completed procedures, desktop still hijacked

Discussion in 'Malware Help (A Specialist Will Reply)' started by jperry, Dec 29, 2005.

  1. jperry

    jperry Private E-2

    Hello,

    I've been working on all of the procedures listed to remove spyware, I followed the general removal procedures as well as the spySheriff procedures but my desktop is still being held captive. I have not been able to this work in Safe Mode. I am attaching the requested logs for you to view and hopefully to help me out.
    Thank you in advance,
    Jim
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MGs.

    Please follow step 7 of the READ ME and install HJT properly. You are running it from the ZIP files. Also remember to exit browsers before running HJT.
    Also attach the required BitDefender log.
    Why can't you boot into safe mode? Explain the problem! SmitRem will not work properly if run in normal boot mode.

    You also need to uninstall Spyware Cleaner. It is a rogue tool that is not going to help you.
     
  3. jperry

    jperry Private E-2

    Hello,
    Please find my HJT log attached, I have saved HJT and run the scan and saved the file correctly. I am also attaching the BitDefender log as well. I am not able to start up in safe mode right now because I don't have the administrator pass word from our network adminstrator. My computer was set up at work on our network so I need the administrator password for safe mode. Hopefully I will have the password soon. I believe our network administrator is out of town and has not returned my calls at this time. I do not see Spyware Cleaner anywhere that I can delete it. I thought I had already deleted this program. Any further help is greatly appreciated.
    Thanks,
    Jim
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot
    O9 - Extra button: (no name) - SolidConverterPDF - (no file)
    O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
    O18 - Filter: text/html - (no CLSID) - (no file)
    O18 - Filter: text/plain - (no CLSID) - (no file)

    After clicking Fix, exit HJT.
    Reboot and see if you can delete the below using Windows Explorer:
    C:\Program Files\Spyware Cleaner <--- the whole folder


    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    How are things running at this time?
     
  5. jperry

    jperry Private E-2

    Hello,

    I followed all the steps from your most recent reply except I still cannot find Spyware Cleaner so I have not been able to delete this. Can you give me more specific instructions on where to find this. I cannot locate it in Program Files.
    My desktop still remains captive.
    Thank you,
    Jim
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is possible that just the registry entry remained that I had you fix. The folder may already have been gone! Continue with the below:

    Fixing Locked Desktop
    Also you should right click on your Desktop and select Properties. Then click the Desktop tab and then the Customize Desktop button. Now in the next window that comes up click the Web tab. Make sure at the bottom that Lock desktop items is unchecked. Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too. Then click OK. Apply. OK.

    Now attach a new HJT log and also let me know if your Desktop problem is fixed.
     
  7. jperry

    jperry Private E-2

    Thanks,
    My desktop is back in working condition and all seems fine on my computer.
    I've attached the HJT log after going through you most recent procedures.
    Thanks again,
    Jim
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Now that you are clean make sure you do step 1 of the READ & RUN ME to dump bad restore points and then continue onto the below:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds