Registry filth

Discussion in 'Malware Help (A Specialist Will Reply)' started by BFLeigh, Jan 30, 2006.

  1. BFLeigh

    BFLeigh Corporal

    Is this the correct forum for help with cleaning out malicious registry crap?

    MS Antispyware yesterday blocked a startup program and asked my okay on it, and there was something already on the blocked list. A dialer of some sort. Accessing Real-Time Protection, I've found that it's somehow made its way onto my Trusted Sites list, albeit a deactivated one. Details are as follows:

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\adservs.com\www.csx*

    I headed to that area in the registry and it's absolutely stuffed with malware.

    I've ran through the tutorials at the top of the forum/the usual walkthroughs MajorGeeks recommends; ran all my spyware and virus checkers (Adaware, MS Antispyware, Spybot and AVG Anti-Virus Free Edition). Yet it remains. Before I started surgery on the registry I thought I'd come here first.

    Thanks in advance!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is nothing wrong with that entry. It was more than likely added by Spybot or SpywareBlaster for your protection. There are a thousand or more of them in the Domains key. That is, assuming it is in the Restricted Zone and not the Trusted Zones.
     
  3. BFLeigh

    BFLeigh Corporal

    I can't seem to cut and paste the alerts logged in MS Antispyware to show you word for word, the best I can tell is that this adservs.com got onto my Trusted Sites list without me authorising it. Another thing I've find in MS Antispyware talks about hypermart.net.

    This one is quite strange and I don't know - as you said - which ones are supposed to be there and which ones aren't. I might be able to cut and paste the folders in the registry key but there are lots of them and many of them have disgusting titles.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I said before, most of them are there due to programs like Spybot and they are in the Restricted Zones. However if it is detected because it is in the Trusted Zone, that is a different story. You can easily look in your Interne Explorer Security settings and see what is in the Trusted and Restricted Zones. You can also view them from the registry. If the data value is a 4, they are in the Restricted Zone. If the data value is a 2, it is in the Trusted Zone.

    Perhaps you should work thru our standard cleaning procedures below so we can make sure you have no malware problems.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .
     
  5. BFLeigh

    BFLeigh Corporal

    The Bitdefender scan definitely surprised me.

    I've been trying to find where it is in MS Antispyware I can actually view my blocked startup files, instead of taking the time to go to a quicktime movie webpage and get it then to ask me if qttask.exe is allowed to be loaded. Only when I do that can I see this dialer, if it is a dialer. It's apparently in a folder called video1 in Program Files but even with Hidden Files viewable, I don't see such a folder.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did the BitDefender scan surprise you?

    You have to complete the rest of the READ ME.

    Attach the PandaActiveScan log too. And then follow the procedure in step 7 exactly to makes sure HijackThis is installed properly and attach a log from it too.
     
  7. BFLeigh

    BFLeigh Corporal

    Pandascan attached. It actually found a dialer on the PC, I knew it. And two spyware things

    The Bitdefender scan (and now this one) surprised me because I'm fastidious with my spyware and virus scanning. Is it better to get rid of some of these programs and just run Bitdefender and Pandascan two to three times a week?

    HijackThis log coming right up.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what other tools your are referring to. Name them all.

    No I would not run BitDefender and PandaScan multiple times per week. It takes way too long. You may just need better protection and maybe you should read this:

    How to Protect yourself from malware!

    Why do you have all of the hosts backup files?
     
  9. BFLeigh

    BFLeigh Corporal

    My current arsenal contains MS Antispyware, Spybot, Adaware, Spyware Blaster and AVG Free Edition for virus-checking. They are all current versions and updated to the 2nd of Feb 2006.

    Host backup files? Should I delete them?
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes delete the backup hosts files. You should only have the actual hosts file and it should only have one line (besides the starting comment lines) and that line should be 127.0.0.1

    All of the tools you are using are fine but a paid version of Spy Sweeper would be much better than free MS Antispyware (beta).

    You HJT log shows no malware but the below can be fixed:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = Error


    Did you delete any of the files found by Panda? If no, delete the below:
    C:\WINDOWS\optimize.exe C:\WINDOWS\pcconfig.dat
    C:\WINDOWS\system32\WrapperOuter.exe
     
  11. BFLeigh

    BFLeigh Corporal

    I've fixed that R1 line; and now I've deleted both those files. I'll talk with the brains trust here about paying for Spy Sweeper. I'll strongly recommend it.

    What's the best way to go about deleting these backup hosts files? Which log/location did you see them in?

    How can I check to see if this dialer thing is gone?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually there were three files to delete. I did not put it one carriage return:
    C:\WINDOWS\optimize.exe
    C:\WINDOWS\pcconfig.dat
    C:\WINDOWS\system32\WrapperOuter.exe

    Just use Windows Explorer and go to the folder and delete them. See the PandaActiveScan log for the file names and path to where they are at.

    Run a new Panda scan and attach the log after doing the above.

    Also for your initial problem with:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\adservs.com

    What is the data value in this registry key?
     
  13. BFLeigh

    BFLeigh Corporal

    optimize.exe deleted.

    A new Bitdefender scan is almost done. I'll run the Pandascan again after it. Something's happened, the same problem is located in C:\System Volume Information folder. It's not finished but it says its deleted it again. What have I done wrong? System Restore is supposed to be on or off during this?

    Looking in the registry, that particular key isn't there now among the filthy stuff but there is an adsrve.com key. 0x00000004 (4) is the data value of * and the type of * is REG_DWORD.

    EDIT: Bitdefender scan finished and attached.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't worry about System Restore until we are done fixing all problems. For now we want it enabled.

    If the data value is 4, ignore what MS AS was telling you because as I stated earlier, it is not an issue. The Domain is in the Restricted Zone which is what you want.
     
  15. BFLeigh

    BFLeigh Corporal

    I am still concerned if that video1 folder/others like it are still there. Thanks for all your help so far chaslang :)

    Pandascan has just found one instance of spyware this time. Unable to disinfect it. Here's the attachment:
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    I'm not sure what you mean about video1?? Who is telling you there is a video1 folder? And where did it say it was?
     
  17. BFLeigh

    BFLeigh Corporal

    MS AS won't let me cut and paste the events logs from the Real-Time Protection and Advanced Tools areas. I'll try and take screenshots. As I said, manually trying to find certain MS AS areas to manage them is becoming quite difficult.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Startups are easy to find. They are under Application Agents. You just need to select the Manage Allowed/Blocked link. Their output is not very good though since MS AS was not designed to allow the next window to be large enough to view all of the text on it properly and it is not resizeable. But what does this have to do with a video1 folder?
     
  19. BFLeigh

    BFLeigh Corporal

    This seems to be best way of explaining it. MS AS had qttask.exe on its blocked list so it asked permission to unblock, to do this it had to show the other blocked startup registry files. For the first time did I see what the mouse pointer is pointing to.

    I can't seem to be able to post a pic file that big. Here it is a BMP.
     

    Attached Files:

  20. BFLeigh

    BFLeigh Corporal

    Secondly, here is the same page but scrolled up to the actual date (two days ago) it happened. The age of the dialer is strange, as I've received qttask.exe alerts from MS AS repeatedly but two days ago was the first time with the dialer also there in same dialog box.

    I apologise for splaying out these pictures, can I turn them into links somehow?
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But what are you asking me? If you do not want it blocked, then un-block it.

    This application does not need to load at startup anyway. So I'm not sure what your problem is. The actual Startup is frequently completely removed from the registry using HJT or manual editing of the registry. Quicktime works fine without loading this at startup. It should only be run when you need quicktime and then it should be killed afterwards.

    We are no longer in the realm of Malware. So at this point, if you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  22. BFLeigh

    BFLeigh Corporal

    AHA. Here it is:
     

    Attached Files:

  23. BFLeigh

    BFLeigh Corporal

    That folder/file doesn't seem to exist, unless talking about historically blocked Startup Registry Entries?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's old info! Clear the list!
     
  25. BFLeigh

    BFLeigh Corporal

    I've also found these three things in the Manage Allowed/Blocked IE Trusted Sites Blocked Folder:

    adservs.com
    hypermart.net
    syserrors.com

    Are these malware?
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's why they are blocked. Don't you recognize the first one from your very first message.
     
  27. BFLeigh

    BFLeigh Corporal

    I do. That's why I'm confused - should remove those sites altogether or should I delete the stuff in the Domains folder of the Registry? Or neither? If MS AS/etc put the Domains folder's contents in there I though they'd all be in the Blocked Trusted Sites thing.

    Whoa, MS AS orange alert thing just came up - adservs.com tried (how it 'tried' exactly, I don't know) to do something to my PC and MS AS blocked it. Those pop-up alerts come and go too fast for me to read them and now I can't find the log of it.

    I'm going to go to bed now and have another stab at this tomorrow. Any thing I should do before I come back here? Scan again with Bitdefender/Pandascan?
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! They are being blocked which is what you want to happen. Removing them would allow the bad sites to be accessed.

    I think you should uninstall MS Antispyware, reboot, and then attach a new HJT log for me.

    Then I think you should reinstall MS Antispyware, update it and do a full scan. Basically start over again so you clear all the history crap out of MS AS. Now you can start deciding what to allow and not to allow from a clean starting point.

    Do you have SpywareBlaster installed and updated with all protections enabled? It is in the How to protect thread I gave you?

    Do you have Spybot installed and updated and did you use the Immunize feature?
     
  29. BFLeigh

    BFLeigh Corporal

    Blaster and Bot are both updated and yes they are protecting everything they can.
     
  30. BFLeigh

    BFLeigh Corporal

    Here's the log. I'll download the MajorGeeks file of MS AS and update it now.
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay your HJT log looks OK! Notice that now QuickTime (qttask.exe) is loading at startup. This process is not necessary and quicktime can just be run when needed but this can sometimes be a personal preference. Most people just disable this from loading at startup (which is what I always do). Two ways to do this are:

    1) to have HJT fix the O4 line which will stop it from loading

    2) or use msconfig to disable the startup

    I don't like option 2, since I do not like the idea of using msconfig and having it in selective startup mode.
     
  32. BFLeigh

    BFLeigh Corporal

    Bewdy.

    I've run Bitdefender and Pandascan again and they've both found nothing.

    Thanks again!
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Make sure you complete all the steps in the How to protect thread l gave you in message # 21.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds