Trojans and Spyware, Oh my

Discussion in 'Malware Help (A Specialist Will Reply)' started by pegg, Aug 27, 2006.

  1. pegg

    pegg MajorGeek

    I have had SLOW downs on my computer (Win XP home, SP2, running AVAST, Zone Alarm, SpyBot, Ad-Aware, Spyware Blaster, CCleaner). I did A-squared last week and it found 3 trojans, 2 in the folder for CWShredder so I deleted that program.

    I read the READ and RUN first section and am finishing my Panda scan now (so far there are 3 viruses and 9 spyware found). SpyBot found zero. My problem was with the GetRunKey.bat file. I ran it and it made 15 files and none were called "runkeys.txt". I made a folder called this and put all the files into it. BUT I can't attach the whole thing -- I'd have to do 5 separate postings of 3 sets of .txt -- any other idea? I ran the XPHome fix and the Get Run Key again but it didn't make a difference?

    Bitdefender found a bunch of problems too. (see attached)

    I'll have to try Microsoft Windows Defender in normal mode.
     

    Attached Files:

  2. pegg

    pegg MajorGeek

    Panda Scan

    Hmmm, I can't click on the "Save Report" button for Panda Scan because I don't see it! The box is only about 3/4 open and I can't drag it open to the left or to the bottom to get my report. Ugh, I'll have to go through all that again.
     
  3. pegg

    pegg MajorGeek


    I merged all 15 separate .txt files into one report and noted the name of each .txt that the info came from -- I hope that this isn't too confusing for you...Much easier then sending 15 reports.

    Windows Defender said it fixed the "t clock" -- I never heard of this and didn't know it was installed (I see that it is listed here in the runkeys.txt.

    I tried 2 different Registry Cleaners a week ago also and I ran them 3 times (twice in Safe Mode) and after a couple seconds of running my pc went to the dreaded Blue Screen!! So I don't know what that means but I figured it can't be good which is why I decided to do some intensive spyware scanning.
     

    Attached Files:

    Last edited: Aug 27, 2006
  4. pegg

    pegg MajorGeek

    Here is the Hijack this (I followed all directions).

    I tried 3 more times to do the Panda Scan but the browser window that opened up for the scan would never open up all the way to allow me to see the "Save Report" button to be able to send you one. (I can try in normal mode since Safe Mode has the screen enlarged....?)
     

    Attached Files:

  5. pegg

    pegg MajorGeek

    I don't know if it's my PC or a problem with the Panda Scan site...I can't get it to scan my computer with AVAST on / off, in safe mode, in normal mode, scanning local disks or documents or my computer or anything. Sometimes it just sits there like it's frozen...other times it will totally disappear (the open scan window and the Panda Scan original page I went to).

    I only got it to work that first time but couldn't save the log as mentioned below.
     
  6. pegg

    pegg MajorGeek

    Anyone online right now to help with this?
     
  7. pegg

    pegg MajorGeek

    OK - tried today and got Panda Scan to work in normal mode and it found 8 spyware when I scanned "Local Disks"

    (When I did this in safe mode back earlier in the proceedings it found 3 virus and 6 spyware when I scanned "My computer". then I saw the "Using PandaActiveScan rules that said to scan "Local Disks")

    Active Scan says one of the spyware is "Virtumonde" so I went to the special spyware removal section and downloaded VundoFix.exe. I ran it but it came back with "no infected files" (?)
     

    Attached Files:

    Last edited: Aug 28, 2006
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The more messages you post in your thread, the longer it takes to get a response. Each message moves you to the end of the work queue and we work from oldest to newest thread order. So each time you bumped your thread by adding another message, you went to the end of the queue. This made it take more than 24 hours to get an answer!

    Make sure you stop using MSconfig to control startups (per step 7 of the READ ME). Youare currently in selective startup mode and you must be in Normal Startup mode. Fix this now!

    You need to uninstall Viewpoint Media Player as requested in step 0 of the READ ME. While there, you should also uninstall all the below old versions of Sun Java:
    J2SE Runtime Environment 5.0 Update 1
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 7
    Java 2 Runtime Environment, SE v1.4.2_05

    Extract the GetRunKey.zip file into the folder where you extracted ShowNew. Then try running GetRunKey again and attach the runkeys.txt log. Then also attach a new log from ShowNew.


    Did you download and or install TrueSwitch to switch ISPs? I see the below in your ShowNew log.
    C:\WINDOWS\TrueInstall.exe


    Did you install and do you use software from Support.com?
    O16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} (Support.com ActionRunner Class) - http://help.rr.com/Foundrysdccommon/download/tgctlar.cab
    O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/download/tgctlcm.cab
     
    Last edited: Aug 28, 2006
  9. pegg

    pegg MajorGeek

    Thanks for letting me know the procedure. I had to keep adding posts to get my logs in since it took several hours and even a couple days (for Panda). I didn't want to be scolded for not including all my logs.


    I see no other explanation anywhere about how to get into Normal Startup mode (I believe I am in it now, although I WAS in selective when some logs were made) At some point (before you posted this) I got to normal startup with msconfig I'll admit since I know no other way.


    I followed Step 0 but had no idea this program was "bad". I was confused about old "versions" of J2SE because they were updates, I didn't think of them as old versions and I missed the really old one.


    I have attached a new newfiles.txt that I ran after doing a runkeys.txt log 2 different times. I re-downloaded the zip folder to 2 different folders and re-installed it 2 different ways and I still get 16 little .txt files created rather than one .txt file !! :eek: Once again I compiled it all into one text (I copied the order for the report from someone else's runkeys.txt and put the "from: xx.txt for each separate part of the report.


    This was installed for SBC Yahoo DSL but I no longer need it.


    I use Road Runner now for my ISP so this came with the installation.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All steps should be completed before posting and then only two messages are need to attach all logs and they should be posted only a minute or so apart. When you added all the other posts (some with many hours in between) you wasted all your time on hold.


    I quote direct from the link give in step 7 of the READ ME:
    Make sure that you are now in Normal Startup mode (this is not to be confused with Normal Boot mode vs Safe Boot mode).


    The list in step 0 is all bad. You don't have to decide anything for yourself. It tells you to uninstall all the Viewpoint stuff.


    This is not supposed to be necessary and we don't want you to do this. Something is wrong someplace if GetRunKey is not working. You did not follow my instructions in my last message. I said to unzip GetRunKey.zip into the SAME folder as ShowNew.bat. Please do that and attach a new ShowNew log. Then try GetRunKey again. Follow these steps in the order written. If it does not produce a runkeys.txt log automatically, DO NOT make one yourself. Just tell me.

    Then try running GetRunKey.bat from the command prompt. I have a feeling the problem is that you created a user account with spaces and an ampersand in the name (bad idea), thus making a combined user account (also a bad idea). You have Pam & Jeff . I believe what is happening (and you will see it from the command prompt window) is that the commands are failing on the ampersand and you will see a very strange error message in the command prompt window. Something like & was unexpected at this time

    Also run this new version of GetRunKey2.bat and attach the GRKdebug.txt log and the xtemp100.txt log (if it is found) and also the runkeys.txt log that I'm betting that it will create.
    Attached Fileshttp://forums.majorgeeks.com/images/attach/zip.gifGetRunKey2.zip (6.6 KB, 0 views)


    and also the runkeys.txt log that I'm betting that it will create.


    The delete that file.
     
    Last edited: Aug 30, 2006
  11. pegg

    pegg MajorGeek

    ...sorry, I was confused about this msconfig thing. I am in Normal Startup mode...I printed and followed everything the best I could and I did it the way you quoted but then I thought you were telling me I wasn't to do it that way. :confused: Sorry for the confusion.

    Again, I honestly looked at everything -- just missed it.


    Actually I did at first -- and it asked to override the grep.exe file from the one program with the other one and I said yes because I knew we'd run the .bat program...it still didn't work. That's when I deleted everything and downloaded new .zip files in case something was wrong with the first ones and then put them both in a C:spyware folder (but then they made sub-folders and that's not what you wanted)


    Did a search and could not find the xtemp100.txt
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so now GetRunKey ran properly. As I suspected the problem was due to the koing user name you chose with the & in it. This is acceptable for true Windows programs but it is not acceptable for anything that is a DOS related program. Your TEMP environment variable (and a couple others) are setup using this Pam & Jeff string and it was causing GetRunKey to terminate when it tried to process the TEMP environment variable. So now that we have figured out why you could not run GetRunKey, let's return to your malware problems.

    You don't really have any major issues, but let's fix a few things.


    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;http://localhost
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} - http://install.wildtangent.com/Activ...veLauncher.cab
    O16 - DPF: {89D75D39-5531-47BA-9E4F-B346BA9C362C} (CWDL_DownLoadControl Class) -
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://zone.msn.com/bingame/apop/def...ploader_v6.cab

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now boot into safe mode and use Windows Explorer to delete (if found)


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (if found)
    C:\Program Files\Common Files\{888D6E02-0AE9-1033-0826-040416200001} <--- the whole folder:
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\0HM3OHYF\122[1].net
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\WXAZCTYB\ourvacationphotos[1].zip

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode and post a new HJT log.

    Now delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\
    C:\Documents and Settings\Pam & Jeff\Local Settings\Temp\

    Make sure you tell me how things are working now.

    If your PC is running slow, I doubt it is malware. It more like just things that your are running. And you could then consider whether you need to load things like below:
    O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
    O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
    O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Snapfish\SNAPFI~1\data\Xtras\mssysmgr.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
     
    Last edited: Aug 30, 2006
  13. pegg

    pegg MajorGeek

    You are very wise.

    Did the merge with the registry plus this step.
    Don't even have a folder called NetworkService.

    I did this for IE although Mozilla Firefox is my default browser (so I deleted cookies and history there also)

    I'm not dense - really - but since I did a HJT log at the beginning and then you said "a new HJT log" and not "the new HJT log" I've included 2 logs, the one done first and the one done after all these steps were taken.


    I ran SpyBot earlier today and it said I had 6 places where there was SmitFraud. So I came here and did the special removal procedures for that and the PandaScan that followed showed 9 spyware and 2 possible Hijacking tools. Once again it showed the Virtumonde that appeared the other day but when I run the special removal tool for that it came out "clean" again.

    I guess my concern now is:
    1) These various malware that shows up in SpyBot and AdAware that I have NEVER seen before (but that was before the steps you just told me so...)
    2) The 3 Blue Screens that happened instantly when running the registry tools (RegSeeker and Registry Mechanic)
    3) Yes, I'd like to unload all those startup entries you mentioned to speed things up...can you point me to the thread that mentions how to do that?

    Thank you -- you have been very patient and very helpful.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you do! It is a hidden folder and is on all XP systems. You must not be logged in with Administrator priviledges or you did not do step 2 of the READ ME correctly. Also you Virtumonde files being detected are in this folder!


    Spybot cannot fix Smitfraud and often it is not deteting the real Smitfraud infections that the tools are meant to fix. It is usually a different problem. Run a new scan and if still detected, attach a log from Spybot.

    I need the logs but it is probably because you did not delete the files in the NetworkServices folder.

    What is Ad-Aware detecting and is it still detecting it?
    Blue Screens are rarely malware related problems.

    Do you ever need to use the Startup items at anytime? If not, just have HJT fix them.

    By the way your current HJT log is clean!
     
  15. pegg

    pegg MajorGeek

    Well it's a mystery then as to where it is. I've always had it checked to "view hidden folders" but I have doubled checked several times for these scans and repair issues. I logged in as myself (an admin. in safe mode and specifically under "admin" in safe mode -- and both ways in normal mode). View hidden folders is still checked and I have done a search on the entire C:\drive for this NetworkService folder. Sorry I can't find it. I have attached a Screen shot of C:\Documents and Settings so you can see what I see when I look there (but I also looked in some other directories for it).

    What do you suggest?


    You're right -- it did not detect it again (Attached is the first log made before the fix yesterday; the second log is today's scan). As you can see in the 2nd log it is giving me a warning about Active Desktop which I assume is related to the fix we made. Do I tell SpyBot to "fix" this since I think it's something we did to the desktop?


    Nothing was detected today after yesterday's fixes.

    Thanks

    Yeah. Thanks for all your help.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are only mentioning the view hidden files & folders option but you did not say whether you have the other options set correctly. How about this one:

    Uncheck the Hide protected operating system files (recommended) option

    You will not see system folders if this option is checked. It must be unchecked as specified in the READ ME. If the NetworkServices folder is showing up in the scans, it does exist. See the image below.

    Yes fix that. That one is due to a SmitFraud infection change. It is strange that Spybot only mentioned it on the second scan.
     

    Attached Files:

    Last edited: Sep 1, 2006
  17. pegg

    pegg MajorGeek

    Oh my word, I really did read the READ ME FIRST thread and I sure thought I did everything. I am so sorry for taking up so much of your time.

    I found these 2 now and deleted them.

    I will run SpyBot again and have it fix this active desktop thing.

    The only issue now is once in awhile we'll be online and then close the browser and then open it back up (we have cable connection - Road Runner) and our browser just won't find anything -- an error message saying the server won't connect -- page can't be found. And/or the computer slows way down (like I just edited this post because after I hit "submit reply" it took over a minute to post -- sometimes it suddenly will take a long time for pages to load) Then we restart the computer and everything is fine. So I don't know if it's our computer (usually everything is very fast - this will just change suddenly while we're on the web), the connection or malware. This is only once a day at the most.

    But other than that things are running better.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is anyone else sharing the connection to the internet? Like are you using multiple PCs via a router? Make sure no one is running P2P or bit torrent type applications. They act like servers and hundreds of people could be connecting into the PC and downloading. This will slow down all PCs connected to the network.
     
  19. pegg

    pegg MajorGeek

    No - no one else is doing anything - no router, no hubs, just this one pc plugged in directly to the cable "box" for Road Runner.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not sound like malware. It sounds more like somehing with your connection. Next time it happens try doing the below:

    Go to Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns (note there is a space between ipconfig and the / )
    • Hit Enter
    • Now enter this ipconfig /release
    • Now enter this ipconfig /renew
    • Exit the command window
    Does this change anything when you are having the problem?
     
  21. pegg

    pegg MajorGeek

    We didn't have a connection issue until Sept. 11 - so that was probably 2 weeks since the last time there was a problem.

    NO -- what you had me do didn't make a difference at all -- I still couldn't connect to the internet or get e-mail.

    I restarted my computer though and everything was fine. Does that tell you anything?

    Since this isn't happening much now, I'm not concerned but I wanted to answer your question about it.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Next time don't restart your PC. Just try turning off your cable modem. Then turn it back on. Does that help?

    If not, do you have a router? If so, power cycle it. Any change?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds