spy ware i think

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jcdgl, Mar 3, 2007.

  1. jcdgl

    jcdgl Private First Class

    hi there
    you were so helpful the last time i had problem i was hoping you could help me once again. I have been able to run problem free for some time now all of a sudden my spyguard has picked up something trying to change my home page from yahoo to google. I have run my avg virus scan nothing showed up. I also ran ad-aware professional, spyboy search and destroy and cc clean with no help . both in regular mode and safe mode. I finally did a restore to another date can you help me figure out what or who is trying to hijack my home page
     
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.

    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
    • CounterSpy
    • AVG Antispyware Log - ONLY IF NEEDED you were not able to run CounterSpy
    • Bitdefender - from step 6
    • Panda Scan - from step 6
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis
     
  3. jcdgl

    jcdgl Private First Class

    Thanks for answering and I will work on each of these steps but it may take a couple days with my work schedule.
     
  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    We'll be here, when you are ready.
     
  5. jcdgl

    jcdgl Private First Class

    Ahhh can you help mycomputer has been running fine since i ran CC clean. all of a sudden tonite it went nuts. all my icons are .ink files i can not get to anything or download anything I got the internet by shear accident. can you tell me what to do I can check from work computer or my son's laptop
     
  6. jcdgl

    jcdgl Private First Class

    I am not sure if I am sending this correctly but I really need help:cry


    Ahhh can you help mycomputer has been running fine since i ran CC clean. all of a sudden tonite it went nuts. all my icons are .ink files i can not get to anything or download anything I got the internet by shear accident. can you tell me what to do I can check from work computer or my son's laptop
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you may have lost File Associations.

    Try running this: LNK (Shortcut) File Association Fix

    It is possible that you may need other fixes for other file associations. The above link comes from the below page where other file associations fixes can be found.

    http://www.dougknox.com/xp/file_assoc.htm


    This is really not a malware problem in itself; however, it is not totally unlikely that malware caused the problem. We cannot answer that at this point since we don't really know your malware status at this point.
     
  8. jcdgl

    jcdgl Private First Class

    :cry thanks but when I click the link it trys to go and then says that it can not be opened I tried the CTRL ALT DEL to open the task manager as per instructions on your link to XPfile assocations fixes but I don't understand what to do after i open regedit.exe. It will not allow me to download or unzip anything. All shortcuts and program files are lableled .LNK. even in safe mode
    Do you think I should take out to some one or continue to work at it myself.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like you have no file association for .ZIP files either which is what the first link was trying to download.

    Assuming that you are at least able to get regedit.exe to run. Try the below

    Now Copy the bold text below to notepad. Save it as fixLNKREG.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. If this does not work, it also means you have lost file associations for .REG files. If that is the case, further down after this patch.
    If double clicking on the fixLNKREG.reg patch did not work, run regedit.exe from Task Manager as you mentioned doing before. Then in the Registry Editor click File, Import, and then navigate to the fixLNKREG.reg patch saved on your Desktop and double click on it. Click OK to allow it to add to the registry.

    Did that work? If so, continue on to the next patch below.

    Now Copy the bold text below to notepad. Save it as fixEXE.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. If this does not work, repeat the steps you did above to import the patch into the Registry Editor.
    Did any of this work?
     
  10. jcdgl

    jcdgl Private First Class

    none of my programs work not even notepad says cannot open notepad.lnk
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How are you trying to open notepad?

    Create the files on another PC if necessary and then transfer them to the problem PC if you can.
     
  12. jcdgl

    jcdgl Private First Class

    programs/accessories/notepad my son has a laptop but he will not be available untill sunday. I will try to save them to a disk at work today. However I am not sure my pc will recognize my cd rom drive.. anything is worth it at this point.
    I am not sure if this will help diagnose the problem but here is what happen that nite. I was on pc when it froze up I shut down when I rebooted Adaware blocked several cookies so I cleaned out temp files and ran CC clean. When I rebooted Adaware popped up showing several reg changes and was trying to block a bunch of other stuff Spyguard then kicked in telling me that something was changing my home page. I had to do a hard shut down I rebooted in safe mode and everything was gone
     
  13. jcdgl

    jcdgl Private First Class

    I was able to create a cd at work with the fix files I will try when I go home
    wish me luck.. Oh yes I forgot THANKS for trying to help me

    And to run notepad, I suggest you try it from Task Manager's File, New Task (Run...) box and enter notepad.exe
    Run the Registry Editor the same way but type in regedit.exe
     
    Last edited by a moderator: Mar 16, 2007
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good luck! ;)

    You may have problems with other file associations too. Those fixes were only for .reg, .lnk, and .exe file associations. But let's see where that gets you.
     
  15. jcdgl

    jcdgl Private First Class


    i have to admitt i am usually very confident with computer stuff (stuff do you like that lol) but when it comes to working with the registry i get really nervous. If I hit F10 I can get to system recover. I believe that it said that i will not lose any data files only programs that we have downloaded. The only thing I am trying to save are my daughters pictures . they have music but they can always redo that what do you think is my safest bet
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes performing a System Restore to a point in time before this problem began is an option. You will not loose things you have downloaded. The downloaded files, any pictures you have saved, any data from programs....etc will still be on your PC. Programs that you installed, changes/tweaks to programs ... etc are things that will be lost. They are all things stored in the registry which is mostly what system restore will impact. So for example if you restore to a point in time before Spybot was installed, Spybot would no longer run but the files for it would still show on your harddisk. You would have to reinstall it for it to work again. That's just one example. Updates to all programs including Windows that had been made after the date to which you are restoring are also lost. But you can just update again afterwards.
     
    Last edited: Mar 16, 2007
  17. jcdgl

    jcdgl Private First Class

    thanks I am going to try to move my pics which is the only important thing to me to photobucket and then try system restore just not sure enough to attempt working with reg. if you don't here from me for a bit you will know i did not succeed rolleyes but will not do this until sometime sat.
     
    Last edited by a moderator: Mar 16, 2007
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Good luck.
     
  19. jcdgl

    jcdgl Private First Class

    OK this is where i am at now. did system rcovery when i clicked on adaware to see if it was actually there or just an icon it started trying to block everything in sight i think. I did a shut down when I booted up everthing was back to lnk files again. I have now done my second recovry and have deleted adaware. Do you have a clue where to go from here to find out what is imbedded in my computer to continue causeing this problem Hopefully I will not have to shut down I am scared to. Also am i useing the correct reply link or should i use quick reply
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you mean System Restore or do you mean system recovery which is not the same. Recovery disks are CD provide with new PCs to bring them back to the same state they were in when they were shipped to you.

    Why are you running Ad-Aware anyway? We did not request it in our procedure. Previously you said you ran into problems after running CCleaner, so now are you telling me it was really after running Ad-Aware that you have problems. What is Ad-Aware finding that it wants to delete? Attach a log!!! It will not fix things on its own, you have to click on a selection to tell it to delete things anyway.

    For us to be able to help you, the steps that Shadow_Puter_Dude gave you in messsage # 2 must be followed and nothing else! Then you must attach the 6 requested logs. That is our only visibility into your problems. Without this information we cannot assist you.
     
  21. jcdgl

    jcdgl Private First Class

    I went to F10 and did what my computer called system recovery it restored my programs but I did not lose my data. No you did not request me to use ad-aware i have always run that program to help block stuff from getting into my computer. I would send tell you what it is trying to block but I have completely deleted ad-ware from my computer so far so good. I will proceed with Shadow puter dude's steps this afternoon
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, just attach the logs when you complete all the steps.
     
  23. jcdgl

    jcdgl Private First Class

    thes are the logs that have been performed I will send the next along shortly
     

    Attached Files:

    Last edited by a moderator: Mar 19, 2007
  24. jcdgl

    jcdgl Private First Class

    final logs

    Also I forgot to mention that I could not run these in safemode
     

    Attached Files:

    Last edited by a moderator: Mar 19, 2007
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not show any real major problems although there are a few things to do as given below. Perhaps what you thought was a problem was due to you installing Google Desktop and/or Toolbar. Your home page is also not set to Yahoo. It is set to some junk from HP.
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now uninstall the below software:
    J2SE Runtime Environment 5.0 Update 10
    Java 2 Runtime Environment, SE v1.4.2_03
    Symantec Network Drivers Update

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below folders which may be left behind by the uninstall:
    C:\Documents and Settings\Owner\Local Settings\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also delete the below folders:
    C:\Documents and Settings\Owner\Application Data\Viewpoint
    C:\Program Files\Viewpoint"

    Are there any files in the below folder? If so, tell me what you see.
    C:\Program Files\Common Files\{5C69FD7D-0897-1033-0611-040804030001}

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    After clicking Fix, exit HJT.
    Now run Ccleaner
    Now reboot in normal mode

    Now delete the below file too.
    C:\WINDOWS\wnu_223.exe

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  26. jcdgl

    jcdgl Private First Class

    everything went well but in your message you said my homepage was something formHP I have it set at earthlink.net. Also I do not remember ever loading google desk top and/or toolbar. I think that is what spyguard was trying to prevent. Also can you recommend any programs to run beside Ad-ware to prevent this from happening again. Computer seems to be running fine
     

    Attached Files:

    Last edited by a moderator: Mar 19, 2007
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well yes and no! Actually you have all of the below configure which included earthlink.

    It may have been on your PC when you got it or you may have installed something recently that included it. Look in your logs and you will see Google in a few places. If you do not want it, you should uninstall the below:

    Google Toolbar for Internet Explorer

    You should also uninstall the below left over from Symantec which is still running a service on your PC and wasting resources:

    Symantec Network Drivers Update"


    All of our recommendations are included in my final instructions which I will give to you know.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  28. jcdgl

    jcdgl Private First Class

    on my add and remove programslist i have live update 1.90 (symantic corporation) I can not find symantic drivers update to remove
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall it!


    Then run this Getting Uninstall Programs List From The Registry and attach the requested log.

    Also attach another HJT log. If that Symantec Service is still there, we will have to remove it manually.
     
  30. jcdgl

    jcdgl Private First Class

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like you did not uninstall live update 1.90 before getting that log. Is this true? If so, uninstall it and then attach a new log from GetUnKey.
     
  32. jcdgl

    jcdgl Private First Class

    View attachment GetUnKey.txt

    no i did not uninstall I was not sure if it was the correct progam, but it done now. I also did all my updates including service pack 2 that would never install succesfully before but it worked this time. I also reinstalled CCleaner and Spyguard and loaded sunjava instead of the other program(sorry don't remember the name anymore but it was in your instruction.. You have been GREAT thanks for your help. Thankfully I am on spring break right now so i as ableto do all the work that i needed to
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Let's finish cleaning up the trash from Symantec.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach a new HJT log. I want to see if the below service is still trying to load.

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
     
  34. jcdgl

    jcdgl Private First Class

    good morning this is the latest hijack log
     

    Attached Files:

    Last edited by a moderator: Mar 21, 2007
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Symantec Network Drivers Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteSNDSrvc into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot if it tells you it needs to.
    After reboot, delete the below folder if found:
    C:\Program Files\Common Files\Symantec Shared

    Now attach a new HJT log!
    How is everything running?
     
  36. jcdgl

    jcdgl Private First Class

    View attachment hijackthis.log
    If thing is running well except a few quicky things but I think that I just have to get used to some of the thing that service pack 2 does and the new version of Netscape. There are a few programs that I still have to reinstall but that is due to the recovery that I did. Now if you could only fix the cracked drain that almost flood my kitchen and my daughter's broken nose we would be great;)
     
  37. jcdgl

    jcdgl Private First Class

    ok chas here is a question for you. What is a BHO. my son had to reinstall earthlink total access theis morning so my husband could get to his e-maill spy guard picked up an attempt to change my homepage from
    ElinkScamBlocker.ElinkScamBHO.1
    location: c:/Program files earthlink total access\toolbar\EScamBlk.dll

    I tried to copy the report log from spyguard but there is no way..
    Can you tell me what this may be
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I could fix the drain but it is difficult to do remotely. ;) But I'm only good at breaking noses! :D


    BHO = Browser Helper Object. Here is a reasonable description for you: http://en.wikipedia.org/wiki/Browser_Helper_Object


    You have to be more careful with program names. You keep saying spyguard which would be a malware program. What you are using is SpywareGuard which is okay. If you don't allow the the BHO then you may not be able to use you Earthlink email or toolbar.
     
  39. jcdgl

    jcdgl Private First Class

    yes it is spywareguard i think we are good now i can't even tell you haw much i appreciate you help I have recommended majorgeeks to everyone i can think of if they need help
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and thanks for the recommendations.

    Make sure you have completed those final steps I gave to you in message # 27.
     
  41. jcdgl

    jcdgl Private First Class

    I finished all the steps and made sure i saved a printed copy of what to do before requesting support. Thank you again but before I go I have one unrelated question. Now that I have time to notice things, it says you are from Northern Jersey. I grew up in Wayne and spent my adult years in south jersey around seaside heights until we moved to florida/ I was just curious where in north jersey. No worry in that is not info you want to share
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While it is a good reference to use to try and fix problems on your own, before posting here you really need to use the current online copy of the READ ME. Just like malware changes, so does the READ ME. And version numbers of programs change too. So you have to be sure you have current versions of all programs. For example there have been about 5 or 6 versions of ShowNew since December.

    You're welcome. I sent you a PM!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds