that helps to allow it to fix some of the problems it found. Otherwise you should try fixing them by hand.

    See the below to help you avoid future problems.
    How to Protect yourself from malware!
     
  11. macman

    macman Private E-2

    Do yourself a favor. Get a mac. Or run Linux on your PC. Its the only chance you've got at keeping the spyware off your machine. And for god's sake, stop using IE. Switch to Firefox.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post's like this are not going to help the user resolve their current problems. And not everyone has the option to get a Mac or wants the complications of running and administering a Linux OS. Let alone having to learn a new OS.

    Also he you read our sticky threads (including the one posted in my last message), you will already see that we recommend using FireFox.

    I'm online doing more surfing then most people, and I have never had a malware problem! That's right never! If you properly update, protect with the proper software, and watch where you surf and what you click on and say yes to, your chances of getting infected are significantly lower. In additon, while I do have and use FireFox, I primarily use IE and still have no problems. I use IE because most people do. So I use it to be more familiar with problems others may experience.
     
    Last edited: Mar 18, 2005

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds