Thorny Malware Problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by potterjazz, Sep 11, 2009.

  1. potterjazz

    potterjazz Private E-2

    I am helping a friend who has a Dell Inspiron 1520 laptop with Windows XP Home Edition SP3. She had ZoneAlarm Security Suite installed and operational, so far as I can tell, throughout the time she has owned the unit. Here's the skinny: she started having odd redirects while in Firefox 3.5.? and then, more recently, freezeups, inability to open Outlook, etc. I did the following:

    1. Diagnosed the Outlook as a set navigation frame problem, found a program switch to reset that, and Outlook loaded fine.
    2. Discovered that she had been instructing ZoneAlarm to block any program that its many alerts asked her about. The result was that the firewall was blocking all sorts of outgoing TCP and UDP associated with favorites in Firefox, and neither IE7 nor Firefox could their home pages even though I could Ping the associated servers (www.google.com). I reinstalled ZoneAlarm, but the blocking continued (no doubt due to incomplete uninstall). Concluded that perhaps there was a malware problem and came to MajorGeeks Forums and started going through the standard procedure recommended for Malware Removal as recommended here.
    3. Tried to begin the XP Cleaning Procedure by attempting to install Superantispyware prog. Refused to install, so I uninstalled ZoneAlarm Security Suite. This restored access to pages on the web from both IE7 and Firefox 3.5.? and Superantispyware then was able to install, but when I then ran it, got an unspecified error (one that generates a request to send an error report to Microsoft).
    4. Tried to use Restore both before and after uninstalling ZoneAlarm and notice that there are no restore points going back from now to about August 20, and then regular ones going back from there every few days. When I select these and attempt to activate the restore function, it hangs and nothing happens.
    5. Before instituting all these measures, I ran Hijack This and post it here just in case there is a clue therein. Below please find the log. Note that this log was produced before I re-installed and then uninstalled ZoneAlarm.

    Any clues will be most appreciated.
    Potterjazz

    *******************

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:29:16 PM, on 9/10/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16876)
    Boot mode: Normal

    Edit by chaslang: Inline HJT log removed. READ & RUN ME FIRST. Malware Removal Guide sticky not followed.
     
    Last edited by a moderator: Sep 20, 2009
  2. potterjazz

    potterjazz Private E-2

    I solved this problem myself, but find it odd that no one had *any* ideas about how to approach this problem...there are numerous well-known fixes that experienced malware geeks should have known about. I guess Major Geeks ain't what it used to be, or my information was too detailed so no one actually read the post.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You never ran the READ & RUN ME and attached the required logs and in addition you bumped your thread before we got to it. Thus you are just getting an answer now. Majorgeeks is much more than it "used to be". We are 100 times busier and too many people (like you) don't follow instructions posted in the stickies. You had a WareOut infection and perhaps others.
     
  4. potterjazz

    potterjazz Private E-2

    Suit yourself, but I read and followed READ AND RUN ME advice to the letter, in fact, followed its recommendations in the stated sequence, and attached all logs of anything that WOULD RUN (everything in the cleanup procedure section for Windows XP but HiJackThis refused to run), but the series of recommended progs in the XP cleanup section wouldn't install, or wouldn't run, other than HijackThis. So you got what logs there were. And clearly, it was enough to go to work on the problem....several folks at Experts-Exchange got me a series of useful suggestions in six hours. You apparently don't like criticism, but at best, you're the pot calling the kettle black. Have a nice day.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All you mentioned in your first message was SUPERAntiSpyware and having a problem installing it. Then you went on to talk about ZoneAlarm Security Suite which is not part of our procedure. You never said anything about trying to run Malwarebytes, ComboFix, RootRepeal, or MGtools in you message. The cleaning procedure specifically states not to attach HijackThis logs that you have run on your own.

    If you could run HijackThis then MGtools most likely would run too. And HijackThis is embedded into MGtools and is automatically installed and run properly when MGtools is run.

    Great then you have a place to go for your future problems since you don't like the way we work.

    It is not a problem with criticism, it is a problem with people not following instructions properly and not giving us all the facts.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds