Battle with Spyware/Adware/Malware/Hijack/Virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Mr. Satan, Sep 29, 2004.

  1. Mr. Satan

    Mr. Satan Private E-2

    http://img11.exs.cx/img11/5120/Argh.jpg

    Alright, I always scan for adware/spyware and virus more then 5 times a week using Ad-Aware SE Personal v1.05, Spybot: Search & Destroy v1.3, & Norton Antivirus 2004 Professional which I keep updated EVERY time I run the programs.

    A few days ago I came home from school and decided to check on my downloads. I turned my monitor on to find about 20 IE windows open and various "psuedo-alert" messages. I proceeded to close them all, however in haste I accidently clicked "No" to a "trick" message (One in which pressing YES means you dont want it and NO meaning you do) so something ended up getting installed on my comp, but I figured "No sweat".

    After closing all the windows and message pop-ups I ran Ad-Aware and Spybot. Not surprisingly they detected a lot of crap and removed it...or so I thought. After rebooting my comp everything seemed normal, but after a few minutes a internet window popped up advertising registry cleaner. Anoyed, I ran Ad-Aware and Spybot again and they found a few things again, but not as many. I removed the crap and rebooted again...same thing happend.

    Next, I ran Norton Antivirus 2004 Pro. It detected some viruses but couldn't delete 3/5 of them. So I rebooted in SAFE MODE and did it manually. However the problem was not eliminated. So I began to search the web for an answer. I found out about and downloaded AboutBuster, CWShredder, and Hijack This but none of them detected anything.

    Also, I went into regedit and did a pretty thorough search for adware and spyware type entries and deleted all that I found but the problem still exists. I've also been through msconfig several times as well as went through my "Program Files" folder and deleted anything that didn't belong.

    Now I'm very frustrated. The only thing I've managed to do is increase the time in which the pop-ups occur. Also, not long after rebooting, my CPU usage will shoot up to 100% >_<.

    On another forum, someone said they had a problem very similar to this and the cause was the "Peper Trojan".

    Here Is My LOGFILE From HIJACK THIS


    TASKMANAGER (after ending about 15 "iexplore.exe" process >_>)

    http://img17.exs.cx/img17/3082/R_Processes1.jpg
     

    Attached Files:

    • hjt.txt
      File size:
      4.3 KB
      Views:
      2
    Last edited by a moderator: Sep 30, 2004
  2. Mr. Satan

    Mr. Satan Private E-2

    Argh, I apologize for posting my HIJACK THIS log before requested. I copied and pasted my post from another forum and added a few things, posted, and then saw the rule about HIJACK LOGs >_< - I was going to edit and change it but I couldn't find any "EDIT" button.

    Oh, and, sorry about the double post but...*points above*
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First, you must get HijackThis off the Desktop and into its own folder. You have it here:
    C:\Documents and Settings\Sean Kiles\Desktop\Hijack This\HijackThis.exe
     
  4. Kodo

    Kodo SNATCHSQUATCH

    I edited your post and uploaded your log as an attachment.
    Never the less, it would be highy suggested to follow Chaslangs instructions above and then post a new one.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You beat me to it Kodo! I was getting to it eventually. ;)

    Mr. Satan,
    Assuming you now have HJT in its own directory not on the Desktop and not a temp folder, have it fix the following (make sure you exit all browser sessions before fixing. I know some will still show in Task Manager due to you problem.)

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch

    And a question. Did you place these restrictions in your system using a tool like SpywareBlaster or another? If not, you may want to fix these too.
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
     
    Last edited: Sep 30, 2004
  6. Mr. Satan

    Mr. Satan Private E-2

    Okay, I did whatcha said with HIJACKTHIS and...
     
  7. Mr. Satan

    Mr. Satan Private E-2

    I guess the log didn't attach to my last post so...
     

    Attached Files:

    Last edited by a moderator: Sep 30, 2004
  8. Kodo

    Kodo SNATCHSQUATCH

    Ok, your log looks clean to me
    I saw that you have PopUp stopper companion installed. I don't know anything about that program or its' legitimacy as far is it not installing malware on your machine and I can't find any info about that in particular.
     
  9. Mr. Satan

    Mr. Satan Private E-2

    I don't know if this helps or not but the advertisments consist of an online casino and various spyware and pop-up blockers (Which are obviously not legit).
     
  10. Kodo

    Kodo SNATCHSQUATCH

    Fix this too
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present

    and humor me by removing the pop-up stopper companion. It's just one more avenue that we can eliminate for sure.
     
  11. Mr. Satan

    Mr. Satan Private E-2

    I'm not gonna remove Pop-up stopper. It's legit, I've used it for many years.

    Here's another bit of info: When I go into Full Safe Mode to run antivirus progs and what-not, instead of internet explorer pop-up ads appearing, my "My Documents" folder will pop up
     
  12. Mr. Satan

    Mr. Satan Private E-2

    {UPDATE}

    I am unable to "fix" 06.

    I check it, click fix, click SCAN and *poof* it's still there.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Remember what I asked and you never answered,

    "And a question. Did you place these restrictions in your system using a tool like SpywareBlaster or another? If not, you may want to fix these too.
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present"

    Most likely it is something like SpywareBlaster and/or SpyBot S&D that you use to place these restrictions yourself.
     
  14. Mr. Satan

    Mr. Satan Private E-2


    Yeah, SpywareBlaster.


    Also, on Ad-Aware I keep finding the damed VX2 crap and it never goes away. I even used the special VX2 removal plugin for Ad-Aware.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you Ad-aware SE and the VX2 cleaner from safe mode?
     
  16. Mr. Satan

    Mr. Satan Private E-2


    Yep. Still came back.
     
  17. Kodo

    Kodo SNATCHSQUATCH

    this is a suggested fix recently posted on another forum. Try it out please and let us know if it works for you. The last successful clean was posted on the 30th so I'm hoping that this will do it for you.

    When done shut down/restart and run a full scan. One of the most important things it to make sure you do this for all profiles (users on your pc)
     
  18. Mr. Satan

    Mr. Satan Private E-2

    Well, I was about to do all of that but...now I dont have the problem anymore...weird.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So perhaps the original Ad-aware SE and the VX2 cleaner scans worked!
     
  20. Mr. Satan

    Mr. Satan Private E-2

    Seems I spoke too soon. I didn't get any pop-ups for a long time (like all day). To be sure I decided to run Ad-Aware SE overnight while I (1) Hosted my Teamspeak Server (2) Was on Teamspeak (3) Was downloading things in TorrentStorm .

    I come back home afterschool, turn my monitor on and POOF I see my taskbar filled with internet explorer windows of pop-ups >_<

    I switch to ad-aware and see it has found 4 things (none of which are VX2 - So I guess I finally got rid of that) and I remove them. I also noticed some crap called "My Daily Horoscope" has been auto-installed >_<

    I closed all the windows, uninstalled MDH and here I am >_>
     
  21. Kodo

    Kodo SNATCHSQUATCH

    can you post another log?
     
  22. Mr. Satan

    Mr. Satan Private E-2

    Here it is.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why is this stuff running when getting a HijackThis scan?

    C:\Program Files\Teamspeak2_RC2\server_windows.exe
    C:\Program Files\Teamspeak2_RC2\TeamSpeak.exe
    C:\Program Files\BPFTP Server\bpftpserver.exe
    C:\Program Files\Sunbelt Software\iHateSpam\siMain.exe
    C:\WINDOWS\system32\defrag.exe
    C:\WINDOWS\system32\cleanmgr.exe
     
  24. Mr. Satan

    Mr. Satan Private E-2

    I left my computer on all night and when I came home after school I had no pop-ups!

    I am thinking that TorrentStorm is behind the pop-up thing.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So what is this? It's a game?
     
  26. Mr. Satan

    Mr. Satan Private E-2

    TorrentStorm is a program for downloading .torrents.

    Since I stopped using it and uninstalled it, I have had no problems whatsoever! Also, I started using FIREFOX.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So I guess your problems are all solved now! That's good!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds