bitgrabber spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by trampster, Dec 30, 2006.

  1. trampster

    trampster Private E-2

    Hi,
    I downloaded and installe bitgrabber and as a result I now have two iexplore processes running all the time and I get popups.

    I have followed all the stuff in the READ & RUN ME FIRST Before asking for Support thread and have attached the logs as requested.

    I also have AVG free anti virus and Windows Defender both of which have failed to detect it.
     

    Attached Files:

  2. trampster

    trampster Private E-2

    Here are the last three attachments as requested
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    What you got is called a LOP infection! We will fix this!

    Is the below Proxy Server setting something you configured?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.1.1.8:3125


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Make sure viewing of hidden files is enabled (per the tutorial).

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now immediately reboot into safe mode an continue with the below steps!

    Now run Windows Explore and locate the below folders and delete them:
    C:\Documents and Settings\Daniel\Application Data\BitGrabber
    C:\Documents and Settings\Daniel\Application Data\seekbluemess
    C:\Documents and Settings\All Users\Application Data\Load coal internet blah
    C:\Program Files\BitGrabber
    C:\Program Files\seekbluemess

    Now reboot in normal mode
    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds