Help removing Spyware/Virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Wcamper, Nov 2, 2004.

  1. Wcamper

    Wcamper Private E-2

    I have been having several problems with my computer that I think are virus related. Planet nana website keeps opening, my javascript is disabled and I cannot enable it, internet explorer is slower than normal and my computer shuts down (blue screen) after using internet explorere for a couple of minutes. I have run AVG, The Cleaner, spybot and Adaware and cleaned everything out but it just comes right back again.

    Last night I followed the directions on "How to: Spyware, Trojan and Virus Removal". I disabled System restore (step 1). I did not find any of the services listed in step 2. I enabled viewing of hidden files and unchecked the hide file extensions for known types (step 3). I downloaded all of the tools listed in step 4.

    I performed an online scan at Trend Micro and found and deleted 4 viruses. I performed an online scan at Symantec and did not find any viruses. Both of the online scans were performed in normal mode because I could not get my computer to connect to my ISP in "safe mode with networking". I am running Windows XP home edition with SP2. I then rebooted in safe mode and ran AVERT stinger (no problems detected), CCLeaner, Ad-Aware SE (275 problems), Spybot (4 problems), CWshredder (no problems), Kill2me (no problems), about:buster (no problems) and HSRemove (no problems).

    I then rebooted and went to Internet Explorer to see if I stil had the problems I was having. My javascript was enabled and I did not get the blue screen. Spyware blaster blocked a file evertime I went to MSN.com (sorry but I forgot to wrtite down the name). Internet explorer still seemed to be running very slow, but I only have dial up so that is a judgement call. After I logged off from Internet explorer and my ISP my computer made several attempts to reconnect to my ISP that were not initiated by me, so I don't think I have everthing cleaned out of my computer. I ran Hijack this and saved the log file. I am not very confident in interperating this file but it seems to me that I have a lot in my file, which further supports my feeling that my computer is not yet clean. Can someone look at my hijack this file or give me other suggestions as to what Else I can do from here?

    Thanks in advance,

    Bill :rolleyes:
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wcamper,

    Thanks for taking the time to write a nice detailed summary of what you have tried. This is good info for us and it also lets us know that you have run each and every step. It also gives positive reinforcement to the usefulness of the procedures as you can see they did find and fix many things.

    Make sure you have HJT Version 1.98.2 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. Wcamper

    Wcamper Private E-2

    I have the HJT file from Monday, but yesterday (Tuesday) my wife attempted to use the computer, went on line and got several blue screen shutdowns. I'm not sure what else was reloaded yesterday so I will rerun all of the virus scans tonight, get a new HJT file and post it tomorrow morning.

    Thanks for the help.

    Bill
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay Bill! Post it as an attachment when you get it.
     
  5. Wcamper

    Wcamper Private E-2

    I ran through the complete "How to: Spyware, Trojan and Virus Removal" process again as I detailed in my intitail post. Everything came up clean except Spybot found 4 problems under "DSO Exploit" and Kill2me said it removed Look2me if it was present.

    Attached is the hijack this log file.


    Bill
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the version of Spybot you have and download, install and repeat your safe mode scan with: SpyBot-Search & Destroy 1.3.1tx

    The DSO Exploit problem (a bug in Spybot) should be gone.

    I'll look at the HJT log later! I have to run right now.
     
  7. Wcamper

    Wcamper Private E-2

    I downloaded SpybotSD 1.3.1tx, removed the existing version of spybot using the remove programs in the control panel, and installed SpybotSD 1.3.1tx. The installation gave several errors:

    SpybotSd.exe unable to locate component
    This application has failed to start because framedyn.dll was not found, re-installing the application may fix this problem.

    when I tried to update I got:

    The external update application has been corrupted please make sure you download the "updater" update to replace it.

    The external "blindman" application has been corrupted please use the update function to get it again.


    I checked for and downloaded all the updates and got the following errors:

    failed to load ZIPDLL.DLL
    failed to load UNZDLL.DLL

    after all of this I ran spybot, it said that it found no problems but it only took about 2 seconds to do the scan so I don't think it really did anything.

    I uninstalled and reloaded spybot several times and always got the same result.


    Since I did complete a scan with the older version of spybot is the HJT file I sent yesterday still valid? Can you look at it and see if there are any obvious problems?


    Bill
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay there was a problem in our download links yesterday. Please go here and get the proper full program download for Spybot: http://www.majorgeeks.com/download2471.html
    Install it and update it online.

    Afterwards run the SpybotSD 1.3.1tx file you downloaded the other day. It is a patch to fix the DSO Exploit problem in Spybot. Yes, I'll look at your log.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O1 - Hosts: 203.161.127.141 www.dcsresearch.com
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKCU\..\Run: [Xkheg] C:\WINDOWS\System32\w?nspool.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O15 - Trusted Zone: http://*.windowsupdate.com

    Now reboot in normal mode and post a new HJT log. And tell me how things are working.
     
  10. Wcamper

    Wcamper Private E-2

    I fixed the lines you suggested in HJT. I also reinstalled Spybot and Spybot 1.3.1tx as you suggested. When I run spybot I get an error message"Unable to locate component. This application has failed to start because framedyn.dll was not found. Re-insatlling the application may fix the problem." I reinstalled spybot a couple of times but I still get the error. Even though I get the error I am still able to run spybot. The first time I ran it I got 5 problems, 4 of which were DSO Exploit. The second time I ran it it came back clean.

    I then rebooted the computer and got the message that my disk is dirty and it ran chkdsk. After that was complete my computer booted up and then immediately gave me a blue screen error "Stop: 0x0000008E(0XC0000005, 0X8054B534, 0XF86C7844, 0X00000000)". I then rebooted and everything has been working fine, no more blue screens, no more unexpected web pages opening, no more java script problems, etc., at least not yet.

    Do you think I may have a hardware problem in addition to the spyware/virus I had? One other nuisance I have is that windows keeps telling me that I don't have any anti-virus software installed even though I have AVG installed. I updated AVG and ran a scan which came back clean.

    I have reposted my HJT file as you requested. Please let me know if it looks OK to you.


    Thanks for all of your help.
    Bill
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You HJT log looks clean.

    You may want to check in the Software Forum on why WinXP does not recognize your AVG antivirus package.

    Any more problems with blue screens or anything else?
     
  12. Wcamper

    Wcamper Private E-2

    I had one more blue screen and once the computer just locked up. For the last few days I haven't had a problem but I expect they will probably return. Any suggestions?

    Bill
     
  13. Kodo

    Kodo SNATCHSQUATCH


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds