Spysheriff?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Robyn, Jun 19, 2005.

  1. Robyn

    Robyn Private E-2

    About a week ago, I was infected with what I think was smitfraud. I got the following message on my desktop "Security warning A fatal error in IE has occured at 0028:C0011E36 in VXDVMM(01) + 00010E36. Error was caused by Trojan-Spy.HTML.Smitfraud.c. " Also, at that time, a virus scanner named psguard kept installing on my computer. I followed instructions at bleepingcomputer.com and wildersecurity.com for smitfraud removal. I got my desktop back and everything seemed ok. The next day I got the following message on my desktop "SYSTEM STOPPED System has been stoppeddue to a serious malfuntion. Spyware activity has been detected. It isrecommended to use a spyware removal tool to prevent data loss. Do notuse the computer until all spyware is removed." Also, a program called spysheriff keeps showing up on my C drive. I followed instructions in this forum (thread 64011 "spysheriff and wallpaper") and it seemed to correct the problem. I left my computer on all night and this morning the "system stopped" message and spysheriff were back. Today I followed all instructions in thread 35407 on this forum. None of the scans detected anything with the exception of Spybot. It detected something called EffectiveBand Toolbar. I have been trying for over a week to get rid of this problem. Any help would be appreciated.

    Robyn
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Robyn

    Robyn Private E-2

    Here is the log file
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know for a fact that Daily Weather Forcast is clean?
    C:\Program Files\Daily Weather Forecast\weather.exe


    The below is a browser and should be closed before running HijackThis.
    C:\Program Files\Mozilla Firefox\firefox.exe

    Look in Add/Remove programs for the below and uninstall if found:
    SpySheriff
    Need2Find


    Do you know what the below item is for? I believe it is bad! If you agree, then leave it in my cleanup steps below, otherwise skip it.
    C:\Program Files\snco\cadw.exe


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).


    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\Program Files\snco\cadw.exe


    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Program Files\Need2Find\bar\1.bin\ND2FNBAR.DLL
    O4 - HKCU\..\Run: [Thlr] C:\Program Files\snco\cadw.exe
    O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
    O8 - Extra context menu item: &Search - http://kc.bar.need2find.com/KC/menusearch.html?p=KC
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Need2Find <--- the whole folder
    C:\Program Files\snco <--- the whole folder
    C:\winstall.exe
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.


    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    Now reboot in normal mode and do the following.

    Fixing Locked Desktop
    Also you should right click on your Desktop and select Properties. Then click the Desktop tab and then the Customize Desktop button. Now in the next window that comes up click the Web tab. Make sure at the bottom that Lock desktop items is unchecked. Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too. Then click OK. Apply. OK.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixadt.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixadt.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.


    Now post a new HJT log. And tell us how things are working.
     
  5. Robyn

    Robyn Private E-2

    Followed all instructions. Still have the "system stopped" message. New HJT file attached.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please answer my questions from the previous post (and this on too). You need to help me help you.

    Also, did SpySweeper restore the below or did you not fix it:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm

    Is you message actually a Desktop wallpaper or is it just a popup message?

    Were you able to do the Locked Desktop Fix?
    Did the registry merge work okay?

    Try this slightly changed variation of the registry patch.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixadt.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixadt.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
     
    Last edited: Jun 20, 2005
  7. Robyn

    Robyn Private E-2

    Answers to questions from first post
    -I have no idea what weater forcast\weather.exe is--deleted it
    -Need2find was a tool bar used by Kazaa--deleted it anyway
    -no idea what snco\cadw.exe is--deleted it

    Answers to questions from second post
    -Yes, I fixed R0-HKLM.... but it came back when I rebooted. Deleted it again and it came back again.
    -The registry merge did work
    -The message is wallpaper-not a popup message. In control panel/display/desktop, it shows this image. No way to get access to other wallpapers.
    -Yes, I was able to do the locked desktop fix.

    BTW, I really appreciate the help you are giving me.

    Robyn
     
  8. Robyn

    Robyn Private E-2

    Used the new registry patch. Rebooted, and my desktop is back to normal. Yeah!! Hopefully, it will stay this time. Thanks again for all your help.

    Robyn
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may need to disable SpySweeper to stop it from changing it back. Normally it gives you a message about a change to your settings and if you do not approve the change (the one we are making) it will change it back to the bad value.

    What happen with the registry merge? What error message did you get?

    When you did the Locked desktop fix, did you have any of the problems I indicated? Are they back again?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I just saw your last message about the new registry merge working. That's good.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds