Winfixer, Yield Manager...and who knows what else.

Discussion in 'Malware Help (A Specialist Will Reply)' started by piedle, Nov 20, 2005.

  1. piedle

    piedle Private E-2

    Hello out there,

    I have reached boiling point with the spyware/adware currently on my hard-drive. I'm relatively new to the whole thing so please bear with me.

    I've followed the instructions indicated at the top of this forum, and although the various spyware removal programs have cleaned various infections and threats, I'm still presented with various popups when I connect to the internet. It also re-directs my browser on occasion.

    As far as I know I have taken all the necessary steps and soon I will cry over my keyboard.

    Attached is my HJT log. If anyone can help, it would be greatly appreciated.

    piedle.
     

    Attached Files:

  2. piedle

    piedle Private E-2

    have i done something wrong with my post? No replies! If i have can someone let me know :)
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Give this a run: Running Spy Sweeper...

    Make sure you attach the Spy Sweeper log when finished and also attach a new HJT log too.
    It will take quite awhile for the Spy Sweeper scan to run. It is very intensive and should resolve your Look2Me problems.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also note: Your OS and IE version are seriously out of date and represent a major security risk. After we fix your current problems, you MUST get updated. You multiple issues to fix still.
     
  5. piedle

    piedle Private E-2

    Thanks so much for the reply.

    I use Mozilla Firefox, which is why my IE is out of date.
    In terms of OS... I was told by a freind who claims to know what hes talking about that windows Service Pack 2 causes more problem than help?

    Just ran spysweeper and updated definitions. Ran the sweep. Stayed connected to the internet and it froze up after about five minutes, which it seems to do. Am currently using my sisters ibook to post this... is it necessary I stay connected while I sweep?

    Thankyou so much for your help!
     
  6. piedle

    piedle Private E-2

    Okay so now spysweeper freezes my whole computer irrespective of whether im connected or not.

    Should I run sweeper in safe mode?

    Sorry to keep bothering!
     
  7. piedle

    piedle Private E-2

    I'll make sure I definitely update my service pack and IE. Sorry for my lack of knowledge :)
     
  8. piedle

    piedle Private E-2

    Here is the error log from Spy Sweeper. Everytime I sweep, it freezes up and I have no choice but to restart.
    When I do so, I am given this error log.

    Thanks,

    piedle.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still need IE to get MS updates and some other websites require it too. You must update. Your friend is wrong about SP2! You just must not install it while malware is present. You need your updates.

    Disconnect (unplug the cable) from the internet and run SpySweeper. If that does not help then run Spy Sweeper after booting in safe mode.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not a log from a Spy Sweeper scan. See message number 13 in this thread for and example of what it looks like: http://forums.majorgeeks.com/showthread.php?t=77858
     
  11. piedle

    piedle Private E-2

    Hey,

    Unfortunately I cannot get a log file because sweeper keeps freezing up at a certain point.
    when I try to run sweeper in safe mode it tells me that there is an authentication failure, and tells me to reinstall.
    I do that, and then get the same error message.

    I can't win!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try to fix a few things manually. First run msconfig and select normal startup (as the procedure for running HijackThis requests). We need to see all items on your PC.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Windows Update Service (or if not found look for wuamgrd) ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Windows Update Service

    If that does not work try entering the short name: wuamgrd

    Now exit HJT but do not reboot if told it need to do so. We will do that later after restarting HJT to fix other problems.


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    O4 - HKLM\..\Run: [www.hidro.4t.com ] enbiei.exe
    O4 - HKLM\..\Run: [scvhost.exe] scvhost.exe
    O4 - HKLM\..\RunServices: [scvhost.exe] scvhost.exe
    O4 - HKCU\..\Run: [klop] C:\WINDOWS\50.tmp
    O20 - Winlogon Notify: msupdate - msupdate32.dll (file missing)
    O20 - Winlogon Notify: ShellServiceObjectDelayLoad - C:\WINDOWS\system32\p04ulah91d4.dll
    O21 - SSODL: SysTray.Exys - {7368D5FC-6F5C-4f5b-B964-E67214F67852} - C:\WINDOWS\System32\dghlgcha.dll (file missing)
    O21 - SSODL: SysTray.Excn2 - {1722ECFF-4356-4f5b-B534-E67294FE75E9} - (no file)
    O21 - SSODL: SysTray.Exmr - {73F8D5FF-6F5C-4f5b-B964-E6F214F6F852} - C:\WINDOWS\System32\gfmanpmk.dll (file missing)
    O21 - SSODL: BIIHBCBA - {21747355-5137-5A30-3FD6-13DE34C83737} - C:\WINDOWS\System32\Bdhqjd32.dll (file missing)
    O23 - Service: Windows Update Service (wuamgrd) - Unknown owner - C:\WINDOWS\System32\wuamgrd.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\system32\p04ulah91d4.dll
    C:\WINDOWS\system32\enbiei.exe
    C:\WINDOWS\system32\scvhost.exe <--- Be very careful. This is scvhost.exe not svchost.exe. DO NOT DELETE svchost.exe
    C:\WINDOWS\50.tmp

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now try to run SpySweeper and save the log if it runs and post it later when you come back.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  13. piedle

    piedle Private E-2

    Wow thanks for all that.
    Funnily enough I have just got the scan working in safe mode. I reinstalled Sweeper for the fourth time and it started to work.

    Do you recommend I stop the sweep and follow all the instructions you just posted? or leave the scan going?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you download SpySweeper from the link I gave you? Or did you get it from somewhere else??
     
  15. piedle

    piedle Private E-2

    definitely from where you told me to download it from.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you already have it running, let it finish. Then work thru the procedure I gave you below anyway. Some items may be gone due to SpySweeper so just ignore them if you do not see them and continue. Afterwards post the spysweeper and new HJT logs.
     
  17. piedle

    piedle Private E-2

    ok. will keep you posted. (hehe)
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! In addition to posting the two logs, don't forget to tell me how things are working.
     
  19. piedle

    piedle Private E-2

    after running it in safe mode, it fixed a whole heap of threats but there was a potential memory root infection which when it tried to clean it froze up 3 times in a row. So i couldnt get a log.

    I'm going to get my wisdom teeth out today! so I'll return to this tonight or tomorrow...depending on how much the general anaesthetic slows me down.

    Hope that when i return you can help me solve this!

    thanks mate
    piedle
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just do what I gave you in message # 12.
     
  21. piedle

    piedle Private E-2

    none of the files in mesasge 12 exist in my windows/system folder. system32 only exists in windows/lastgood/system32 ...but unfortunately none of the files you specified in #12 exist for me to delete.
    Unless im doing something wrong?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not ask you to look in the system folder. I said the c:\window\system32 folder.
    It is impossible to not have a system32 folder. Without it, your PC would not boot.
    You must not have done step 2 of the READ & RUN ME.
     
  23. piedle

    piedle Private E-2

    As I said. There is not one folder in the windows directory named system32. Only System.
    I completed a search for the location of the system32 folder, and could only find it in c:\windows\LastGood

    And those files you recommended to delete are not there.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not true! Take a look at your HijackThis log and where all the files for your Windows OS are running from. For example:

    I did not say search, I said use Windows Explorer to look for the files. That means manully navigate to the folders. Windows Search will not look in the system32 folder unless you setup the options in Windows Search to look in hidden and system folders.
     
  25. piedle

    piedle Private E-2

    the only reason i searched is because I couldnt find it in explorer.
    Will get back to you.
    Thanks mate
     
  26. piedle

    piedle Private E-2

    Hey

    Even though the hijack this log says that a directory of that name exists...ive granted access to hidden files and folders...and it just doesnt exist in the C:\windows directory...

    I'm confused
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the attached ZIP file and extract the getWfiles.bat file from it to C:\

    Then double click on the .bat file. It will create a file named c:\wfile-list.txt
    Put this new file into a ZIP file (hope you know how to do that) and upload it back here as an attachment.

    Attached Fileshttp://forums.majorgeeks.com/images/attach/zip.gifgetWfiles.zip (324 Bytes)


    Also download the below getsys32.zip file and extract it someplace you can locate it. Then use windows explorer to locate the getsys32.bat and double click on it to run the bat file. This will create a file named c:\sys32hs.txt
    Also put this file into a ZIP file (it will be too big to post otherwise). Attached the ZIP file to your next message.

    Attached Fileshttp://forums.majorgeeks.com/images/attach/zip.gifgetsys32.zip (296 Bytes)
     
  28. piedle

    piedle Private E-2

    Hey there chaslang

    Here is one of the two zip files you asked for. There was not enough room for the wfiles.zip to be attached but i assume i could do it with a new post.

    piedle
     

    Attached Files:

  29. piedle

    piedle Private E-2

    hmm.my wfiles txt, zipped up..its too large to be posted.

    any suggestions?
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Split the file in half and zip each half.

    By the way, as I said before. The c:\windows\system32 folder does exist. The short log from the command I had you run, even shows one baddie you must delete:
    c:\windows\system32\hr4o05h3e.dll which does show. It is left over from the Look2Me infection.

    I'm not sure what it is that you are doing or not doing but what I just had you run does not lie. The folder is there.

    I'm going to make a modification to the getsys32.bat file to also have it scan for all files/folders. Currently it only look for hiddden & system files which is what hr4o05h3e.dll is. If you cannot see it, then viewing of hidden, system files, and file extensions is not enabled.
     
  31. piedle

    piedle Private E-2

    Okay this is really starting to freak me out. I am definitely not savvy on the spyware front, but I know how to explore folders and I promise you there is not a folder named system32 in the windows directory. one does exist in windows/lastgood and windows/lastgood.tmp but not in the root windows directory.

    Im pretty sure i have hidden folder viewing enabled, I did so in advanced folder options, and as all of the semi-transperent folders are showing now. Which i assume are the hidden files and folders.

    I cannot find that file that you sent in your previous post. the leftover from look2me. when i couldnt find it while exploring. i did a search for it and the computer did not find it either.

    Could these virus' have penetrated the computer so extensively that it's wrong about the system32 folder? or that it's made it impossible to find?

    This is crazy

    piedle
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The folder is there! Look at the log you posted. The files and folders in that log are from the c:\windows\system32 folder.

    In order to use Windows Search, it must be configured properly or is will not search for hidden files or in system folders. See how to configure below:

    Searching for Hidden Files on WinXP


    Also try downloading and installing the below and use it to look for files and folders. It os much more powerful than Windows Explorer.

    ExplorerXP
     
  33. piedle

    piedle Private E-2

    yep I'm aware you have to go into more advanced options and select hidden folders. Still come up empty handed.

    And yes I am aware it shows up in the log. But it is just non-existant in c:\WINDOWS. You have to believe me, it's not there!
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It shows from DOS which means it is there. Run ExplorerXP and look for it.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also run regedit and navigate to the below registry key and make sure the value for the SuperHidden attribute is set to 1

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One other thing you could try that may help:

    Open command prompt and type: attrib -a -h -r -s c:\windows\system32

    Note the spacing (no space after the minus signs)
    Let me know if you see it now.
     
  37. piedle

    piedle Private E-2

    yep i definitely see system32 in ExplorerXP
    weird.
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now you see why I kept insisting it was there. Even without all this searching I know it has to be there because as stated before, without that folder your PC would not even boot.

    Use ExploreXP to delete that file I mentioned in message # 30. Also go all the way back to message number 12 and look for those items too and delete if found. Also do what I said in message # 36 and see if the folder becomes visible in Windows Explorer.
     
  39. piedle

    piedle Private E-2

    deleted the baddie from msg thirty. All good.

    None of the other files you said to delete in msg 12 existed.

    And yep, now the folder is showing in windows explorer. Why would it have not been there?

    Do you know of any other programs that can help me get better control of these this computer? That ExplorerXP thing is great. So much easier to navigate.

    Okay...so I'm pretty sure i've finally done what you have said up to this point. What next?

    Is this what you do for a living? How do you get finances when I'm getting this advice for free? thanks so much man.

    And you're in jersey, home of one of my fave TV shows. I dont believe i even have to say it's title. :)
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Something had changed the folder attributes to be totally hidden.

    What kind of programs is it that you are looking for?

    Post a current HJT log! How are things running?

    You're welcome! No I do not do this for a living? But I should! There is no shortage of work.

    Yeah! But that's just a TV show!
     
  41. piedle

    piedle Private E-2

    Here is my hijack this log
     

    Attached Files:

  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  43. piedle

    piedle Private E-2

    thankyou so much my friend. What do you think gave me this virus in the first place? i do a bit of torrent downloading...could that be the cause?

    thanks again.
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    P2P sites are notorious spreaders of malware problems so it's possible.
     
  45. piedle

    piedle Private E-2

    hmm...it seems when i try and install microsoft updates, it startes for a few minutes but then reboots my computer without downloading the update.
    Then tells me :The system has recovered from a serious error.
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is an issue for the Software Forum. But answer these:

    1) Is your copy of WinXP legitimate and own by you? Was it activated with Microsoft?
    2) Did you go thru the Windows Genuine Validation phase on the download site? With out getting this validation you cannot download. Exactly how far did you get?
     
  47. piedle

    piedle Private E-2

    Okay so now ive reached the point where SP2 installs about halfway then says

    "Windows Service pack cannot install.

    The Product key to install Microsoft Windows may not be valid. For more information about why you have received this error message, and steps you can take to resplve this issue visit www.howtotell.com"
     
  48. piedle

    piedle Private E-2

    Hmm...so if one were to have not purchased it, would one not be able to be granted to service pack 2?
    hypothetically speaking.
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Correct and also no other downloads/updates from Microsoft Update either. Like Windows Media Player, DirectX, Internet Explorer etc.
     
  50. piedle

    piedle Private E-2

    is there an alternative free OS?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds