surfsidekick and more?

Discussion in 'Malware Help (A Specialist Will Reply)' started by ppreheim, Apr 11, 2006.

  1. ppreheim

    ppreheim Private First Class

    A friend from church brought me this computer and I am trying to rid it of pop ups. I did all in the do me first file +the surf sidekick stuff. The computer has gone from unusable to annoying. It still has pop ups but it can be used. When I did the bitdefender online scan it completed the scan but froze when it was done. I could not get a printout of the log. It did find 120 items and 45 viruses but could only fix 119 of the 120 items.
    Panda log and HJT log provided
     

    Attached Files:

  2. ppreheim

    ppreheim Private First Class

    Microsft Antispyware ran last night and found some more stuff. One of the findings was Qoologic. I figured I better do the stuff in that special removal thread so I did. Attached are the three log scans and a new HJT. Thanks for the help in advance. I am also getting some zeno pop ups.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! Limewire may be at the root of all these problems. You have a bunch of baddies on this PC. This may take a few steps but let's see what we can do in the first run.

    Download - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later to run it.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click OK.

    Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\WINDOWS\DOWNLOADED PROGRAM FILES\f3initialsetup1.0.0.15.inf
    C:\WINDOWS\system32\feawuith.dll
    C:\WINDOWS\jpsjjgjA.exe
    C:\WINDOWS\Lktbgzsf.dll
    C:\WINDOWS\errorhandler.exe
    C:\windows\system32\qpdsregq.exe
    C:\WINDOWS\system32\nwinqrag.exe
    C:\WINDOWS\system32\dwdsregt.exe
    C:\WINDOWS\system32\dmonwv.dll
    C:\WINDOWS\system32\kkhmu.dat
    C:\WINDOWS\system32\fmsjic.exe
    C:\WINDOWS\system32\vvjni.exe
    C:\WINDOWS\system32\ltrjakf.dll
    C:\WINDOWS\system32\grqrtht.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\xtekp.exe


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself. However BOOT INTO SAFE MODE during this reboot and do not run anything but what I request. DO NOT open any browsers!

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes. (You may not see these! If not, just continue.)
    C:\Program Files\Common Files\??crosoft\d?xplore.exe
    C:\PROGRA~1\ASEMBL~1\wowexec.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=wKX1ILEOi+Vh7AfA98Gm4Me69ZMbubcDyUaazwlbdhe5db443nNig5YZ4MOr6MS8+TBqEkSAtxwRJzXtIjdEJIIQXMtkSd7kIfHug/ArzJ/okbFgijoLlIiNI5G2JZXZJq0jLoRnkE0rgGmCwfEDDK2bqqDBJUcCTXfRkhzqn30OjAB6pWVURpiynPMKSLfM6sHlWuDRcyrIGSf22kSO9A==
    F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\vvjni.exe
    F2 - REG:system.ini: UserInit=userinit.exe,grqrtht.exe
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: BMG3.LongTooth - {8110581C-FEA4-47AC-ADBC-DE958DD0F354} - C:\WINDOWS\system32\{8110581C-FEA4-47AC-ADBC-DE958DD0F354}.dll (file missing)
    O2 - BHO: (no name) - {88B82A4C-E48B-B12B-A81D-BA5E17683393} - C:\WINDOWS\system32\feawuith.dll
    O2 - BHO: (no name) - {D5F224B8-3D4F-3A58-F697-415C8C9D7609} - C:\WINDOWS\Lktbgzsf.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O3 - Toolbar: Search - {33676672-676C-76E0-B73B-543587D2AF4E} - C:\WINDOWS\Lktbgzsf.dll
    O4 - HKLM\..\Run: [jpsjjgjA] C:\WINDOWS\jpsjjgjA.exe
    O4 - HKLM\..\Run: [{23-31-1C-CA-ZN}] C:\windows\system32\qpdsregq.exe CORN001
    O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\nwinqrag.exe CORN001
    O4 - HKCU\..\Run: [Notn] "C:\Program Files\apsi\wtta.exe" -vt yazb
    O4 - HKCU\..\Run: [Tiyezu] C:\Program Files\?ssembly\?explore.exe
    O4 - HKCU\..\Run: [ruzr] C:\PROGRA~1\COMMON~1\ruzr\ruzrm.exe
    O4 - HKCU\..\Run: [EQBranch] "C:\Program Files\EQBranch\EQBranch.exe"
    O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\nwinqrag.exe
    O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
    O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZCxdm594YYUS
    O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
    O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
    O15 - Trusted Zone: http://click.getmirar.com (HKLM)
    O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
    O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
    O16 - DPF: {00000000-0000-0000-0000-000020040000} - http://207.234.185.217/ABoxInst_int13.exe
    O20 - Winlogon Notify: Controls Folder - C:\WINDOWS\system32\tqddd.dll (file missing)
    O20 - Winlogon Notify: ShellCompatibility - C:\WINDOWS\system32\OgmInfo.dll (file missing)

    Now exit HJT
    Run Windows Explorer and double check to make sure the below files are all deleted (some we already got with killbox):
    C:\Documents and Settings\Owner\Local Settings\Temp <--- Delete all file and subfolders in this Temp folder. Only the ones from your current PC bootup date may be refused as your PS is using them.
    C:\Program Files\apsi <--- the whole folder
    C:\Program Files\EQBranch <--- the whole folder
    C:\Program Files\?ssembly <--- the whole folder
    C:\Program Files\Common Files <--- the whole folder
    C:\PROGRAM FILES\EQAdvice <--- the whole folder

    C:\WINDOWS\system32\feawuith.dll
    C:\WINDOWS\jpsjjgjA.exe
    C:\WINDOWS\Lktbgzsf.dll
    C:\WINDOWS\errorhandler.exe
    C:\WINDOWS\keyboard51.dat
    C:\WINDOWS\ubber60.ini
    C:\windows\system32\qpdsregq.exe
    C:\WINDOWS\system32\qndsregj.exe
    C:\WINDOWS\system32\nwinqrag.exe
    C:\WINDOWS\system32\dwdsregt.exe
    C:\WINDOWS\system32\dmonwv.dll
    C:\WINDOWS\system32\kkhmu.dat
    C:\WINDOWS\system32\fmsjic.exe
    C:\WINDOWS\system32\vvjni.exe
    C:\WINDOWS\system32\ltrjakf.dll
    C:\WINDOWS\system32\grqrtht.exe
    C:\WINDOWS\system32\BMGi_b.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\xtekp.exe


    Now reboot into normal mode and after reboot double check the same HJT entries I had you fix above and if any still remain, fix them again a second time.

    Now attach a new HJT log and a new log from FindQool

    Also tell me how things are working!
     
    Last edited: Apr 11, 2006
  4. ppreheim

    ppreheim Private First Class

    Did as requested. Some of the files were no to be found when I was exlporing to delete them. All of the files after
    C:\Program Files\EQadvice were not found

    Absolutly no pop ups so far!!!

    Attached are the log files.

    I did get some errors on reboot to normal mode. MIcrosoft Money had some errors as did spysubtract.

    Thanks for everything. Hanging on the forum if you have any more advice for me
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Shutdown MS Antispyware and other similar tools and then have HJT fix the below lines:

    O4 - HKLM\..\Run: [eewbia] C:\WINDOWS\system32\fmsjic.exe reg_run
    O4 - HKCU\..\Run: [bbdck] C:\WINDOWS\system32\fmsjic.exe reg_run

    Then attach a new HJT log. Is eveything still working OK?
     
  6. ppreheim

    ppreheim Private First Class

    Fixed those two lines and posted the new log.

    No pop ups at all. Still get the pop up subtract program error and the Microsft Money files stuff but those are easy fixes to reinstall. Is the pop up subtract program even worth it?

    Should I advise them to remove Limewire as well?

    Thanks for all the help
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You never said what the actual error were so I have no idea what you are seeing. I do not use any popup blocking programs! I don't find them to be necessary. Just use Firefox if popups are a problem. It has built in popup blocking.

    In this forum (and most other malware forums) no one would tell you to keep Limewire or any other P2P program. In fact some forums will refuse to provide any fixes until ALL P2P software is uninstalled. The more recent versions of Limewire are "supposed to be malware free" but P2P is by design not safe and is a spreader of malware. It is your friends decision in the end.
     
  8. ppreheim

    ppreheim Private First Class

    The Micro Money just keeps trying to install and asks for the discs. SHould be just an easy install.

    no pop ups whatsoever while using the internet.

    Thanks for all the help and I will advise the owner on how to avoid this in the future.

    Again, thanks
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Maybe not! Sometimes the MS Installer gets messed up. You could try just putting the disks in to see if it fixes it, but it may not. This would however be an issue for the Software Forum.
     
  10. ppreheim

    ppreheim Private First Class

    more problems. I dont know if there is something hiding but I just got this computer back and have followed the do me first thread and it found a ton more. Logs are below. I also cannot get Microsft outlook to work, nor can I get a new version of Microsoft Money to work that was working after the first run through this stuff. Logs are posted below, please advise.

    Thanks in advance
     
  11. ppreheim

    ppreheim Private First Class

    trying to upload files it looks like I forgot. WOnt let me. I have the bitdefender scan as an rtf file and it wont take it. It says the active scan is too big, and it says I have already loaded a HJT scan in this thread
     
  12. ppreheim

    ppreheim Private First Class

    Lets see if this works

    Also, I have deleted Norton and am trying to install Avast. The install goes fine but I get a worning that Norton is still running even though I deleted so I manually delete all Norton folders but they keep coming back.

    Still wont let me upload the HJT file
     

    Attached Files:

  13. ppreheim

    ppreheim Private First Class

    Update: Used Norton removal tool found on this site to get rid of Norton as advised by Chu bbakka. Worked like a charm, thanks chu bbakka!!!!

    Hopefully I will be able to post the new HJT log ran after removal of norton. I still see some winantivirus stuff on there so I know there are still some uglies on this computer. Please advise..

    Thanks in advance
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not supposed to delete programs. You are supposed to uninstall them. Is that what you meant?

    Who installed the following junk: WinAntiVirus Pro 2006

    Let's get an installed programs list from HijackThis too!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
    By the way, you did not follow the directions for creating a Bitdefender log. But don't worry about it now, I don't need it.
     
  15. ppreheim

    ppreheim Private First Class

    Yeah, I misworded it. I uninstalled Norton via the add/remove function. When it said I still had Norton running I kept trying to manually remove the folders with delete but they kept coming back. Seems fine now and Avast is working smoothly.

    The owners of the computer installed the junk. I have informed them not to install anything that appears in a pop up.

    I knew I did something wrong with bitdefender. Sorry.

    Attached the uninstall list.

    Thanks for all the help!!!!!!
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First run Add/Remove programs and uninstall the below:
    Notifier
    RelevantKnowledge
    Viewpoint Media Player


    Is the below line due to something you install or use?
    O11 - Options group: [INTERNATIONAL] International*

    Now download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the mailscan.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move mailscan.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.

    Now Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Service Hosts ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Service Hosts

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: IEFW Object - {B5141620-C2B2-4D95-9F0F-134D99C87AB0} - C:\Program Files\WinAntiVirus Pro 2006\iefwbho.dll (file missing)
    O2 - BHO: DPCUpdater Object - {DE8BDE42-16D9-4CCC-9F4F-1C3167B82F60} - C:\WINDOWS\system32\ddaby.dll (file missing)
    O4 - HKLM\..\Run: [WinAntiVirusPro2006] "C:\Program Files\WinAntiVirus Pro 2006\WinAV.exe"
    O4 - HKLM\..\Run: [CompanionWizard] "C:\Program Files\Common Files\Companion Wizard\compwiz.exe" /silent
    O20 - Winlogon Notify: ddaby - C:\WINDOWS\system32\ddaby.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\WinAntiVirus Pro 2006 <-- the whole folder
    C:\WinAntiVirus Pro 2006 <-- the whole folder
    C:\Program Files\common files\Companion Wizard <-- the whole folder
    C:\WINDOWS\system32\FT_SilentSudokuInstaller.exe
    C:\WINDOWS\system32\qndsregj.exe
    c:\windows\keyboard101.dat
    c:\windows\ubber60.ini

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  17. ppreheim

    ppreheim Private First Class

    Followed directions with these exceptions.

    Notifier was not in add/remove manager
    Could not find Service Hosts in the services.msc
    Service Hosts was not found in the register per HJT

    All other instructions were followed

    HJT log is posted. Computer seems to be running normally. Thanks for your time. Will check back tonight after work to see what else is needed. THanks again
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's strange! They showed in the previous logs!

    Still have another bad service to remove!

    Now Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Firewall service... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    FWSvc

    If you receive any error messages just ignore them and continue.

    Now exit HJT but and reboot if it tells you it needs to.

    Then after reboot attach a new HJT log.

    You did not answer my question about the below line:
    O11 - Options group: [INTERNATIONAL] International*

    Also does the person who this PC belongs to use Alcohol Software's CD/DVD writing application named Alcohol 120%? I'm questioning the service that is running with the file named C:\WINDOWS\System32\ScsiAccess.EXE

    I would like to get some more info on the C:\WINDOWS\System32\ScsiAccess.EXE. Locate it using Windows Explorer and then right click on it and select Properties. Now see if there is a Version tab in the window. If so, select the Version tab and on the next window select each of the listed Item names (one at a time) to get more info about the file. The most important Item is the company name. If there is no Version tab, tell me that too. If there is no Version tab, use the below link to scan this file and attach the report of what is found:

    http://virusscan.jotti.org/
     
  19. ppreheim

    ppreheim Private First Class

    Sorry about not answering the previous question. I actually remembered this on my drive to work.

    O11 - Options group: [INTERNATIONAL] International

    I don't have the faintest idea on what this is. Am wondernig however if this might be something from IE7? I installed that for them when I couldn't find a recent version of IE6 from Microsoft.

    As far as Alcohol120% I am pretty sure they don't use it. Am waiting for confirmation that should happen sometime tonight however. Thanks again and I will run the steps as directed when I get home late tonight.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Make sure you get the properties info and run the online file scan on ScsiAccess.EXE
     
  21. ppreheim

    ppreheim Private First Class

    Followed all instructions. Logs attached.

    There wasn't a version tab with the ScsiAccess.EXE file so I ran the online scan which didn't find anything. Log posted. Well I couldn't find a log button so I copied and pasted into notepad.

    Thanks again
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean other than my concerns on this ScsiAccess.EXE file. Please try putting it into a ZIP file and uploading it here as an attachment. Hopefully it will be small enough to do that.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  24. ppreheim

    ppreheim Private First Class

    Here it is. Let me know and I will do what you think is best.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well from the file itself I still cannot tell who created it, but it does seem to be a valid application. It could be part of something that was installed. It does appear to even have a method of uninstalling the service, but since we do not know what application it belongs too it could break something the user needs if stopped. I have stopped this service on other PCs in the past and it did not appear to affect anything. At least there were no comments about it causing any problems.

    For now, if you are not having any other malware issues, I would just leave it alone.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  26. ppreheim

    ppreheim Private First Class

    Flushed the System restore.

    Will walk the owner through the protecting themself thread. Thanks for all the help. You are a life saver!!!!!!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds