did read me first stuff - still need lots help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nukescott, Apr 9, 2005.

  1. nukescott

    nukescott Private E-2

    followed read me first instructions, but still have some items I can't permanently remove. I'm infected with adware.findspyware as found by symantec. I also have an extra toolbar under address bar with menus like "remove toolbar, pharmacy, adult, insurance, internet, gambling finance". I get adult popups and am often redirected to adult sites when I type in the address bar.

    I'm running windows ME

    specifically done the following :
    disabled autorecover.
    ran trendmicro virus scan. it found a trojan called TROJ_SMALL and said it cleaned it. Nothing else. I then ran symantec. It found adware.findspyware in C:\windows\system\sesmgr.exe. I deleted the file and made sure it was really gone by running ccleanup.

    I went to safe mode (can't get to internet from safe mode to do virus scans).
    ran spybot w/ addons. It found alexa_related in c:\windows\web\relaated.htm and removed it - which I confirmed.

    I ran ad-adware which found 2 critical objects - which it removed.
    ran stinger - didn't find anything
    ran about buster - nothing
    ran cws tool - didn't find anything.

    rebooted in safe mode and reran all scans (but virus scans) again, with nothing found. Rebooted normally (with autorecover disabled), and still have problems.

    I've run hijack this, but there isn't much there.

    How do I get rid of these 2 nasty bugs?
    Thanks
    ran cccleanup - cleaned a little.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. nukescott

    nukescott Private E-2

    here are two hijack this logs. one from safe mode, and the other from normal mode. Thanks.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you running msconfig to disable some things from loading:

    O4 - HKLM\..\Run: [MSConfigReminder] C:\WINDOWS\SYSTEM\msconfig.exe /reminder

    If so, run msconfig and select normal startup, then reboot an post a new HJT log. We do not need HJT logs from safe mode. They are typcically not that useful.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will also need to disable Spybot S&D's TeaTimer. It could block us from fixing some items.

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After doing the previous steps do the following:

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: ActiveX Control - {91287A97-0024-4FD4-BABE-01F77E614862} - C:\WINDOWS\SYSTEM\MSXBQ.DLL
    O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\SYSTEM\IE2CLTR.DLL
    O2 - BHO: IE SP2 AddOn - {69E8A624-9C57-47D7-A2F1-5F0B6782A57B} - C:\WINDOWS\SYSTEM\SPAKX.DLL
    O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\SYSTEM\IE2CLTR.DLL

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\SYSTEM\MSXBQ.DLL
    C:\WINDOWS\SYSTEM\IE2CLTR.DLL
    C:\WINDOWS\SYSTEM\SPAKX.DLL

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  7. nukescott

    nukescott Private E-2

    first I was running msconfig to greatly reduce the amount of junk that loads on startup. I turned everything back on (including stuff I've had off for many months). I get a LOT of stuff that loads that I think is useless. some compaq easy access button thing whines it's missing pieces. I'd rather only load what Ineed for the machine to run, with a reasonable level of security...

    2nd whatever I have/had clobbers spybot - had to reload it (several times). I think I turned of teatimer - but not positive.

    removed the 4 items you indicated with hijack this.

    DID NOT FIND the indicated dlls in C:\Windows\system... lots of other stuff but not those. Made certain i had hidden files on.

    ran the cleaner, rebooted, and the extra toolbar is gone (al teast for now). And I'm not seeing popups (at least not yet).

    Attached is a new log. Can you verify the original problem is fixed, and if possible, indicate what other stuff i can remove from startup - startup with all of this stuff takes forever. What do I need, and what's extra fluff?

    Thasnk so much.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tell me which stuff you normally did not want to load. We can in most case have HijackThis permanently prevent them from loading as long as you are sure you do not need them.

    As far as those DLLs you could not find, are you sure you have enabled viewing of hidden files and that you have unchecked the option to Hide extensions for know file types?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below two should be uninstalled using Add/Remove programs:
    O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
    O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup

    If you cannot find an uninstall, have HijackThis fix those two lines and then boot to safe mode and delete:
    C:\Program Files\SpyKiller <--- the whole folder
    C:\Program Files\BestPopUpKiller <--- the whole folder

    Then reboot and post a new HJT log.
     
  10. nukescott

    nukescott Private E-2

    I'm a bit hesitant to remove spykiler and the popup killer (especially spykiller). They are what I've been for a few months using to stop these items, and they load on startup. Are these problem prone, or potentially the cause of some of my problems? I did notice that spykiller found a few items that neither spybot nor ad-adware found, and that the detailed registry scan it does takes about 5 times longer to complete than either of the other products - so I suspect it may be better, but I'll admit to being uninformed.

    I can use spybot from now on, and I suspect i could load that on startup instead. Is this a better product.

    just want to verify that I should really delete software I've paid for and installed recently.

    Thanks again
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    SpyKiller is on this list http://www.spywarewarrior.com/rogue_anti-spyware.htm of rogue/suspect spyware removal tools. Read the information there for yourself. All products by this company should be suspect including their popup blocker (which is not needed if you switch to FireFox as a browser).

    I'm not sure what it is finding that the others are not but this is typical and in its case it could be false positives. If you want to see what I mean,. run download, install and run Spy Sweeper See if it finds anything after you have run SpyKiller.
     
  12. nukescott

    nukescott Private E-2

    ok things are working much better now, but I have one more Q - when I run hijackthis it looks as if I'm loading 3cmlink two times at startup (executables 8 and 10 in list). And when I surf the net, I randomly get error messages something like, "Explorer - 3cmlink caused an error... and will now close". It's been a problem for a long time - maybe it's best addressed in a different forum. Is this supposed to be running twice, and how do i stop it if it's not?
    Can I get rid of the 04 line in hijackthis that has 3cmlink listed? Any chance doing so will render teh computer useless?

    Thanks again
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Without the O4 line, your modem would more than likely not function properly.

    Have you tried looking for new device drivers for your modem? You right about this belonging in another forum (like Hardware for example).

    But let's take a quick look at Generating a StartupList log using HijackThis.

    Run HJT and on the first screen, click the button that says "Open the Misc Tools section". In the next window first select "List also minor sections (full)" and then click the button that says "Generate StartupList log". CLick Yes to the Do you want to continue prompt. Now a notepad window will come up with the Startuplist.txt file. It is already saved in the the directory HJT is running from. So just come back here and upload the file as an attachment to your next message.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds