Spyware Problems-Hijack This Log Posted

Discussion in 'Malware Help (A Specialist Will Reply)' started by Blade897, Feb 23, 2006.

  1. Blade897

    Blade897 Private First Class

    I've been experiencing many pop up's on my computer even when i'm not browsing the internet, but when my modem is on. Also, i am getting System Alert: Syware infections, and also Virus alerts saying my Computer is Infected. from my Windows Security Center.
    I have ran Nortons Anti Virus, Spybot Search and Destroy, And the newest Ad-aware. But i still am having problems.

    I've gone through my HJT log, is there anything else that i need to delete?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - start by running the steps in the below link to remove the SmitFraud infection you have:
    SpywareStrike, Smitfraud, SpySheriff, SpyAxe & PSGuard Removal

    make sure you save the smitfiles.txt log and attach it later. Then continue with the below.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)

    • Bitdefender
    • Panda Scan
    • HijackThis
    • Smitfiles.txt


    .
     
  3. Blade897

    Blade897 Private First Class

    Ok Thanks for the help, however, somethings happened while i was attempting to fix the computer. The original message i posted was intended to fix my dad's computer. I ran all the steps you gave me for his computer and ended with the Panda Active Scan (However i did not get a chance to finish BD scan on his computer) So i had the panda active scan running on his computer and in the morning, it had somehow stopped running, the screen was no longer there, as if a pop up message took it away. Then the next thing i do is go onto my own computer and see the EXACT same thing is happening to mine, same Spyware alert messages, popups, and same Trojan (Zlob) have appeared. So i ran every step from the guides (Smit, All of scans except Panda) you gave me in safe mode, I also had to remove SpyFalcon following your god thankful easy advice. These have greatly reduced pop-ups but i still recieve a couple. I've also purchased Spy Sweeper which has helped.

    But anyway, Panda scan was terrible, for one, i could never get it to scan for the entire time, either there would be a pop up problem and attempt to close it ended up with having to close all of my IE browsers. However, it came up with around 50 spywares, 5 hacking tools and aroudn 8 dialers (for my dad's comp it was around 80,000 spywares, scan would always have some type of problem)

    btw, my Bitdefender scan is to big for attachment what should i do?
    And this HTJ log is different from the first because it is off of my computer and noy my dads.

    Again, thanks much for the help MG's you've helped me many times.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's only talk about one computer. I assume we are working on yours from message number one.

    Where is the smitfiles.txt log?
     
  5. Blade897

    Blade897 Private First Class

    Right my computer, hold on i'm uploading those now i was distracted by trying to upload bdscan. I'm putting it in a zip is that alright?

    Thanks for the fast reply btw

    EDIT: Just to make sure you know, i was first talking about my dad's computer but i was saying it was mine because i never figured it was transistion to my own computer. So Message 3 was then transistioning to talk about my computer which is waht the Smitscan, bdscan, and newest HTJ is for, and if you could please concentrate only on the newest scans, that would be great, and thanks again so much for your help
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If your Bitdefender log was too big, you probably have to much stuff from either other applications quarantine folders or a bunch of stuff from System Restore. Compress the file into a ZIP file and attach that.
     
  7. Blade897

    Blade897 Private First Class

    Ok Done, thanks again for the quick reply :)

    EDIT: I would re-upload in the same scans but i can't since i already posted them in this thread. So Smit and BD scan uploads are in Message 5, and HTJ is in message 3.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to empty your Norton NPROTECT folder which is full of garabage.

    You should uninstall Viewpoint Manager & Viewpoint Toolbar unless you really use them (this was requested in step 0 of the READ ME). If you use them, you would be the first in 30,000 or more people to be using them.

    You did not follow step 7 of the READ & RUN ME to install HJT properly. As a result, you installed it exactly where we request that it not be install.
    C:\Documents and Settings\Great Commander Joey\My Documents\Unzipped\hijackthis\HijackThis.exe

    You did not pay attention to step 3 of the READ ME either. Uninstall ALL but one AV.

    Please correct this before continuing!

    What version of Limewire are you running? Many of them contain malware?

    I'm looking at your HJT log now?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\Program Files\aoae\tuac.exe
    C:\Documents and Settings\Great Commander Joey\Application Data\??curity\w?auclt.exe
    C:\WINDOWS\TEMP\win170.tmp.exe
    C:\WINDOWS\TEMP\win113.tmp.exe
    C:\WINDOWS\TEMP\win170.tmp.exe
    C:\WINDOWS\TEMP\win113.tmp.exe
    C:\WINDOWS\TEMP\win170.tmp.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
    R3 - URLSearchHook: (no name) - {EC2B5C19-E985-E309-A3F8-E93BF6752991} - C:\WINDOWS\system32\lmcuorp.dll (file missing)
    R3 - URLSearchHook: (no name) - {94DD0F4F-E280-B155-ACAD-ECCB59EF08C7} - C:\WINDOWS\system32\rsdo.dll
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: (no name) - {94DD0F4F-E280-B155-ACAD-ECCB59EF08C7} - C:\WINDOWS\system32\rsdo.dll
    O4 - HKCU\..\Run: [Widp] "C:\Program Files\aoae\tuac.exe" -vt yax
    O4 - HKCU\..\Run: [Mlere] C:\Documents and Settings\Great Commander Joey\Application Data\??curity\w?auclt.exe
    O20 - Winlogon Notify: winxdl32 - C:\WINDOWS\SYSTEM32\winxdl32.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\aoae <--- the whole folder
    C:\Documents and Settings\Great Commander Joey\Application Data\??curity\w?auclt.exe <--- I'm not sure exactly what the real folder name is but I would guess it says security. Delete the whole folder.
    C:\WINDOWS\TEMP\win170.tmp.exe <--- it would be best to delete every file you can in this TEMP folder
    C:\WINDOWS\TEMP\win113.tmp.exe
    C:\WINDOWS\TEMP\win170.tmp.exe
    C:\WINDOWS\TEMP\win113.tmp.exe
    C:\WINDOWS\TEMP\win170.tmp.exe
    C:\WINDOWS\system32\rsdo.dll
    C:\WINDOWS\SYSTEM32\winxdl32.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Make sure you tell me which files you find and do not find.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  10. Blade897

    Blade897 Private First Class

    Ok thanks much for the help. I did all the steps that i could, i did not find the temp files you were talking about but in processes i deleted other temp files that showed up, but with different numbers (154, 113 etc) i could not find C:\Windows\system32\rsdo.dll

    Things seem to be working fine at the moment, no pop-ups so far, nor any error messages. (I have ZA also just installed too, and i am not sure about limewire.)
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run Limewire and check the version number?

    You still have the Viewpoint stuff installed. Does that mean you really use it?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I said before, delete all files in C:\WINDOWS\TEMP
    Don't just look for any of the winxxx.tmp.exe files. You have the below in your log:

    C:\WINDOWS\TEMP\win154.tmp.exe
    C:\WINDOWS\TEMP\win159.tmp.exe
    C:\WINDOWS\TEMP\win154.tmp.exe
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see if we can get that O20 line fixed. Start by downloading two tools we will need:

    - Process Explorer

    - Pocket KillBox

    Extract them to there own folder somewhere that you will be able to locate them later. You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winxdl32.dll once and then click the kill button. After you have killed all of the winxdl32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of winxdl32.dlland kill it.


    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O20 - Winlogon Notify: winxdl32 - C:\WINDOWS\SYSTEM32\winxdl32.dll


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.

    C:\WINDOWS\SYSTEM32\winxdl32.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.


    After reboot post a new HJT log and tell me how the steps went.
     
  14. Blade897

    Blade897 Private First Class

    Steps went great, everything worked fine, i'm not even getting pop-ups which is a plus, again i can't thank you guys enough for your free support i truely do appreciate it.

    I'm going to go to bed, i won't respond until much later, but thanks again for the help!
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks better, but you still have not answered message # 11?????

    We have a little more clean up to do but first I need answers to questions.
     
  16. Blade897

    Blade897 Private First Class

    Oh sorry, Limewire version is 4.10.3

    Thanks again for the help. As for Viewpoint manager, i don't want it, i just got rid of it.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then attach a new HJT log from after removing Viewpoint so we can do a final inspection and cleanup!
     
  18. Blade897

    Blade897 Private First Class

    Alllllrrriiiighhhtt! :)

    Here's the newest log. Thanks again much for all your help
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just have HJT fix the below line and verify that it remains gone:

    O20 - Winlogon Notify: winxdl32 - winxdl32.dll (file missing)

    Then you should be done! If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  20. Blade897

    Blade897 Private First Class

    Alright thanks so much for the help you have no idea how many hours you've saved me.


    The only other thing i need is help on my dad's computer, but i'm going to go through all the steps we went through on his computer, and i'll give you the scan log's once it's all ready.

    Thanks again for the help,
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome!

    Please start a new thread for the other PC. Also make sure all steps of the READ ME are run and that you attach the logs from step 6 and step 7. Before running any of the tools, I would recommend emptying any Recycle Bin, Norton Nprotect folder (if any exist) and any quarantine folders first. This will keep logs smaller and scans will run a little faster too.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds