Winantispyware etc...!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Internationaldave, May 6, 2006.

  1. Internationaldave

    Internationaldave Private E-2

    Hey everyone,

    having trouble with winantispyware pop ups and something keeps changign my keyboard functions around, when i do ctrl ', instead of @ i get ".

    Can anyone help.

    Dave. :confused:
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    First give the below a run and be sure to attach the log from VundoFix:

    Virtumonde aka Trojan Vundo Removal


    Now how are things working. If you still have problems then please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. Internationaldave

    Internationaldave Private E-2

    Thankyou for your hasty reply. I have completed the initial steps to safeguarding my pc. I have run all of the programs, plus a few others have already downloaded (ewido, spydoctor etc..) and i have my logs which i will post now. However, i restarted in normal mode, ran spybot, nortons, ewido, spydoctor, ad-aware, registry doctor and theyre all still there. i have a program instantly giving me net cookies to advertisments etc.. and magic.controlagent is still there.

    Can you see anything in the logs?

    Once again, many thanks

    Dave. :cool:
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach the VundoFix log!

    If Ewido and Spyware Doctor are only trial versions, uninstall both of them. Is there a reason you did not use Windows Defender as requested in the READ ME?

    Now download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    You also need to run the below procedure:

    SpywareQuake Removal Procedure

    Then attach the requested smitfiles.txt log.
     
    Last edited: May 8, 2006
  5. Internationaldave

    Internationaldave Private E-2

    My apologies for being so stupid! I fell for the old advertising trick when trying to download windows defender and installed registry doctor instead! Please forgive my momentary lapse of concentration!

    I have now downloaded and run windows defender, it came up with nothing. I forgot to mention that vundofix also came up with nothing, i have posted the log with this msg.

    I have run through these instructions, it found no trace of spyfalcon or spyaxe etc... I have uninstalled ewido and spyware doctor too.

    I have run spybot to check for magic.controlagent. It is now gone, however the cookies still come back and now a thing called active.desktop is appearing, adding registry keys to HKEY users.

    Dave. :cool:

    P.s I hope you get paid for doing this stuff, your advice is amazing!! :)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not really true. In your smitfiles log the below info are all signs of the infection that was fixed by the procedure:
    Cookies will always be on your PC anytime you surf. They are not really problems and are always simple enough to remove if desired. Cookies can even be very useful to you.

    Specifically which registry keys are you referring too? It may be that you still have some lingering effects from the SmitFraud infection that we need to address.

    No I do not get paid!

    Let's finish some additional cleanup and then see where thins stand.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [ijpxbeo] c:\windows\system32\ijpxbeo.exe ijpxbeo

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (note many of these may already be gone from the previous steps):
    c:\program files\eMedia Codec <--- the whole folder
    c:\windows\system32\1024 <--- the whole folder
    c:\windows\system32\cache32dsrf4535dfs <--- the whole folder or file whatever it is.
    c:\windows\system32\ijpxbeo.exe
    c:\windows\system32\ot.ico
    c:\windows\deskbar.ini
    c:\windows\inst <--- the whole folder or file whatever it is.
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now. If you still have some problems with your Desktop being hijacked, run only step number 8 in the below link:

    SpySheriff (aka SpywareNo) Removal
    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  7. Internationaldave

    Internationaldave Private E-2

    Thankyou Mr pc wizzard (note the Terry Pratchet reference!) The registry keys have been fixed, i seem to have gotten rid of the pop-ups and random cookies sent to my pc.

    I found no trace of 1024 folder, ot.ico or ts.ico, and ijpxbeo.exe seems to have gone after ccleaners efforts in safe mode.

    I have full control again over everything apart from my @key, i still have to press shift 2, which should be ". But oh well, if thats all i have to complain about in life, i need to get out more!

    HJT log posted with this message as requested.

    Am i clean now?

    Dave.

    p.s, I hope i have not insulted you by commenting on whether you got paid, i am not prying, i just think your work and advice is fab. Apologies if i did.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you mean. Did you write something incorrectly. Pressing Shift 2 is always what you need to do to get to the @ key so I see nothing wrong with this.

    No I was not insulted, I appreciate the compliment.


    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  9. Internationaldave

    Internationaldave Private E-2

    I bet you're in the States aren't you? I'm in Britain, and on my keyboard shift 2 should make the " sign, and shift ' should make the @, so i'm guessing it's just altered the configuration to the US version. I'll look into changing that.

    I thought all was well, but magic.controlagent is back this morning. I now have a feeling it has something to do with Limewire. I use it to download mp3's, and i hadn't used it until last night. I'll run the steps again, i still have all the notes on this thread. I'll give you a shout if i still need help.

    Once again, thanks a million buddy, you're the best!

    Dave. :)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! I forgot about the fact that keyboards here are different! ;)

    Magic Control Agent will not normally be removed by the READ & RUN ME steps or any scanning programs. It typically requires some special tricks to remove. This is because it hides (referred to as stealth) at least one process that will not even show on HJT unless a special method of running HJT is used. And even then it will not always show. I will give you something to run below but first a question. Is it being detected by Spybot? What exactly is it reporting?

    Download & run Blacklight Beta
    • Hit I accept. It will take you to download page.
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the Blacklight log file here.
     
  11. Internationaldave

    Internationaldave Private E-2

    Ok, this is weird. I have done nothing other than your steps, and it did not find nor remove anything. I did not remove the registry keys when spybot picked it up, (oh yes, spybot found it everytime i ran it, other than the first scan after the 'read me' instructions.) The second scan found it, but it has gone now. I had some residual files from emediacodec in the registry but ihave deleted them and they seem to stay gone. I cannot tell you now what it was finding, i think it was something like HKEY_Local machine_software_lanconfig_mc. I am not sure now of the exact route, but i know for sure that it was 'LANCONFIG' and 'LANCONFIG_MC' that it was finding.

    I have run blacklight, and i will attach the log. Weird eh!

    Davey. :D
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The LanConfig key is one of the typical registry keys found with MagicControl Agent.
    BlackLight did not show any hidden processes so if Spybot is still clean, I would not worry about it.

    Just make sure you complete the How to protect thread steps.
     
  13. Internationaldave

    Internationaldave Private E-2

    Thanks chaslang, my system has been given new life thanks to you. Peace out Mr Wizzard.

    Davey. :)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds