ehg_comcast hitbox fastclick adserver malware problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by chixinixi, Feb 4, 2006.

  1. chixinixi

    chixinixi Private E-2

    Hi Guys:
    Have an HP a 810n running Windows XP. Have an ongoing problem with LOTS of spam and some constant adware. I have run AdAware, Microsoft AntiSpyware and Ewido in safe mode to delete adware but it comes back udner HP-owner cookies. I have taken a look at the running processes online and can't find anything fishy. Can't figure out the problem here. Can you help?

    Here is my Hijack This log

    • Edit by bjgarrick: Unrequested, Inline HJT log removed!
     
    Last edited by a moderator: Feb 4, 2006
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Welcome to MajorGeeks.com!

    Please follow forum guidelines and perform cleaning steps in the sticky thread before posting HijackThis logs.

    Now, please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    http://www.majorgeeks.com/images/grenade.gif Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    • Make sure you check version numbers and get all updates.
    http://www.majorgeeks.com/images/grenade.gif Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    http://www.majorgeeks.com/images/grenade.gifAfter doing ALL of the above and you still have a problem, make sure you have booted to normal mode and run the steps in the below thread to properly use HijackThis and attach the log:

    http://www.majorgeeks.com/images/grenade.gif Downloading, Installing, and Running HijackThis
     
  3. chixinixi

    chixinixi Private E-2

    Sorry regarding previous post.
    Downloaded and saved hijack this as directed.
    What does about:blank issue mean?
    Enabled viewing hidden files.
    Running Norton antivirus and antispam.
    Ran AdAware, Ewido, Microsoft antispyware in Safe Mode. Repaired and Saved log files.
    Ewido found doubleclick Hitbox, and tribal fusion cookies which never seem to delete permanently. Similar found with with AdAware. Microsoft antispy found nothing.
    Disabled then re enabled system restore.
    Hope it's okay to attach reports and HJT log.
    Hope you will let me know what you think and advise.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must complete step 6 of the READ & RUN ME.

    I don't know what you are referring too with your question:
    What are you reading?
     
  5. chixinixi

    chixinixi Private E-2

    Thank You.
    Ran Microsoft Windows MalSoftware removal-found nothing.
    CWShredder- nothing
    Kill2me said fixed look2me infection if present

    In HJT under configure
    Default screen: About:Blank
    Wonder what that means.

    Ran Bitdefender (report attached)
    Ran Panda Active Scan (report attached)

    Please advise.

    Thank you most kindly.
     

    Attached Files:

  6. chixinixi

    chixinixi Private E-2

    Also ran another HJT log in case it's needed.
    Hope it's okay to attach.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's get an installed programs list from HijackThis.

    Run HijackThis, click Open the Misc Tools section
    Click "Open Uninstall Manager"
    Click "Save List" (generates uninstall_list.txt)
    Click Save, to save it to a file where you can find it.
    Upload this file as an attachment too.
     
  8. chixinixi

    chixinixi Private E-2

    List as requested.
    Thank you for your help.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not have any real malware problems to be concerned with. You can do the below:


    Steps to delete f3initialsetup1.0.0.8.inf:
    - Click Start, Run, and enter cmd in the box and click OK. This opens a command prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s f3initialsetup1.0.0.8.inf
    del f3initialsetup1.0.0.8.inf
    exit


    If you were worring about cookies, don't! They are normal and you will always have them unless you never surf. You can just clean the ones you want to remove using CCleaner or similar and keep the ones you want.
     
  10. chixinixi

    chixinixi Private E-2

    When I hit run cmd OK a screen comes up with
    C:Documents and Settings\HP_Owner>

    When I hit enter it duplicates itself.

    Should I be using another key to move to the next line and do the steps you recommend?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's just the prompt! Enter the commands I gave you. After the first command (the one with cd) the prompt will change to show the C:\WINDOWS\Downloaded Program Files>
     
  12. chixinixi

    chixinixi Private E-2

    I think somethng might not be right here (or I am ignorant.)
    I cannot type under the line following
    C:Documents and Settings\HP_Owner
    I hit enter and it moves the curser only to duplicate the same.

    I can only type the lines you recommend following the "prompt" , but it doesn't show
    C:\WINDOWS\DownloadedProgramFiles>
    is not recognized as an internal or external command

    When you say "that's just the prompt!" I don't know what that means.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you open the command prompt window, it opens up and displays the current directory that you are in. It does this by having the prompt (the text you are seeing) set to be the current directory followed by the greater than sign (the >). A prompt basically let's you know the computer is ready for to accept you next command. So when you open the command prompt it should show below text and to the right you will enter the first command (which I show in bold):

    C:\Documents and Settings\HP_Owner> cd C:\WINDOWS\Downloaded Program Files\

    Then you hit the enter key and the prompt should change to:

    C:\WINDOWS\Downloaded Program Files>
     
  14. chixinixi

    chixinixi Private E-2

    Thank you for your patience. I think I got that done properly. What did it do?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you did all of the commands, it deleted a file in that folder that PandaActiveScan detected. It listed it in your log as:

    Code:
     
    Potentially unwanted tool:application/funweb    Not disinfected C:\WINDOWS\DOWNLOADED PROGRAM FILES\f3initialsetup1.0.0.8.inf
    
     
  16. chixinixi

    chixinixi Private E-2

    I did all of the commands.
    What about the other things detected in the Panda file and the other antivirus scan?
    Also what do you recommend to get rid of the obnoxious amount of spam I am getting? I have Norton antispam on the highest setting and I am using the setting on the comcast preferences. Can I do anything else?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Panda only detected cookies which I alread told you about.

    Bitdefender deleted what it found.

    Spam is not really malware. If is no different than getting junk paper mail from you mailman everyday. Spam is due to you getting your email address on spam lists. Once you are on one, you wind up on more. Don't ever reply to spam emails. Even when they say click here to be removed. All that does is confirm your email address is valid and you will get more spam. Also be careful who you give you email address to. Spam filtering programs are far from perfect. If you really are annoyed with the spam, don't use that email account anymore for anything. Just get a new email address and don't give it to anyone accept people you really want to have it. Use the one that is getting spammed now for when you order stuff on line or need to give an email address on line to access websites etc. That way all your spam goes to your "spam collector email address" and you just dump most of what comes into it.
     
  18. chixinixi

    chixinixi Private E-2

    Okay.
    Thank you.
    I always send the spam to Report As Spam without opening it.
    Guess I need to think of a new email address.
    Thanks for everything!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to open a new email account somewhere. You cannot just change your email address. What do you use for an email account? (like hotmail.com, msn.com, etc).

    You're welcome.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well what I said is not quite correct. Depends on who you get email from. If it is from your ISP. You should be able to change your email user name.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds