For the love of god!!!! I need advice!! SPYWARE!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Insanity_Rules, Mar 27, 2005.

  1. Insanity_Rules

    Insanity_Rules Private E-2

    ok, well i got some spyware, now i also have hijack this. i'm familiar with the software, yet i have no idea where this spyware is. here's my hijack log:

    Logfile of HijackThis v1.99.1
    Scan saved at 11:26:51 AM, on 3/27/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Edit by chaslang: Unrequested inline log removed

    I understand that it's a lot but please help...
     
    Last edited by a moderator: Mar 27, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have an HSA hijacker. We require that you follow the steps in our sticky threads before posting HijackThis logs and we also have guidelines on when and how to post the logs. Please follow the steps below.

    You should also uninstall LimeWire as it is a source of adware/spyware.


    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Insanity_Rules

    Insanity_Rules Private E-2

    ok... I've downloaded all those spyware tools and did all the scans, yet i still have the problem. Porn links keep getting added to my favorites, my home page keeps going to the "about:blank" page even after i've changed it. :confused: I'm stumped. So i downloaded the new hijack this and ran it like you said and now i have the log as a attachment to this posting. You've been such a help already, thank you. However i need to get rid of this prob. anything in the hijack log that shouldn't be there please tell me to delete it.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about this but HijackThis logs must posted from normal boot mode unless otherwise requested. I will try to give you a fix below but without a normal boot mode log this may not work. Also if you have rebooted since posting your log, some filenames may have changed.

    Also one additional note, in my first message I specifically requested that HijackThis not be installed to the Desktop which is where you have it:

    C:\Documents and Settings\Dan\My Documents\HijackThis.exe

    Before starting the procedure in my next message please correct this and install it as requested.

    Is there a reason why you did not run the Trend Micro online scanner?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have Kazaa installed, you must uninstall it.
    Also look in Add/Remove programs for the below and uninstall if found:
    P2P Networking2


    Make sure you have both about:Buster and HSremove downloaded from the READ ME FIRST. And make sure you have UPDATED the database for about:buster. I believe it is up to number 25.

    You need to print or save these instructions locally because after this reading this sentence you will need to physically unplug your connection from your cable, ADSL, or dial-up modem to your PC and then you MUST exit all browsers and DO NOT run any again until requested.

    Okay, unplug your internet connection and exit browsers now!!!!


    First click Start, Run, and enter services.msc and click okay.
    Now locate the Workstation NetLogon Service in the services list and double click on it. Now stop the Workstation NetLogon Service and then disable it.

    Now close the services.msc window (unless the service appears to have restarted - we'll come back to this if necessary later).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    P2P Networking2.exe
    C:\WINDOWS\system32\Isass.exe <--- this begins with capital "i" , it is not a lower case "L"
    C:\WINDOWS\system32\sdkkx32.exe
    C:\WINDOWS\system32\crra32.exe
    C:\WINDOWS\mfcdm32.exe

    After killing all the above processes, click "Back" button that is just under the process list next to the Run button.

    Select the "Delete an NT service" on the left-hand side. A "Delete a Windows NT Service" window will pop up. Try entering the following into the box and then click OK:

    Workstation NetLogon Service

    If that does not work try cutting and pasing in the following short name: 11Fßä#·ºÄÖ`I
    You must use cut and paste since the characters cannot be easily typed.

    Tell me what happens while doing the above. If you are told that the service must be stopped. You need to go back up to where we stopped and disabled this service as mentioned previously. Then repeat the above steps to have HJT Delete this NT Service.

    After killing all the above processes and deleting the NT Service, click "Back" on the lower right. Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now (DO NOT OPEN ANOTHER BROWSER UNTIL AFTER POWER DOWN AND POWER UP, see below):
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\umfvl.dll/sp.html#44768
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\umfvl.dll/sp.html#44768
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\umfvl.dll/sp.html#44768
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\umfvl.dll/sp.html#44768
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\umfvl.dll/sp.html#44768
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\umfvl.dll/sp.html#44768
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {EE3CA21E-372C-DE90-33D0-A3C66AF29F68} - C:\WINDOWS\system32\javadk.dll
    O4 - HKLM\..\Run: [P2P Networking2] C:\WINDOWS\system32\P2P Networking\P2P Networking2.exe /AUTOSTART
    O4 - HKLM\..\Run: [Isass] C:\WINDOWS\system32\Isass.exe
    O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\Program Files\Internet Explorer\IEXPLORE.EXE
    O4 - HKLM\..\Run: [sdkkx32.exe] C:\WINDOWS\system32\sdkkx32.exe
    O4 - HKLM\..\RunServices: [Isass] C:\WINDOWS\system32\Isass.exe
    O4 - HKLM\..\RunOnce: [crra32.exe] C:\WINDOWS\system32\crra32.exe
    O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
    O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\mfcdm32.exe (file missing)

    Then exit HJT after clicking FIX

    Run Windows Explorer and look for and try to delete (sort the listing in windows explorer by Modification dates and look for possibly other similarly name files from the same date - let me know if you find others even if they have different 3 character extensions like .dat, .ini, .dll, .exe but DO NOT delete anything on your own.):
    C:\WINDOWS\umfvl.dll
    C:\WINDOWS\system32\javadk.dll
    C:\WINDOWS\system32\P2P Networking <---- the whole folder
    C:\WINDOWS\system32\sdkkx32.exe
    C:\WINDOWS\system32\Isass.exe
    C:\WINDOWS\system32\crra32.exe
    C:\WINDOWS\mfcdm32.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. If you cannot find or delete them, note which ones and continue (tell me the results when you come back here).

    - Run about:Buster and save the log to ab1.log (make sure you let it do the second scan).

    - NOW PULL THE POWER PLUG TO YOUR PC! Yes, you read that correctly. This is very important! I do not want you to power down the normal way.

    - After that wait a minute or two and then power up into safe mode (still with no internet connection available and do not open any browsers). Only run what I request.

    - Empty your Recycle Bin and delete all files in the c:\windows\prefetch folder. In fact as an additional measure do the following, run Ccleaner that you installed while running the READ ME FIRST.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    - Run HSremove and then run about:Buster again and save the log to ab2.log (let it do second scan)!

    - Immediately after about:buster completes, reboot in normal mode. (you do not need to pull the powser plug here. Just reboot.)

    - Plug your cable to the internet back in now.

    - Open and close a couple of IE sessions and then with IE closed get a new HJT log.

    - Now come back here and post both about:Buster logs and the new HJT log. And tell me what happened during the procedure.

    Let me know anything else that you notice.
     
    Last edited: Mar 28, 2005
  6. Insanity_Rules

    Insanity_Rules Private E-2

    Wow, it seems to have worked. No more "BS" home page, the favorites don't come back. nodda!!!! thank you so much!! here's the hlt log and buster log.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds