Spyware Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by chauterence, Dec 31, 2005.

  1. chauterence

    chauterence Private E-2

    Hi everybody, my name is Terence.

    To make a long story short, you can read here:

    http://aaotracker.4players.de/thread.php?sid=&postid=1542931

    As I have just recently installed 'HiJackThis!' Here is my log file as well posted in the above forums, where a guy told me to post here for professional examination of the log:

    EDIT: Inline HJT log removed


    On the other hand, I think I might have something in my system as a result where at in random moments, my VirusScanner would catch the following same viruses over and over again. If someone could help me locate the root of this problem as well:

    http://img358.imageshack.us/img358/1674/image20rm.jpg
     
    Last edited by a moderator: Dec 31, 2005
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Please run the steps outlined in this thread first as it gives a good known state to work from in removing any virii, malware you have ;)

    READ & RUN ME FIRST Before Asking for Support

    once done post the logs required in the guide ( or if any steps cannot be followed mention and errors or why they wouldnt run )

    Cheers and a specialist will be along shortly to assist :)
     
  3. chauterence

    chauterence Private E-2

    Ok, so I ran every step under that thread, and cleaned everything that Spybot, Microsoft AntiSpyware, etc found.

    I ran Bitdefender and found a few things that couldn't be deleted as well.

    Mostly some of the viruses that my antivirus found in the above picture.

    I also ran Panda ActiveScan and didn't see any "autoclean" option so I'll just post the log along with Bitdefenders and HJT's.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That does not appear to be a full log from BitDefender. The report of the problems seems incomplete. They always give more info than that.

    You should empty your Sun Java Cache because there are a bunch of things in there that are infected.

    Did you look in Add/Remove programs for WinTools?

    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [002k0uzo.dll] RUNDLL32.EXE 002k0uzo.dll,b 23236562

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:

    C:\WINDOWS\SYSTEM32\mscache.sys
    C:\WINDOWS\system32\002k0uzo.dll
    C:\WINDOWS\system32\shell32.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).


    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Reminder Note: Once we have determine you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  5. chauterence

    chauterence Private E-2

    Things seem to be running more smoothly now. :)

    Here is my updated HJT report:
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
    Last edited: Dec 10, 2007

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds