Free PC Performance Scan

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » Spyware / AdWare » Windows Spyware Infection Notice

Spyware / AdWare - Windows Spyware Infection Notice posted in the Security & Safety forums; I keep getting the windows spyware infection notice. I think there were some adawares and other things on my comp. And advice on what to do would be great thanks....

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 12-12-2005
Bronze Member
 
Join Date: Dec 2005
Posts: 3
AznAnim8 - See this Members User comments on their Profile page
Default Windows Spyware Infection Notice

I keep getting the windows spyware infection notice. I think there were some adawares and other things on my comp. And advice on what to do would be great thanks.
Attached Files
File Type: log hjt.log (4.7 KB, 6 views)



Last edited by joe5; 12-12-2005 at 03:44 PM.
  #2  
Old 12-12-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hi there AznAnim8 , welcome to PCHF.

Yup you are indeed infected , and with a pretty nasty piece of work. But we'll clean that up for you.




First of all I need you to download some programs for use later.

Download this file and unzip it to your desktop

Download about:Buster from here. Once it is downloaded extract it to c:\aboutbuster and check for updates. Do NOT use it yet

Download CWShredder from here, install it, check for updates but again, don't use it yet.

Download and install Ewido Security Suite Trial from here. Run and update the program but do not scan with it yet.
(see for installation instructions in the "Prework" link below in my sig.)

Please download CCleaner


Ensure hidden files and folders are set to show;
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.


Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).

How to disable system restore:

WinXP.
  1. Click the Start button.
  2. Right-click My Computer, and then click Properties.
  3. On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.

Next, go to Start->Run and type "Services.msc" (without quotes) then hit Ok
Scroll down and find the service called

Remote Procedure Call .

When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows.

Please disconnect from the Internet and unplug your modem for the duration of this fix You may want to print the rest of these instructions.

Reboot your computer into Safe Mode by tapping F8 while booting up and continue for the rest of the fix in SAFE MODE


Open HJT and click config > misc tools > “delete an NT service”
Copy and past:

RPC

Click OK.



While in safe mode, double click on the HSfix.reg file you downloaded at the beginning. Grant it permission to add the registry items.

Then Open cwshredder that you downloaded in the first step. Close all browser windows and click on the fix/next button.

Bring up task manager Ctrl-Alt-Del and end these processes if they are present

javark.exe
crvv.exe


Now run hijackthis and click the scan button, when it has finished scanning put a check against the following and click 'fix checked'

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\vzapy.dll/sp.html#10001
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vzapy.dll/sp.html#10001
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\vzapy.dll/sp.html#10001
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\vzapy.dll/sp.html#10001
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vzapy.dll/sp.html#10001
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\vzapy.dll/sp.html#10001
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\vzapy.dll/sp.html#10001
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = :0
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {3EE87594-07E8-2AA2-49D8-1EA0E2CAC359} - C:\WINDOWS\system32\atlpx32.dll
O4 - HKLM\..\Run: [javark.exe] C:\WINDOWS\system32\javark.exe
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\crvv.exe


Now find and delete the files in bold , and run Ccleaner.


Now navigate to the c:\aboutbuster directory and double-click on AboutBuster.exe. Click Begin Removal to allow AboutBuster to scan. When it has finished, AboutBuster will open a 'Scan Completed' window. Click OK. Another information window will open. Click on Exit. AboutBuster will inform you that a log has been created. Click OK. I will need you to post that log later.


Run Ewido and do a full System Scan with it.

Save the report it creates.

Now reboot,and run hijackthis again and attach a fresh hjt log along with the about buster log and the Ewido log.



Also i see you have the Messenger service running , if you don't use it . i would advice to disable it:

Please download Shoot The Messenger
Download and run the small (22 kbyte) "ShootTheMessenger.exe" utility. It will display the current status of your system's Messenger Service. The button near the bottom of its window will allow you to set the service to whichever state — running or disabled — that you desire.
If, for any reason, you should ever choose to re-enable the Windows Messenger Service, simply re-run ShootTheMessenger to do so.
And you also don't have an firewall or AV , with out those youre gone get reinfected in no time.
You could have a look in our download section for some free apps.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 12-12-2005 at 03:46 PM.
  #3  
Old 12-13-2005
Bronze Member
 
Join Date: Dec 2005
Posts: 3
AznAnim8 - See this Members User comments on their Profile page
Default

Hi, I tried to do my best at following your directions. Here's the new log.
EDIT: Please only post logs as attachments. Thank you. LGW
Attached Files
File Type: txt HJT Log.txt (14.2 KB, 0 views)



Last edited by ladygreenwitch; 12-13-2005 at 05:24 AM. Reason: Log not posted as attachment
  #4  
Old 12-13-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Originally Posted by AznAnim8
Hi, I tried to do my best at following your directions. Here's the new log.
Sounds like you had some difficulties? Can you explain where you had problems? With this infection it is importend that the instructions are performend all in safemode , precise and in one go , or it comes back. As it has.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 12-13-2005
Bronze Member
 
Join Date: Dec 2005
Posts: 3
AznAnim8 - See this Members User comments on their Profile page
Default

Yeah, I did everything in safe mode, and all at once. But for the Remote Procedure Call. I could only stop and disable the (Helper). And for the about buster, after I finished scanning, it would say there was an error which didnt open a new window for a log or anything. Those are the only real things that I had trouble with I think.


  #6  
Old 12-13-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

The about buster error was probebly the reason it came back again , let's try again and if you get the error again , please write the error down.


You probebly still have the apps but i include them anyway to be sure:






Download this file and unzip it to your desktop

Download about:Buster from here. Once it is downloaded extract it to c:\aboutbuster and check for updates. Do NOT use it yet

Download CWShredder from here, install it, check for updates but again, don't use it yet.

Download and install Ewido Security Suite Trial from here. Run and update the program but do not scan with it yet.

Download CCleaner

Ensure hidden files and folders are set to show;
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.

Next, go to Start->Run and type "Services.msc" (without quotes) then hit Ok
Scroll down and find the service called Service: Remote Procedure Call (RPC) Helper. When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows.

Please disconnect from the Internet and unplug your modem for the duration of this fix You may want to print the rest of these instructions.

Open HJT and click config > misc tools > ?delete an NT service?
Copy and past:
11F??#????`I
Click OK.

Reboot your computer into Safe Mode by tapping F8 while booting up and continue for the rest of the fix in SAFE MODE

While in safe mode, double click on the HSfix.reg file you downloaded at the beginning. Grant it permission to add the registry items.

Then Open cwshredder that you downloaded in the first step. Close all browser windows and click on the fix/next button.

Bring up task manager Ctrl-Alt-Del and end these processes if they are present:

d3em.exe
addzr32.exe
crvv.exe


Now run hijackthis and click the scan button, when it has finished scanning put a check against the following and click 'fix checked'

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\xnemu.dll/sp.html#10001
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\xnemu.dll/sp.html#10001
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\xnemu.dll/sp.html#10001
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\xnemu.dll/sp.html#10001
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\xnemu.dll/sp.html#10001
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\xnemu.dll/sp.html#10001
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\xnemu.dll/sp.html#10001
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {74ED8331-E220-3723-791F-3C434792B49D} - C:\WINDOWS\iepo.dll (file missing)
O2 - BHO: Class - {CDD74C7B-AF77-7456-5366-3D4E3A448F23} - C:\WINDOWS\crwg.dll (file missing)
O2 - BHO: Class - {E7E5A02C-DB25-B04F-7E08-9316EF15C3B6} - C:\WINDOWS\system32\addzr32.dll
O4 - HKLM\..\Run: [d3em.exe] C:\WINDOWS\d3em.exe
O4 - HKLM\..\RunOnce: [addzr32.exe] C:\WINDOWS\system32\addzr32.exe
O23 - Service: Remote Procedure Call (RPC) Helper ( 11F??#????`I) - Unknown owner - C:\WINDOWS\system32\crvv.exe (file missing)


Then delete the files in bold (if still present), and run Ccleaner.

Now navigate to the c:\aboutbuster directory and double-click on AboutBuster.exe. Click Begin Removal to allow AboutBuster to scan. When it has finished, AboutBuster will open a 'Scan Completed' window. Click OK. Another information window will open. Click on Exit. AboutBuster will inform you that a log has been created. Click OK. I will need you to post that log later.

Run Ewido and do a full System Scan with it. Let it clean anything it finds. Save the report it creates.

Now reboot,and run hijackthis again and post a fresh hjt log along with the about buster log and the Ewido log.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Partition Hard Drives merlin Windows Tutorials 2 02-22-2008 09:05 AM
[Fixed] Whenever i try to play a video my pc freezes! FyawurX Windows XP/2000 41 12-14-2005 08:42 PM
[FIXED] Windows Media Player problem Bencho Windows XP/2000 15 11-15-2005 12:57 PM
[Resolved] Boot up issue enner100 Motherboards 26 08-02-2005 03:08 AM

All times are GMT +1. The time now is 11:03 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top