Tooo tricky for me.

Discussion in 'Malware Help (A Specialist Will Reply)' started by scully91, Aug 9, 2005.

  1. scully91

    scully91 Private First Class

    Toooo tricky for me. I cant seem to get rid of some spyware/trojans i have picked up. It all seemed to start when i downloaded MSN to use instead of internet explorer. I have tried to get rid of it but it dont show in the add/remove programs. Anyway thats one problem.
    The other is occasionally my AVG pops up and says i have a virus, generally in c/windows/system32/*****. I go and delete the file and yet it comes back. The hijack this log reads terribly. There is something called a BHO or something (think its o12) and i have removed it in safe mode (its got loads of ffffffffffff`s in it) but it still seems to be there. Pops are coming all over the place and putting icons on my desktop.
    Can i post a hjt log for you to tell me which bits to remove. I have done all the spyware thingy that you ask.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal then continue with the below, otherwise complete the sticky thread steps first.

    Follow the steps below exactly (you must install HJT properly):

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. scully91

    scully91 Private First Class

    Here it is Chaslang.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Open Control Panel and select Add/Remove Programs look for the below programs and uninstall them if found:
    Search Maid
    Security IGuard
    Virtual Maid
    PSGuard
    AntivirusGold

    Now exit Add/Remove Programs.

    NOTE: Some of the items mentioned in the below steps may or may not be there. If not found just ignore them and continue. These problems come in a variety of forms and different filenames can be used each time.

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINNT\system32\cmd.exe
    C:\WINNT\popuper.exe
    C:\WINNT\system32\intmonp.exe
    C:\WINNT\System32\msole32.exe
    C:\WINNT\system32\shnlog.exe
    C:\WINNT\system32\intmon.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.bestwebslinks.com/search.php?qq=%1
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bestwebslinks.com/bar.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bestwebslinks.com/search.php?qq=%1
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bestwebslinks.com/search.php?qq=%1
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.bestwebslinks.com/search.php?qq=%1
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.bestwebslinks.com/search.php?qq=%1
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.bestwebslinks.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    F2 - REG:system.ini: Shell=Explorer.exe, msmsgs.exe
    O2 - BHO: HP Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINDOWS\system32\hp9431.tmp
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\svcproc.exe
    C:\WINDOWS\system32\msmsgs.exe
    C:\WINDOWS\system32\shnlog.exe
    C:\WINDOWS\system32\intmonp.exe
    C:\WINDOWS\System32\intmon.exe
    C:\Windows\System32\helper.exe
    C:\Windows\System32\ole32vbs.exe
    C:\Windows\system32\msole32.exe
    C:\WINDOWS\system32\hp9431.tmp
    C:\wp.exe
    C:\wp.bmp
    C:\bsw.exe
    C:\Windows\sites.ini
    C:\Windows\popuper.exe
    C:\Program Files\Search Maid<--- the whole folder
    C:\Program Files\Security IGuard<--- the whole folder
    C:\Program Files\Virtual Maid<--- the whole folder
    C:\Windows\System32\Log Files <--- the whole folder
    C:\Program Files\AntivirusGold <--- the whole folder
    C:\Program Files\PSGuard <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and continue with the below.

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixsmit.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Double-click on the fixsmit.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to add to the registry say yes.
    Now please download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program.
    Now post a new HJT log. And tell me how things are working.
     
  5. scully91

    scully91 Private First Class

    Ok.
    1.Not sure about the c/winnt things. The said items were found under windows but if i tried to delete them they wouldnt go away.
    2.Tried to remoce everything in hjt but again didnt seem to disappear.
    3.Dunno where to find any of these
    C:\wp.exe
    C:\wp.bmp
    C:\bsw.exe
    C:\Windows\sites.ini
    C:\Windows\popuper.exe
    4.C:\Windows\System32\ole32vbs.exe has been removed but ole32.dll still remains (wasnt sure if to remove it or not)
    5.Removed intmon and intmonp plus the same with .exe. on the end.
    6.There is a picture of a ghost with a line through it called "spyware" in the program files. its the same picture that appears on my desktop. Does that need to go please?
    Here is the new hjt log. Still not clean so what have i missed and where do i find it please?
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The c:\winnt text should have been c:\windows
    Sorry about that! I forgot to edit it after pasting it in. What items did you mean you could not delete?

    Also what did you mean that things "didn't seem to disappear"? What things? Can I assume you mean just those R0/R1 lines with bestwebslinks.com on them?

    You also said:
    That is where to find them. Either they are there or they are not. As I said in my instructions, you may not find everything.

    Do not touch ole32.dll because it is a valid file!

    Also you said:
    Are you referring to an icon for a file? What was the filename? What is the fullpath to the file?

    Where you able to merge the fixsmit.reg patch into the registry without any problems?

    Have HJT fix the below lines (make sure no browsers are open when you click fix):

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.bestwebslinks.com/search.php?qq=%1
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bestwebslinks.com/search.php?qq=%1
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.bestwebslinks.com/search.php?qq=%1
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.bestwebslinks.com/


    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot and then get a new HJT log and post it.
     
  7. scully91

    scully91 Private First Class

    1.Ok, the things i couldnt delete were in the misc tools thing you told me about but its ok they have now gone.
    2. If i cant find these
    3.Dunno where to find any of these
    C:\wp.exe
    C:\wp.bmp
    C:\bsw.exe

    But found the c/windows/sites.ini one but it just says "sites" and when i open it it shows me this on notepad :
    [http://www.iqsearch.net/casino/carnival2/index.html]
    [http://www.iqsearch.net/info/spyware2/search.php?qq=spyware]
    [http://www.iqsearch.net/info/dating2/search.php?qq=date]
    [http://www.iqsearch.net/info/pharmacy/search.php?qq=online pharmacy]
    [http://www.iqsearch.net/casino/monaco3/index.html]
    [http://www.iqsearch.net/info/internet_security/search.php?qq=network security]
    [http://www.iqsearch.net/info/sport_betting/search.php?qq=sport betting]
    [http://www.iqsearch.net/info/spyware4/search.php?qq=popup blocker]
    [http://www.iqsearch.net/casino/clubdice2/index.html]
    [http://www.iqsearch.net/info/makemoney/search.php?qq=job]
    [http://www.iqsearch.net/info/electronics/search.php?qq=air cleaner]
    [http://www.iqsearch.net/info/spyware/search.php?qq=spyware]
    [http://www.iqsearch.net/casino/carnival1/index.html]
    [http://www.iqsearch.net/info/online_dating/search.php?qq=webcam]
    [http://www.iqsearch.net/info/credit_cards/search.php?qq=credit cards]
    [http://www.iqsearch.net/casino/monaco1/index.html]
    [http://www.iqsearch.net/info/pharmacy2/search.php?qq=phentermine]
    [http://www.iqsearch.net/info/loan/search.php?qq=loan]
    [http://www.iqsearch.net/casino/clubdice_poker1/index.html]
    [http://www.iqsearch.net/info/music/search.php?qq=mp3]
    [http://www.iqsearch.net/info/dating/search.php?qq=personal]
    [http://www.iqsearch.net/info/adipex/search.php?qq=adipex]
    [http://www.iqsearch.net/casino/monaco2/index.html]
    [http://www.iqsearch.net/info/spyware3/search.php?qq=spyware]
    [http://www.iqsearch.net/info/cars/search.php?qq=car insurance]
    [http://www.iqsearch.net/info/finances2/search.php?qq=loan]
    [http://www.iqsearch.net/casino/clubdice1/index.html]
    [http://www.iqsearch.net/info/pharmacy/search.php?qq=viagra]
    [http://www.iqsearch.net/info/carisoprodol/search.php?qq=carisoprodol]
    [http://www.iqsearch.net/casino/carnival3/index.html]
    [http://www.iqsearch.net/info/travel/search.php?qq=travel]
    [http://www.iqsearch.net/info/makemoney/search.php?qq=Internet Marketing]
    [http://www.iqsearch.net/casino/clubdice2/index.html]

    Which looks suspiciously like something i didnt ask for!!!! Shall i remove it ;-))

    C:\Windows\popuper.exe was found and removed.

    4. The spyware thing is in c/windows/system32/spyware, there is also another one called "date" which is a love heart which also used to be on my desktop which appeared with all this spyware (obviously clicking on it would have sent me to one of the sites they were trying to promote)
    5. Yes i did the fixsmit.reg thing ok.
    6. I have fixed the lines you said in hjt
    7. I have reset the web settings (how do i get rid of msn though?)
    8. Here is the new hjt log for you and thankyou.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete the "sites" file you found.

    What is in this folder c/windows/system32/spyware or is it a file?

    What is in this folder date or is it a file?


    What MSN are you referring too? You start page should now be www.majorgeeks.com

    Your HJT log is clean.
     
  9. scully91

    scully91 Private First Class

    Delete the "sites" file you found

    DONE

    What is in this folder c/windows/system32/spyware or is it a file

    ITS A FILE. WHEN U OPEN C/WINDOWS/SYSTEM32 ITS THERE ALONG WITH PHARMC AND DATE (SUSPICIOUSLY LIKE THE ONES YOU HAVE TOLD ME TO DELETE IN "SITES")


    What is in this folder date or is it a file?

    ITS DATED 8 AUGUST

    What MSN are you referring too? You start page should now be www.majorgeeks.com

    I DONT HAVE AN IE ICON ANYMORE SO CANT ACCESS IT. I USE AOL TO ACCESS THE NET AND SOMETIMES IE. BUT I DONT HAVE IE ANYMORE OR AT LEAST I DONT HAVE AN ICON. I JUST WANT THE OLD IE ICON BACK AND IE PAGE, NONE OF THIS MSN THING ;-))
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make a temp folder somewhere (or use one you already have) and move the spyware, date and pharmc files to that temp folder for now. After a few days of running your PC without any problems, delete the files. This is just to be safe and make sure you do not need them for something.

    I still don't know what you mean by MSN thing. What MSN thing? Do you mean an icon for MSN is on your Desktop?

    You can easily just put a shortcut to IE on your Desktop by dragging it to the Desktop (using Windows Explorer) and then selecting Create Shortcut. You can also right click your Desktop and select Properties. Then click the Desktop tab and select Customize Desktop. Now on the General tab make sure Internet Explorer is checked. Using the second method should be your first choice.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds