PDA

View Full Version : Components of Spybot blocked during 1st scan and deleted on 2nd boot



MapMistress
2012-09-08, 15:02
Hello,

I've had a problem with some sort of malware-hijacker or spyware on my computer for 3 weeks now. I've even tried overwriting the harddrive in every possible format, Windows, DOS, filling the drive with zeros and then reformatting the drive and installing a new operating system. But whatever it is, that doesn't seem to work either.

I realize that I reinstall Win98, old OS, but relatively few malware works on such an old OS which is why I like to use it. But this one has me stumped and it is literally deleting parts of Spybot Search & Destroy software so that I can't quite figure out what it is to remove.

I'll get really detailed as I've kept detailed handwritten notes of what components of Spybot it has deleted.

DETAILS OF WHAT COMPONENTS OF SPYBOT ARE DELETED

#1) I downloaded two older versions of Spybot from OldApps.com. The first didn't work (not enough memory on my computer for 1.6.2). So I downloaded a 2nd which was version 1.4.

#2) When I began the installation process, something was already wrong during the 2nd download for the install. In the section of the install which read Current File and Overall process it displayed a series of characters.

Current File Progress $öÄ(double bars)KB of ¼ÿ(triple bars)ú¿ñ KB (¼ÿÄ(triple bars)ú¿ñ%)

#3) When the 2nd portion of download completed, I opted to get the rest of .sbi files before 1st boot of program, so they were instantly downloaded and I started the program for the 1st time.

#4) On first scan, it did detect both
CoolWWWSearch.Leftovers
Fraud:UltraAntivir2009

Both of which were supposed to have been removed. But there was a 3rd problem, I began getting error messages during the scan, like something was blocking the scan or deleting scan files from within the .sbi files of Spybot. From the Sep-5-2012 download of the "includes".

Error messages read:
There were problems in the include file C:\PROGRAM FILES\SPYBOT - SEARCH_DESTROY\Includes\Adware.sbi.
See 'Include errors.log' for details.

The specific files omitted giving error messages from the Spybot first boot scan were:
3581 of 169613 in the Adware.sbi
4982 of 169613 in the AdwareC.sbi
33977 of 169613 in the Hijackers.sbi
95432 of 169613 in the Malware.sbi
97231 of 169613 in the MalwareC.sbi
131001 of 169613 in the PUPS.sbi
132511 of 169613 in the PUPSC.sbi
141954 of 169613 in the Spyware.sbi
145465 of 169613 in the TrojansC-03.sbi
151523 of 169613 in the TrojansC-04.sbi

#5) I went into Advanced options and tried to have a look at the different .sbi files and I'll admit that at that point in time, there was a list of files in the different Trojan.sbi's-- all of them. I tried a few more scans and each came up clean. But on the third scan I began getting memory error messages and had to Alt-Ctrl-Delete to close the program. It was saying "Not enough memory resources". And I had closed out every program in operation, except Windows Explorer.

#6) On 2nd reboot, I went back into Advanced options to have a look at what the names of the scanned files might be in all those .sbi files. BUT. Some of the entire files were then empty. Nothing in them anymore. Specifically all the Trojan scan files were gone. Trojans.sbi was empty. TrojansC.sbi was empty. TrojansC-02.sbi was empty. TrojansC-05.sbi was empty.

Another odd thing about 2nd reboot is that some program autochecked two programs to "ignore" in the PUPS.sbi. The autochecked "ignore" files, were CDilla and Side Step.

#7) Tried to uninstall program from Control Panel in so I could reinstall and redownload. Wouldn't uninstall. Froze up computer. So I did a Cyberscrub-Gutmann of whole program (including files in Applications folder).

#8) I started up the 1st part of Spybot install again, to redownload the 2nd portion of download. Same thing as before. Only this time I did first boot of program before downloading the .sbi files (includes.exe). When I downloaded the includes.exe (this time from a different server), it immediately gave me memory error messages and I had to close out program and restart. Upon 2nd boot of program, again, all the Trojan .sbi files were empty, even though fully downloaded.

So I figure that whatever is on my computer is somehow stopping Spybot from scanning for it, giving the error messages during the scan and then on 2nd reboot of Spybot, all Trojan .sbi files are deleted. And once again, in the PUPS.sbi section, CDilla and Side Step were checked to "ignore". I didn't check those files myself, so it must have been automated on the Trojans .sbi files delete.

Can anyone tell me what these files are in each of the .sbi's error messages so I can figure out what I have on my computer?
3581 of 169613 in the Adware.sbi
4982 of 169613 in the AdwareC.sbi
33977 of 169613 in the Hijackers.sbi
95432 of 169613 in the Malware.sbi
97231 of 169613 in the MalwareC.sbi
131001 of 169613 in the PUPS.sbi
132511 of 169613 in the PUPSC.sbi
141954 of 169613 in the Spyware.sbi
145465 of 169613 in the TrojansC-03.sbi
151523 of 169613 in the TrojansC-04.sbi

Any suggestions? I've already overwritten the harddrive in Windows, DOS, filled it with zeros wiping the partitions, reformatted partitions and reinstalled the OS......TWICE, and not even that gets rid of what this is. Even wiped the BIOS for 48 hours and switched out memory chips to clean memory chips. That doesn't seem to help either.

Any suggestions would truly be appreciated as I've been at this for 3 weeks.

Please help or tell me what this is so I can remove it from my harddrive. I know Blog.com blocks my browser completely from logging in telling me malware is on my computer. I can't log in or view anyone's blogs. And I tried to ask them, but got no response to what name of program of malware that they were blocking. Do you have any idea? Since this is what it does to Spybot, deleting or stopping certain scans within the .sbi files?

On final note:

IPs that tried to send "Red Packets" thru my firewall during Spybot downloads were.
210.177.15.244 on 1st download
159.253.133.130 on 2nd download
222.186.27.87 when logging into forum to post this

tashi
2012-09-08, 17:44
Hello MapMistress,


I realize that I reinstall Win98, old OS, but relatively few malware works on such an old OS which is why I like to use it. But this one has me stumped and it is literally deleting parts of Spybot Search & Destroy software so that I can't quite figure out what it is to remove.
Please see the topic, "UPDATED WINDOWS - Your first line of defense" http://forums.spybot.info/showthread.php?t=425



#1) I downloaded two older versions of Spybot from OldApps.com. The first didn't work (not enough memory on my computer for 1.6.2). So I downloaded a 2nd which was version 1.4.
1.4. Such old versions are not supported, it might be wise to take that computer off the Internet. :)

2005 topic: Why are CDilla & SideStep checked in Ignore Products?
(http://forums.spybot.info/forums.spybot.info/showthread.php?t=336)
Best regards.

MapMistress
2012-09-14, 11:22
I think you misunderstood what I was saying. Maybe I should get a little more detailed in hopes to clarify.

The malware that was on my computer was NEW, August 2012. I use a specially tweaked win98, which is a FRESH, NEW operating system re-installed every 15-30 days on a harddrive overwritten 50-100 times beyond Department of Defense standards each time. That's right. I've re-installed a fresh, new clean install of Win98 about 240 times in the last decade.

SO... I notice just about everything that someone attempts to put on my computer, which gets wiped off the harddrive within 15-30 days after the attempt.

What was put on my harddrive this time, a month ago, came from specifically the Backpage.com advertising server. A group of hackers were doing this on the server where people place and pay for their ads. I'm 90% certain that this malware-hijacker program was placed on my computer when placing an ad there at the end of August.

Although my OS in Win98, I'm not on the original install, but rather clean install #238 of Win98 in the last decade.

AND, only 2% of malicious software actually works on my specially tweaked OS. I'm not stupid. I know precisely which components of Microsoft's operating system that can be removed and I also know that each time I reinstall the Win98 and remove those components, that my computer instantly sends out a message to Microsoft Security as does every other computer when people tweak the OS and remove components of the OS.

-------------

So with that in mind, what was put on my computer was NOT old, it was NEW and most of it didn't even work on my tweaked OS. The CoolWWWSearch, was just a small fraction of the larger malware program.

And if you had read statement number #1, I said I ORIGINALLY DOWNLOADED Spybot 1.6.2. And it wouldn't work at all. The malware rendered Spybot 1.6.2 useless. I'll say it again, in case you missed it the first time.

I originally downloaded Spybot 1.6.2 and the NEW malware from August 2012 (with a CoolWWWSearch trojan as a small component of it), rendered the Spybot 1.6.2 useless. Wouldn't work at all.

Spybot 1.6.2.46 is what Spybot still offers on their main front page of their site to all operating systems, right? Anyhow, when version 1.6.2.46 didn't work, then I opted to download an older version (from OldApps.com) which was version 1.4. The older version installed, however, the malware from August 2012 wiped out the all the Trojan detection files, rendering them useless in Spybot.

-----------

SOLUTION:

I overwrote the harddrive and overwrote the Operating system, overwriting the drive 50 times beyond Department of Defense standards. Filled the drive with zeros. Wiped the BIOS for 24 hours. Switched out to clean memory chips. Reformatted the harddrive using the Windows installation disk.

Installed a fresh, clean new install #240 of Win98. Then before upgrading the browser to a more recent version of IE, I installed Spybot 1.6.2.46 again and THIS TIME version 1.6.2.46 installed when before, it wouldn't function at all.

Seems the trojan CoolWWWSearch was still partially there, but not functioning anymore. Removed it from registry. Blocked anything else from installing in the browser. Installed a newer version of IE.

Scanned about 8 times. No malware. No spyware. No trojans. The computer now scanning clean on Spybot 1.6.2.46, with the fresh new install of the Win98 operating system.

However, there is one small problem even though clean now. The CoolWWWSearch component of the wiped/overwritten malware has altered the UserAgent string for Internet Explorer. Really odd thing was that it changed the UserAgent string to one for Netscape Navigator 4.0 and I've NEVER had Netscape Navigator 4.0 installed on this particular harddrive.

http://www.webuseragents.com/ua/560000/mozilla-4-0-compatible-msie-win32-

So now I'm having to mess around with the registry to fix the UserAgent string to fix it, even though scanning clean of all malware, clean of all spyware, clean of all trojans in Spybot 1.6.2.46.

False Netscape Navigator 4.0 UserAgent string that it (CoolWWWSearch) inserted for Internet Explorer browser was:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
UserAgent "Mozilla/4.0 (compatible; MSIE; Win32)"

and

HKEY_USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
UserAgent "Mozilla/4.0 (compatible; MSIE; Win32)"

Clearly I have to manually put them back to their appropriate Microsoft Internet Explorer settings. Are there any other registry keys for the User Agent that anyone else can think of that I have to fix? Or do I have to figure this out all on my own?

And don't say that it's only Win98 having the problem, because I already googled this UserAgent string and surfed the different message boards on the net, there's all kinds of posts about people using Spybot and getting this odd user agent inserted. Here's some links of others claiming the same problem on different operating systems (with Spybot) who are getting the same message.

http://www.sevenforums.com/windows-updates-activation/250005-windows-could-not-search-new-updates-code-80004002-a.html
*****Windows 7: post 2 weeks ago*****, another person-- same altered UserAgent

Clearly the girl above, 2 weeks ago, who is on Windows 7 shouldn't have a UserAgent string for Netscape Navigator 4.0. Like I said, I'm 90% certain that it was a Backpage.com server for ads, hacked in August 2012 that's where this malware came from. It was NOT on my computer in July 2012. And since I reinstall my OS every 15-30 days, I notice everything.

http://forums.techguy.org/windows-xp/513339-spybot-report.html
Windows XP: same altered UserAgent on a Spybot scan

http://forums.spybot.info/showthread.php?t=1048
A different OS: same altered UserAgent on a spybot scan

Spybot's message on the scan on mine and everyone else's (irregardless of type of operating system--all operating systems), is that it notes that the User Agent string is inserted, "registry change, nothing done."

Spybot 1.6.2.46 example (all types of Operating Systems):
VIEW REPORT:

Internet Explorer: [SBI $0BC7B918] User agent (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent


Obviously, Spybot hasn't added this to their software yet to correct.

So what all needs to be fixed manually in the registry, until Spybot adds as a correction to their software?

Remember, this was fresh new malware August 2012 from Backpage.com Server, Credit Card server hackers, even if some of us are on old or new operating systems.

Are there other components of User Agent strings that need to be fixed manually?

It's not just me on Win98, but clearly also happening to Windows 7 users in the last 2-4 weeks as well.