bussolaweb "invasion" II

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by berutti, Sep 5, 2004.

  1. berutti

    berutti Private E-2

    Hy everbody I'm italian.
    I had bussolaweb "invasion" since one year or more.
    I tried with the updated versoin of SpyBot and Ad.aware 6, but same days later it comes again.
    Someone has somethin to suggest pleas.
    Poi se lo spiegasse in italiano sarebbe ancora meglio
    Thanks everyone. Carlo :)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Begin by following all the steps in this Sticky thread < READ ME FIRST: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    Note: I already know your Ad-aware is out of date. Ad-aware 6 is old. The latest is Ad-aware SE v1.03 and the reference file is from 30.08.2004

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.
     
  3. berutti

    berutti Private E-2

    Incredible I did everything what suggested but 48 hours later bussolaweb agian af homapage, whay can I do more?
    P.S. CCleaner erased some godd files also pdf, can then be retrived?
    Bye + thanks
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    CCleaner cleans temporary folders. If you had files that you need to keep in temporary folders (not a good idea), they are gone.

    Read this http://forums.majorgeeks.com/showthread.php?t=38752
    and post your HijackThis log as a .txt file attachment.

    If it took 48 hrs to show up again, are you sure it is not happening because of where you are connecting to.

    You should use SpyBot's immunize feature and should consider downloading and installing SpywareBlaster and enable its protection capabilities. Get it here: http://www.majorgeeks.com/download2859.html
     
  5. berutti

    berutti Private E-2

     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  7. berutti

    berutti Private E-2

    Hi here is the logfile waiting for the analysys thanks Carlo
     

    Attached Files:

    Last edited by a moderator: Sep 10, 2004
  8. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    First and foremost, you completely skipped Chaslangs instructions. Problem with running Hijack This is we know what you did or did not do. If you had done all Windows Updates, you would have service pack 2. As you can see, you do not:
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    Which means your Internet Explorer and operating system are out of date, including many important security fixes that could help prevent problems. You also failed to then follow the Hijack This instructions which explain to empty Hijack This into its own directory, not a temporary directory or desktop, hell you even ran it from the friggin zip file: C:\Documents and Settings\Sara\Impostazioni locali\Temp\Directory temporanea 1 per hijackthis_198.zip\HijackThis.exe. You did not close running programs, your browser was open, antivirus, firewall, quicktime and so much more. Arrgh.

    Are you running TWO anti-virus programs? I see Sophos and AVG running. This is a major no-no. Uninstall one of them. Immediately. Now.

    Still reading? Did you uninstall one of those anti-virus programs? Cool, lets move on.

    These are the reasons people here try to remove spyware and can not. They do not follow instructions, nor ask for help in areas they may be stuck. Our success rate is much higher if you work with us. Your asking us to help you, then fighting us.


    Ok, here we go with what I can find for you to remove with Hijack this and me still bitching ;) I would definetly go to safe mode and run the virus scanners again, including Trend and Symantec. Links are in the tutorial:
    http://forums.majorgeeks.com/showthread.php?t=35407

    I dont know what this one is, there are some viruses with mp3.exe out there. If you dont know, delete it:

    C:\windows\mp3[1].exe

    Remove:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    O4 - HKLM\..\Run: [zzz025v] c:\windows\mp3[1].exe r
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To add to MA's advice, after fixing the lines in HijackThis, reboot in safe mode and locate the below file and delete it:

    c:\windows\mp3[1].exe

    If you have a problem finding it make sure you have enabled viewing of hidden files as per the read me first instructions (see Getting Prepare: step 4)
     
  10. berutti

    berutti Private E-2

    Don't get angry, it's difficult for me understand in english so may I get wrong as you say!
    1) I disinsatalled sophos
    2) "Microsoft Windows XP Service Pack 2 (SP2) fornisce nuove tecnologie di protezione proattive per Windows XP per una migliore difesa contro virus, worm e utenti malintenzionati. Oltre a una potente infrastruttura di protezione, SP2 consente di migliorare le opzioni di configurazione della protezione di Windows XP e fornisce maggiori informazioni per semplificare il processo decisionale degli utenti relativo alla protezione.

    NON FARE CLIC SU DOWNLOAD SE SI DEVE AGGIORNARE UN SOLO COMPUTER: un download più adeguato e di dimensioni inferiori sarà presto disponibile sul sito Web di Windows Update. Per ricevere un download ottimizzato di SP2, attivare la funzionalità Aggiornamenti automatici in Windows XP. Visitare il sito Web Proteggi il tuo PC . "

    This means that SP2 is not yet avaiable throgh windows update but ol by download, but they suggest non to do it by download for a single pc + wait few day to get it by windows update so taht it will be shorter an fitted for my installation
    3) However in the meantin I made the download but not yet executed waitnig for youy thinking abuot it.
    4) when I try do delete c:\windows\mp3[1].exe, it gives me acces denied as the file is in use, so prabaly it is the real troble, I shoul I proceed.

    Waitin answer fot 3) e 4) thanks again Carlo
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you fix the line in HijackThis:
    O4 - HKLM\..\Run: [zzz025v] c:\windows\mp3[1].exe r

    and then boot to safe mode and try to delete the file
    c:\windows\mp3[1].exe

    If it still give you a problem, bring up Task Manager (CTRL-ALT-DEL) and select processes. Look for mp3[1].exe and if running, end it. And then try to Delete the file.
     
  12. berutti

    berutti Private E-2

    Can you explain me better what does ti mean?
    "Did you fix the line in HijackThis?"
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have to run HijackThis put checks on the those lines you were given and then click Fix.
     
  14. berutti

    berutti Private E-2

    Ok
    I finally realised then fixed it then reboot and deleted the file and its link :)
    Now tuo questions.
    1) I have both zone alarm (sicne years) and now SpywareBlastet (installed on your suggest) should I keep both? I should I execute Spywareblaster every time I boot, as I don't fint as to confiugure it automaticaly?
    2) Should I excuted the update to SP2 via download or should I wait that it comes avaiablte form windoes update?
    Thanks see you! Carlo
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Keep ZoneAlarm! But what version is it?
    Yes keep SpywareBlaster. Did you enable of the protection features it has?

    Is your problem with bussolaweb invasion fixed?

    Once you get your since into good working order (no malware, no viruses etc) then you should do the SP2 upgrade. But take a look over in the Software Forum. There is a bunch of discussion over there on doing a problem free upgrade.
     
  16. berutti

    berutti Private E-2

    Keep ZoneAlarm! But what version is it?
    - Pro 5.1.011.000
    Yes keep SpywareBlaster. Did you enable of the protection features it has?
    - Yes but I did not fint the configuration feature to load it automatically ad start up. shold I put It manually into the folder of the programs that should be executed at each boot?

    Is your problem with bussolaweb invasion fixed?
    _It looks so, In confident

    Once you get your since into good working order (no malware, no viruses etc) then you should do the SP2 upgrade. But take a look over in the Software Forum. There is a bunch of discussion over there on doing a problem free upgrade.
    -ok
    --
    Carlo
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below is quoted from SpywareBlaster's help file:



    Enabling Protection

    Enabling SpywareBlaster's powerful protection is easy:

    1.) Open SpywareBlaster
    2.) Click on the "Enable All Protection" link under Quick Tasks on the main screen.
    3.) Exit the program - you're done!

    SpywareBlaster does not need to remain open for its protection to be active!

    Simply use the Check for Updates feature at least once a week to download the latest protection (or consider AutoUpdate).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds