Still have Spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by patz, Dec 28, 2005.

  1. patz

    patz Private E-2

    I followed and ran all the items in the read me first, except Panda where I keep getting an error on the page when I try to scan. I even bought Webroot Spy Sweeper, but I still get the same 6 problems., yieldmanager, advertizing, atwola and adserver cookies plus trojan-downloader-dh.

    I am attaching the ijack this log I ran after I ran the Spy Sweeper, so I don't know if that was a mistake or not. any help would be appreciated
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MG's!

    Please attach the require BitDefender log.
     
  3. patz

    patz Private E-2

    Sorry, this is the latest scan.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to use the instructions to turn it into a text file. Take a look at what you posted. Don't worry about it know though. Looks like you just ran that now and we expect it to be run before HJT is posted.
     
  5. patz

    patz Private E-2

    sorry, what do you want me to do, run Hijack again?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have to ask a question about something. I see you are using Volcano Chat. Was you PC infected before or after using this program? That is have you been using it for awhile without problems or did you recently install it and now you have problems?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Just answer my other question about Volcano Chat. I'll be posting something for you do do in a little while.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would still like to hear you answer about Volcano Chat!!!

    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\Program Files\eshh\rsec.exe
    C:\WINDOWS\system32\m?hta.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R3 - Default URLSearchHook is missing
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [Microsoft Windows Session Manager Subsystem] C:\windows\smss.exe
    O4 - HKLM\..\Run: [drsmartloadb] c:\\drsmartloadb.exe
    O4 - HKCU\..\Run: [Dmos] "C:\Program Files\eshh\rsec.exe" -vt yazr
    O4 - HKCU\..\Run: [Syimbb] C:\WINDOWS\system32\m?hta.exe
    O20 - Winlogon Notify: MSSYCLM - C:\WINDOWS\system32\mvn2l95o1.dll (file missing)
    O20 - Winlogon Notify: ssldr - C:\windows\
    O20 - Winlogon Notify: WebCheck - C:\windows\system32\guard.tmp (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (some may already be deleted)
    C:\windows\smss.exe <---- only delete if found here. DO NOT delete it from c:\windows\system32
    c:\drsmartloadb.exe
    C:\Program Files\eshh <--- the whole eshh folder
    C:\WINDOWS\system32\m?hta.exe <--- do not delete MSHTA.EXE which is valid. See if you find something similar. Don't delete if not sure. Ask first.
    C:\WINDOWS\system32\mvn2l95o1.dll
    C:\windows\system32\guard.tmp

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Reminder Note: Once we have determine you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  9. patz

    patz Private E-2


    I don't know ha that program is, I didn't install it nor do I use it.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Besides what you installed here to work on fixing your problems, what else if anything have you installed in your PC lately? Any new software, games, hardware etc?

    Also look in Add/Remove programs to see if it appears in there.
     
  11. patz

    patz Private E-2

    Volcano chat is not in the Ad Remove Programs folder. I have not added any programs but ad ware and spy ware removal programs that were in it READ ME FIRST folder.

    What happened sI went to a website "KEYGEN", when I clicked on the link from the Google Search all He%* broke loose. Ads started popping up, nortons found a bunch of crap that I have been trying to get rid of for a week.
    I am attaching the latest Hijack file.
     

    Attached Files:

  12. patz

    patz Private E-2

    Also I found 2 MSTHA files in windows\system32, on had no icon and the only thing under properties was that it was created on 12/25/05, I didn't delete it.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's get an installed programs list from HijackThis.
    Run HijackThis, click Open the Misc Tools section
    Click "Open Uninstall Manager"
    Click "Save List" (generates uninstall_list.txt)
    Click Save, to save it to a file where you can find it.
    Upload this file as an attachment.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must stop using msconfig to control startups.

    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    See the directions in the link for download,installing and using HJT in step 7 of the READ ME.
     
  15. patz

    patz Private E-2

    Here it is!
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They both cannot be named mstha.exe. What were their full names and what were the file sizes. The one that has no real icon and is mstha.exe is probably the valid one and is probably about 24 K in size.

    Properties and Version info will tell you it is: Microsoft (R) HTML Application host if it is valid.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Kill these two processes with HJT:
    C:\Program Files\Common Files\VCClient\VCClient.exe
    C:\Program Files\Common Files\VCClient\VCMain.exe

    Then have HJT fix the below lines.
    O4 - HKCU\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe
    O4 - HKCU\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exe

    Then reboot into safe mode and delete:
    C:\Program Files\Common Files\VCClient <--- the whole folder.

    Now reboot in normal mode and attach a new HJT log. How are things running now?
     
  18. patz

    patz Private E-2

    Ok 1 is an application 28.5 KB, version 6.0.2900.2180. The other one is an application 396 KB, no version, just compatility tab and summary tab. Funny thing it is not in alphabetical order, it comes after mypixdx.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is the full file name? You are not telling me the extension.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And this is because it is not showing you the hidden characters in the file name. That is why what you saw in the HJT log had a ? in the the name. There are sometimes 2 or 3 hidden characters that are unprintable in the filename.

    The one that is 396 k should be deleted.
     
  21. patz

    patz Private E-2

    Here is he HJT log, in Normal startup mode.

    The reason I was not giving you an extenstion is there is none listed even in detail view. When I went to delet it it said it was a system file, should I still delete it.

    There was no VentC folder. I found the file and it is part of my Verizon wireless phone connection to use my cell phone as a modem, so I did not delet it. I did not reconize the program when you said it was a chat program.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Probably because you did not do step 2 of the READ & RUN ME:
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I said delete

    C:\Program Files\Common Files\VCClient <--- the whole folder.

    I did not say to delete your Verizon stuff. Which is in:
    O23 - Service: Venturi2 Client (Venturi2) - Venturi Wireless - C:\Program Files\Venturi2\Client\ventc.exe

    Are you saying that VCClient is part of Verizon and not Volcano Chat?
     
  24. patz

    patz Private E-2

    OK I deleted that folder. I was seeing hidden and system files, but had "don't show extensions for known file types" checked. It is an exe file. Delete it?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes the 396k one. But in Windows Explorer does it look like mstha.exe?

    How did you do the below in message # 8 without extensions showing:
     
  26. patz

    patz Private E-2

    I did a search and found the files to delete

    mshta.exe 396 KB Application, is what it says, not in alphabetical order
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes delete that file but I did not say to use search. I said use Windows Explorer. If the file had been hidden or was a system file, Windows Search would not find it.
     
  28. patz

    patz Private E-2

    I used windows explorer, did a search in explorer after looking manually. To see if there were any other files. I deleted all that were found.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! But for future reference, that is still a Windows Search and will not find hidden or system files without doing what is here:

    Searching for Hidden Files on WinXP
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  31. patz

    patz Private E-2

    I ran Nortons Anti Virus found and deleted 4 threats, but 1 is still there. It is reported in The compressed file USYP_0001_N57M2911NetInstaller.exe within C:\RECYCLER\xS-1-5-21-1023205051-3768162446-2419710393-1005\Dc45.cab is a Security risk threat It is listed as WinFixer
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But that is in your Recyle Bin which should have been emptied manually and Ccleaner should have emptied it too. Are you using that stupid Norton N-Protect feature?
     
  33. patz

    patz Private E-2

    I don't know! I went back and purged all the files from he Nortons protcted recycle bin manually. I'll run a new scanand see. I'm not gettng popups though.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Just let me know!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds