new pc has security compromised

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Omegamerc, Nov 24, 2004.

  1. Omegamerc

    Omegamerc MajorGeek

    I was bombed w/progs and popups everywhere over night; so i installed Adaware SE, Mcaffee, popupmanager, hijackthis!, spywareblaster, spybot search and destroy. It cleaned i would say 95% of the problem; the thing is i still every couple of hrs get a pop up. I upped my security levels on the internet to high even put the windows firewall up. I think my registry has been fondled with and im not sure how to fix it; Most of the pop ups keep coming from 3 websites; 69.20.56.3 and 206.161.125.149. *PLEASE DONT ENTER THEM IN IE I DONT WANT YOU INFECTED ALSO* Any idea how i can "restore" my registry back to normal w/o reinstalling? Also i noticed that Popup manager keeps being removed from my pc for w/e reason.
     
  2. Omegamerc

    Omegamerc MajorGeek

    List of progs running

    wuaclt
    taskmgr
    mcvsftsn
    nvsvc32
    mcvsrte
    alg
    spool
    svchost x4
    explorer
    lsass
    services
    winlogon
    csrss
    mcshield
    smss
    McVSEscn
    mcagent
    mcvsshld
    wdfmgr
    system (no .exe)
    system idle process (no .exe)
    rundll32.exe (<- popsup when surfing/clicking IE stuff)
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow all the steps in this Sticky thread < READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    And what do you mean by "restore" my registry back to normal?
     
  4. Omegamerc

    Omegamerc MajorGeek

    127.0.0.1 localhost
    127.0.0.1 www.igetnet.com
    127.0.0.1 code.ignphrases.com
    127.0.0.1 clear-search.com
    127.0.0.1 r1.clrsch.com
    127.0.0.1 sds.clrsch.com
    127.0.0.1 status.clrsch.com
    127.0.0.1 www.clrsch.com
    127.0.0.1 clr-sch.com
    127.0.0.1 sds-qckads.com
    127.0.0.1 status.qckads.com

    I read out and looked at my host file with a host reader and all this was present; i managed to get here http://www.pcbasic.com/printthread.php?t=21539 ; i googled it up after looking at what was calsp.dll ; it turned out that that person had a EXTREMLY similar case to mine and eventually ended up looking at a HostFile-Reader from :
    http://download.broadbandmedic.com/ in previous atempts at running Hijackthis i also found 69.20.16.183 (along with several other similar ips) on IE. This was a serious doozy; i think a Host Reader should be included as a step into eliminating popup ads and random searches + installation of unwanted progs on your pc.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what state you are in right now. Did you run all the steps of the READ ME? Do you have a problem with calsp.dll? If so, you need to get LSP-Fix before removing that file.

    All lines in your hosts files except
    127.0.0.1 localhost

    are not necessary. Those other lines are just directing you back to your local PC instead of those URLs.

    If you have run all the steps of the READ ME FIRST and you are still having a problem, you should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log file as an attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Make sure you have HJT version 1.98.2 and follow the guidelines on where to install it and how to post a log as an attachment.
     
  6. Omegamerc

    Omegamerc MajorGeek

    I was posting my host file log; i didnt post any HJT log since i know what belongs there and what doesnt belong there. LSP-Fix doesnt fix anything
     
  7. Omegamerc

    Omegamerc MajorGeek

    OK it seems that adaware + spybot werent removing Vx2 even in safe mode after saying it was cleaned up. I downloaded VX2 finder and i got it cleaned; now my Q is about the "additional files" that apear afterwards; are these a problem also? if so i can open reg edit and delete folder by folder of them but im not sure if this is OK, been trying to find a readme or a post with info on what eles to do with VX2Finder other then "click the button" but i have failed in that sense. Any help apreciated.

    Additional Files---

    Keys Under Notify---
    crypt32chain
    cryptnet
    cscdll
    ScCertProp
    Schedule
    sclgntfy
    SensLogn
    termsrv
    wlballoon

    Also i still have the LSP problem even after running LSP fix
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If that is all VX2finder showed, it did not find anything you need to fix with it. Here is an example thread where there was a problem found with VX2finder: http://forums.majorgeeks.com/showthread.php?t=35656

    What is your LSP problem? LSP fix does not fix anything by itself, you have to tell it which files to remove from the LSP chain and then it removes them and corrects the chain.

    Does HJT show a broken chain?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds