Malware still there after READ & RUN ME

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by aknotter, Jul 18, 2006.

  1. aknotter

    aknotter Private E-2

    When I run Spybot Search & Destroy I find several
    instances of SpyWare. Anenue A, inc., DoubleClick,
    Mediaplex, and sometimes Advertising.com.

    I remove them, then the next time I connect/sign in to
    Yahoo, they re-appear. I can also remove them by
    "deleting cookies" within IE properties (or by using
    ccleaner). I'm running IE ver 6.0.2900.2180.xpsp
    _sp2_gdr.050301-1519.

    My machine is an HP Pavilion a527x, product number;PC
    032A-ABA, Software Build;42NAheBLU4, Hardware BOM;
    0nB121110,Software BOM;NA50, Service ID;061-804.

    I have followed you instructions in "READ & RUN ME FIRST
    Before Asking for Support" through step 6. Including the
    CWShredder and Kill2Me.

    Bitdefender found nothing, but Panda ActiveScan indicated
    that there are 7 infected files. All appear to be cookies, but
    I don't know how to prevent them from running.

    And, signin/signout on Yahoo will cause the DoubleClick
    malware to reappear. Staying signed in longer will result
    in more malware showing up.

    I have attached BDSCAN.TXT, ACTIVESCAN.TXT and
    HIJACKTHIS.LOG which are the "saved" logs from their
    respective scanners.

    You might also want to see a 'print screen' of an error that
    frequently appears at boot up - see MsWinDefender2.doc.
    (Only able to have 3 attached files and I think the logs
    are probably more important than the 'print screen'.
    I'll send it later if you want to see it.)

    Are these types of Malware serious, or am I just wasting
    my time (& yours) trying to get rid of them?
     
    Last edited: Nov 14, 2006
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Cookies are not problems that you need to worry about. They are harmless as noted in step 11 of this link How to Protect yourself from malware!


    You do have a few lines you can have HijackThis fix but they are not big problems.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)


    After clicking Fix, exit HJT.:

    Other than that, you are clean!
     
  3. aknotter

    aknotter Private E-2

    Thank you very much for your reply. I'll certainly
    follow your suggested steps. I'm quite relieved to
    have verified that cookies are not that much of
    a threat (still, they're a nuisance).

    I do appreciate the time it must take you folks
    to research and respond to the many request for
    assistance you must receive.

    Thanks again
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! You can just remove cookies anytime you like from your browser or by using a tool like CCleaner. Just be aware that if not careful you dump you good cookies too (things that save passwords to auto login and more). That is why CCleaner is a better choice. It allows you to choose which cookies to always keep.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds