HELP - SPYWARE - LOP.COM driving me NUTS

Discussion in 'Malware Help (A Specialist Will Reply)' started by knots76, Mar 13, 2005.

  1. knots76

    knots76 Private E-2

    Hello. Please help. Pop-ups driving me nuts...Ad-Aware & Microsoft Spy-Ware not working to help. Can't search from IE Address bar. :mad:

    This is my logfile.

    Thanks a million

    Logfile of HijackThis v1.99.1
    Scan saved at 6:59:39 AM, on 3/13/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Edit by chaslang: Unrequested inline log removed.
     
    Last edited by a moderator: Mar 13, 2005
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First:

    Please EXTRACT HijackThis from the ZIP File to a Safer location. Here's how:

    To create a new folder:
    Click START > My Computer > Local Disc C: > Program Files
    Now, RightClick on an Empty Area and select New > Folder & name it HijackThis and ENTER

    To Extract HijackThis:
    Now, Right Click your HijackThis ZIP File and select Extract All > Next > and browse to your newly created HijackThis Folder
    (C:\Program Files\HJT) and click Next.

    Now run HJT from there. Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    The reason HJT needs its own safe folder is so that backups will be safely preserved. That way, if a mistake is made in the removal process, the mistakenly deleted entry can be restored.


    Second:

    Please make sure ALL browsers are closed when running HJT. You must close each of the following: your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc.

    Third:

    There are no signs of you running the online scans from the READ ME!

    Please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an ATTACHMENT.
    All instructions are covered in the sticky thread
    NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting


    Now post a Hijack This log as an ATTACHMENT to your message (Do NOT copy/paste the log into your post). Please close unnecessary running programs before you run HijackThis. You must close each of the following: your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc.

    DO NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. knots76

    knots76 Private E-2

    Between everything I tried - I am now able to search from the address bar and the Casino pop-up hasn't come back. I tried so many things that I don't know what really worked. Now I'm still seeing the add for a VBScript Registry Cleaner and have no idea where that one is coming from. Should I still follow the steps posted earlier or do you have another suggestion? :(
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an ATTACHMENT.
    All instructions are covered in the sticky thread
    NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting


    Now post a Hijack This log as an ATTACHMENT to your message (Do NOT copy/paste the log into your post). Please close unnecessary running programs before you run HijackThis. You must close each of the following: your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc.

    DO NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  5. knots76

    knots76 Private E-2

    Hi again. I did do the virusscan, spybot and the Microsoft Antispyware...only found cookies. How do I attach?
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Attach a current HJT log using the Manage Attachments feature at the bottom of this window.
     
  7. knots76

    knots76 Private E-2

    I'm sure I saw services.exe!
     

    Attached Files:

  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add or Remove Programs for the following and Uninstall them if found:

    My Web Search
    My Web Search (Smiley Central or FWP product as applicable)
    My Way Speedbar (Smiley Central or other FWP as applicable)
    My Way Speedbar (AOL and Yahoo Messengers)
    My Way Speedbar (Outlook, Outlook Express, and IncrediMail)
    Search Assistant - My Way

    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://dell.myway.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://minisearch.startnow.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.dell4me.com/myway
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.dell4me.com/myway

    R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll

    O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll

    O4 - HKLM\..\Run: [RegServer] regserve.exe
    O4 - HKLM\..\Run: [Regsfilepingsettings] C:\Documents and Settings\All Users\Application Data\Road Four Regs File\Gram Amok.exe
    O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\system32\gah95on6.exe
    O4 - HKCU\..\Run: [grammess] C:\DOCUME~1\LINETTE\APPLIC~1\CHICIN~1\for spam.exe

    O15 - Trusted Zone: *.musicmatch.com (HKLM)


    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled and navigate to and DELETE the following if they should remain:

    C:\Program Files\MyWaySA ←–– Delete this whole folder if it exist!

    C:\WINDOWS\system32\gah95on6.exe

    C:\Documents and Settings\All Users\Application Data\Road Four Regs File\Gram Amok.exe

    C:\Documents and Settings\LINETTE\Application Data\CHICIN~1\for spam.exe

    regserve.exe ←–– Search for this file and delete when found!


    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.
    Note: Dont forget to update Spybot S&D by selecting "Search For Updates"


    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    Reboot to Normal Windows

    FINAL STEP

    Reset Web Settings & Default Security Settings:


    To Reset Web Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK


    To Default Security Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Security Tab and click Default Level for Internet, Local Intranet, Trusted Sites, and Restricted Sites.


    After you have completed ALL of the above task, Scan with HijackThis and attach the new log.
     
  9. knots76

    knots76 Private E-2

    I thought the Search Assistant - My Way was from Dell?
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    EDIT: BY BJGARRICK

    Procede with the rest of the fix :)
     
    Last edited: Mar 14, 2005
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    BJ is correct about those R0 & R1 lines. Although they do appear to be Dell, they are being redirected via MyWay. You should fix all of them as he has suggested.

    If you want a true dell page, use www.dell.com or www.dell4me.com


    And reset web settings too as suggested.
     
  12. knots76

    knots76 Private E-2

    please see the attached logfile.

    thanx very much
     

    Attached Files:

  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Do one last scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://dell.myway.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.dell4me.com/myway
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.dell4me.com/myway

    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)

    O4 - HKLM\..\Run: [Regsfilepingsettings] C:\Documents and Settings\All Users\Application Data\Road Four Regs File\Gram Amok.exe
    O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\system32\gah95on6.exe
    O4 - HKCU\..\Run: [grammess] C:\DOCUME~1\LINETTE\APPLIC~1\CHICIN~1\for spam.exe


    Again, make sure All Browser Windows are Closed when you Click FIX.


    NEXT

    Reset Web Settings & Default Security Settings:


    To Reset Web Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK


    To Default Security Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Security Tab and click Default Level for Internet, Local Intranet, Trusted Sites, and Restricted Sites.


    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled and navigate to and DELETE the following if they should remain:

    C:\Documents and Settings\All Users\Application Data\Road Four Regs File\Gram Amok.exe

    C:\WINDOWS\system32\gah95on6.exe

    C:\Documents and Settings\LINETTE\Application Data\CHICIN~1\for spam.exe


    NEXT:
    Run CCleaner


    Reboot to Normal Windows , Scan with HijackThis and attach the new log.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.

    Good Luck!:)
     
  14. knots76

    knots76 Private E-2

    :cool: Hi Again. The log file is attached. I notice that my default homepage is now www.msn.com
     

    Attached Files:

  15. knots76

    knots76 Private E-2

    Hi Again. The log file is attached. I notice that my default homepage is now www.msn.com
     
  16. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Log is clean! Are you currently experiencing any further problems?
     
  17. knots76

    knots76 Private E-2

    :cool: GREETINGS FROM THE VIRGIN ISLANDS! THANK YOU!!!!!!!!!!!!!!! SO FAR SO GOOD. YOU GUYS ARE GREAT!

    And I'll surely leave the "free" stuff online alone. :)
     
  18. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Good Deal!:)

    You should see this article on How to Protect yourself from malware!
     
  19. knots76

    knots76 Private E-2

    it's back :(

    i notice a change in msn as my search page and microsoft antispyware reported a hijacker on scan. also the entries are back for HijackThis............and I can't get Myway from my files.
     

    Attached Files:

  20. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://dell.myway.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://minisearch.startnow.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.dell4me.com/myway
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = https://www.dell4me.com


    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:

    Download Ad-Aware SE Personal 1.05 , Install and Update.

    Note: Be sure you have Ad-aware SE referencefile SE1R32 10.03.2005

    After you get Ad-Aware updated to Reference file SE1R32 10.03.2005 click START and then check "Perform Full System Scan" and remove all found infections.

    NEXT:

    Run CCleaner


    FINAL STEP

    Reset Web Settings & Default Security Settings:


    To Reset Web Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK


    To Default Security Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Security Tab and click Default Level for Internet, Local Intranet, Trusted Sites, and Restricted Sites.


    Reboot, after doing ALL of the above, let me know how things are running now. Be sure to do EVERY step as listed above.

    Good Luck:)
     
  21. knots76

    knots76 Private E-2

    well here goes
     

    Attached Files:

  22. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    What were the results from the Ad-Aware scan?

    HJT log is clean, how are things running?
     
  23. knots76

    knots76 Private E-2

    Ad'Aware found 2 MRUs and I deleted them. I think my problem got wose with the Microsoft Anti-Spyware. It would say that something was trying to take over Internet Explorer and that I should Block or Ignore. Regardless of what I chose - the defaults would change to dell4me/myway and the HJ would show the R1 etc entries again. So I uninstalled it.

    It seems as if MSN is still moving slow though and the default search - MSN looks very strange but I haven't searched in MSN for a while anyway. I'll keep you posted on the status and thanks for your help.

    BTW, it's ok for the one R1 entry to show majorgeeks as the home page?
     
  24. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Yes!

    In the mean time you should see this article on How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds