spycraft.com hijacker

Discussion in 'Malware Help (A Specialist Will Reply)' started by judyg, Aug 21, 2010.

  1. judyg

    judyg Private E-2

    Our laptop today got malware that is trying to redirect us to spycraft.com. No other programs will open for more than a half of second, then a popup comes with a security warning saying the file is infected and will try again to redirect us. We've disconnected the computer from the internet, but now, how do we get rid of this program? HELP PLEASE
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you REALLY cannot complete any of the below in normal mode then do try safe mode. But normal is preferable ;)

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. judyg

    judyg Private E-2

    Thank you for your reply. I am going through the read and run me first and will be downloading step 7, maybe not tonight. But everything has been done in Safe Mode as nothing will open in normal mode. I appreciate your help.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, attach logs once done, I will be here waiting. :)
     
  5. judyg

    judyg Private E-2

    Kestrel13, good news and bad news. The antispyware only found cookies, but running the Malwarebytes in safe mode found 5 trojans. Once they were gone, the computer seems to be running okay. But I thought I should finish up and complete the Read and Do First Instructions. I downloaded Combofix, but not to the desktop (It didn't give me a choice, but just did) I NOW have the box checked to ask where to download. With a search there are over a 1000 objects of combofix. I'd like to just delete them at this point, but when I go to the folder where it says it is, it isn't and it won't let me delete them from the search results (says cannot read from the source file or disk). I feel like I made this mess myself, but would appreciate any suggestions. Thank you for your time.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay, so please attach the logs regardless of what was found or not found.

    What browser are you using? If it downloads directly to the root drive (usually C) Then just move it to the desktop.
    Download to desktop.

    I don't know what you mean. At this point you have not even run combofix so how can there be 1000 instances of CF related files??

    You said:
    So simply download it to the desktop. :)
     
  7. judyg

    judyg Private E-2

    QUOTE=Kestrel13!;1527404]Okay, so please attach the logs regardless of what was found or not found.

    What browser are you using? Mozilla Firefox.

    If it downloads directly to the root drive (usually C) Then just move it to the desktop.
    That's the problem, I couldn't find it is the C drive so I did a search for it. There are over a 1000 entries, mostly duplicates of the application, one file with a .pf, etc.

    Using windows explorer under Local Disk C, there is an Computer looking Icon (not the application one) for ComboFix. Under that ComboFix is the entire contents of my computer listed the first being another Local Disk C. Wow, and under that another ComboFix and then another......repeating itself.

    I am unable to find the real icon to run the program or move it. when I right click on one of many ComboFix.exe after the "search" and click "open containing folder" it takes me to a folder of "Downloads" and it isn't there, at least that I can recognize. Even by using todays date it's not there.


    I don't know what you mean. At this point you have not even run combofix so how can there be 1000 instances of CF related files??
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Save Files to > and choose where. I don't see what the problem is. What do you have it set up to do, where to download to after looking in tools > options within firefox?
     

    Attached Files:

  9. judyg

    judyg Private E-2

    Also, I am running windows xp. Thanks again
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just answer my question re: where downloads are set to be saved. :)
    And how did you manage with the other software you should be downloading as per our procedures? Is it just combofix you're having an issue with or everything?
     
  11. judyg

    judyg Private E-2

    It was set to save in a folder called "downloads" that my husband had made. That is where it tells me to go and find it, but it isn't there. The Malwarebytes and antispyware are there from yesterday, but not the comboFix.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please click on Tools inn the Firefox browser and on the first tab, you will see the second part asks where to download items to. Hit the browse button and then click on Desktop. Now download Combofix and it should be on your desktop. Run it and attach the log which will be at C:\ComboFix.txt.

    Kes also needs the logs attached for:
    SAS
    MBAM
    C:\MGLogs.zip ---> this from running the C:\MGTools.exe ( If you did not save it to the C: drive, and it is on your desktop, run it from there and when it is done you should find it on the C: drive.)
     
  13. judyg

    judyg Private E-2

    Wow, thanks. Installing and running comboFix seemed to do the trick. and spycraft seems to be gone too. I am going to try and attach all the logs. Superantispyware and malwarebytes were used in the safe mode. I was then able to go to normal mode. ComboFix and MGTools were run in the normal mode. I am now replying on my husband, Dave's "lately" infected, but hopefully not anymore laptop and will attempt to attach files. Should I do the toggle system restore? So appreciate your help.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good job. Now let's just remove a few things and you are all set to go.

    Use windows explorer to find and delete:
    c:\documents and settings\dave\Local Settings\Application Data\kcoukgshu

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now use add/remove programs to uninstall your old versions of Java:
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    ...and install new Java ;)

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6
     
  16. judyg

    judyg Private E-2

    Tim and Kes, thank you so much. Followed everything to the end and our laptop is better than ever. Loved your "good job" encouragement comment :) And you both did an excellent job on this long distance help. Your services were greatly appreciated.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome :)
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Safe surfing!! :) Glad we could be of service.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds