Chaslang...Dell Backup/ already downloaded

Discussion in 'Malware Help (A Specialist Will Reply)' started by writer997, Jul 1, 2005.

  1. writer997

    writer997 Private E-2

    Trojan.Clicker.Instas.A

    I knew something was wrong when my son opened his e-mail on my puter. It flickered yellow...so I followed all the steps in READ ME FIRST. It wouldn't let me run a scan at MicroTrend...Norton didn't show anything. So, I ran BitDefender after everything else was done and it showed Trojan.Dropper.Rameh.B and Joke.Winshoot.A the first time. It was flickering like crazy during the scan. I was hoping it was all gone...it said it couldn't quarantine it, so it deleted it.
    But......I ran it again and this time it came up with Trojan. Clicker.Instas.A this time. Same thing....couldn't quarantine, but said it deleted it. It is still on the puter hiding somewhere else still. Is there a removal tool to get rid of this thing? I can send you a HJT file if you need it. Thanks for any help you can give me! :)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Trojan.Clicker.Instas.A

    Did you run ALL the steps in the READ ME? You only mentioned the online scanners.

    After completing ALL the steps, do the exactly as the below indicates.


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).

    By the way, is the same PC that you could not get to boot a few days ago.
     
  3. writer997

    writer997 Private E-2

    Re: Trojan.Clicker.Instas.A

    Thank you Chaslang for the response.
    Yes I have run all the steps.....This is my own personal computer at home and Dell 4300 Dimension with WinXP Home.
    I had a problem getting Micro Trend to run the first time. So I ran BitDefender and it found the Trojan and virus. My Dell Backup came on and I used my disc to fix whatever was wrong....ie; missing files that the Trojan apparently was deleting. After running the disc, I was able to do the Micro Trend scan and Norton. They were 0 problems. They did flicker a pale yellow and pink when I ran them. All the other steps were 0 except for the HSRemove which fixed 8 things. I am attaching my logfile as requested. :cool: Thanks a lot......the other puter (my son and daughter in law's) is on hold for now until I have more time to work with it. It may have to be scrubbed and Windows reinstalled. :rolleyes:
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Trojan.Clicker.Instas.A

    You do not need to run HSremove or about:buster unless you are having HSA or about:blank hijacker problems. (Which you are not having) HSremove always reports 8 items being removed even on a totally clean pc. It is a bug.

    HijackThis logs must always be posted from normal boot mode unless requested otherwise. Yours was from safe mode. Please repost after you look at the rest of the stuff below.

    Do you use these AIM settings:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimtoday.com/search/aimtoolbar.jsp

    Some people consider these to be problems!

    Goto Add/Remove programs and uninstall: WeatherBug

    You have too many Toolbars. Do you use all of them? Do really use:
    - Real Toolbar
    - AIM Toolbar
    - MSN Toolbar
    - Google Toolbar
    - AdwareFilterToolBar <--- this one is malware - SpyAssasin. Look in Add/Remove programs for AdwareFilter or AdwareFilterToolBar or SpyAssasin and uninstall any of them if found.

    You want to know how many toolbars I have? Zero! I do not find them necessary.

    I tend to doubt that Windows Clean-Up Pro is needed or useful.
     
    Last edited: Jul 2, 2005
  5. writer997

    writer997 Private E-2

    Re: Trojan.Clicker.Instas.A

    Okie Doke........I removed everything you had on the list.
    Here is the HJT file in normal mode....I wasn't sure which mode you wanted it in. Thanks for taking the time to do this for me. ;)
    I didn't realize I had all that junk on there, although I did like the weather thingy, but I can do without it. :cool:
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Trojan.Clicker.Instas.A

    Try using this Weather Watcher instead of the malware containing Weatherbug.

    So I assume you want to keep Real Toolbar & MSN Toolbar?

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\Program Files\AdwareFilter\adwarefilter.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ms101.mysearch.com/sa/srchlft.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O4 - Global Startup: AdwareFilter Background Protection.lnk = C:\Program Files\AdwareFilter\adwarefilter.exe
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/2438d7c7946c22d3c101/netzip/RdxIE601.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\AdwareFilter <--- the whole folder
    C:\Program Files\AWS <--- the whole folder

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  7. writer997

    writer997 Private E-2

    Re: Trojan.Clicker.Instas.A

    Thanks.....I think I got it all....here is the next logfile. :D
     

    Attached Files:

  8. writer997

    writer997 Private E-2

    Re: Trojan.Clicker.Instas.A

    I still had to use my Backup Dell Installed Programs when I tried to load the Weather Watcher. So, something else is still going on in the puter. :(
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Trojan.Clicker.Instas.A

    I'm not sure what you mean. What to you mean your "Backup Dell Installed Programs"?

    What does this have to do with installing Weather Watcher?
     
  10. writer997

    writer997 Private E-2

    Re: Trojan.Clicker.Instas.A

    Yes, when I started to download, the pop up window came on and said I needed to insert my disc for Back up Dell Installed Programs. Not sure why. :confused: It worked after I used the disc though. :) Is something going on that I don't know about? :confused:
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Trojan.Clicker.Instas.A

    And are you saying this message came up when you started downloading? Or did it come up when you started installing the software for Weather Watcher?

    Is it giving you any indication of what it is supposedly doing at this time. I don't know why you would need to insert this CD to install Weather Watcher. It has nothing to do with any of the Dell Software installed on your PC.

    When I get PCs from Dell or Gateway, the first thing I do, is uninstall almost all the crap they put onto the PC. Most is unnecessary and unwanted/annoying and is only trial based software anyway.
     
  12. writer997

    writer997 Private E-2

    Re: Trojan.Clicker.Instas.A

    I uninstalled and reninstalled the Weather Watcher.
    It looks like when I try to download anything and run it ......that is when it pops up. It says......
    The feature you are trying to use is on a CD-Rom or other removable disk that is not available. Insert the Backup Dell Program disc and click ok. :confused:
    Do I need to run a Windows repair?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Trojan.Clicker.Instas.A

    You need to be more precise in your explanation.

    Is the problem when you:
    - try to install the program you downloaded
    - or when you try to run the program after installing it

    Is that all it tells you or does it give more detail!

    Does this happen for any program you try to install?

    Do you have all of your Windows Updates?
     
  14. writer997

    writer997 Private E-2

    Re: Trojan.Clicker.Instas.A

    I have all my Windows Updates.....That was the exact wording in the box...plus the browser box. It was when I was trying to run it. It works now. It wasn't a problem ;) :) :cool: during the download process, only when I was trying to open it to run it. Sorry, I wasn't more exact in what I was saying. I downloaded BIGFIX from your site to see if it would do it again., but it didn't. So, hopefully whatever the problem was, it is fixed now. Thanks Chaslang for all your help! When I get the other puter up to where I can do something with it, I will give you a holler! Thanks again!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Trojan.Clicker.Instas.A

    You're welcome.
     
  16. writer997

    writer997 Private E-2

    I keep getting the Dell Backup request to run the disc when I try to open any downloaded spyware tools. Got any ideas how to fix this? It is okay when I run the disc....but when I reboot, it does it all over again.
    I was wondering if something else is hidden somewhere that we didn't see.You said my logfile was okay.....so it must be something else or hidden real well.
    :confused:
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I do not believe this is a malware problem. It sounds more like a problem with your Windows Installation or some junk that Dell has installed. You should probably ask Dell why this is happening. It could some how be related to something they have done to install software on your PC and it could be related to Windows Installer. You could also check in the Software Forum.

    I doubt it has anything to do with running downloaded spyware tools. And do you mean run the installation of the downloaded tools? Or do you mean you already installed the tools and you are trying to run the programs themselves? This could happen for anything you download an install now (not just spyware tools).

    Please do not start new threads for problems you have already been working. I'm moving you back to your original thread.
     
    Last edited: Jul 11, 2005
  18. writer997

    writer997 Private E-2

    Thanks for getting back to me.....I will get Dell online to help me figure this one out then. Thanks for the come back. It was the downloaded programs I was trying to open. :D
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds