Spyware removal help needed

Discussion in 'Malware Help (A Specialist Will Reply)' started by sharonwebb19, May 24, 2006.

  1. sharonwebb19

    sharonwebb19 Private E-2

    I have followed your do this 1st instructions. Bitefinder and panda scans were not done in safe mode. Log attached, hope I have done this ok. Would appreciate your help this spyware is really getting on my nerves. I couldnt attach bdscan cos I got this error: bdscan.txt:
    Your file of 1.51 MB bytes exceeds the forum's limit of 250.0 KB for this filetype.

    Thanks very much
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Why is your Bitdefender log so big? Did you forget to empty quarantine folder as instructed in step 0? Did you change the default configuration of the scan so that it reports all files (even clean ones) being scanned? Or was there a lot of stuff in System Restore being found? Try compressing the file into a ZIP file and uploading the ZIP.

    You also need to complete step 7 of the READ & RUN ME.

    What malware problems are you actually having?
     
  3. sharonwebb19

    sharonwebb19 Private E-2

    Hope I have done the zip file ok. Not sure why its so big, I did delete quarantined files, it found
    Identified viruses = 28
    Infected files = 1768!!
    Dont like the sound of that.
    Not sure what my spyware is called because I keep getting different named ones, did have winfixer, errorsafe (think thats what it was called). Basically websites keep opening telling me my computer is infected and I should buy their programs to fix it.
    Think I have done step 7, sorry I am new to this! would appreciate any help you could give.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you have not done step 7. You have not attach a HijackThis log yet.

    Your Bitdefender log was not 1.51 Mb and it was also not created properly. You created a straight text file. You did not follow the directions in step 6. And you had not emptied your Quarantine folder. Look at the log yourself. The starting items are in C:\Program Files\Norton AntiVirus\Quarantine\ and then many others are just in System Restore.
     
  5. sharonwebb19

    sharonwebb19 Private E-2

    Sorry I did step 7 just forgot to attach the log! Do I need to redo the bdoscan? - if so how do i remove system restore stuff?. I emptied the antispyware quarantine but forgot about Norton, sorry to be such a pain!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Don't worry about it now.

    I have some questions!

    1) Are the below AdwareAlert and CA PestPatrol purchased products or free trials?

    O4 - HKLM\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot
    O4 - HKLM\..\Run: [eTrustPPAP] "C:\WocXP\Spyware scanners\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe"

    AdwareAlert had been on a rogue tool listing report and has now been delisted but it is still not very good. It should be uninstalled.

    PestPatrol is good but if it is a free trial version, it is just wasting system resources since it cannot fix anything. So if free, uninstall it.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\Documents and Settings\WocUser\My Documents\?ystem32\tracert.exe
    C:\WINDOWS\DOBE~1\javaw.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [ReJf5vH] C:\WINDOWS\ugtgor.exe
    O4 - HKCU\..\Run: [Kui] C:\Documents and Settings\WocUser\My Documents\?ystem32\tracert.exe
    O4 - HKCU\..\Run: [Wnie] "C:\WINDOWS\DOBE~1\javaw.exe" -vt ndrv
    O20 - Winlogon Notify: ShellCompatibility - C:\WINDOWS\system32\lvjq0915e.dll (file missing)
    O20 - Winlogon Notify: winbfi32 - C:\WINDOWS\SYSTEM32\winbfi32.dll <--- this may come back and could require other steps to remove!


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:

    C:\Documents and Settings\WocUser\My Documents\?ystem32 <--- the whole folder
    C:\WINDOWS\DOBE~1\javaw.exe
    C:\WINDOWS\ugtgor.exe
    C:\WINDOWS\SYSTEM32\winbfi32.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  7. sharonwebb19

    sharonwebb19 Private E-2

    Ok here is new log. I tried to do all that was asked but the very 1st thing you asked me to kill under documents and settings was not there (I did have view hidden files on), after booting in safe mode the 2 windows files javaw and ugtgor were not there. It wouldnt let me delete winbfi32.dll file - it was not read only and not running under task manager.
    Everything else worked ok. Thanks for your time, really appreciate your help. I havent had any unwanted webpages open so far but havent been on line long since the 2nd log.
    I have been on line quite a bit since the 1st log so hope this hasnt affected anything.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please answer my questions!
     
  9. sharonwebb19

    sharonwebb19 Private E-2

    Oops sorry, they were free ones. I have uninstalled them as suggested.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They were in your previous HJT log. Please attach a new HJT log.

    Is everything still working OK?
     
  11. sharonwebb19

    sharonwebb19 Private E-2

    Im sure that was the new log, but I have done it again just in case. I opened hijack this again and pressed do a system scan and save a log file. The latest log is attached.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I suspected, those programs are still loading at startup. Have HijackThis fix the below lines:

    O4 - HKLM\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot
    O4 - HKLM\..\Run: [eTrustPPAP] "C:\WocXP\Spyware scanners\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe"

    Then delete the below folders if they exist (you may need to reboot to safe mode to delete them):
    C:\Program Files\AdwareAlert <--- the whole folder
    C:\WocXP\Spyware scanners\CA <--- the whole folder
     
  13. sharonwebb19

    sharonwebb19 Private E-2

    Thanks Hijack this fixed the 2 files. The Adwarealert one wasnt there and the other folder could be deleted in normal mode. I attach my latest hijack this log. Thanks for this even though the spyware is still there computer is running much better already.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Spyware is still present because we are not finished yet. I needed to get those two other applications removed before continuing.

    Okay let's finish your cleanup. Start by downloading two tools we will need:

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.
    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Also make sure your running in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winbfi32.dll once and then click the kill button. After you have killed all of the winbfi32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of winbfi32.dll and kill it.

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O20 - Winlogon Notify: winbfi32 - C:\WINDOWS\SYSTEM32\winbfi32.dll

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files". Once you have saved it double click it and allow it to add into the registry when prompted.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.


    Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.

    C:\WINDOWS\SYSTEM32\winbfi32.dll


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now attach a new HJT log and tell me how the steps went.

    Also let me know if you are having any other malware problems.
     
  15. sharonwebb19

    sharonwebb19 Private E-2

    ok didnt find any winbfi files under process explorer. Fixed the winbfi file in hijack this. got a bit confused with the regedit4 thing so i did it in the wrong order but redid the other steps again after in case it caused problems, sorry about that! new hijack log attached. Computer seems to be running normally.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!


    Note: I don't recommend having both SpywareGuard and Windows Defender (or any other full realtime protection tool) running at the same time. This can be a waste of system resources and it can cause conflicts between the two. In addition, it can make like difficult for you since there could be duplicate warning messages from the applications. Personally I would just use Windows Defender which is a more recent and more frequently updated tool. It is also free like SpywareGuard.
     
  17. sharonwebb19

    sharonwebb19 Private E-2

    Yippeee :) thank you soo much for all your help, could never have done it without you!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds