About to break down over this... x.x;

Discussion in 'Malware Help (A Specialist Will Reply)' started by Gea, Sep 6, 2005.

  1. Gea

    Gea Private E-2

    After a long week I have *stupidly* infected my computer with some hard to get out stuff. It is NOT detectable by spybot,ad aware, or Microsoft Anti-Spyware. Some of the things it put on my computer were, and I already have gotten rid of them. Norton also caught three trojans since this started. Anyways, I know nothing of such things so I am going to do the hijackthis log for my next post as well as give you a photo of what the bar looks like.

    Some things this does:

    -Added a bar to IE that does NOT go away when the third party box is unchecked.
    -It runs through AOL Instant Messenger and spreads itself via sending links to your list.
    -Added spyware as well as adware that was easily removed. Stuff that popped up additional windows is all gone.
    -It does NOT change my homepage.

    Consider me clueless and please have patience with me, I feel simply horrible. x.x;
     

    Attached Files:

    • bar.jpg
      bar.jpg
      File size:
      71.4 KB
      Views:
      33
  2. Gea

    Gea Private E-2

    Here is the log.
     

    Attached Files:

  3. Gea

    Gea Private E-2

    I fixed it. Thanks though. x,x;
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! But double check to make sure none of the below are in your log now. If they are, you need to follow the READ ME FIRST sticky thread cleaning procedures.

    Look for these:


    D:\WINDOWS\system32\windir32.exe
    D:\WINDOWS\system32\windir32.exe
    D:\WINDOWS\etb\pokapoka65.exe


    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.ezwebsearching.com/sp2.php
    O4 - HKLM\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
    O4 - HKLM\..\Run: [System service65] D:\WINDOWS\etb\pokapoka65.exe
    O4 - HKLM\..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe
    O4 - HKCU\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
     
  5. Gea

    Gea Private E-2

    I did. And I ran through everything it said twice. Those programs try to come back every time. I *think* they are being blocked from actually doing anything, but something is obviously reputting them everytime I get rid of them. Solutions?

    Mind you those are all the things I did fix the first time. Microsoft Anti-spyware actually has now caught and prevented them from installing the bar... but they still exist. I went into safe mode with killbox and got rid of it. Scanned with multiple things, repaired infected files, etc. Nothing.

    However as of *right* now its fixed, even though I had to refix it today.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you still have problems (like they keep coming back) make sure you ran ALL of the READ ME FIRST and then follow the below steps:


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  7. Gea

    Gea Private E-2

    Just another note. Microsoft Anti-Spyware caught windir32 trying to make itself run on startup. That was blocked of course...
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I cannot fix what I cannot see, so sometimes what is required is to uninstall programs like MS Antispyware and similar so that the problem can show itself completely. Then we can try to clean it. You may have to remove Ewido too because it may also see the problem.

    You also need a real firewall to be installed. The one in XP SP2 is not adequate and should be disabled after installing another true firewall. See some of the ones in: How to Protect yourself from malware!
     
  9. Gea

    Gea Private E-2

    I have a firewall thank you, and it works quite well. I know exactly how I became infected, and it is user error. The computer is quite secure and never has any problems besides user error, that I am sure of.

    Also... I don't mean to umm... Point out anything but I feel this is relevant. After much research on what actually puts these things on a computer I have come to the conclusion it is the W32/Sdbot-ABM worm. This is a very recent strain of the Sdbot worm, which is fairly common but has many different strains. Anyways... nothing is recent enough to detect it or even says it exists besides Sophos and they just *in Semptember no less* started putting it into their software, which does not have a free trial and I already have virus protection elsewhere, which I am happy with.

    Point being how do I go about getting W32/Sdbot-ABM worm off of my computer?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry I did not notice the Norton Firewall Serivce in your log before.

    The reason I was telling you to fix the lines with windir32.exe is because I knew it was the problem. And yes I also know that it is the W32/Sdbot-ABM worm.

    I am trying to help you fix the problem. If it keeps coming back you will need to do what I requested in my previous post. That is, uninstall MS Antispyware and Ewido so we can see the problems manifest themselves and then we can work on removing them.

    We already deleted the windir32.exe file once. If it is back (did you look to see if it is back) then there could be another reason for this. Like another infected file is restoring it. Also there could be another registry location trying to Run the process.

    Please download WinPFind

    Extract it to the root folder of drive C ( C:\ ). This will create a folder called WinPFind in the C:\ folder. Inside c:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.

    When it is done, it will show the results of the scan. Click on the Copy to Clipboard button and then paste the contents of the log in your clipboard. Then save it to a file using notepad and upload the text file here as an attachment.
     
  11. Gea

    Gea Private E-2

    I am running WinPFind. However... I am reluctant to shut off anything for two reasons.

    1. If it was going to show itself, it would have in my first log.

    2. Having to already go in and repair this computer twice, I am very very reluctant into wasting another afternoon of scanning and manually taking stuff out.

    I understand you are trying to help, and I *really* appreciate that.
     
  12. Gea

    Gea Private E-2

    Log.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not true because installed programs could be blocking it. And also you already said MS Antispyware saw it again! Are you still seeing it? If so, you still have problems. If not, perhaps it is finally gone.

    Removing malware and making your computer work properly is hardly a waste of time.

    The decisions are yours! If you are not having anymore problems then I assume we are finished.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds