Spyware and trojan help

Discussion in 'Malware Help (A Specialist Will Reply)' started by blackprophet, Apr 29, 2005.

  1. blackprophet

    blackprophet Private E-2

    I found your article on removing spyware, trojans and malware from your computer. I followed all the instructions but am still having problems.

    In my cleaning I found numerous spyware as well as two trojans. I have since removed all of them but am still having problems. The two problems Im having are these.

    I was reciving the error message at load up of windows "D0CE0C16B1.DLL: system cannot find file" This message is what led me to your site. I followed the article you posted to do before I post, and then I started getting this error message "E6F1873B.DLL: system cannot find file" and I stopped getting the previous one. So I saw in a previous post you telling someone to erase the first file so I did while doing the rest of the stuff in safe mode that you had in your tutorial. Now I get both messages at the start up of Windows. I have searched and cant find E6F1873B.DLL on my computer.

    Also when entering a user name and password in IE, If I use the tab to switch boxes, there is a pause in between, and that box freezes, which leads me to believe there still may be a trojan on my computer.

    I am running Windows 98SE, IE 5 and have just recently installed the sun java (as per your instruction). Any help would be appreciated.
     
  2. blackprophet

    blackprophet Private E-2

    Also I have a process running that I cant Identify: Erab.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. blackprophet

    blackprophet Private E-2

    Ok will do and will post sun or mon night.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Make sure you follow the steps properly and attach the log.
     
  6. blackprophet

    blackprophet Private E-2

    I was extracting hjack this and my Virus Checker said that it has a virus in it. Is this normal?

    The virus is W32/Generic.worm!p2p.
     
  7. blackprophet

    blackprophet Private E-2

    Here is the log file
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to update your virus defintions. This is a known bug in McAfee Virusscan program.
     
    Last edited: May 3, 2005
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    LimeShop is known to contain adware. You should uninstall it.
    I would also uninstall Party Poker (if it had an uninstall).


    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\APPLICATION DATA\ERAB.EXE


    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {39A73277-B810-0EC2-8753-645579FB7947} - C:\WINDOWS\SYSTEM\GXA.DLL (file missing)
    O2 - BHO: (no name) - {FD38E89E-7050-0C86-7D21-79C2CA5F469E} - C:\WINDOWS\SYSTEM\PVJUW.DLL (file missing)
    O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
    O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
    O4 - HKCU\..\Run: [Eute] C:\WINDOWS\Application Data\erab.exe
    O4 - Startup: PowerReg Scheduler V3.exe
    O4 - Startup: PowerReg Scheduler.exe
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\PROGRAM FILES\PARTYPOKER\IEEXTENSION.DLL
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\PROGRAM FILES\PARTYPOKER\IEEXTENSION.DLL

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\APPLICATION DATA\ERAB.EXE
    C:\PROGRAM FILES\PARTYPOKER <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  10. blackprophet

    blackprophet Private E-2

    Followed instructions and computer is working well, did not get error messages. Will Repost in a few day with more info on how its running. In the mean time here is my new logfile
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean! To help keep it that way you need to run ALL the steps in the below thread (especially ones that you have not already done - you need a firewall ASAP).

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds