did read and run but still having problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by wackojacko, Jan 2, 2006.

  1. wackojacko

    wackojacko Private E-2

    i still get a bar at the top of the screen telling me abolut spy ware and i can't get my home page to stay the same it always changes here is my hijack this log scan
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Step 6 of the READ ME requests two online scanner logs please attach them.

    Also step 7 gives directions for installing HijackThis properly. Please follow those steps and install HJT properly.

    Is this a contiunation of your other thread: i need help with a trojan adclicker

    If so, you must stay in one thread.
     
  3. wackojacko

    wackojacko Private E-2

    ok i re did the scans and re down loaded the hijack properly but it would not let me upload anouther of the hijack log scan thank you for your patience and help
     

    Attached Files:

  4. wackojacko

    wackojacko Private E-2

    ok sorry about that i found the files needed and here they are thankyou for your patience
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not have to re-download it. You just need to follow the directions to install it properly. The reason you cannot upload it again is because it is probably exactly the same as the last one which means you still did not install it properly and still have it running from:

    C:\Documents and Settings\admin\My Documents\HijackThis.exe

    You must follow the directions and create a c:\Program Files\HJT folder and then unzip the downloaded file into that folder.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your online scanner logs are a good example of why we enforce step 6 of the READ & RUN ME. This is just a statement of fact. There is nothing that you did wrong. I just wanted to point this out because when you look at the BitDefender log you will see tons of bad stuff deleted that would not show in a HijackThis log and it was not picked up by any of the other tools.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After getting HijackThis installed properly, continue with below.

    First empty your Norton Quarantine if anything is still in it.

    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\DOCUME~1\user\LOCALS~1\Temp\1F2.tmp.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R3 - Default URLSearchHook is missing
    O2 - BHO: Class - {9DCBB1DC-3AC3-F6EF-3D33-03958BE2C94C} - C:\WINDOWS\crln32.dll (file missing)
    O2 - BHO: Class - {BA72B260-086C-8201-41C8-0314544BE181} - C:\WINDOWS\system32\netew32.dll (file missing)
    O4 - HKLM\..\Run: [1F2.tmp] C:\DOCUME~1\user\LOCALS~1\Temp\1F2.tmp.exe
    O4 - HKLM\..\Run: [1F3.tmp] C:\DOCUME~1\user\LOCALS~1\Temp\1F3.tmp.exe
    O4 - HKLM\..\Run: [1F3.tmp.exe] C:\DOCUME~1\user\LOCALS~1\Temp\1F3.tmp.exe
    O4 - HKLM\..\Run: [1F2.tmp.exe] C:\DOCUME~1\user\LOCALS~1\Temp\1F2.tmp.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Documents and Settings\user\Local Settings\Temp\1F0.tmp <--- it would be best to delete all file allowed in this temp folder
    C:\Documents and Settings\user\Local Settings\Temp\1F2.tmp
    C:\Documents and Settings\user\Local Settings\Temp\1F2.tmp.exe
    C:\Documents and Settings\user\Local Settings\Temp\1F3.tmp
    C:\Documents and Settings\user\Local Settings\Temp\1F3.tmp.exe
    C:\Documents and Settings\admin\Favorites\SITES ABOUT\Ab scissor.url
    C:\Documents and Settings\admin\Favorites\Only sex website.url

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Reminder Note: Once we have determine you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. wackojacko

    wackojacko Private E-2

    hello i got hijack this into the right place finally but when i pressed fix and then went into safe mode i don't know how to find the files i right click on start to get to explore and go to the cthe files i need to c: drive but then can't find the files i need to delete can you tell me what exactly i need to do thanks again for your patience
     
  9. wackojacko

    wackojacko Private E-2

    hey thanks for your help here is my final hijack this log thanks for all your help i'm really thank full for all your help

    your new friend and loyal fan

    jack
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's rather simple. There is not too much to explain. After opening explorer just expand the folders in the left pane until locate where you want to get to and click on it. It is like opening a file cabinet and looking thru the folders stored in it and in each folder of the file cabinet there are more papers which is the same as the files in the folders on your disk drive.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You HJT log is clean. Just make sure you look for an delete the files if they are still there.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds