spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by peony44444, Jan 5, 2006.

  1. peony44444

    peony44444 Private E-2

    i did everthing in read me first. i could not boot into safe mode.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MG's!

    Why problem are you having trying to boot into safe mode?
    Also it would be better if you explained what problems you are having. Just saying "spyware" does not help us very much.

    If you cannot run in safe mode, all steps should be followed in normal boot mode. When you complete ALL the steps attach to your a message the three requested logs.
    (Bitdefender, PandaActiveScan, and HijackThis). Make sure you follow step 7 exactly to get HjackThis installed properly.
     
  3. peony44444

    peony44444 Private E-2

    when i booted in safe mode and when the name came up i clicked on it then the computer froze. i rebooted and tried again and the same thing happened.
    i have view manager and i uninstalled it.
    spybot found
    elitum.elitebar
    virtumonde
    microsoft found
    virytumondo.c
    bitfernder found
    ddayw.dll

    i will attach the logs.

    computer is having alot of pop ups and is running slow.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Follow all the directions in the READ ME. Run ALL steps in normal boot mode then attach the logs requested in step 6 (both BitDefeneder and Panda). The goto step 7 and make sure you click the link and follow directions for installing HJT properly and attaching a HJT log.
     
  5. peony44444

    peony44444 Private E-2

    when i boot in safe mode none of my icons show on the desktop.

    i get a message saying
    mcaffe active scan has found a suspect file on your computer.
     

    Attached Files:

  6. peony44444

    peony44444 Private E-2

    here is my log. im not sure if it went through before
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your HijackThis log posted last time but you must attach the BitDefender and Panda logs from step 6 of the READ ME. Please make sure you follow the directions.

    Also if for any reason, you cannot run steps in safe mode, they should be performed in normal boot mode. While having no icons in safe mode can be a pain, it does not really stop you from working. CTRL-SHIFT-ESC will bring up Task Manager and you can either run explorer.exe from it to bring back your Desktop or individual programs can be run using Task Manager's File, New Task (Run...) menu selections.

    You still have some of Symantec AV running and also you have McAfee AV and AOL's AV. See step 3 of the READ ME. Personally I would not run any of AOL stuff but that is your choice if you are using them for an ISP. Either way, only one AV program must be used. Decide which one you want an uninstall the other.

    Most of your problems are coming from a Virtumonde (which that great AOL as they advertise on TV, has no idea is even present). You need to follow the steps in the below link but start at step 3 since you did the starting steps already.

    Virtumonde aka Trojan Vundo Fix w/ Tool

    The lines from your log you will need to use to complete this procedure are:
    O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} - C:\WINDOWS\system32\ddayw.dll
    O20 - Winlogon Notify: ddayw - C:\WINDOWS\system32\ddayw.dll

    We will do some additional cleanup after you complete the procedure and attach a new HJT log.
     
    Last edited: Jan 7, 2006
  8. peony44444

    peony44444 Private E-2

    in safe mode i coulnt run the micr malicious removal tool. i had a question, can i run a few of the scans at the same time or should they be run one at a time?
    also, i dont have the infected computer hooked up to the internet because it is so bad when it is. can i run the vundo fix tool before i do the two online scans?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can fix the Vundo problem first but if not performed in safe mode it may not work.
     
  10. peony44444

    peony44444 Private E-2

    i did all the steps in safe mode. after it did the fix and hijack this ran. only the 020 dday.w showed up in the hijack this. the 02 dday.w wasnt there. im pretty sure i did everything correctly. after i closed hijack this and tried to reboot the computer froze. i left it for awhile then it was still frozen so i pressed the button to turn it off, it still wouldnt so i ended up pulling the plug. then i booted up in normal and ran hijack this. i notice that the dday is still there.
     

    Attached Files:

  11. peony44444

    peony44444 Private E-2

    here are the logs
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it looks like the steps did not work for some reason. Sometimes this happens due to various protection software like MS Antispyware or the items you have running from AOL ....etc getting in the way. Let's try a different approach that I have used. If this does not work, you may have to disable and or uninstall some items in order to get the Virtumonde infection fixed.

    Okay let's use my older manual approach to fixing Virtumonde. Start by downloading two tools we will need:

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of ddayw.dll once and then click the kill button. After you have killed all of the ddayw.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above in the winlogon.exe process but look for geeba.dll (you may not find any cases of geeba.dll).


    Next double click on explorer.exe and again click once on each instance of ddayw.dll and kill it.

    Now repeat the above in the explorer.exe process for geeba.dll (you may not find any cases of geeba.dll).

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} - C:\WINDOWS\system32\ddayw.dll
    O20 - Winlogon Notify: ddayw - C:\WINDOWS\system32\ddayw.dll
    O20 - Winlogon Notify: geeba - geeba.dll (file missing)



    Copy the bold text below to notepad. Save it as fixVundo.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.

    C:\WINDOWS\SYSTEM32\wyadd.ini
    C:\WINDOWS\SYSTEM32\wyadd.ini2
    C:\WINDOWS\SYSTEM32\wyadd.bak
    C:\WINDOWS\SYSTEM32\wyadd.bak1
    C:\WINDOWS\SYSTEM32\wyadd.bak2
    C:\WINDOWS\SYSTEM32\wyadd.tmp
    C:\WINDOWS\System32\ddayw.dll

    C:\WINDOWS\SYSTEM32\abeeg.ini
    C:\WINDOWS\SYSTEM32\abeeg.ini2
    C:\WINDOWS\SYSTEM32\abeeg.bak
    C:\WINDOWS\SYSTEM32\abeeg.bak1
    C:\WINDOWS\SYSTEM32\abeeg.bak2
    C:\WINDOWS\SYSTEM32\abeeg.tmp
    C:\WINDOWS\System32\geeba.dll

    If you find any other files in this folder that begin with ddayw or abeeg and end with any other extension ( the .ini is an an extension) delete them to.

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot locate the below folder with Windows Explorer and delete it:
    C:\PROGRAM FILES\Oemji

    Now attach a new HJT log and tell me how the steps went. Doing this in normal boot mode does not always work. So we may have to retry again in safe mode.
     
  13. peony44444

    peony44444 Private E-2

    ok. here is the log....i hope this works! i hate to think i have to do it again.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Your Vundo problem is gone. I would suggest you Reset your Main Default pages to something other then Dell MyWay unless you reall prefer this.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway


    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  15. peony44444

    peony44444 Private E-2

    i cant believe its gone. can i get rid of any of the other "crap" thats on the computer?

    also what needs to stay checked in msconfig startup and what can be unchecked?
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is really not a topic for this forum. It is not malware and it is a difficult and often a subject of much debate on what particular persons needs or uses and what they do not need. Why do you want to use msconfig? If you don't want to load particular programs at startup, don't load them. If you sometime want to load items and other times do not then maybe you want to use a better approace than msconfig. A better tool is: Startup CPL

    You can easily search on line a google or yahoo (or similar) to find out what a process is. You can also use a links like:

    http://www.bleepingcomputer.com/startups/
    http://www.liutilities.com/products/wintaskspro/processlibrary/

    to find info on processes. Based on this info you can normally figure out if that is something you need.

    Examples of what I put in the never need category and should never be loaded ( additional comments in this color )
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background <--- in fact this should be disabled or uninstalled. Use this: Disable/Remove Windows Messenger
    O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" <--- how often does one need printer diagnostics


    The below are in the category of not required but do you like or use the feature. But consider whether you really need to always have it running. How often do you use this program and why not just run it when needed?
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
     
  17. peony44444

    peony44444 Private E-2

    thank you so much for all your help. in the beginning the instructions told me to enable everything in the startup folder in misconfig, that is why i asked which should be checked and unchecked because i didn't remember how it was before i started. things are running great now! should i delete anything that i downloaded? (example. fix vundo, killme, biodefender scan etc.)
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well then decide if you want to remove any of the items or not. Like I said some are not really needed. You can experiment using Startup CPL or msconfig before permanently removing items from loading. You will find that much of what I mentioned you will never miss.

    You can remove special tools like FixVundo and Killme. Other tools downloaded you may as well keep since they could prove useful to you. Even ProcessExplorer and PocketKillbox are very good tools to have around. Most of the items don't use any resource unless you run them and some like ProcessExplorer and PocketKillbox use very little disk space.
     
  19. peony44444

    peony44444 Private E-2

    i have a dumb question ....i have two desktops. mine and my daughters. ive been on my name to clean everything out. my daughter hasnt gone on her name yet. was i supposed to do all this on her name too? or did we clean the entire computer? (please say we cleaned out the entire computer....)
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normally it is a good idea when a PC is infected to check out all accounts on the PC. At a minimum, you should at least log into it an make sure there are no visible malware problems. The best things to do is to run the READ ME (you can skip step 6) for all accounts Since you already have everything downloaded and installed, it is much faster the second time.
     
  21. peony44444

    peony44444 Private E-2

    ok here is the log......im crossing my fingers
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you know running HJT incorrectly from:
    C:\DOCUME~1\Katie\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    You aleady had it installed properly before and that is the reason we want it installed properly (i.e., so that any user account can run it from C:\Program Files\HJT) From any Desktop folder, only that use account can see it. You are now running it from the ZIP file. Please run it properly in the future.

    That said, this log is clean anyway. However, we do not recommend having anything in the Trusted Zone like below:

    O15 - Trusted Zone: *.musicmatch.com (HKLM)

    unless it is absoulutely necessary (and it rarely is). I have MusicMatch and it works fine for me and it is not in the TZ.
     
  23. peony44444

    peony44444 Private E-2

    can i have the link to uninstall msmessager?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you mean? Why do you want to uninstall MSN Messenger?

    Or did you mean Windows Messenger? They are not the same thing.

    You can use the below to remove Windows Messenger:

    Disable/Remove Windows Messenger

    I already gave you this link a number of posts back.

    MSN Messenger would be uninstalled using Add/Remove programs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds