help needed with spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by cookieboy, Feb 10, 2005.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What about regmon?
     
  2. cookieboy

    cookieboy Private E-2

    sorry my mistake -copy/pasted your instructions and missed of bottom paragraph.can i still get file
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nope! You'll have to do it again! This time before starting, shut down all other processes including your Avast antivirus application (should help to reduce the size).

    Do not start filemon until everything else is ready to go!
     
  4. cookieboy

    cookieboy Private E-2

    have tried this regmon doesnt seem to be capturing anything (did the 1st time)
    sorry to be a pain
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you configure the parameters again? Is the line actually back in your HJT log right now?

    Make sure you exit every unncessary application (AV and Firewall too) especially Internet Explorer before starting Filemon. Make sure everything is setup (ready to click fix in HJT, and regmon is already running and setup) before starting filemon. Otherwise the file gets too big and hard to analyze. After the capture is done you should make sure you stop the Filemon asap. Also restart your PC to get your AV and firewall running. You do not want to run without them too long.
     
  6. cookieboy

    cookieboy Private E-2

    when i open regmon it goe staight to the previous filter settings if i ok this it goes to regmon but the large window is blank and nothing seems to monitered. if i follow the instructions through the log file i save is empty.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try erasing the filter settings and OKing that. Then exit Regmon and hopfully it is like starting over. You said you were able to get it to capture last time on the filters I had you set? Is that true?
     
  8. cookieboy

    cookieboy Private E-2

    have tried that already, also deleted regmon and unziped it again but it still goes staight to the filter box . when i did it 1st time the was lots of lines changing in the main window i dont get that now
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try using nothing for the filter and then try making the R1 line fix.

    For filemon, set the filter to c:\windows\user.dat
     
  10. cookieboy

    cookieboy Private E-2

    ok enclose files nothing in regmon
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We need to get Regmon to trigger! Make sure you do not have capture disabled. Look at the magnifier glass and make sure does not have a red mark in it. You can also see it under the File menu. Make sure Capture is checked.

    Try setting the Regmon filter to:
    CurrentVersion; ProxyOverride
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have to get some sleep now! See if you can experiment here and get this to work. Otherwise we will have to continue later.

    Good Night!
     
  13. cookieboy

    cookieboy Private E-2

    ok many thanks for your continued supprt. seemed to work this time enclose logs. dont know if this helps but rebooting clears the R1 line it only comes back when online.
    enclose logs
    cheers
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks to me like something you have setup with Avast, is changing your dial settings:

    1342 16.95480960 Ashserv:FFE1CCE7 OpenKey HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings SUCCESS hKey: 0xC29E2000
    1343 16.95482320 Ashserv:FFE1CCE7 QueryValueEx HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableAutodial SUCCESS 1 0 0 0
    1344 16.95483360 Ashserv:FFE1CCE7 QueryValueEx HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\NoNetAutodial SUCCESS 0 0 0 0
    1345 16.95484800 Ashserv:FFE1CCE7 SetValueEx HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableAutodial SUCCESS 0x0
    1346 16.95485760 Ashserv:FFE1CCE7 SetValueEx HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\NoNetAutodial SUCCESS 0x0
    1347 16.95486800 Ashserv:FFE1CCE7 CloseKey HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings SUCCESS

    As far as the ProxyOverride R1 line, I see the HJT fixing of it but I do not see anything bringing it back in your log. Perhaps at this time when you captured it. It did not come back yet. We need to see that. What filter settings did you have on Regmon?

    Try these:
    ProxyOverride;Internet Settings;EnableAutodial

    Don't bother with Filemon this time. Make sure you wait long enough or do something than makes the R1 line come back before stopping Regmon. I guess something like, Fix with HJT and then open a browser is sufficient based on what you said. If so, as soon as you open the browser, stop Regmon's capture.
     
    Last edited: Mar 11, 2005
  15. cookieboy

    cookieboy Private E-2

    hi CL
    good morning! seems strange - its evening here
    regmon filter last time was current version;proxyoveride
    didnt open ie last time
    enclose new log -cheers
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well according to that log, it looks like your system is configured to use a proxy server and Internet Explorer is changing the settings to add https:// back in. You need to check you configuration to make sure you're connection is setup properly.

    Boy it was a bad idea to use Internet Settings in the filter!
     
  17. cookieboy

    cookieboy Private E-2

    what should i be looking for ? is there any way i can send you the settings?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run Regedit and navigate to the below key:

    HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings

    Then click on File and select Export. Give it a filename like IEsetttings (a .reg will automatically be added to it). And save it where you can find it. You will need to compress this into a ZIP file and the upload it here.

    Did you take a look at you Avast settings like I suggested?
     
  19. cookieboy

    cookieboy Private E-2

    hi just got back to pc
    enclose settings - will check avast
    cheers
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm still looking at all of your settings. You have a bunch of items in there that I do not know what they are. But one thing is for sure, you have AutoDial enabled. There is a key saying:

    "EnableAutodial"=dword:00000001

    Here is a full list of items that are either different than I expect (compared to my settings) or that I do not have at all.
    You also show a bunch of connections (I thought you said you are not on dialup? Did you use to use dialup? Do you have to do anything special to connect to the internet?

    Here are the names of the additonal (other than defaults) connections I see:
    "CallNet"
    "Direct Connection"
    "Freeserve For Eastdon"
    "OneRel.Net"
    "Freeserve for ryders.fslife.co.uk"
    "Connection to onetel.net"
    "tiscali new"

    You must be using some kind of special connection mechanism.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is your Security level set to in Internet Explorer?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should see step 7 in the below thread and configure items as it indicates but before setting any of those options, after you click the Custom Level button, at the bottom in the Reset custom settings area, first Reset to Medium and click the Reset button. Then make sure you other settings are as I give in step 7.

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds