Description of my "spyware "problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by krazykat, Dec 11, 2004.

  1. krazykat

    krazykat Private E-2

    Hello,

    I have been able to get rid of all but one "sypware" using Ad-Aware and Spybot. The one remaining is the appearance of http://anal.freegayspace.com about 1-2 minutes after I open MSN explorer or IE6. The pages usually have different url's like http://sbchbarchatthere.321.ch OR http://odgamechatthere.321.ch. I use WIN XP Home with SP2 and IE6. I have make a Kijack This log and would like to post for analysis.

    Thanks, krazykat
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis is the last step! You should attempt to follow ALL the steps in this Sticky thread < READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    If still having a problem after the above, you should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log file as an attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Make sure you have HJT version 1.98.2 and follow the guidelines on where to install it and how to post a log as an attachment.
     
  3. krazykat

    krazykat Private E-2

    chaslang & Sgt sweetie

    I have done all the things and scans you requested before I post. I still have the "porn page problem" whicl loads about 1-2 minutes after I open MSN explorer.

    The additional scans found 2-3 files which were removed.

    One additional item, that might mot might not be related: About 3 minutes fter logging on to my MSN account I receive the message that "MSN can not connect to the e-mail server" . I click OK to remove the error message ---- but I am now unable to go to any other web sites, even MNS home page. I get the "Page not founf "error. BEFORE the "can not connect to e-mail server" I have no problem connecting to any other web page eg. GOOGLE, CNN, MSN, majorgeeks.

    So, attached is my hijackthis log file for yor review. Thanks in advance for your time.

    There is no file attached because whenI click on "manage attachements" I do not receive a bouse window to go to the file. What am I doing wrong???

    krazykat
     
  4. krazykat

    krazykat Private E-2

    haslang & Sgt sweetie

    I have done all the things and scans you requested before I post. I still have the "porn page problem" whicl loads about 1-2 minutes after I open MSN explorer.

    The additional scans found 2-3 files which were removed.

    One additional item, that might mot might not be related: About 3 minutes fter logging on to my MSN account I receive the message that "MSN can not connect to the e-mail server" . I click OK to remove the error message ---- but I am now unable to go to any other web sites, even MNS home page. I get the "Page not founf "error. BEFORE the "can not connect to e-mail server" I have no problem connecting to any other web page eg. GOOGLE, CNN, MSN, majorgeeks.

    So, attached is my hijackthis log file for yor review. Thanks in advance for your time.

    There is no file attached because whenI click on "manage attachements" I do not receive a bouse window to go to the file. What am I doing wrong???

    krazykat
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Next time please run ALL steps of the READ ME FIRST. You never ran the online scans. Did you skip anything else?

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for any of the below processes and if found end them:
    bwqdkar.exe
    yawuha.exe
    msass43.exe


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    O4 - HKLM\..\Run: [ljrgemrdrbnp] C:\WINDOWS\System32\bwqdkar.exe
    O4 - HKLM\..\Run: [Windows Compliant] yawuha.exe
    O4 - HKLM\..\Run: [Windows Media Player] msass43.exe
    O4 - HKLM\..\RunServices: [Windows Compliant] yawuha.exe
    O4 - HKLM\..\RunServices: [Windows Media Player] msass43.exe
    O4 - HKCU\..\Run: [Windows Media Player] msass43.exe


    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\msass43.exe
    C:\WINDOWS\SYSTEM\blank.htm
    C:\WINDOWS\System32\bwqdkar.exe
    C:\WINDOWS\system32\yawuha.exe

    Now reboot in normal mode and post a new HJT log. Please attach it as a .log or a .txt file not a .doc file. And tell us how things are working.
     
  6. krazykat

    krazykat Private E-2

    Chaslang,

    THANKS for the reply and the instructions.

    I have followed your instructions and attached a new hijackthis log.

    After I made the corrections I went on line for about 10 minutes as a check and the porn pages DID NOT pop up as before. So, for the 10 minute test, they appear to be gone. I will do a longer test after I post this reply.
    Thanks again for your time, Let me know if there are additional instruction concerning the new hijack this log.

    AGAIN thanks, at least for the short test the porn pages did not pop up.


    I have added some comments/results, underlined, to some of your instructions. I could not complete some of the items, but I listed the things I was able to do.

    Next time please run ALL steps of the READ ME FIRST. You never ran the online scans. In safe mode my modem would not connect.( I did see that I could have completed this step in normal mode after a second read), Did you skip anything else? Not that I know of.

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for any of the below processes and if found end them:
    bwqdkar.exe not present
    yawuha.exe not present
    msass43.exe ended

    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\system32\msass43.exe deleted

    C:\WINDOWS\SYSTEM\blank.htm "blank.htm" not present in \SYSTEM. I did find it in C:\WINDOWS\SYSTEM\OOBE\BLANK.HTM but DID NOT DELETE also found C:\windows\PCHealth\HelpCtr\System\panels\blank.htm but DID NOT delete.

    C:\WINDOWS\System32\bwqdkar.exe NOT PRESENT. I did find this file C:\Documents and Settings\Allusers\Applications Data\Spybot – Search & Destroy\Recovery\CallingHomebiz.zip\bwqdkar.exe but DID NOT delete

    C:\WINDOWS\system32\yawuha.exe this exact file was not present but \yawuha.exe – up.txt was present---- I deleted.
    krazykat
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are still forget to post as a .log file or a .txt file. Please do not post .doc files for logs.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should reset your home page to whatever you normally use. Right now it is still set to


    <SPAN style="mso-fareast-font-family: 'MS Mincho'">R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
     
  9. krazykat

    krazykat Private E-2

    chaslang,

    THANKS for the reply and help. Looks like the problem is fixed --- no "porn" pages popped up during 2 hours of log on time.

    I have reset the IE home page to my normal URL. Should I need to post again I will remember to post a .txt file.

    As a preventive measure ----- are ther any "pro active" spy ware programs. Ones that scan and watch for known spyware and block install; so you do not need to do scans to clean up a mess after the program(s) load and do their dirty work?

    Norton AntiVirus and other anti-virus programs stand by and intercept virus programs and prevent install. Is there spyware programs that work the same way?

    THANKS again,

    krazykat
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds