Step by step, and no love. or spyware extermination.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Juno's Eye, Feb 7, 2005.

  1. Juno's Eye

    Juno's Eye Private E-2

    I found the post about not asking for support until going through these steps. here's my report of these steps:

    1. Checked for "Network Security Service" or "Workstation Netlogon Service" or "Remote Procedure Call (RPC) Helper" on WIndows 2000 machine. none running.

    2. hidden files and file extensions: shown.

    3. programs: downloaded and installed. Can't stay in safe mode with the computer, as it spontaneously reboots. proceeded in normal mode.

    4. Virus and security scanning: updated norton 2005, scanned.

    found Adware.Elitebar.B, Adware.Huntbar (WToolsA.exe and WtoolsB.exe)
    and then Adware.Binet, Adware.CDT, Adware.EliteBar (sfee.exe, twice)
    Norton did sweet F-A about removing any of these.

    5. Ran McAfee AVERT Stinger. Came up all right.

    6. Ran CCleaner. Lovely program. It's now on all the computers I own.

    7. Ran Ad-aware SE. 45 objects found. as I was attempting to remove those objects, the computer rebooted even though I was in normal mode (that seems normal - it's just that in normal mode it takes longer before it decides to reboot.) Ran Ad-Aware again. 48 objects, this time.

    8. Ran Spybot: search and Destroy. 12 problems found. found immunize, ran that feature.

    9. Ran Microsoft AntiSpyWare Beta 1. (I know it's not on the list but my hardware technician left it for me, and why not use it?) found one problem.

    10. ran CWShredder. removed CWS.Bootconf, CWS.Searchx, and Hosts File redirections.

    11. ran L2me fix, even though it said I didn't have it.

    12. ran HSRemove. it says you only have to run it if you have homesearch assistant; I don't care. I'm still getting wacky popups. it reports that it removed 10 items. well. better safe than.

    13. ran AboutBuster, or tried. the system spontaneously rebooted again. that's so annoying. upon reboot, I got two popups. three.

    Bah. still having problems. I go to Windows update, and discover that this computer needs 15 critical updates and service packs, plus 4 windows 2000 updates. okay. that's only going to take a hundred years to install. I have been at this solidly for eight hours now, and this is my third day of attempting to remove this stuff for my friend. I want to go home. I want clean clothes. I want to sleep in my own bed. I want to sleep.

    45 minutes into the windows update install, the system rebooted.

    When do I get to the point where a horde of cabana boys rub my shoulders and run me a bubble bath? Stupid Trojans.

    windows update, file by file. all went okay until I got to the rather large one, and then it rebooted again.

    It's been nine and a half hours, going through these steps. I've followed them as best I can. what else do I need to do before I can post a Hijack this log?

    Juno
     
  2. TheOldThug

    TheOldThug First Sergeant

    Juno

    You have been hard at work. Very frustrating I know. You mentioned the elite tool bar. You might want to try this from safe mode only. Elite remover Then send us a HJT log.

    Please try to turn OFF any applications that are not needed It makes it much easier to look at the HJT log.
    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, INCLUDING YOUR WEB BROWSER, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder for example C:\Program Files\HJT

    Good Luck :)
     
  3. TheOldThug

    TheOldThug First Sergeant

    Juno

    You may want to go here also and look at what they have to say. You can search for some of your other known problems also.

    Adware.Elitebar.B
     
  4. Juno's Eye

    Juno's Eye Private E-2

    I did what I could baou closing down programs but it seems that there were a lot of programs hiding on me while I was trying to do this.

    I tried the second set of steps but after attempting five symantec scans and having the comupter generate errors in Winlogon.exe and shut down spontaneously, I just gave up in frustration.

    but, that's the Hijack this log. Thanks
     

    Attached Files:

  5. TheOldThug

    TheOldThug First Sergeant

    Looks like at the minimum you probably have a VX2 infection. I will get Chas or PP to loo at it for you.
     
  6. Juno's Eye

    Juno's Eye Private E-2

    Thank you. I'm going to go read about VX2 infections so I'm not completely lost.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do not use Microsoft AntiSpyWare Beta! It has lots of problems right now and is not worth the trouble. It has False detections which results in removal of items you need and in some cases has even broken Microsofts own firewall. At this point you would be better off uninstalling it and use only what we indicate.

    As Thug point out you do have a VX2 infection and also a few other problems. One is a O15 Trusted Zones hijack (I call it that for now). This Trusted Zones issue is a nightmare that about 10 people per day (maybe more) are now coming here to try and get fixed. They are a nightmare because they keep coming back.

    Let's begin with the following steps.

    Please download the following tools and save them where you will be able to find them. I save stuff like this to a C:\downloads\Spyware-Stuff folder and I put each in their own subfolder. It makes it easy to find. Make sure you download them from the links below:

    L2MeFix Tool
    Generic Detection Tool - NT/2000/XP

    VX2.BetterInternet Finder XP/2k - Version Msg126
    Pocket KillBox

    Also please download http://ralphcaddell.com/Uploads/deldomains.zip and unzip it to your desktop. Do not run it yet.


    Please make sure that Viewing of Hidden Files is Enabled as per the tutorial.

    Please print out these instructions now or save locally so that you can operate with All Browser Windows CLOSED and with your connection to the internet physically unplugged.

    Exit Browsers now before continuing and unplug your cable.


    First Step:

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINNT\system32\pxrad.exe
    C:\WINNT\system32\prfcons.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R3 - URLSearchHook: (no name) - _{CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - (no file)
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O4 - HKLM\..\Run: [Desktop Search] C:\WINNT\isrvs\desktop.exe
    O4 - HKLM\..\Run: [ffis] C:\WINNT\isrvs\ffisearch.exe
    O4 - HKLM\..\Run: [u37R37l] pxrad.exe
    O4 - HKLM\..\Run: [antiware] C:\winnt\system32\elitejei32.exe
    O4 - HKCU\..\Run: [f0o5RXJtO] prfcons.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O15 - Trusted Zone: *.admin2cash.biz
    O15 - Trusted Zone: *.awmdabest.com
    O15 - Trusted Zone: *.bettersearch.biz
    O15 - Trusted Zone: *.c4tdownload.com
    O15 - Trusted Zone: *.finefind.nettraffic2cash.biz
    O15 - Trusted Zone: *.iframe.biz
    O15 - Trusted Zone: *.megapornix.com
    O15 - Trusted Zone: *.newiframe.biz
    O15 - Trusted Zone: *.overpro.com
    O15 - Trusted Zone: *.private-dialer.biz
    O15 - Trusted Zone: *.private-iframe.biz
    O15 - Trusted Zone: *.sp2admin.biz
    O15 - Trusted Zone: *.sp2****ed.biz
    O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - (no file)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINNT\isrvs\desktop.exe
    C:\WINNT\isrvs\ffisearch.exe
    C:\winnt\system32\pxrad.exe
    C:\winnt\system32\elitejei32.exe
    C:\winnt\system32\prfcons.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Then, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin

    And Click OK.

    Second Step:

    Find the files from deldomains.zip on your Desktop and RightClick on the deldomains.inf file and select Install.


    Third Step:
    Reboot to Normal Windows. Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log.

    NOTE: Please do not run any other options or files in the l2mfix Folder!

    Fourth Step:

    Extract all the files from the Generic Detection Tool into its own folder.
    Then run find.bat. Post the log it creates back here as an attachment. Make sure you wait long enough for it to complete. A notepad window will pop up when done.

    Fifth Step:

    Plug your cable to the internet back in and run your browser and come back here and attach the l2mfix log, the output.txt file from find.batalong with a new HijackThis log. This will require two messages since there is a two attachment limit per message.

    Please DO NOT REBOOT after scanning for these logs!! Otherwise problems may mutate and spread. Wait for me to get back to you with the next steps.
     
  8. Juno's Eye

    Juno's Eye Private E-2

    all right, here are my logs.
     

    Attached Files:

  9. Juno's Eye

    Juno's Eye Private E-2

    and this is the third.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot the attachment of the find.bat output.txt file. But don't worry about it now. Wait until the next steps!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Step 1:

    Print or save these instructions locally now because you will have to be disconnected with no browsers open in the next step.

    Please make sure ALL Browser Windows are Closed and also you should physically disconnect from the Internet by unplugging your cable.

    Go to the L2MFix Folder on your Desktop and DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.
    Just be patient and let it run. It should eventually spit out another log in Notepad. Please attach that log later when the remaining steps are completed.

    Again, don't run any other files in the L2MFix folder.

    Step 2:

    Run "find.bat" from the Generic Detection Tool again!

    Okay after doing the above DO NOT REBOOT. Now reconnect to the internet and come back here and post and attach the find.bat log along with the L2MeFix Log.
     
  12. Juno's Eye

    Juno's Eye Private E-2

    okay...
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have files that appear to be related to an HSA hijack problem. Did you have hijack issues at a point in time.

    Use Windows Explorer to locate and delete the following in the system32 folder:

    C:\WINNT\SYSTEM32\
    appaq32.exe Tue Jan 18 2005 1:16:56p A.SH. 11,596 11.32 K
    atlds.exe Sun Jan 30 2005 6:16:36p A.SH. 11,215 10.95 K
    ckqkn.txt Tue Feb 1 2005 3:55:48p A.SH. 0 0.00 K
    d3aj.exe Sat Jan 15 2005 6:42:22p A.SH. 10,824 10.57 K
    javask.exe Wed Jan 12 2005 4:15:34a A.SH. 11,454 11.18 K
    msci32.exe Thu Feb 3 2005 2:14:10p A.SH. 10,824 10.57 K
    msda.exe Tue Feb 1 2005 8:51:58p A.SH. 11,032 10.77 K
    netue.exe Fri Jan 14 2005 6:15:58p A.SH. 10,824 10.57 K
    winjt32.exe Thu Jan 27 2005 9:53:08p A.SH. 0

    Let me know if you have problems finding or deleting any of those.

    Then, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin

    And Click OK.

    Then reboot and get a new HJT log to post so we can work on the last few problems.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please post questions for your problem/issues in your own threads. This question has nothing to do with this thread either.
     
  15. Juno's Eye

    Juno's Eye Private E-2

    the last time I had to delete files out of Windows Explorer I was doing it in safe mode. should I assume the same here, or no?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can attempt this in normal mode. If you have problems, try safe mode. Let me know the results.
     
  17. Juno's Eye

    Juno's Eye Private E-2

    Hee. I think I just realized that I cannot boot to safe mode in this case, because if I do I will destroy all the good work we have done so far. allright. enought with the stupid questions and I will get on with it.
     
  18. Juno's Eye

    Juno's Eye Private E-2

    I already see some things in this fresh hijack this log that tell me that i'm not out of the woods just yet. deleting those files in mormal mode came off just fine, though.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O4 - HKLM\..\Run: [Desktop Search] C:\WINNT\isrvs\desktop.exe
    O4 - HKLM\..\Run: [ffis] C:\WINNT\isrvs\ffisearch.exe
    O15 - Trusted Zone: *.finefind.nettraffic2cash.biz
    O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - (no file)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINNT\isrvs <-- the whole folder

    Let me know if this folder cannot be deleted.

    Then, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin

    And Click OK.

    Find the files from deldomains.zip on your Desktop and RightClick on the deldomains.inf file and select Install.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  20. Juno's Eye

    Juno's Eye Private E-2

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINNT\isrvs <-- the whole folder

    Let me know if this folder cannot be deleted.

    it deleted just fine, but I noticed two folders called elitebar and elite something else. I left them, but i figured i'd let you know.

    the log is there, and those little buggers are back! i don't know what I screwed up.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They are always annoying to get rid of!

    Copy and paste the information in the below quote box to notepad. Save it to a file that you will have access to later when you boot into safe mode. Name it fix.reg. Then boot into safe mode, run Windows Explorer and locate the fix.reg file. Doubleclick it and grant it permission to add in the registry entries.
    After that run HijackThis and fix (if still there):
    O4 - HKLM\..\Run: [Desktop Search] C:\WINNT\isrvs\desktop.exe
    O4 - HKLM\..\Run: [ffis] C:\WINNT\isrvs\ffisearch.exe
    O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - (no file)


    Then reboot in safe mode and delete the folder again if it is there.

    Then reboot in normal mode and post a new HJT log.

    Delete those EliteBar folders you saw too.
     
  22. Juno's Eye

    Juno's Eye Private E-2

    you know what?

    I think we did it.

    But here is the log just in case....
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! They are gone. But let's check again after a few reboots and some surfing. These have been very troublesome to remove permanently. They always seem to come back.

    NOTE:
    I would uninstall Microsoft AntiSpyware it is only a beta and has been more trouble than it's worth. Too many false detections and it has broken some items on users PCs in many cases. It has even broken Microsoft's own firewall in multiple cases.

    Use the stuff we recommend instead in the below link. In fact make sure you do all the stuff (or there equivalents) in this link too:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds