Warning! you are in Danger! Spyware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by griff713, Apr 17, 2005.

  1. griff713

    griff713 Private E-2

    Need a hand killing this piece of garbage... can someone
    help me out here? I have hjt installed in an appropriate
    directory - but haven't figured what I'm doing wrong....
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Follow our standard cleanup process (posted below) first. And then we may need to do some additional work. These have been annoying lately. Also search your PC for files named desktop.html, wp.exe, wp.bmp and let me know if you find them. desktop.html is typically in c:\windows\web and wp.exe and wp.bmp have been found in the root of drive C which is c:\


    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus RemovalMake sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. griff713

    griff713 Private E-2

    Ok - did all the above - Ad-Aware found several spyware (an embarrassing
    amount - all removed...) then One of the others showed three files and
    two could not be removed, as they were "in use" ... BTW - I'm running
    Win2k Pro.... booting off my CD and going to console, I was able to kill
    those last two.... but the background is still there..... I had trouble
    running the onlinescans - but when I ran IE instead of netscape - it worked.
    nothing new there.... I also trashed MSJVM and installed Sun's Java.


    desktop.html is there - but the wp.exe and wp.bmp are not....

    do you want a HJT log? Can do -


    - griff
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's what I asked for in my previous message.
     
  5. griff713

    griff713 Private E-2

    thanks in advance, chaslang - The
    hjt log should be attached....
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The only thing I see in you log is the below:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.makemesearch.com/?said=429
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    Is the www.makemesearch.com valid?

    Did you delete the Desktop.html file in c:\windows\web?

    Also you should right click on your Desktop and select Properties. Then click the Desktop tab and then the Customize Desktop button. Now in the next window that comes up click the Web tab. Make sure at the bottom that Lock desktop items is unchecked. Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too. Then click OK. Apply. OK.
     
  7. griff713

    griff713 Private E-2

    I went thru your suggestions... and it seems to have killed it,
    thanks for your help! The desktop web suggestions you had
    didn't quite translate to Win2k, but i checked the web desktop
    anyway - verifed it - and things look "normal" again.... no
    annoying screen screwup..... Ya know, I'm just waiting for
    someone to track down the folks who write this stuff and sue
    them under the "War Games" laws.... someone's gonna do it
    eventually, and then maybe some of these "ooh, I'm so clever-ad men"
    will stop with these intrusions.....

    Anyway - thanks again....
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds