Nasty Vista Spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by drchris, May 6, 2008.

  1. drchris

    drchris Private E-2

    Hi guys,

    I've foolishly run a crack for winrar and now Im full of spyware and malware!

    A few things Id like to point out.

    -- My internet no longer works. Its showing up as 'local only' on my pc. I've tried repairing the connection but nothing. The internet stopped working after running combofix. Not sure if its that or the actual restart that messed it up.

    -- Microsoft Live Messenger wont close. Every time I right click, exit, the windows messenger, it will close and just start automatically. Because of that, I believe that my system is still infected.

    -- Ive run all the cleaning software recommended, and indeed it has cleared out a lot of nasty stuff, but clearly they've missed out a few things.

    Attached are combofix.txt and mglogs.txt. The other logs i couldnt find.

    Thanks for your help. Much appreciated.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Have you tried the below:

    1. Click on the Start button.
    2. Click on the Settings menu option.
    3. Click on the Control Panel option.
    4. When the Control Panel opens, double-click on the Network Connections icon. If your Control Panel is set to Category View, then double-click on Network and Internet Connections and then click on Network Connections at the bottom.
    5. You will now see a list of available network connections. Locate the connection for your Wireless or Lan adapter and right-click on it.
    6. In the next windows, simply click on the Repair menu option.
    7. Let the repair process perform its tasks and when it has finished, your Internet connection should be working again.
    Did you save them as requested? We really need to see these logs.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you running this PC with no protection software at all?

    Did you uninstall the cracked version??? If not, you should uninstall it now.

    You need to put your PC into normal startup mode with MSconfig as requested in step 1 of the READ ME. You must not use MSconfig like this. See the tips in the READ ME. Then attach a new MGlogs.zip file by doing the below.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.



    Then attach the below log:
    • C:\MGlogs.zip
     
  4. drchris

    drchris Private E-2

    hello chaslang
    thanks for the fast reply! really appreciate it!

    right, i tried the repair thing a few times. i think all it does is it drops and reassigns the ip to the network card. anyway, i just plugged the cable to the other lan port and it works.

    what im worried about tho is what spyware is left on my pc. every time i exit windows live messenger it just starts back up. i uninstalled completely and installed but still the same problem.

    i found both the other logs which ive attached
    they're both the 'first' logs created in both programs. the 'latest' logs (after running progies for a few times just to be sure) just say that my pc is clean.
     

    Attached Files:

  5. drchris

    drchris Private E-2

    ok done, here u go!

    thanks once again :cool

     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I repeat, did you uninstall the cracker version of WinRAR yet???

    Your logs do not show any malware reasons for this. You need to address what I asked in my last message about not having any protection installed. Your PC is wide open for all kinds of problems. You need to get the below installed ASAP:
    • an antivirus
    • realtime antispyware blocker
    • a better firewall - the Vista firewall while better the in Win XP is still not adequate.
    It is possible that doing the above may just help especially if it is malware related.

    You do have a Browser Helper Object for Windows Live that seems to be missing (again this is not malware). Let's fix this and also a couple other non-malware items and also remove one minor left over from malware.

    First since you said your last log with SUPERAntiSpyware was clean, uninstall it now because we are finished with it.



    Uninstall the below old versions of software:
    Java(TM) 6 Update 5

    Then reboot.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {6D5802C1-BE8D-4D2B-90CE-8E1B0E33B02B} - C:\Windows\system32\mlJDtsqq.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. drchris

    drchris Private E-2

    hello chaslang
    again, thank for your help :)

    i'm at work now, I will follow your steps when I get home

    i have however uninstalled winrar and deleted related directories.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good! ;)
    Just get the protection software in place as I have suggested. Refer to the below link for tools you can use for free which are quite good.

    How to Protect yourself from malware!

    After getting protection in place finish my other instructions and attach the new log. Then tell me how things are working. It is possible that Windows Live Messenger restarting is not related to malware.
     
  9. drchris

    drchris Private E-2

    thanks for the tips :)
    attached is the latest MGlogs.zip

     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have not installed any protection software.

    Also you did not say if you are still having problems.
     
  11. drchris

    drchris Private E-2

    yeh i know. i was just looking for my motherboard cd which has kasperspy. i'll install something asap.

    well no real problems to be honest. as i said before the only thing thats puzzling me is the messenger re-starting when i close it. perhaps its a malware "aftermath", which has been left there even after the malware was cleaned.

    ive looked at the logs myself as well and my pc looks clean...so much appreciated for that chaslang.

     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is also why I said you need to get ALL 3 components of protection in place. If it is somehow related to malware, installing them could block it. Remember you need all 3 components. Kaspersky AV alone is not adequate and if Kaspersky is not current and you cannot get updates for it then it is not worth installing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds