spyware problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by bhulk, Aug 1, 2006.

  1. bhulk

    bhulk Private E-2

    I have been having some trouble with spyware. I ran various scans in safe mode and removed a lot of spyware. But this particular thing called toolbar888 wont go away. Its really annoying, it launches ads and says messages like "your computer is infected, click here to download software to help you". and i cant get it to go away. I ran mostly all the scans in the "Read and run me" thread, but i couldnt run the online scans due to some "personal reasons" (siblings wanting to play). Thanks in advance :). I attached a hijack this log and an ewido log.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. bhulk

    bhulk Private E-2

    Im sorry i just cant get the online scans to work :(. The bitdefender one took seven hours, i had to leave it on overnight and someone closed it. (i dont really want to wait another seven hours) I am unable to run the Panda Scan because internet explorer keeps directing me to sites to download antivirus software, and my homepage is different. I think the bitdefender removed some things, but i dont have the log. Heres the hijackthis log.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I will give you a fix and we will run a couple of other quick scnas afterwards to make sure we got everything. These are very fast scans (a few seconds for each one).


    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of awtss.dll once and then click the kill button. After you have killed all of the awtss.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    opnomjg.dll
    winhld32.dll

    Next double click on explorer.exe and again click once on each instance of awtss.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    opnomjg.dll
    winhld32.dll

    Now just exit Process Explorer.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes. (If they cannot be killed or keep restarting, just continue!)

    C:\WINDOWS\system32\ishost.exe
    C:\WINDOWS\system32\issearch.exe
    C:\WINDOWS\system32\isnotify.exe
    C:\WINDOWS\system32\ismon.exe


    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: (no name) - {873eb32d-ae1a-4183-89bd-45a77f761be4} - C:\WINDOWS\system32\ixt1.dll
    O2 - BHO: (no name) - {B2D70148-0313-4E7A-A8A8-3BC5FE257231} - C:\WINDOWS\system32\awtss.dll
    O2 - BHO: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll (file missing)
    O2 - BHO: (no name) - {E521797A-22DE-4B46-8B2F-8E98AB77B942} - C:\WINDOWS\system32\opnomjg.dll
    O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
    O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll (file missing)
    O3 - Toolbar: Safety Bar - {052b12f7-86fa-4921-8482-26c42316b522} - C:\Program Files\Safety Bar\Safety Bar.dll
    O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
    O20 - Winlogon Notify: awtss - C:\WINDOWS\system32\awtss.dll
    O20 - Winlogon Notify: opnomjg - C:\WINDOWS\SYSTEM32\opnomjg.dll
    O20 - Winlogon Notify: winhld32 - C:\WINDOWS\SYSTEM32\winhld32.dll


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    exit


    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\ishost.exe
    C:\WINDOWS\system32\issearch.exe
    C:\WINDOWS\system32\isnotify.exe
    C:\WINDOWS\system32\ismon.exe
    C:\WINDOWS\system32\ixt1.dll
    C:\WINDOWS\system32\awtss.dll
    C:\WINDOWS\system32\sstwaa.bak
    C:\WINDOWS\system32\sstwaa.bak2
    C:\WINDOWS\system32\sstwaa.dat
    C:\WINDOWS\system32\sstwaa.dat2
    C:\WINDOWS\system32\sstwaa.ini
    C:\WINDOWS\system32\sstwaa.ini2
    C:\WINDOWS\system32\sstwaa.tmp
    C:\WINDOWS\system32\opnomjg.dll
    C:\WINDOWS\SYSTEM32\winhld32.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot run Windows Explorer and delete the below folders if found:
    C:\Program Files\ToolBar888
    C:\Program Files\Safety Bar

    Now attach a new HJT log and tell me how the steps went.
    Make sure you tell me how things are working now!


    Now run the below procedure and attach the runkeys.txt log.
    Now run the below procedure and attach the newfiles.txt log.
    Also answer a question! Why do you have the below running and why is it running twice?
    C:\WINDOWS\system32\sndvol32.exe
    C:\WINDOWS\system32\sndvol32.exe
     
    Last edited: Aug 2, 2006
  5. bhulk

    bhulk Private E-2

    Thank you for your help :). Everything seems to be running smoothly and i dont see any signs of spyware. Also, i dont know what C:\WINDOWS\system32\sndvol32.exe is and i dont know why its running twice.
     

    Attached Files:

  6. bhulk

    bhulk Private E-2

    i just ran an ad-aware scan and it said i had spywarequake:eek:. weird im not getting any popups from it and its not in the program files folder.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's part of Windows. It the Volume Control program for your sound.
     
  8. bhulk

    bhulk Private E-2

    oh, so am i clean? also, thanks
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Not yet! I looking at your logs but had to run out for awhile. Will post a fix soon.
     
  10. bhulk

    bhulk Private E-2

    alright, thanks :)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O20 - Winlogon Notify: winhld32 - winhld32.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\YAXUninst.exe
    C:\WINDOWS\system32\oins.exe
    C:\WINDOWS\System32\opnnmki.dll
    C:\WINDOWS\system32\sstwa.ini

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log. Also attach new logs from GetRunKey and ShowNew.

    Make sure you tell me how things are working now.
     
  12. bhulk

    bhulk Private E-2

    Everything is running fine, im not having any problems, thanks :). I attached the logs.
     

    Attached Files:

  13. bhulk

    bhulk Private E-2

    I got a popup to an adult site a while ago so i think there is still some malware.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did that regisry patch add in without generating any errors? Many of the things it was supposed to fix are still present.

    Please download and install Registrar Lite

    Run Registrar Lite navigate to the following keys and take ownership of them (explained further down):

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer

    HKEY_LOCAL_MACHINE\software\microsoft\mssmgr



    To take ownership of teh key do the following:
    • Copy & Paste one registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the regitry key.
    • Click-on Security in the Menu
    • Select Take Ownership
    • Now leave RegistrarLite running and continue
    • Now run that registry patch again from message # 11.
    • Tell me the results. Any errors?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate to HKEY_LOCAL_MACHINE\software\microsoft\mssmgr
    • Does the above mssmgr key still exist! If so, right click on it and select Delete.
    Now attach a new log from GetRunKey!
     
  15. bhulk

    bhulk Private E-2

    no there wasnt any errors :). i attached the runkeys.txt. thanks for your help
     

    Attached Files:

    Last edited: Aug 2, 2006
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that got everything! That means that the malware had changed the ownership of those registry keys so that even you (the administrator) could not delete them.

    How are things working? Anymore popups?
     
  17. bhulk

    bhulk Private E-2

    Yep popups = gone and everything is running swell :). Thanks for all your help, you guys rock! This is the only place i go to for malware help. If i see any problems within the next day or 2, ill post another reply :). thanks :)
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds