strange problem with adware

Discussion in 'Malware Help (A Specialist Will Reply)' started by RicardoB, Apr 17, 2005.

  1. RicardoB

    RicardoB Private E-2

    I have a difficult problem with adware.popup that was detected under a routine system scan by Norton Antivirus.

    I am running XP Professional SP2

    there is a folder named SBSI on c:\Windows\Help\

    It contains a file named cabcom.dll, which is the one identified by Norton.

    the problem is, the file cannot be removed, the reason is, it's included in the notificaty key if winlogon hklm/Software/Microsoft/WindowsNT/CurrentVersion/Winlogon/notify.

    I have no idea how the dll is called, but using process explorer from sysinternals I found that the .dll is listed under winlogon.

    I checked all the usual registry entries (run, runonce) and win.ini, system.ini, the starup folder, nothing.

    I tried manually deleting the registry entries, for both, winlogon/notify and where the .dll is registered in system.root, it doesn't work because the application rewrites the registry keys, if I change a value or rename the key it fixes it.

    I can't unload the application, I tried killing the handler with process explorer but it doesn't work.

    I tried booting up in safe mode, even with only the command prompt, and it's the same.

    I looked at Symantec's removal instructions but it only says to scan the system and whem prompted delete all the identified files, that was what failed in the first place.

    Spybot, ad-aware and another spyware tool I used don't even detect it.

    It's not mentioned by McAfee or Panda, nor it is in the Microsoft knowledge database.

    I don't think the .dll is doing much, first because it would be blocked by the firewall, second because sp2 blocks all pop-ups, I haven't noticed any unusual activity, nor browser hijacking or anything like that. I have monitored the TCP activity and the .dll is not trying to contact anything over the internet.

    The question is, how do I get rid of it? I've searched in google and only found one more site that offers a removal tool, since I don't know the tool I didn't want to install it (I am paranoid).

    the strangest thing is that Symantec says the only way to install this thing is through another application that requires it. I haven't installed any free application/tool/program whatever in a very long time (and this adware has only been in my system for a few days), I have only installed licensed software, mostly very technical stuff (such as vmware) of visual studio tools for office, so I have no clue how this went into my system.

    Any help will be very appreciated.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We must start by running standard cleaning procedures given below.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. RicardoB

    RicardoB Private E-2

    Hi,

    I ran several scanners in safe mode, along with Norton, they only detected several tracking cookies, except for Norton that detected adware.adpopu (cabcom.dll) but couldn't delete it.

    this is the hijackthis logo

    Edit by chaslang: Inline log attached

    :)
     

    Attached Files:

    Last edited by a moderator: Apr 17, 2005
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I requested that you run ALL the steps in the READ ME FIRST not some of them. Which parts did you skip. Looks like one item you skipped was the Trend Micro online scanner.

    Also, HJT logs must not be posted inline. My previous message indicated that it must be attached. I attached it for you this time. Please remember to attach them from now on.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you setup the below Proxy Overrrides?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = dynhost.inetcam.com;register.inetcam.
    com;;localhost

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\Help\SBSI\cabcom.dll
    then click OK. If a dialog box confirming this action appears, click OK. If you get an error message just OK it and continue.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: MSEvents Object - {B8B55274-0F9A-41E5-9067-A3539BD9E860} - C:\WINDOWS\Help\SBSI\cabcom.dll
    O20 - Winlogon Notify: cabcom - C:\WINDOWS\Help\SBSI\cabcom.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\Help\SBSI <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now run Ccleaner (installed while running the READ ME FIRST).
    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  6. RicardoB

    RicardoB Private E-2

    No, I didn't setup any proxy overrides.
     
  7. RicardoB

    RicardoB Private E-2

    I followed the process, but when I booted in safe mode and intended to delete cabcom.dll it told me the file was being used by another application, I checked if it was read only and it was not.

    This is the hijackthis log, as you can see the entries are still there, the reason is that cabcom.dll seems to restore the registry keys if they are deleted or changed in any way (it even has defined functions to do this).

    I contacted the publisher and they sent me an application, I suppose to uninstall it, I couldn't look into this because outlook blocked the attachment and asked them to send me a .zip file. In any case, I was planning on running it on a virtual machine first to see what it does.

    The other option I was thinking of was to setup a software restriction policy to not allow cabcom.dll to run, the problem is that it's launched by winlogon.exe that runs every time you logon, even on safe mode, and because the application rebuilds the registry key you can't get rid of it. I am hoping a software restriction policy would prevent it from running and then I could safely remove the file and the registry keys, what do you think?

    here is the hijackthis new log (attached this time).

    by the way, thank you very much for your help.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you forget to exit C:\Program Files\Internet Explorer\iexplore.exe before running HJT or is it running on its own?

    If you did not set the ProxyOverrides do you recognize the two URLs: dynhost.inetcam.com
    register.inetcam.com
     
  9. RicardoB

    RicardoB Private E-2

    Hi Chaslang,

    I made sure I closed all internet explorer and all windows explorer windows, as well as the email client.

    regarding that url dynhost.inetcam.com, not, I do not recall it, I checked the website and seems to be a streaming video site but I have never visited it before.
     
  10. RicardoB

    RicardoB Private E-2

    Hi Chaslang,

    I am happy to say that I found a way to remove this thing (crossing fingers).

    I used the Microsoft's recovery console, basically I bootted up from the Windows XP CD, and when it loaded I typed R, then it asked for the Administrator's password, but the console doesn't really log on, it only needs the password to access the harddrive (and it won't give you access to all of it).

    with the command prompt I just navigated to the folder and delete the guilty files.

    Then rebooted and run hijackthis, the logo showed the old registry entries but was indicating that the file was missing (which I loved), so I have hijackthis fixing them. Then ran the scan again and the keys were gone (before they would come back). To make sure I quit hijackthis and starte again, same result, then I manually open the registry and took a look, they were gone.

    This is apparently a not so well known tool, being a programmer I am not too much into admin tools so I have to search a bit for it but it paid off.

    It could be a way to remove nasty stuff when everything else fails, although it's probably not for the average user.

    Thanks for all your help. (btw I removed the proxy as well, I didn't set it up so it shouldn't be there).
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Happy to hear you got it worked out!

    The Recovery Console is a very well known tool that we do use to resolve some problems. It will not always work either. The problem we have in many cases is that users do not always have a bootable XP CD. That is they may only have disks there PC manufacturer gave them and it is only a restore to original condition type disk.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds