Spy Sheriff assistance needed

Discussion in 'Malware Help (A Specialist Will Reply)' started by emorris, Oct 27, 2005.

  1. emorris

    emorris Private E-2

    I have been working on this for 2 days and I am spent. I need a little help.

    Long story, short I made a huge error in judgement and opened a foreign file. I know better and have warned people about doing this exact thing hundreds of times. I was in a hurry and it bit me. Needless to say, I've learned my lesson, unfortunately the hard way.

    Anyway the little friend that I acquired was apparently this Spy Sheriff program.

    I'll start by giving you my system specs:
    Win XP (service pack 1) all critical updates installed
    1.13 Ghz, 512 MB RAM
    I use Norton Antivirus (DAT files are on a weekly scheduled update)
    Ad Aware & Spybot S&D (Updating each time before using)
    Sometimes I will use Hijack This
    I also use Mozilla products (Firefox & Thunderbird)

    Here is everything that I have done from the time that it was opened until now:
    As soon as it was opened and my antivirus went haywire, I disabled my network connection. I didn't know what this was capable of doing and didn't want to risk having my identity stolen. My network connection is still disabled at this moment (I am using my company laptop to do my research).

    Before it got completely out of hand, I was able to run an Ad Aware scan and a virus scan, removing what it found. Things still did not appear correct, so I started disabling processes, getting a critical one and causing a reboot.

    Once the reboot was complete, Spy Sheriff started doing a scan. Not being familiar with this and assuming that this was some sort of Microsoft product, I allowed it to run it's scan (I'm a genius, eh?). Of course, afterward I realized what had happened. I wasn't able to close this out and my desktop was locked, so I disabled "explorer.exe".

    By disabling explorer, this was the only way that I was been able to do anything. I ran another Ad Aware scan (full system scan), Spybot & Antivirus and removed all additional items that were found. I could only do these things by opening task manager and selecting file -> New Task (Run...) and browsing to the .exe and running each one.

    After each scan came a reboot only to find that my desktop was still locked. I didn't have my laptop at home yesterday, so everything that I did was blind and just guesswork. I navigated around folder to folder (by using the browse in the last paragraph) locating objects that had been created on the same day/time as when I originally opened the file. In each instance I wrote down what I had deleted knowing that it would be in my recycle bin and that I coule restore it if need be. I researched each item today and found that I hadn't deleted anything adverse. More reboots, same problem.

    Fast forward to today.
    I downloaded the latest version of Hijack This and put it on a floppy while at work. I ran a scan and researched each item before deleting. After a reboot, I still had the same issue.

    I attempted to do a system restore from a couple of days ago and this failed.

    I did a search and stumbled upon your website and followed the steps in this post: http://forums.majorgeeks.com/showthread.php?t=35407. Exceptions were: 1) Microsoft Windows AntiSpyware (I'm not connected to the internet and it's too large for my floppy disk) & 2) All online scans in section 5 (not online).

    I also followed the steps in this post: http://forums.majorgeeks.com/showthread.php?t=65945, although I didn't find all items in step 5.

    I've tried to do my due diligence and avoid asking for help, but I am at a loss and just don't know what else to do.

    Here are the current symptoms:
    I can reboot and the system will almost be up. My desktop icons begin appearing and then the system will apparently stop. I am unable to select anything on my desktop or access my start menu. I am basically frozen and the only way that I am able to perform any functions is bring up task manager and kill explorer. I get the same symptoms when I bring the system up in safe mode.

    Suggestions?
    Thanks in advance.
    Ernie
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. emorris

    emorris Private E-2

    Yes, I was able to complete every step in that post.
     
  4. emorris

    emorris Private E-2

    I figured I would go ahead and post my hijack this report in case I may have missed something.

    Edit by chaslang: Inline & incomplete log removed.
     
    Last edited by a moderator: Oct 28, 2005
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the directions I gave you.
    What you posted is not a complete log and it was not attached as required?
     
  6. emorris

    emorris Private E-2

    I apologize. Attached is the log. Please advise.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your OS and IE version are way out of date and represent a major security risk. After we fix any current problems, you must get updated.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/1167cb48d77963482901/netzip/RdxIE601.cab
    O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
    O20 - Winlogon Notify: docent0 - docent0.dl (file missing)
    O20 - Winlogon Notify: st3i - C:\WINNT\q192635895.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\LimeShop <--- the whole folde
    C:\WINNT\q192635895.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  8. emorris

    emorris Private E-2

    I'm not sure how my OS is outdated because I run windows update almost weekly (not doubting you, by the way). I will make sure and do an update once I get back on line (I am using my laptop for web browsing/research while my PC is down).

    I use Mozilla Firefox for web browsing instead of IE. The only time that I use IE is when I run Windows Update. I will update it regardless. Probably best.

    Attached is the new HJT log file.

    This apparently fixed my problems. One of those items must have been locking me down. I never imagined spyware could bring a system to its knees like it did mine. Why do people create this @#$&? Frustrating!

    I certainly appreciate your help!
    I need to get busy updating my system now...

    By the way, is there any way to proactively prevent spyware vs. doing scans post infection?

    Again, I can't thank you enough.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See for yourself. This is what your log indicates you are running:

    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Windows XP is up to SP2 and so is IE. Perhaps you are not updating properly. I have seen many people indicate they went to Windows Update and got updated, and when I check....I see no updates.

    Your log is now clean.

    Everything you need to do (including Windows Update) is in the following sticky thread:

    How to Protect yourself from malware!
     
  10. emorris

    emorris Private E-2

    Thanks again for everything.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Make sure you run all of those steps. After getting your updates, double check to make sure they were installed properly by looking at you HJT log. You should see something like:

    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Note the bold print items.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds