modem security

Discussion in 'Malware Help (A Specialist Will Reply)' started by steve_kenai, Jun 22, 2007.

  1. steve_kenai

    steve_kenai Private E-2

    hi every one. im new to thread and computers and have a question. what is a good program for veiwing all in and out going info from computer? ive run a few basic programs but dont know how to use them or if they were even the right ones. seems like at random times my comp resources are all but gone like some program is using them. however if i pull the plug to the modem this never happens. thanks!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    This may not be the correct forum for your question.

    At what level are you talking about? Do you mean you want to look at the IP packets? If so, there are tools for doing that but they are not basic programs and if you don't know how to use basic programs (as you mentioned) then you will not be able to use more complex programs. Nor will you be able to understand all of the raw output.

    If you are worried that you have malware problems, you need to follow our standard cleaning procedures give below.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. steve_kenai

    steve_kenai Private E-2

    that took forever. thanks. sorry for wasting your time. it worked just had to run the spybot in safe mode. found realspy and realspy logger. i think it is gone. thanks again.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome, but as far as I know Real Spy is a commercial tool that is often install by employers, schools, spouses, parents,....etc to spy on what a PC is being used for. If this was installed by your or employer and you are trying to remove it or already did, you could be subject to legal action.
     
  5. steve_kenai

    steve_kenai Private E-2

    its my home comp, that i picked up at a yard sale. i also tried the about blank thing but got very confused when asked to remove some stuff, step 7 and 8. it all looks suspicios to me and being pre own plus the kids sometimes get on it and download every thing with a pic on it. i am going to run through every thing in order today and make sure that i did not miss any of the real spy files. there were files all over the place. by then i should have an idea if the old syptoms are gone.:zzz if not then at least having that program gone should make it easier to clean some more.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then the previpous owners could have installed it. That is assuming it was really RealSpy that Spybot found. False positives do occur with many scanners. Since you did not attach any logs from the scan (including Spybot which you said found this) I cannot say for sure if it was valid.

    Why??? This has nothing to do with an about:blank or HSA hijacker.

    If you want help, you need to complete the instructions I gave to you already.
     
  7. steve_kenai

    steve_kenai Private E-2

    was not false pos found the appl. and found hot keys to onpen it contr atl s. it had been turned off since befor i owned it. must not have been the problem. i followed all the steps again today only now the real spy did not come up.
    ( cable unplugged)first step manually removing all prgrams that i did not install or did not know of, except .net framework, it told me that some programs would not work if uninstalled so i thought id ask. did look it up on internet, apeared to be ligit program, can i remove it safely?
    then ccleaner in safe all accounts. not much after doing this yesterday, some yahoo mail temp files and excit stuff from looking up files.
    (sorry did not save report it seemed like just me checking my mail, if i need to do it over again let me know)
    next in safe spybot, nothing no report given
    recomended prgram did not work in safe, said access denied tried each account, so i used avg7 from the directions again nothing found, also no report.
    then restart in safe with networking, did not work because the ie browser would not go online, said that fast ethernet was connected but would not, cannot find server was message displayed, so rebooted in norm and continued, fast ethernet connected and had to connect dail up also to get online? is that normal to have to be connected to broadband and dialup at the same time to get online? (while i was in safe with networ i tried to creat new connection, wouldnt let me, go through all motions then no new connection would be displayed) so i did the bitdefender in norm, found nothing, no report.
    then panda, nothing found no report
    then get runkey, shownew and hijack in that order in norm boot up. attached are the logs.
    i did the blank thing because in your post it said before going any further you might want to try ... , so i clicked on the link and tried the first one.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you should not uninstall .NET Framework. It wull be required for many things and it is from Microsoft. It will just have to be redownloaded (from MS Update) and installed again if you uninstalled it.

    Based on your logs you have no malware problems. You main problem is really that this PC is totally unprotected. No antivirus, no realtime antispyware protection, and no true software firewall. This is a major security risk which must be corrected.

    You should however have HJT fix the below lines. Two are unnecessary and on is left over from an incomplete uninstall of Yahoo software:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"

    Then you need to start working thru the below to get properly updated and protected ASAP.

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds