Got stuck following instructions

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by topshelf, Dec 14, 2004.

  1. topshelf

    topshelf Private E-2

    Please help... I am trying to remove a spyware virus from my computer by following the advice in your public postings and have reached a point where I need some additional help. I have followed the directions in Major Attitude's "Spyware, Trojan and Virus removal" and did not remove it so I printed the instructions in Chaslang's "Generic Solution to HSA & About:Blank hijack" and have gotten stuck on step #5 because I do not have a path and filename listed in the R0 & R1 lines of my HijackThis log that is in the form that the instructions say it should be. My R0 & R1 lines appear as follows:

    R0 - HKLM\Software\Mircosoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com

    R1 - HKCU\Software\Mircosoft Internet Explorer\Main,Window Title = Mircosoft Internet Explorer provided by Comcast

    If anyone could help me to get past this step, I would greatly appreciate it. Thanks!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! That's because HSremove has already been run and has changed the symptoms. Please follow the below guidelines and post your complete HJT log. Also, tell me your expected (desired) home page.

    Make sure you have HJT Version 1.98.2 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. topshelf

    topshelf Private E-2

    Ah… ok. I have attached my HJT log. My home page should be www.aol.com. The virus had changed it to something else, but after I performed the spyware removal instructions that I read on the forum, it is working again. Unfortunately, my desktop background is still changed and I am still getting pop-ups that say that there is spyware on my computer. Thanks again for your help!!!
     

    Attached Files:

    • HJT.txt
      File size:
      4.2 KB
      Views:
      4
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really must get your updates from Microsoft! You are out of date and that is not safe.

    Please download the lastest HijackThis (just came out) and use it from now on: HijackThis 1.99

    Make sure you have system restore disabled and viewing of hidden files enabled.
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O2 - BHO: Cls - {CF021F40-3E14-23A5-CBA2-7173706D1316} - C:\WINDOWS2\System32\spm1316.dll (file missing)
    O2 - BHO: (no name) - {DFB9F770-4BB1-4834-B075-0C75E59E4943} - C:\WINDOWS2\System32\jmmkb.dll (file missing)
    O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS2\System32\runsrv32.exe
    O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS2\System32\runsrv32.exe
    O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
    O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
    O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS2\System32\runsrv32.exe


    Let's Reset Web Settings now:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to www.aol.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    If your background is still messed up! Right click on your Desktop, select Properties and then change your background.
     
  5. topshelf

    topshelf Private E-2

    I don't seem to be getting the pop-ups anymore, but I still can't seem to change the desktop background. Do you have any idea why? I have attached a new HijackThis log. Thanks!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You log looks good. For the Desktop problem, try this.

    Right click your Desktop, select Properties, Desktop tab, click Customize Desktop, click Web tab. Make sure down at the bottom you do not have Lock Desktop items checked. Also in the Web Pages box make sure nothing is checked and tell me what you see in that box.
     
  7. topshelf

    topshelf Private E-2

    The only thing in the Web Pages box is "Security" and it is checked. Do you think that is what the problem is?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds