Half-squashed infection--Need help with sysprotect
I got a big infection today, shame on me. This included Spyware Quake, Smitfraud-C, safety toolbar, and sysprotect. I squashed most of it manually or with Spybot, but Sysprotect remains elusive. Here's my log--it's shorter than I expected it to be. Looks like there's some leftover stuff, too.
Edit: New symptom: Browser rerouts to or a popup appears with the URL
www.worlddatinghere.com.
Logfile of HijackThis v1.99.1
Scan saved at 6:07:51 PM, on 9/6/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
New logfile. The only things I had turned off were Rundll P17, NMBgMonitor, and 827a6046.exe. The 827a file I deleted myself, and I recognized P17 as some spyware-related thing I've seen before, if memory serves.
Logfile of HijackThis v1.99.1
Scan saved at 9:29:50 PM, on 9/6/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Rt click smitfraudfix.exe ->>Extract all the archive content to your desktop Open the Smitfraud folder Double-click smitfraudfix.cmd Select 1 and hit Enter to create a report of the infected files. The report can be found at the root of the system drive, usually at C:\rapport.txt Open that file, Ctrl+A to copy, and post a copy of that log as a reply to this thread
Scan done at 7:54:54.48, Thu 09/07/2006
Run from C:\Documents and Settings\Rick\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
C:\WINDOWS\system32\issearch.exe FOUND !
C:\WINDOWS\system32\ot.ico FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Rick\Application Data
C:\Documents and Settings\Rick\Application Data\Microsoft\Internet Explorer\Quick Launch\SpyQuake2.com 2.3.lnk FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
C:\DOCUME~1\Rick\STARTM~1\SpyQuake2.com 2.3.lnk FOUND !
C:\DOCUME~1\Rick\STARTM~1\Programs\SpyQuake2.com FOUND !
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND !
C:\DOCUME~1\Rick\FAVORI~1\Antivirus Test Online.url FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
You may want to print out these instructions for reference
We need to temporarily disable Spybot SD so it doesn't interfere with our fix
Disable
Spybot S&D "resident tea timer"
1) Run Spybot-S&D 2) Go to the Mode menu, select " Advanced Mode" 3) In the left pane, click Tools ->> Resident 4) Uncheck " Resident TeaTimer" and OK any prompts 5) Reboot your PC
Go
here and Download
Ewido Antimalware 4.0 (
30 day free trial version) Save it to Your Desktop
Double Click
Ewido-setup (It will create its own folder)
Once the program starts You will be at the
Status menu
Under "Your computers Security" Click change status on Resident shield to inactive Click Update now (next to last update) After the update loads Under Automatic updates Uncheck download and install updates automatically(recommended) (you can always select maual updates the next day)
At the top toolbar Click
Scanner Then the
settings tab
Under How to act? Set default action for detected malwareTo Quarantine Under how to scan All boxes should be checked Under Possibly unwanted software All boxes should be checked Under reports Select Automatically generate report after every scan Uncheck Only if threats were found Under what to scan Scan every file should be highlited
Exit Ewido (Do not run it yet)
Next Re Run Hijackthis and place checks beside the following entries
Close all other open windows except Hijackthis and Select "
Fix checked"
Next Using Windows Explorer (Rt Click Start ->>Explore and using the tree of folders on the left)
Locate and delete the following
folder
C:\Program Files\Safety Bar
Locate and delete the following
file
C:\WINDOWS\system32\827a6046.exe
Close Windows Explorer
Reboot your PC into Safe Mode This can be done by
Restart your PC, and after it starts, but before you see the Windows Splash screen Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices) Use your arrow keys and select Safe Mode and then Enter
Next Open the
SmitfraudFix Folder, then double-click
smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter. Wait for the tool to complete and disk cleanup to finish. You will be prompted : " Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter. The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question " Replace infected file ?" by typing Y and hit Enter.
A reboot may be needed to finish the cleaning process, if your computer does not restart automatically please do it yourself manually. Reboot in
Safe Mode.
The tool will create a log named
rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
Next Run Ewido
Click scanner Select Complete system scan
Once the scan finishes
Select Apply all actions (The items found will be quarantined) Click save report as (Another window will open) Save it to your desktop (By default It will be saved in the Ewido folder as) C:\Program Files\ewido anti-spyware 4.0\Reports
Exit Ewido
Reboot your PC in
Normal Mode
Double click the report-scan txt. you saved to your desktop It will open in Notepad Copy and paste that report as a reply to this thread
Do not run any other options untill instructed to do so
Finally Re run Hijackthis and post a fresh hijackthis log
Your reply should include
your rapport.txt from Smitfraud your report_scan.txt from Ewido a fresh Hijackthis log
Scan done at 14:35:12.17, Thu 09/07/2006 Run from C:\Documents and Settings\Rick\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT Fix ran in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll
C:\Documents and Settings\Rick\Local Settings\Temp\Cliprex_WhenUSave_InstallerInst.exe -> Adware.SaveNow : Cleaned with backup (quarantined). E:\DAEMON Tools\SetupDTSB.exe -> Adware.SaveNow : Cleaned with backup (quarantined). C:\Documents and Settings\Rick\Application Data\Microsoft\Internet Explorer\Quick Launch\SpyQuake2.com 2.3.lnk -> Adware.SpywareQuake : Cleaned with backup (quarantined). C:\Documents and Settings\Rick\Start Menu\Programs\SpyQuake2.com -> Adware.SpywareQuake : Cleaned with backup (quarantined). C:\Documents and Settings\Rick\Start Menu\Programs\SpyQuake2.com\SpyQuake2.com 2.3 Website.lnk -> Adware.SpywareQuake : Cleaned with backup (quarantined). C:\Documents and Settings\Rick\Start Menu\Programs\SpyQuake2.com\SpyQuake2.com 2.3.lnk -> Adware.SpywareQuake : Cleaned with backup (quarantined). C:\Documents and Settings\Rick\Start Menu\Programs\SpyQuake2.com\Uninstall SpyQuake2.com 2.3.lnk -> Adware.SpywareQuake : Cleaned with backup (quarantined). C:\Documents and Settings\Rick\Start Menu\SpyQuake2.com 2.3.lnk -> Adware.SpywareQuake : Cleaned with backup (quarantined). C:\Documents and Settings\Rick\Local Settings\Temporary Internet Files\Content.IE5\K9ER4HIR\wlzip32[1].exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc1.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc8.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc12.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc136.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc139.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc151.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc19.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc64.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc26.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc30.txt -> TrackingCookie.Admarketplace : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc33.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc36.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc37.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). C:\Documents and Settings\Rick\Cookies\rick@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc45.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc52.txt -> TrackingCookie.Bfast : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc218.txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc219.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc56.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc58.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc61.txt -> TrackingCookie.Clickbank : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc68.txt -> TrackingCookie.Com : Cleaned with backup (quarantined). C:\Documents and Settings\Rick\Cookies\rick@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). C:\Documents and Settings\Rick\Cookies\rick@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc82.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). C:\Documents and Settings\Rick\Cookies\rick@as-us.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc44.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc131.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc95.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc113.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc87.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc88.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc89.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc90.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). C:\Documents and Settings\Rick\Cookies\rick@linksynergy[1].txt -> TrackingCookie.Linksynergy : Cleaned with backup (quarantined). C:\Documents and Settings\Rick\Cookies\rick@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc132.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). C:\Documents and Settings\Rick\Cookies\rick@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc243.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc179.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc153.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc71.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc35.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). C:\Documents and Settings\Rick\Cookies\rick@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc157.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc181.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc168.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc31.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined). C:\Documents and Settings\Rick\Cookies\rick@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc180.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc189.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc41.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc190.txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc94.txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined). C:\Documents and Settings\Rick\Cookies\rick@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc192.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc193.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). C:\Documents and Settings\Rick\Cookies\rick@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc24.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc264.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
::Report end
-----------------HJT-----------------
Logfile of HijackThis v1.99.1 Scan saved at 5:03:16 PM, on 9/7/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
bamajim
10376 Posts
378
0
Posted September 7th, 2006 01:00
Anubis132
Thanks for the log, hhowever you have turned off some programs in msconfig.
You need to go back into msconfig and turn them all back on. We need to have a full picture of what is going on with your pc.
Once that is done->>Re run Hijackthis and post a fresh log please
thanks bamajim Graduate of Malware Removal University
Message Edited by bamajim on 09-06-200609:15 PM