Help with hijacking

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cwbutler, Dec 20, 2005.

  1. cwbutler

    cwbutler Private E-2

    My computer has malware on it that I can't get rid of. Homepage was hijacked, altrhough I seem to have resolved that (unless the problem is sleeping and wiating to re-attack). but I still have these 6 adware icons on my desktop (for gambling, dating, pharmacy, xxx, spyware and something invovling a man sleeping) that I can'tr get rid of.

    I've done all of the steps in the "do first" section involving AdAWare, CCleaner, MS AntiSPy, MS Malicious Software, SpyBot, CWSHredder, Bitdefender, Panda Activescan, about:Buster and HSREmove. I've run HijackThis, but don't know if I'm supposed to attach that yet. Can you tell me what information I should try to post here - and also, whether JUST the Hijack this stuff needs to be sent as an attachment, or if ANY log should be attached (rather than posted inline).

    Many thanks for your help.

    Craig
     
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  3. cwbutler

    cwbutler Private E-2

    Thanks -

    wasn't sure about whether the non-Hijacks were supposed to be attached or inline.

    If I did this correctly, I've got the files attached.

    Thanks!

    Craig
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Scan with HijackThis and Fix the Following:
    Reboot to Safe Mode.

    Open Windows Explorer, navigate to and Delete the following:
    Reboot to Normal Mode.

    Attach a fresh HijackThis log and the properly converted BitDefender log.
     
  6. cwbutler

    cwbutler Private E-2

    I ran the BitDefender again, but it didn't give me an option to export or save a file. It said nothing was found. I copied the info into a text file and have attached it, but all it tells is how many files were scanned and that nothing was found.

    When I went into Windows Explorer, I was unable to locate the following:

    MON76234.exe
    c:\WINDOWS\SYSTEM32\IDEMLOG.EXE
    C:\Documents and Settings\Lou\Local Settings\Temp\sp.html

    Thanks.
     

    Attached Files:

  7. cwbutler

    cwbutler Private E-2

    Looked like the HJT log didn't upload, so I'm re-sending.
     
  8. cwbutler

    cwbutler Private E-2

    Sorry - know this is annoying. Here's the HJT log (I hope)
     

    Attached Files:

  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your logs a clean.

    How is your computer running?
     
  10. cwbutler

    cwbutler Private E-2

    All the logs are clean, but I still have the icons (which i guess are part of some sort of desktop toolbar) littering my screen, which seems to indicate to me that there's still some sort of infestation. (Anytime the mouse passes over these icons, they open a little sidebar that says "loading" for a couple of seconds.)
     
  11. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  12. PhilliePhan

    PhilliePhan Guest

    You have a Wareout infection.

    If you guys need any assistance removing it, let me know :)


    PP :)
     
  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    cwbutler,

    As PP previously stated you appear to have a "wareout" infection, please follow the below...

    Download FixWareout by Lonny and save it to your Desktop.
    • Please locate your download of FixWareout and INSTALL it.
    • Be sure that Run fixit is checked.
    • Click Finish to begin the fix.
    • Follow the prompts and Reboot when asked to do so.
    • Upon Reboot, follow the prompts and HijackThis should open.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds