Spyware removal - I've followed your instructions

Discussion in 'Malware Help (A Specialist Will Reply)' started by MonkeyCat, Dec 29, 2005.

  1. MonkeyCat

    MonkeyCat Private E-2

    Hi

    I'm having problems with Spyware, mainly in the form of pop-ups (888.com, dell, various casinos etc). I've followed your instructions but still haven't solved the problem. The tools (Spybot, MicrosoftAS etc) have improved the situation but it has not gone away completely. Occasionally (very) I have system freezes and I couldn't follow your instructions 100% as MicrosoftAS wouldn't work in safe mode. I ran this in normal mode, but whenever I do this, the system freezes after the scan (incidentally, the scan results were clear).

    The problems seem to have started since I started using Limewire version 4.9.33. Do I need to uninstall this? I've also received various invitations to download Winfix and have followed the sticky thread on this, but HTF doesn't show up any bad files.

    I attach my HTF, BitDefender, and Pandascan logs. The Bitdefender log seems to indicate a problem. Your assistance is much appreciated.

    MonkeyCat
     

    Attached Files:

    Last edited by a moderator: Dec 29, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not use the paper clip to attach links in line. That makes them harder to read because you must login again. Just attach them like I did in your message. (I changed them.) Looks like you ran Panda before BitDefender. Is that correct?

    I'm also surprise that the below still are found. Did you run Ccleaner on this account or a different account name?
    C:\Documents and Settings\James Heseltine\Local Settings\Temporary Internet Files\Content.IE5\3NPDHPL6\toolbar2[1].htm
    C:\Documents and Settings\James Heseltine\Local Settings\Temporary Internet Files\Content.IE5\F37BVQPL\bridge-c24[1].cab
    C:\Documents and Settings\James Heseltine\Local Settings\Temporary Internet Files\Content.IE5\F37BVQPL\bridge-c24[1].cab[MediaGatewayX.dll]
    C:\Documents and Settings\James Heseltine\Local Settings\Temporary Internet Files\Content.IE5\GTYZSXUN\xml_istbar[1].xml
    C:\Documents and Settings\James Heseltine\Local Settings\Temporary Internet Files\Content.IE5\YB4BEHOR\uninstaller.prod.24oct2005.exe[1].67ed8085ef4da0dd46732bc56aa91a66

    Either delete the files manually or run Ccleaner on James Heseltine and make sure that the Temporary Internet Folder is selected for cleaning.
     
  3. MonkeyCat

    MonkeyCat Private E-2

    OK - I'll attach that way in future. Sorry for the inconvenience.

    I may have run CCleaner as Administrator in Safe mode previously. However, now I've run it under James Heseltine and cleaned up those files (and others) mentioned in your response.

    I ran BitDefender first, then Activescan, definitely.

    I look forward to hearing from you further.

    Thanks.
    MonkeyCat
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When do you get the popups? Is it only when connected to certain sites? Do you every get them while offline?

    Windows is notorious for cause the last question above. You can use the below to fix that:

    Disable/Remove Windows Messenger
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can also have HJT fix the below (but first use Add/Remove programs to uninstall PartyPoker or ladbrokesMPP if found):
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
    O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Program Files\ladbrokesMPP\MPPoker.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
     
  6. MonkeyCat

    MonkeyCat Private E-2

    The pop-ups appear fairly randomly it seems (I don't get them off-line). I've uninstalled Windows Messanger but the pop-ups are still appearing.

    Before I fix the HJT files, do I need to disable file restore?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do not disable system restore until we finish cleaning the PC of all malware.

    You need to tell me what sites you are connected to when you get the popups. They could just be part of the site you are going to. Also becareful if using multiple browser windows when testing this because you will not be able to tell which site is giving the popup. Use only one browser session and figure out where you get the popups. You should not be getting any here at MGs.
     
  8. MonkeyCat

    MonkeyCat Private E-2

    OK - I've fixed through HJT and attach a new file. Also, I've analysed how and when the pop-ups appear on a number of web-sites. Interestingly, one did appear when I was on this site (that was the only browser open) and another has just opened as we speak! Here is what comes up when. COme to think of it, it's the same set of pop-ups on some kind of cycle:

    Upon opening web browser - Blank pop-up headed ‘an error has occurred’
    - Blue pop-up advising that Spyware has has been detected asking to click ‘here’.

    http://www.pokerineurope.com/frontpage/index.php - cyberslots pop-up
    http://www.cricinfo.com/ - 888.com casino pop-up
    http://www.telegraph.co.uk/sport/main.jhtml?menuId=145&menuItemId=-1&view=GAMES&grid=P9 – a different 888.com pop-up
    http://news.bbc.co.uk/sport1/hi/football/teams/b/bolton_wanderers/default.stm - smileys advert
    http://www.pokerstarsblog.com/ - 888.com pop-up

    The ones that appeared when on your site may have appeared when I first opened the browser (but I went straight to this site) and they were 'Mymobiclub and the Blue pop-up advising Spyware has been detected.

    Anyhow, I hope that's enough information and I look forward to hearing from you (hope I've attached the logfile correctly this time).

    Thanks.
    MonkeyCat
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  10. MonkeyCat

    MonkeyCat Private E-2

    Ewido file attached as requested.

    Look forward to hearing from you.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well Ewido fixed a few things. Are you still having problems? If so continue with the below.

    Is your Norton Firewall working okay?

    Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    Download WinPFind

    Extract it to the root folder of drive C ( C:\ ). This will create a folder called WinPFind in the C:\ folder. Inside C:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.

    When it is done, it will show the results of the scan. Click on the Copy to Clipboard button and then paste the contents of the log in your clipboard. Then save it to a file using notepad and upload the text file here as an attachment.
     
  12. MonkeyCat

    MonkeyCat Private E-2

    Ok - attached. It didn't take very long (5 mins) and seems to have automatically created the text file. Did the IE thing as well.

    Thanks.
    MonkeyCat

    PS Firewall is 'on' with worm protection so I don't think this is a problem? I was still having pop-ups after Ewido.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! But you did not say it you still are getting them after the Reset of Web settings.

    If you are, there must be something hiding deeper down. Let's keep digging!

    Run the procedure in the following link:

    Look2Me VX2 Removal

    Then attach both logs. Afterwards tell me if popups are still happening.
     
  14. MonkeyCat

    MonkeyCat Private E-2

    Hi

    Yes, the pop-ups continued after I reset IE. I've run the Look2me fix and attach both logs. As well, we I first came to reply to the post, my system crashed. I sent an error report to Windows and attached the 'virus alert' document as well.

    The pop-ups are still happening!!

    Look forward to hearing from you. Happy New Year.
     

    Attached Files:

  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    To keep things moving along...

    Download AproposFix by Swandog46

    Save it to your desktop or to another folder of its own, but do NOT run it yet!

    Now reboot your computer in Safe Mode! (You must be in safe mode or this fix will not work.)

    Once in Safe Mode, double-click aproposfix.exe which will give you a chice of where to unzip/install the program to). This is called the Destination folder in the window that popsup. So either install it to the Desktop or the folder where you downloaded the aproposfix.exe file to. It will create a new folder named aproposfix. Open the aproposfix folder and double click on RunThis.bat to run the fix. Follow the prompts.

    When the tool is finished, reboot back into normal mode, and post a new HijackThis log, along with the entire contents of the log.txt file that has been created in the aproposfix folder.

    Good Luck!

    Bj:)
     
  16. MonkeyCat

    MonkeyCat Private E-2

    OK thanks. Please find attached. Look forward to hearing from you.
     

    Attached Files:

  17. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please run my previous post once more to confirm it was all successfully removed, then attach the new log with a fresh HJT log.
     
  18. MonkeyCat

    MonkeyCat Private E-2

    2 new logs attached. Pop ups seem to have stopped. Are we sorted?:)

    Thanks
    MonkeyCat
     

    Attached Files:

  19. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Both logs look good, to confirm your clean I would like a fresh WinPFind log from post #11.
     
  20. MonkeyCat

    MonkeyCat Private E-2

    Here you go. How are we?
     

    Attached Files:

  21. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Looks good, are you having any further problems?
     
  22. MonkeyCat

    MonkeyCat Private E-2

    Looking good. Thanks for all your help guys. :)
     
  23. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's strange how running the L2MeFix caused the real hidden problem to finally show itself..... Apropos!!!

    Thanks for jumping in BJ while was snoozing after a very late night!
     
  25. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Anytime :)

    When I noticed that the L2MeFix didnt fix the problem, I had a pretty good idea it was Apropos.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well the Virus alert.doc that was attached showed it was Apropos.
     
  27. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Didn't notice that LOL! I guess I should look at more logs.... ;)
     
  28. MonkeyCat

    MonkeyCat Private E-2

    One final query. Occasionally when I log on, I get a security alert telling me that virus protection is switched off. It says it's off in the security centre, but when I go directly to the anti-virus application, it says it's on. The message telling me it's 'off' disappears after approx 5 minutes (i.e. it switches back to 'on' in the Security Centre).

    Is this a problem?

    Thanks.
    MonkeyCat
     
  29. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I have noticed it doing it with Norton but it shouldnt last that long. I have AVG AntiVirus (I recommend you use this) and it's never done it for me.

    It's probably just a Norton thing.
     
  30. MonkeyCat

    MonkeyCat Private E-2

    My computer was attacked last night immediately after I booted up. I believe I was infected with various kinds of Spyware and am in the process of removing SurfSideKick. I'm following the instructions and just want to clarify one thing; when I first look in Hijack this, I presume I delete the lines with the SurfSideKick references?

    Please calrify as it only says to to look for them and not to delete them.

    Thanks.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If have any problems getting rid of SurfSideKick see the link for a fix in the following sticky thread: Special Removal Procedures
     
  32. MonkeyCat

    MonkeyCat Private E-2

    Yes, that's what I was referring to, the Sticky thread for SurfSideKick. Anyhow, I went with my gut instinct and removed the HJT entries referring to SSK. The folder which was in Program Files (SurfSideKick 3) has now disappeared so I was unable to follow the rest of the procedure.

    There's more Spyware on my system, so I'm going to go through the whole READ ME procedure again and post some new logs with you if that's OK?

    Thanks.
    Monkeycat
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I thought we were in pretty good shape though previously. But that was 20 or more days ago and alot can change in that much time.
     
  34. MonkeyCat

    MonkeyCat Private E-2

    I thought I was in good shape too, and I was until the other night; it seemed to come from nowhere when I booted up the computer.

    I believe I've removed SurfSideKick. I followed the sticky thread and whilst I couldn't find any repairs.dll files, I followed the rest of the procedure and it seems to have disappeared.

    As well, I removed a 'Network Monitor' application from Add/Remove programs. This file was created as a result of the attack, alongside a folder called 'Trus' in C:program Files. I cannot delete this file presently.

    Norton Antivirus identified a virus called 'W32.Picrate' which it was unable to delete as it couldn't access the file. It's located in C:\Documents and Settings\brp.exe

    Bit Defender seemed to remove quite a bit and the log is attached alongside the HJT file. However, I could not run Panda Activescan. I keep trying to choose the scan 'My Computer' option but the link simply won't open. Yes, I accessed this through IE, not Mozilla.

    Your assistance is appreciated.
     

    Attached Files:

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a bunch of new problems. Let's begin with the below.

    Please follow the steps in the below link and attach the requested log:

    Running Spy Sweeper

    Afterewards get a new HJT log and attach it too.

    Did you install Windows Media Player like the below so it runs at startup? This appears to be malware as it is not even in the proper folder name.
    O4 - HKLM\..\Run: [wmplayer] C:\Program Files\wmplayer\wmplayer.exe /auto
     
  36. MonkeyCat

    MonkeyCat Private E-2

    OK. Please find attached Spy Sweeper log and HJT file. Spysweeper keeps blocking an attempt to open www.a-d-aware.com (or something like that).

    Look forward to hearing from you. Where's all this come from?!?:eek:
     

    Attached Files:

  37. MonkeyCat

    MonkeyCat Private E-2

    PS the HJT entry you refer to - no, I have no knowledge of this. Permission to fix?
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\Program Files\wmplayer\wmplayer.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [wmplayer] C:\Program Files\wmplayer\wmplayer.exe /auto
    O4 - HKLM\..\Run: [xp] p2pnetworking.exe
    O4 - HKLM\..\RunServices: [xp] p2pnetworking.exe
    O4 - HKCU\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe
    O4 - HKCU\..\Run: [Tbsa] "C:\Program Files\trus\astr.exe" -vt yazr

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\wmplayer <--- the whole folder
    C:\Program Files\Common Files\VCClient <--- the whole folder
    C:\Program Files\trus <--- the whole folder
    C:\windows\system32\p2pnetworking.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  39. MonkeyCat

    MonkeyCat Private E-2

    Followed your instructions and things seem to be much better. I've exited Spy Sweeper and I'm not being directed to the Adware site. Please find attached a fresh HJT log.

    Are we sorted? (I'm of to bed now so will pick up your response tomorrow). PS Any ideas how this got on my system? It all seemed to appear at once.:confused:

    Thanks again for your help.
    MonkeyCat
     

    Attached Files:

  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Only you can answer that. We have know idea where you surf, what you download, what you click on, what/where/who you get email from etc. You had multiple issues which can come from many different locations. Do you use P2P programs to download anythin? They are notorious spreaders of malware.

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  41. MonkeyCat

    MonkeyCat Private E-2

    OK. I've done the File Restore thing and will look at the thread about protecting from Malware (again). I'm abit unsure on the Java bit, but I'll muddle my way through it.

    Should I uninstall Spy Sweeper now? If I experience problems in the future will I be able to download another trial version?

    I posted a thread about Limewire playing up a couple of weeks ago (yes, I use p2p applications) and downloaded Shazzaware (but uninstalled as I couldn't get my head around changing my browser settings) and subsequently Morpheus, which is still on my system. I believe Morpheus is a 'clean' application.

    Thanks for all your help.:)
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not going to purchase Spy Sweeper you should uninstall it to free up system resources and also after 14 days it will not be of any use to you anymore. You can always download another version in the future but it probably will not work because it will recognize you already had a trial version.

    You really should read all of the How to protect thread including step 10 which gives you the below link to P2P programs:

    http://www.spywareinfo.com/articles/p2p/

    Some versions of Morpheus (similar to other programs) are infected. But in the end, no P2P programs are actually safe since you have opened up the door into your PC. Also when you download, you have no idea who (and really what ) you are downloading from. How do you know that the person you are downloading from does not have an infected system?
     
  43. MonkeyCat

    MonkeyCat Private E-2

    Thanks for your comments on P2P applications. I've recently switched from Norton AV to AVG, and AVG picked up a couple of Trojan Dropper viruses<SIGH>. Looking at the location of these, I've discovered they originated in the wmplayer folder......strange.......looking back on your instructions, you advised to delete this folder in safe mode......and I did.

    However, when I reboot in normal mode, the folder re-appears and cannot be deleted (even after changing from read-only to read-write). I have tried accessing task manager but cannot locate a relevant process to 'kill'.

    I haven't used any P2P applications since the last incident and access pretty much non-dodgy websites.

    How can I get rid of it?

    Thanks.
    MonkeyCat

    PS I've also installed Zone Alarm - do I need this? (i.e. does my wireless router have a firewall?).
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It would be better if you could post a log of what AVG is finding. Something that include file names and paths and the name of the virus.

    Although your wireless router probably does contain a hardware firewall, you should still use a software firewall like ZA.

    Perhaps you should post a new HJT log.

    The standard installation folder for the real Windows Media Player is:

    C:\Program Files\Windows Media Player

    This is not what you had. The executable is named wmplayer.exe just like the other item you had. There is also no reason why it should be loading at startup either.

    What files do you see in the C:\Program Files\wmplayer folder.
     
    Last edited: Feb 1, 2006
  45. MonkeyCat

    MonkeyCat Private E-2

    OK - Here you go.

    Thanks alot.
    MC
     

    Attached Files:

  46. MonkeyCat

    MonkeyCat Private E-2

    PS Could not see the wmplayer folder - presumed this was same as Windows Media Player folder, which doesn't contain any files?
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean! I don't know what AVG was saying about the wmplayer folder but if it does not exist, it makes no sense. Unless AVG already deleted it.

    Your Windows Media Player folder should not be empty. That would mean you do not have Windows Media Player installed.
     
  48. MonkeyCat

    MonkeyCat Private E-2

    A new spyware problem which I believe has come from opening an e-mail attachment. Spybot cleared up alot of this, but cannot delete the folder MyWebSearch (which is in Program Files). I've tried all the usual ways of deleting this manually, to no avail.

    I attach PandaActiveScan Log and HJT File. Forgot to save the BitDefender one, but this came back clean anyway.

    Please advise how I can resolve. Your assistance is, as ever, appreciated.

    Thanks.
    MonkeyCat
     

    Attached Files:

  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's get an installed programs list from HijackThis!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
  50. MonkeyCat

    MonkeyCat Private E-2

    Sorry for the delay; been at work. Please find attached list as requested.

    MonkeyCat
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds