System Intrusion Detected

Discussion in 'Malware Help (A Specialist Will Reply)' started by mystika, Jan 8, 2006.

  1. mystika

    mystika Private E-2

    Okay, I've been working on this for HOURS. I've checked through various forum posts (the similar ones) and have done everything you've suggested.

    I get that annoying System Intrusion Detected bubble, and SpywareStrike kept installing automatically.

    I followed steps 1-6 and removed all that was found. I ran BitDefender (which took about 4 hours) and it found a few things and deleted them. Panda found a few things as well. Both logs are attached.

    Thing is, once I ran BitDefender, I started at Step 1 again and a whole bunch of things were found the second time around - more so than the first. This stuff is all new to me, so not sure whether having the 'net open allowed for extra stuff to be put on my computer. So I ran everything again (except BitDefender & Panda because I didn't want to keep going around in circles) and deleted what was found. Then I ran HJT. I tried to run SmitRem (the .bat file) but it doesn't do anything (??).

    I also ran Ewido (after BitDefender and Panda, before the second clean) and have attached that log.

    Anyhow, here are all my files. Help!!
     

    Attached Files:

  2. mystika

    mystika Private E-2

    PS - since I made Firefox my default browser (and somehow lost all my shortcuts to IE), it looks like SpywareStrike isn't automatically installing anymore... knock on wood. But I still get that wretched bubble.
     
  3. mystika

    mystika Private E-2

    PSS - I lied. It's back.
     
  4. mystika

    mystika Private E-2

    Just making sure I don't get forgotten about way over here on page 2... I'm still eagerly awaiting a response!

    FYI - I've disconnected my internet (I'm on my laptop here), removed SpywareStrike (again), ran my antivirus program and AdAware and neither of them found anything. So I'm remaining disconnected until I know how to stop it from downloading things!

    Thanks in advance!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MGs!

    By continously adding more messages to your first post, you kept loosing your position in the queue and made your message thread already look like it had been answered and was in progress. We work through the queues from oldest to newest and also by oldest to newest unanswered. Each tim you added a message you became newer and the post count of the thread incremented making it look answered.

    The effect is even worse when we are real busy because each of us will be working on threads we already are working on and we did not see that yours needed an answer.

    Please run the below procedure. If you already have SmitRem.exe, DOWNLOAD it again because it was just updated.

    SpywareStrike, Smitfraud, SpySheriff, SpyAxe & PSGuard Removal

    Post the smitfiles.txt log afterwards.

    Run HJT and select all the O18 lines like the below with Logitech on them. Then click Fix.
    O18 - Protocol: bw+0 - {1296C1D6-A5E1-4219-837E-0982F68F3B91} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

    Now attach a new HJT log. Let me know if SpywareStrike is still bothering you after this. You do have other problems we need to fix so don't worry if you still have other malware problems remaining.
     
  6. mystika

    mystika Private E-2

    Oops - sorry. New at this whole 'help forum' thing. Glad you finally got around to me! I was wondering why I was being overlooked...

    Downloaded and ran SmitRem (finally worked this time) and it seemed to do the trick. I ran Ewido afterwards (found 5 files) and AdAware (nothing) as well, then HJT where I fixed all those logitech messenger files (what the heck is that, anyways?).

    I rebooted to Normal Mode and voila! No more pop up window. Looks like no more SpywareStrike. My HJT log (and smitrem and ewido) are all attached.

    My Windows Security Alert still popped up saying I didn't have anti-virus or firewall but I do - I use VCOM System Suite...

    Thanks again for your help - I'm just so freakin' happy that the pop up is gone (along with the program, of course)!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That Logitech stuff is for Logitech Desktop Messenger. You must have bought something from Logitech like a mouse or webcam. The add some dumb software to your system to download news and update info to you. Most people probably do not want this to be done automatically. They seem to have bug in their software that keeps adding more and more lines to the registry. The root is the below line:

    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

    You should consider whether you really need or want this to run. If not, uninstall it via Add/Remove programs.

    Are you sure that Vcom's SystemSuite Task Manager is a firewall? It looks to be just some kind of fix it tool to me. It has CleanUp, SpeedUp and FixUp utilities but I don't see anything else like a firewall or antivirus etc.

    You have remnants of an HSA hijacker. You should run the below tool twice and attach the log later when you come back.

    about:Buster

    I'll be posting some more fixes in a few minutes.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to a review I found, you do not have what you think you have from V-com

    That is unless maybe you have VCOM SystemSuite Professional 6 which does seem to include other items. But your log shows no signs of protections running.

    See: http://www.v-com.com/product/SystemSuite_Home.html
     
    Last edited: Jan 9, 2006
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [winly32.exe] C:\WINDOWS\winly32.exe
    O4 - HKLM\..\Run: [9B5.tmp] C:\DOCUME~1\Laura\LOCALS~1\Temp\9B5.tmp.exe
    O4 - HKLM\..\Run: [9B6.tmp] C:\DOCUME~1\Laura\LOCALS~1\Temp\9B6.tmp.exe
    O4 - HKLM\..\Run: [9B6.tmp.exe] C:\DOCUME~1\Laura\LOCALS~1\Temp\9B6.tmp.exe
    O4 - HKLM\..\Run: [9B5.tmp.exe] C:\DOCUME~1\Laura\LOCALS~1\Temp\9B5.tmp.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\winly32.exe
    C:\Documents and Settings\Laura\Local Settings\Temp <--- delete all files in this Temp folder that it lets you delete. You may need to skip some.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).


    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  10. mystika

    mystika Private E-2

    Okay. Removed Logitech Desktop Messenger. Ran about:buster twice (log attached).

    SystemSuite does have a firewall (Netdefender) but I hadn't turned it on - once I did, it wouldn't even let me access internet or e-mail so I turned it off again. Doesn't my wireless router have a built-in firewall? That's what I was told... any suggestions you have for anti-virus/firewall, I'm all ears.

    Didn't have winly32.exe. Deleted one temp file; wouldn't let me delete the other 2 (weren't read only). As for killing the process, I'm not sure which one I'm looking for in Task Manager (I had 3 svchost.exe's running and I don't know what they are) so I didn't kill anything.

    Deleted all Prefetch files. Ran CCleaner. Reset web settings. Re-ran HJT in normal mode. Log attached.

    Thanks again for all your help in this!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, some routers do have firewalls built in but you should still use a software firewall. All software firewalls do require some administration work on your part to allow or block applications as desired. If you did not allow iexplore.exe and your email appliation to pass thru your NetDefender firewall that could be the problem. Some firewalls are smarter by default and automatically configure for certain applications.

    You must get a software firewall installed and you also need an antivirus application since you do not have one installed and running. Firewalls and antivirus application suggestions are covered in the link further down.

    Your HJT log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
    Last edited: Jan 9, 2006
  12. mystika

    mystika Private E-2

    Gotcha. Will get on the firewall/anti-virus thing right away.

    THANKS SO MUCH!! YOU ROCK!!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds