Please help me get rid of spyware :(

Discussion in 'Malware Help (A Specialist Will Reply)' started by laura679, Nov 17, 2008.

  1. laura679

    laura679 Private E-2

    Hi, I think i've got spyware or malware on my computer. It runs very slow and i get a lot of popups from websites called registry defender or pc shield and they won't go away. I've done the run and read me first and am going to attach my logs. Could you please take a look at them and help me fix it? Thank you,
    Laura
     

    Attached Files:

  2. laura679

    laura679 Private E-2

    Here are the mglogs
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    We are currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Thanks for your patience.

    Kestrel13!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1) Please disable Tea Timer

    How to disable Spybot's TeaTimer

    2) If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    3) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} -
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
    O20 - AppInit_DLLs: C:\WINDOWS\System32\hidserv32.dll
    O20 - Winlogon Notify: 585f00d5502 - C:\WINDOWS\System32\hidserv32.dll



    NOTE:
    HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix exit HJT.

    4) Now we need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    
    KILLALL::
    
    
    File::
    c:\windows\system32\12.tmp
    c:\windows\system32\99.tmp
    c:\windows\system32\hidserv32.dll
    C:\Documents and Settings\Owner\Application Data\02000000e1adf9a7502P.manifest 
    C:\Documents and Settings\Owner\Application Data\02000000e1adf9a7502C.manifest
    C:\Documents and Settings\Owner\Application Data\02000000e1adf9a7502O.manifest
    C:\Documents and Settings\Owner\Application Data\02000000e1adf9a7502S.manifest 
    
    
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\585f00d5502]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "appinit_dlls"=-
    "QuickTime Task"=-
    "iTunesHelper"=-
    "Adobe Reader Speed Launcher"=-
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "appinit_dlls"=""
    
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    5) Please go to Add and Remove Programs and uninstall the following software:

    • Java(TM) 6 Update 7



    Reboot your machine and install the most up to date version of Java available here at the below link:

    Java Runtime 6

    6) Now Run Ccleaner!

    7) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.

    Thanks
    kes
     
  5. laura679

    laura679 Private E-2

    Hey I think i did something wrong because its still running really slow and im still getting the same popups :( It seems to run the computer ok, I can go to my computer or my documents and it goes pretty fast. But when i try to go to any internet pages it runs really slow and still has popups for pc shield or pc defender and now some new one like some mp3 site. Here's my logs.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would like to know what problem you had running ComboFix since the log is in-complete.

    Also...could you tell me if you know anything about the following?

    File::
    c:\windows\system32\GroupPolicy000.dat

    Folder::
    c:\windows\system32\GroupPolicyManifest

    Thanks
    Kes
     
  7. laura679

    laura679 Private E-2

    Ok, so i tried to run it again to see if i got the same result. What happens is combofix is running and it goes to where it says completed stage 50 and then the computer restarts. I thought maybe that was normal because the log was there like it was supposed to be but i guess not :( Also those things you asked about, i looked them up and one is a folder with a bunch of porn cracks and keygens which is totally embarassing cuz i was not looking at porn!!! :cry
    a lot of them say crack and keygen too and one was a music file and one says installer. Should i delete that whole folder? Im still getting the popups. the other one is some file and both of them were hidden. I had to enable the show hidden files and folders to find them and now their light coloured like when its a hidden file or folder.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Have you installed extension for the Python programming language? I'm referring to the below files I see in your logs for Python.They did show up around the time of your infection.

    Note since you are complaining of a slow PC, I'm going to remove BitComet from your Startup list since it is slowing your PC down and it is allowing the opening of many many connections from the internet into your PC full time. P2P and torrent downloaders are not recommended, but if you insist on using them then only run them when you need to use them.

    In addition to BitComet, we will also now use HijackThis to remove a few other items from your startup list that are not malware but are wasting system resources and slowing you down.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
    O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the "Input script here:" part of the window:


    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now please run this: Running GMER to detect Rootkits

    Now Run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    • C:\avenger.txt
    • The log from running GMER
    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  9. laura679

    laura679 Private E-2

    Ok i haven't had a popup since i did those steps :) Things seem to be working a lot better. And a lot faster!!! :-D

    Here are my logs.
     

    Attached Files:

  10. laura679

    laura679 Private E-2

    Oh and im not sure what that python thing is. Should i try to uninstall it?
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You will not be unable to uninstall it since it does not show as being "installed"

    So instead:
    • Right click Start and select Explore to open Windows Explorer.
    • Now use the left window pane to navigate to the C:\Windows\system folder and once in this folder, look for the below files in the right window pane
      • python25.dll
      • pywintypes25.dll
      • pythoncom25.dll
    • When you find the first file, right click on it and select Rename. Then add a .BAK to the end of the file to make it look like python25.dll.BAK
    • Also add a ,BAK to each of the other two files.
    • Now reboot your PC and run all the normal program that you use on your PC in your daily routines. We are just checking to see if any error messages come up in relation to renaming the above files or if any programs stop working properly.
    • If everything runs okay over a few days of normal use. You can simply delete those files we renamed by right clicking on them and selecting Delete.
    Since this PC has no protection installed you need to get protection in place ASAP.

    In the "final steps" below you will find a link for the "How to protect yourself from Malware" thread where you will find a good choice of anti virus to install on your machine amongst our other recommended protection software. Be sure to equip your machine with this as soon as possible!


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
    Thanks
    Kes13!
     
    Last edited by a moderator: Nov 23, 2008

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds