Did 1-6, please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by jclaxton, Jan 8, 2006.

  1. jclaxton

    jclaxton Private E-2

    Hi community,

    I'm running Windows XP. Every time I go online, I immediately get adware, "tracking" bugs, and sometimes other items. I know that this is happening becauase if I run Spyware Doctor just after opening my browser, then delete the bugs found, within minutes I have new problems.

    If you can't read between the lines (read: my use of generic terms like "bugs" and "problems"), I'm not very computer savvy. That said, the post for steps 1- 6 was easy enough for me to follow. I hope that anyone responding to this will assume a very basic level of computer literacy when giving advice. I would really appreciate some help.

    When doing steps 1-6, Ad-Aware found and deleted "trojans," and Bitfinder deleted about 3 trojans (I think) but informed me that it couldn't delete some of the other problems.

    I have attached copies of my Bitdefender and Panda scans.

    Thank you so much for your help. What a great service.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MGs.

    If by the words "adware", "tracking", and bugs you are referring to cookies, there is really no problem. Cookies are normal and in many case can be very useful. The only real way to totally avoid cookies is not to surf. You could also take the approach to block all cookies but you will find that approach not very useful since you will have problems accessing many websites.

    Let's see if you have anything to be concerned about. Continue with step 7 of the READ & RUN ME and attach a HijackThis log.

    The below items were in your Panda log and we should delete them at a point, but let's see the HJT log first.

    C:\WINDOWS\system32\per.exe
    C:\WINDOWS\SYSTEM32\t.exe
    C:\Documents and Settings\lawstudent\.jpi_cache\jar\1.0\java.jar-8fba448-1d67b4be.zip[Installer.class]
     
  3. jclaxton

    jclaxton Private E-2

    Thanks so much for your help.

    I've attached my HJT log. Another word about my problem: On a couple of occasions, Spyware Doctor turned up more than cookies. I didn't write down the names of what it found, but I think it classified them as 'trojans.' This happened right after I ran a clean scan and opened my browser. It makes me think that something on my computer is automatically downloading these things when I go online. Maybe I'm just being a computer hypochonriac. Is there a techie name for that? If not, there should be. Anyway, please let me know what I should do, and if you see anthing at all on my log that you think I can or should do without, let me know. Again, I'm not too savvy when it comes to computers.
     

    Attached Files:

  4. jclaxton

    jclaxton Private E-2

    One little addition: I have a program called SoftTest on my computer for taking exams. I know that it automatically saves an encrypted copy of the exams I take somewhere on my hard drive. I just wanted to point that out it case it turns up in some strange form on my HJT log.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is your copy of Spyware Doctor a purchased version? I would need to know exactly what it is finding before I could help you with that. If it was finding the stuff I will have you fix below, you should ask them why they could not fix what they detected (that is only if you bought it).

    You have some remnants of a form of about:blank hijacker. You should run the below tool twice and attach the log later when you come back.
    about:Buster

    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\per.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\LAWSTU~1\LOCALS~1\Temp\se.dll/space.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\system32\per.exe internat.dll,LoadKeyboardProfile
    O18 - Filter: text/html - (no CLSID) - (no file)
    O18 - Filter: text/plain - (no CLSID) - (no file)
    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Setting\lawstudent\Local Settings\Temp\se.dll <--- empty the whole Temp folder
    C:\WINDOWS\system32\per.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Reminder Note: Once we have determine you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. jclaxton

    jclaxton Private E-2

    Ok. I did exactly what you said, and I have attached the logs you requested to this message. Do they look clean? My computer seems to be running fine.

    Thaks again for your help.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you look clean now. You forgot to answer my question about Spyware Doctor. Is it a paid version that you keep updated?
     
  8. jclaxton

    jclaxton Private E-2

    It is a paid version. I probably wasn't clear in my post. The items that couldn't be erased couldn't be erased by Ad-Aware (according messages that popped up after I ran that scan). Spyware Doctor always erases the advertising and tracking cookies it finds. I just found it strange that after I erased everything found (with my browser closed and by cable unplugged), simply opening my browser after that would lead me to have new tracking and advertising cookies. This happened before I surfed at all: I would clean using SD, open a browser, then immediately run SD again, and it would always find at least 2 new cookies, usually one it labeled "advertising" and one it labeled as "tracking." My home page is nothing squirrelly; it's a national newspaper. At any rate, I'm thrilled that you helped me and that my log looks clean. I really appreciate it.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Advertising cookies are mostly harmless. So are MRUs. Too many programs spend too much time pointing out cookies and MRUs and do not do an effective job fixing the real problems like you had. (The per.exe file and the about:blank hijacker.)

    Don't waste your time worrying about cookies! You are going to get them as soon as you do ANY surfing (i.e. just opening your browser will load a page).

    Now since you use a paid version of SpywareDoctor, I would uninstall MS Antispyware. Using two full blown antispyware detector/scanner/blocking programs like these two can slow your system time and cause conflicts.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  10. jclaxton

    jclaxton Private E-2

    Thanks. I just uninstalled MS Antispyware and followed you other insructions about system restore. You were incredibly helpful.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds