Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Need some help with a massive malware/spyware infection
   
BullGuard Antivirus Forum > General Security > Spyware > Need some help with a massive malware/spyware infection  
Forum Quick Jump
 
New Topic Post reply to : Need some help with a massive malware/spyware infection Printable version of : Need some help with a massive malware/spyware infection
[ << Previous Thread | Next Thread >> ]

Kerrath
New Member


Date Joined Dec 2005
Total Posts : 5
 
   Posted 12-24-2005 6:22 (GMT +2)    Quote: Need some help with a massive malware/spyware infectionAlert an admin about: Need some help with a massive malware/spyware infection
Recently I got a virus, or several, which downloaded a multitude of others to my PC. I got rid of most, but a few remained. One particular one I found was SpySheriff, which I for the most part got rid of, however, some remnant of the original ware was left and repopulated my computer with itself. I attempted to follow some other instructions involving the editing of the win.ini file, but it seems to have been hijacked by some german virus that tells me it is currently in use. Also, I have the TIBS dialer virus, but cannot delete it as it is consistently active. (Luckily it can't hurt me because I am on DSL) There is also a virus called WinSync which runs off of a non-existent program called yoyqrc.exe, with no internet references available.

After all the meddling I have already done in regedit, I don't want to fumble blindly any more for fear it will collapse the pile of registry entries.

Currently, my IE page is hijacked to "About:Blank". (But I don't use IE so it almost escaped my notice.)

Here is my HijackThis log:
(I had three errors when it scanned.)

Logfile of HijackThis v1.99.1
Scan saved at 8:14:16 PM, on 12/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SSA\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Documents and Settings\Craig\Palm Desktop\HOTSYNC.EXE
C:\Documents and Settings\Craig\My Documents\Craig\palm\CardExport\CardGate.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SpyRemover\Remover.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Craig\AIM\aim.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Craig\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
F2 - REG:system.ini: Shell=
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: WebFerret - {A58686ED-FC46-44C3-95C6-4A812AB776F1} - C:\Program Files\FerretSoft\WebFerret\FerretBand.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SSA\smc.exe -startgui
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\yoyqrc.exe reg_run
O4 - Startup: HotSync Manager.lnk = C:\Documents and Settings\Craig\Palm Desktop\HOTSYNC.EXE
O4 - Startup: Shortcut to CardGate.exe.lnk = C:\Documents and Settings\Craig\My Documents\Craig\palm\CardExport\CardGate.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\Craig\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1118340227065
O20 - Winlogon Notify: msctl32.dll - C:\WINDOWS\system32\msctl32.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe
O23 - Service: COM+ System Application (COMSysApp) - Unknown owner - C:\WINDOWS\System32\dllhost.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Distributed Transaction Coordinator (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Sygate Security Agent (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SSA\smc.exe
O23 - Service: MS Software Shadow Copy Provider (SwPrv) - Unknown owner - C:\WINDOWS\System32\dllhost.exe

I'd appreciate the help, and also, I was wondering if the large quanitity of svchost processes was related to it. Thanks! (Ran Spyremover fully updated, AdAware updated, and Norton updated, none could take care of these compeletely)
Back to Top
 

rpggamergirl
Forum Moderator




Date Joined Dec 2005
Total Posts : 1530
 
   Posted 12-24-2005 12:55 (GMT +2)    Quote: Need some help with a massive malware/spyware infectionAlert an admin about: Need some help with a massive malware/spyware infection
It's quite normal to have a few svchost.exe running, I have 4 right now.
Please let me know if you still have problem with Spysherrif after, so I can give instructions on downloading smitrem.

You have a narrator/qoologic trojan there.

You can either do these:
1. Download and install the free version of Ewido Security Suite.
http://www.ewido.net/en/download/
Update first then scan in safe mode. It is important that you download updates and the scan must be done in Safe Mode or it might missed the narrator/qoologic.
 
Or
2. Download AdwareAway -- 5 day trial only(AdWareAway removes qoologic trojans)
http://www.download.com/Adware-Away/3640-8022_4-10423219.html

Fix these entries in Hijackthis log:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
F2 - REG:system.ini: Shell=
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\yoyqrc.exe reg_run
O20 - Winlogon Notify: msctl32.dll - C:\WINDOWS\system32\msctl32.dll
 
Back to Top
 

Kerrath
New Member


Date Joined Dec 2005
Total Posts : 5
 
   Posted 12-25-2005 5:47 (GMT +2)    Quote: Need some help with a massive malware/spyware infectionAlert an admin about: Need some help with a massive malware/spyware infection
After running the Adware Away remover and removing those regkeys, I still have problems with the TIBS dialer and SpySheriff. Here is the logfile of my last spyremover scan.

--- Report generated: 2005-12-24 19:36 ---

Error during check!: Cabrotor [9] (Datei C:\WINDOWS\win.ini kann nicht geöffnet werden. The process cannot access the file because it is being used by another process) ()

Error during check!: MultiBinder1.2 (Datei C:\WINDOWS\win.ini kann nicht geöffnet werden. The process cannot access the file because it is being used by another process) ()

Error during check!: Redlabel (Datei C:\WINDOWS\system.ini kann nicht geöffnet werden. The process cannot access the file because it is being used by another process) ()

Error during check!: Win32.Optix.C (Datei C:\WINDOWS\win.ini kann nicht geöffnet werden. The process cannot access the file because it is being used by another process) ()

Error during check!: Xuron55 [6] (Datei C:\WINDOWS\win.ini kann nicht geöffnet werden. The process cannot access the file because it is being used by another process) ()

Spy Sheriff: Executable (File, nothing done)
C:\WINDOWS\tool5.exe
Spy Sheriff: Executable (File, nothing done)
C:\WINDOWS\country.exe
TIBS: Executable (File, nothing done)
C:\WINDOWS\ms1.exe

There is that german win.ini and system.ini hijacking I said earlier.

Here is an updated HiJackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 7:40:00 PM, on 12/24/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SSA\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Documents and Settings\Craig\Palm Desktop\HOTSYNC.EXE
C:\Documents and Settings\Craig\My Documents\Craig\palm\CardExport\CardGate.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Craig\Desktop\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: WebFerret - {A58686ED-FC46-44C3-95C6-4A812AB776F1} - C:\Program Files\FerretSoft\WebFerret\FerretBand.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SSA\smc.exe -startgui
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - Startup: HotSync Manager.lnk = C:\Documents and Settings\Craig\Palm Desktop\HOTSYNC.EXE
O4 - Startup: Shortcut to CardGate.exe.lnk = C:\Documents and Settings\Craig\My Documents\Craig\palm\CardExport\CardGate.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\Craig\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1118340227065
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Sygate Security Agent (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SSA\smc.exe

Any more help would be appreciated as well. Thanks.
Back to Top
 

Kerrath
New Member


Date Joined Dec 2005
Total Posts : 5
 
   Posted 12-25-2005 7:25 (GMT +2)    Quote: Need some help with a massive malware/spyware infectionAlert an admin about: Need some help with a massive malware/spyware infection
Sorry, I can't figure out why it made the post bold and huge. :[
Back to Top
 

JA$H Vs. SPYSHERIFF
New Member




Date Joined Dec 2005
Total Posts : 13
 
   Posted 12-27-2005 2:26 (GMT +2)    Quote: Need some help with a massive malware/spyware infectionAlert an admin about: Need some help with a massive malware/spyware infection
THE LOGFILES ARE ALL SAFE, i checked them.

ther's only two unknown logfiles:
C:\Documents and Settings\Craig\My Documents\Craig\palm\CardExport\CardGate.exe Check with an antivirus scanner
O4 - Startup: Shortcut to CardGate.exe.lnk = C:\Documents and Settings\Craig\My Documents\Craig\palm\CardExport\CardGate.exe
nothing to worry about.
Back to Top
 

Kerrath
New Member


Date Joined Dec 2005
Total Posts : 5
 
   Posted 12-27-2005 8:30 (GMT +2)    Quote: Need some help with a massive malware/spyware infectionAlert an admin about: Need some help with a massive malware/spyware infection
I don't know why it doesn't show up in the logfile, but I definately do have the TIBS dialer, because first SpyRemover always finds it but cannot remove it, and second, because I have seen the stupid dial-up window pop up before, and when I tell it to cancel, it says something like "Cannot find www. i-xxx.net". The thing is that it got its file, ms1.exe, to boot no matter hhow I start it. Even in safemode, or if I tell the remover(s) to scan before windows completely starts. Every time it finds TIBS' ms1.exe file and cannot remove it because it is in use by another application.

So mainly, I was wondering if you could direct me to a specific remover for it, like the specific remover for smitfraud which I used. Since it executed in dos, I guess it was able to remove the files without the windows file access denials.

So if anyone knows of a TIBS remover, I'd greatly appreciate it.
Back to Top
 

rpggamergirl
Forum Moderator




Date Joined Dec 2005
Total Posts : 1530
 
   Posted 12-30-2005 1:19 (GMT +2)    Quote: Need some help with a massive malware/spyware infectionAlert an admin about: Need some help with a massive malware/spyware infection
Hi,
Have you tried Smitrem?
When you use Ewido, please download updates and do the scan in Safe Mode please.
You may want to print out or make a copy of these instructions before starting, because you will not be able to connect to the internet during most of this fix.
Download http://noahdfear.geekstogo.com/click%20counter/click.php?id=1
and save the file to your desktop.
Double click on the file to extract it to it's own folder on the desktop.
Please download, install, and update the free version of Ewido Security Suitehttp://www.ewido.net/en/download/
[*]When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
[*]When you run Ewido for the first time, you will get a warning "Database could not be found!".  Click OK.  We will fix this in a moment.
[*]From the main Ewido screen, click on "update" in the left menu, then click the "Start update" button.
[*]After the update finishes, the status bar at the bottom will display "Update successful"
[*]Exit Ewido.  DO NOT run a scan yet.
Next, please reboot your computer in Safe Mode:
Open the "smitRem" folder, then double click the "RunThis.bat" file to start the tool. Follow the prompts on screen.  Your desktop and icons will disappear and then reappear again --- this is normal.
Wait for the tool to complete and Disk Cleanup to finish --- this may take a while; please be patient.
Now open Ewido Security Suite.
[*]Click on Scanner
[*]Click on Complete System Scan and the scan will begin.
[*]Save the report to your desktop
[*]Close Ewido
Next go to Start -> Control Panel, click Display -> Desktop -> Customize Desktop -> Web -> Uncheck "Security Info" if present.


Back to Top
 
New Topic Post reply to : Need some help with a massive malware/spyware infection Printable version of : Need some help with a massive malware/spyware infection
 
Forum Information
Currently it is Tuesday, October 07, 2008 11:04 AM (GMT +2)
There are a total of 62.550 posts in 15.599 threads.
In the last 3 days there were 15 new threads and 52 reply posts. View Active Threads
Who's Online
This forum has 26663 registered members. Please welcome our newest member, Trickydicky61.
37 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Win32:trogan (0)07-10-2008 08:03:02 (Trickydicky61)
Pop Up when the System Starts - Suspecting Win32: Trojan-gen{Other} (5)07-10-2008 05:21:03 (Touch)
DCOM Server Process Launcher error (1)07-10-2008 05:18:01 (Touch)
Qhonsvc error probably caused by quick heal (1)07-10-2008 05:13:48 (Touch)
Qhonsvc error probably caused by quick heal (1)07-10-2008 05:13:00 (Touch)