Backweb & WREN.F Trojan - HELP!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by killingmesoftly, Aug 24, 2004.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Shelle,

    Your hosts file is okay.

    Lets do the below:

    Reset Web Settings by opening Internet Explorer. Then click Tools, Internet Options, Programs, and click the Reset Web Settings button. Then go back to the General tab and set your home page back to what you like to use.

    Also use HijackThis and fix the below two lines:
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
     
  2. killingmesoftly

    killingmesoftly Private E-2

    Hey Chas!!

    Ok - - I don't use IE anymore, but I went ahead and did the things you suggested.

    Also, ran another HJT and fixed the two lines you suggested.

    Wanted to tell you that I ran Ad-Aware - found 1 cookie (data miner from tribal.fusion) and quarantined it. Also ran SpyBot - S&D and it found nothing. My AVG scan was clean today too.

    So - - anything else I need to do??

    Bless you my wonderful computer guru friend!
    Shelle
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hi Shelle,

    I think your okay. Don't worry about Tribalfusion cookies. You'll even get those here on MG's. They are not a problem. That are just used to track which advertisements have already been shown to you to avoid sending the same ones over and over again.

    Happy Surfing! ;)
     
  4. killingmesoftly

    killingmesoftly Private E-2

    Thank you Chas!!

    Ok - I guess that means I'm clean, huh?

    I just contacted my webhosting company. They're going to delete my account. I'm going to delete my HD files for my website, uninstall FP, reinstall FP and start building the site from complete scratch.

    I'm NOT looking forward to this - but I don't know what else to do.

    BTW - Do you know what a Thumbs.db is? It's ghosted in a few files of mine. I'm thinking I originally saw it in the Gallery PHP software I downloaded, but it seems to be popping up everywhere.

    AND - AVG healed a pretty little trojan today - Trojan horse Downloader.VB.R
    Interesting, eh??

    Chas?! You are the greatest man!! Thank you! Thank you! Thank you!! :cool:

    Shel
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  6. killingmesoftly

    killingmesoftly Private E-2

    Hey Chas - -

    Thanks for the tip on the thumbs.db. I followed the instructions on that website you listed to unenable the viewing of them. I tried to delete them but I couldn't. It actually deleted some and re-wrote them back into the search function. Weird, but I think it's probably because of some setting I have - trying to protect itself.

    Nope - didn't get any answers at all on the software forum. But, I think I figured it out. My web hosting company completely recreated my account. I completely deleted my files and am now the proud owner of a brand-spanking new, $30, better looking, FP template.! ;)

    I went ahead and published the template (no old files) to my web server and had no problems. Thank the Lord! I'm still keeping my fingers crossed - but I have a LOT of work ahead of me.

    :eek:

    Since I'm asking stupid questions now and I'm not freaking out - - (yet) - Are you familiar with this? - Whenever I click on a link in an e-mail - I get a weird browsing Windows popup that's headed with LOCATE LINK BROWSER. I'm using Firefox and I've looked through the settings and can't find anything that would fix it. Also checked out their website for answers. I'm probably just not looking for it in the right way. Whatever link I click on does open, but this weird window stays up too.

    Oh, and just picking your brain here - - what are your thoughts on the SP2 from MS? It downloaded automatically without my knowledge a few weeks ago. I uninstalled it. I was thinking of waiting a few months before reinstalling it. I have enough headaches for now... *gee*

    Listen - if you're ever in my rural neck of the woods (Mississippi) you and your family must visit so I can cook a wonderful southern meal for you guys! Cornbread, black-eye peas, stewed potatoes and your choice of chicken, steak or pork. I owe you!!!!

    And - if you're ever in need of a resume fixer, writer, editor, proofreader or whatever - you get in touch. I'm actually quite good - believe it or not. Even been published a time or two -

    ;)

    Ok - it's late - I'm rambling. Can you tell I'm a writer by my long, boring missives? Maybe I can get some sleep soon.

    Take care!!!
    Shel
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. killingmesoftly

    killingmesoftly Private E-2

    Chas -

    You are a genius!!!!! Got it solved, no problemo! Glad to know that I'm not crazy or the only one with weird problems.

    I think I'll stick with my original plan and stay away from SP2 for now - I trust your judgement much more than mine! ;)

    Take care of yourself!! Ok, I'll leave you alone for now. You have been great!! Tell Major or Captain or whomever is in charge that you deserve a raise! *grin*

    May God bless you 1000 times more than you have blessed me.
    Shel
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Shel,

    Happy I could help! And thanks for the blessings! Right back at you and your family. Hope your husband has a safe tour in Iraq and returns home quickly. :)

    Take
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds