Working through R+RMF guide prob with spybot administrator rights

Discussion in 'Malware Help (A Specialist Will Reply)' started by fluff29, Apr 6, 2008.

  1. fluff29

    fluff29 Private E-2

    Hi there


    I working through the guide to remove malware. I previously installed spybot yesterday before I found this forum. I have installed the teatimer and I cannot get it off. I have followed the MG's instructions and tried to run spybot from the start menu as administrator but it isn't working. Would anyone know how I can bypass this and switch off the teatimer?
    Many thanks

    Fluff
     
  2. fluff29

    fluff29 Private E-2

    Sorry but I have another problem.

    Trying to install MGtools.exe to the C drive but it keeps saying that I do not have administrator authority to save to this drive and I can only save to jduff. I am logged in as administrator. Does anyone have any clues on what I am doing wrong?

    Many thanks
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You should always add to your first message which Windows version you are using. I would assume it is Vista.

    The READ ME gave you a link to installing and running Spybot and in this procedure the following was included: How to disable Spybot's TeaTimer If your problem is that you just cannot run Spybot, then uninstall Spybot from Control Panel and leave it uninstalled for now until we have a better understanding of what your real problems are.


    Assuming you have Windows Vista, have you disabled UAC as requested? If you cannot get MGtools.exe saved to C:\ then save it to your Desktop and run it from there.

    For what reason are you running the READ ME?
     
    Last edited: Apr 9, 2008
  4. fluff29

    fluff29 Private E-2

    Hi there

    I have now completed what I can. I was receiving TrojanDownloader.xs, antispyware-reviews.biz, abebot threat and wml.exe threats. Slowing my laptop down and I am not sure if they are spying or destroying things. These are all exactly the same format as what everyone else has been receiving (looked at other posts but everyone seems to be slightly different). I am running vista home premium.

    I couldn't find quarantine files or a recycle bin in Norton 360. Also, I did not know how to disable Norton before running combofix.

    I uninstalled spybot, as I had teatimer installed (did this before I found this forum). When I ran spybot a few days ago, it found 15 tracking cookies.

    I had to save MGtools to my desktop, as PC was saying that I didn't have administrators rights, even though I am logged in as adminisatrator.

    I have attached superantispyware log, malwarebytes log and MGlogs.zip.

    I would be grateful if someone could interpret these and provide some advice. I am not used to doing this type of thing and I apologise if I have missed anything out or done something wrong.

    Thanks
    Fluff
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have any idea what the heck the below is? Is it really something for Dell? It looks more like malware than your malware!

    O4 - HKLM\..\Run: [Unattend0000000001{EFB9856D-F923-4656-93CB-7493BB7D0A5A}] c:\dell\cfi\RunGo.lnk

    Is there a reason that you did not attach the ComboFix log? Did it not run properly for you?


    Uninstall the below software:
    Java(TM) SE Runtime Environment 6
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKCU\..\Run: [eHyLIaJ92u] C:\ProgramData\khwnklmp\ghmzcjap.exe
    O4 - HKLM\..\Policies\Explorer\Run: [eHyLIaJ92u] C:\ProgramData\khwnklmp\ghmzcjap.exe

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Users\jduff\AppData\Local\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. fluff29

    fluff29 Private E-2

    Hi there

    Good news is that since I posted my logs yesterday, I haven't had any of the malware pop ups that I have been receiving. Had a couple of problems with what you gave me to work through.

    1. I don't know what the dell line is for that was in your last post. Should it be deleted through HJT?

    2. Combofix wouldn't run. A blue box with white writing appeared and said "The system cannot ...." this is all that I caught before it disappeared.

    3. Sorry but after I deleted the old java and the viewer, I installed the new java. Does this make a mess of things that you are doing?

    4. I ran HJT. I checked both lines and deleted them (at the same time). When I went back in to check that they were gone , the 1st line had gone but a noticed a line similar to the 2nd line ie you had eHyLla92u and when I looked after the deletion, there was a line exactly the same but with
    eHyLIa92u. The only difference being an l in your line and a capital I in the other line. Does this relate to point 5 below? Have I deleted the wrong line or is this another line which is similar?

    5. When I tried to input the input script in Avenger, it came up with the following message:

    Error: Invalid Syntax in command

    "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ eHyLIaJ92HKEY_LOCAL_MACHNE\Software\Microsoft\Windows\ Current\Version\Policies\ Explorer\Run\eHyLIaJ92u"

    Skipping Line (Registry value deletion mode)

    6. When I ran superantispyware (whilst following the read me first report) I didn't perform "broken network connection (winsock LSP chain)" as it had XP next to it and I am running vista. Have it interpreted this correct or should I have repaired this?

    Look forward to hearing from you and my apologies if I have done something wrong (this is the first time that I have done this - only had laptop 3 months).

    Thank you.

    Fluff
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!


    Not a problem this time, but in the future please always do the steps as written. There is a method to the madness.;) And sometimes it can be critical to do only what is requested and exactly when requested.

    You need to attacht the follow up logs that were requested so that we can continue. Also remember to tell me how things are currently working.
     
  8. fluff29

    fluff29 Private E-2

    Hi there

    I have deleted the dell file.

    Avenger didn't work and I have attached the text file.

    Temp files deleted.

    CCleaner run successfully.

    MGTools and avenger logs attached

    I had enabled UAC to protect my laptop and I didn't disable it before I ran the MGtools Getlog the 1st time tonight. I disabled it again and when I ran it the 2nd time the following message appeared. Is this related to the message? I have left UAC disabled at the moment while we work on this. Is it safe to do so?

    Message when I ran MGTools as follows:-

    Cannot export c:\MGTools\temp\xlmsysccsa.txt. Error opening the file. There may be a disk or file system error.


    I have not had any of the pop ups for the abebot threat, spyware.biz, etc since I ran the malware removal read me file:). My laptop is back to normal speed. Everything appears normal apart from the following:

    NB:

    However, my desktop changed to a black background after I ran MGtools the first time on 8 April and now I can only change it to solid colours. I can't add any wallpaper or pictures from the control panel. Is this related to this problem?

    Also just had a warning from Norton that I need to do a manual fix for tracking cookies but it doesn't tell me what to do. The details that were given are as follows:-

    cookie:jduff@server.lon.liveperson.net/hc/7801161
    cookie:jduff@server.lon.liveperson.net/

    Do I need to do anything about this?

    Thank you again for all your help. I will be away now until sunday. I will work through your instructions, if you have got back to me then.

    Thanks
    Fluff
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about this! Somehow I missed your last post and you slipped off my radar. We still have some things to fix especially since the Avenger fix did not work.

    It appears that GetRunKey did not run properly for some reason in this last log.



    I'm not sure what this is related to. It seems to be unique to Vista. I'll have to ask for opinions on this one. Normal fixes used for Win XP do not apply to Vista for this issue.

    Cookies are not problems. Don't worry about them.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [Unattend0000000001{EFB9856D-F923-4656-93CB-7493BB7D0A5A}] c:\dell\cfi\RunGo.lnk
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Policies\Explorer\Run: [eHyLIaJ92u] C:\ProgramData\khwnklmp\ghmzcjap.exe


    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. fluff29

    fluff29 Private E-2

    Hi there

    I have ran everything that you asked.

    I have attached the two reports.

    **I received a successful message which said that the keys and values have been successfully added to the registry.**

    Everything is running well at the moment with none of the bad pop ups. Only thing that I get is warnings from norton for manual fixes for tracking cookies.

    Thank you for your time - I really appreciate it.

    Fluff
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cookies are not problems! Just disable this if Norton allows you to. You will learn more about cookies in the link in my final instructions below.


    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    5. If we had you run Avenger, you can delete all files related to Avenger now.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  12. fluff29

    fluff29 Private E-2

    Hi there

    1. Have done what you said but I did not do point 9 on your list as I have windows vista not windows XP or XE. Should I be disabling system restore and rebooting??

    2. Bit of a panic as I have noticed that some of the files that I thought that were a bit dodgy at the start of the infection are still there (or have reappeared). Could you look at the file names and see if you thing they are dodgy? They were all created on 25/3/08 at 1026am . This is the time when I think this all first happened with the malware appearing after this date.

    All created under users/jduff

    Desktopblackbird.jpg
    DesktopEditorFKWP1.5.exe
    DesktopEditorFKWP2.0.exe
    Desktopfilemanagerclient.exe
    Desktopfkwpl1.5.exe
    Desktopfkwpl2.0.exe
    Desktopfwebd.exe
    DesktopFWebdEditor.exe
    DesktopTrojan.Win32.Blackbird.exe

    3. Should I hide hidden files again?

    4. I can now change my desktop background again. Great :D

    5. Should I delete the following:-
    - Superantispyware and malwarebytes? Do I just right click on them in program files to delete them?

    6. In program dats, there are the following files:-

    - McAffee (think I uninstalled this - can I delete this?)
    - Malwarebytes (will this disappear when program deleted?)
    - Spybot search and destroy (previously uninstalled - should I delete this?)
    - SuperAntispyware.com (will this be deleted when I delete superantispyware?)

    7. What is better windows defender or spyware doctor? I will run it along with Norton 360.

    Thanks again. You have done a great job. I could never have done this - brilliant.

    Fluff
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes Vista does have a system restore that needs to be toggle, but let's wait since it sounds like you may have been reinfected.

    If these files are in C:\Users\jduff then you should delete them. And then empty your Recycle Bin or run CCleaner. Let me know if you cannot delete them.

    Uninstalling ComboFix automatically does this but it is not necessary. Many people don't like anything to be hidden (me included). If you allow files to be hidden, you also allow malware to hide from your view. ;)

    Not delete..... uninstall! However I suggest you re-run a scan now with both of them and attach new logs. Just a safety precaution.

    For any programs that are no longer installed, you can remove left over folders. Note we did not uninstall Malwarebytes or SUPERAntispyware yet! ;)

    Spyware Doctor but only if it is a paid version. Is it paid? If you do keep Spyware Doctor (paid version) you need to disable Windows Defender to avoid conflicts and resource hogging.
     
  14. fluff29

    fluff29 Private E-2

    Hi there

    I am justing giving you an update from work just incase my laptop is having problems tonight. I deleted the dodgy files, ran CC and in the middle of running superantispyware.

    However, when I ran SAS the last time, it only ran for 5 1/2 hours. When I left for work this morning it was at 12 1/2 hours. Do you think it is ok? Will see when I go home tonight if it is still running. What is the maximum time I should let it run for?

    It has picked up a threat in registry called trojan.DNSchanger-codec. Don't think I had this before.

    If SAS is finished when I get home, I'll run the other log and post them for you to look at.

    Thanks

    Fluff
     
  15. fluff29

    fluff29 Private E-2

    I deleted the dodgy looking files with no probs.

    The superantispyware program was still running when I got in from work. I terminated it as it said that it was checking 2 million files on my laptop. I have very little on my laptop I use it mainly for surfing the net. It checked alot less files the last time I ran the scan. It spends alot of time scanning driverstore/filerepository. Not sure if this is relevant and helpful too you.

    I have attached the log from SAS that never finished and I have also ran malwarebytes and have attached the log.

    I right clicked the registry patch (fixme.reg) that you got me to do previously and deleted it. It has not deleted though - should I try again.

    Hopefully thinks aren't as bad as what they look.

    ps Just looked and seen that my windows firewall is on and I think that I will also have a firewall with Norton 360. Should I disable the window firewall? And how should I do it?
     
    Last edited: Apr 24, 2008
  16. fluff29

    fluff29 Private E-2

    Just logged in at work and noticed that the logs didn't attach. Was having difficulty last night getting them to attach and when I tried to reattach it said that it was in the process of attaching. I will re-attach tonight.

    SAS found a trojan.DNSchanger-codec - I haven't been able to do the full scan and therefore haven't deleted it yet.

    My laptop was supplied with McAfee originally preloaded. I thought that windows firewall would have been disconnected before I got it, but it wasn't. I have now disabled windows and kept the norton firewall.

    Cheers
    Fluff
     
  17. fluff29

    fluff29 Private E-2

    Hope logs attach now.

    Fluff
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like SUPERAntispyware got itself confused and could not proper finish. It may be a good idea to run it again in safe boot mode.

    Yes! There should be no reason why you cannot delete this file.

    Norton should have automatically disabled the Windows Firewall. Yes the Windows Firewall should be disable but make sure that your Norton firewall is enable afterwards or you will get messages from Windows Security Center about not having a firewall.


    Are you still having any malware problems?
     
  19. fluff29

    fluff29 Private E-2

    HI

    I have ran superantispyware in safe mode and attached the log.

    I ran malbytes and attached log.

    I managed to delete the fixreg file.

    I then ran ccleaner after deleting the file.

    Had a look in:-

    Jduff/roaming/microsoft/cookies/low/index.dat
    Jduff/roaming/microsoft/cookies/index.dat
    Jduff/roaming/microsoft/cookies/jduff@quantserve[2].txt

    Are the above ok? Getting a bit paranoid now about anything unusual.

    Can I install firefox just now or should I wait until you have finished? I am having to use internet explorer at the moment and thought it might help.


    Look forward to hearing from you.

    Fluff
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cookies are not problems. See the How to protect yourself link I gave you awhile ago.

    Yes! We are finished. SAS and MBAM only found and removed some minor things so you can uninstall them now if you wish.
     
  21. fluff29

    fluff29 Private E-2

    I have uninstalled SAS and malabytes. Have installed firefox.

    Last question - going back to point 9 above, should I be creating a restore point and how should I do it on vista?

    Also, should I be doing a backup of my registry and how do I do it?

    Thank you very much again for all your help. You do a great job and I really appreciate it. Has opened my eyes and I am already making the changes to protect my laptop,
    Fluff
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is what step 9 has explained.

    System Restore does back up the registry but restore points are not maintained longer than 90 days. So it is up to you if you wish to back up the registry yourself. There are many programs listed in the below that can do this:

    http://www.majorgeeks.com/downloads15.html


    Many people have a false sense of security thinking that having a registry backup is going to save them from major catastrophies. If your PC becomes unbootable, a registry back from a third part program will not do you much good if you cannot boot your PC to run the program. However the backups made by System Restore can be used but it is a little complicated. A procedure like below is required:

    http://support.microsoft.com/default.aspx?scid=kb;en-us;307545&sd=tech

    I personally like the above procedure and combine it with using the below tool which makes it very easy to do since you can reduce the number of steps and directly copy registry hives from restore points to the required folders:

    UBCD4Win

    All of this can be rather complicated and overwhelming unless you are fairly competent with Windows.


    Note: you can even run System Restore by booting to safe mode with command prompt:

    http://support.microsoft.com/?kbid=304449


    If you wish to know more about System Restore better, see the below. Even though these are for XP, the concepts still apply.:

    http://www.microsoft.com/windowsxp/using/helpandsupport/getstarted/ballew_03may19.mspx
    http://technet.microsoft.com/en-us/windowsxp/bb264753.aspx
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds