i think i have spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by ferg46, Mar 21, 2007.

  1. ferg46

    ferg46 Private First Class

    hey guys ,

    i know ye like everyone to run the malware guide before posting but i just wanted to know does anybody know how serious this is

    odbcjet.exe

    it tried to get an internet connection through norton today

    thanks
    ps i googled it and this is abetter description of it

    http://www.bleepingcomputer.com/startups/Cn911-16865.html

    again thanks to any help
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All Trojans can be serious and often times they don't come alone. For example the one you named is described to like this:
    Did you remove it?
    Do you still have any malware symptoms?
    Even if you don't, you could still have malware.
     
  3. ferg46

    ferg46 Private First Class

    thanks for the reply,

    i think i have removed it as in i have ran the following scanners

    spybot s&d -->hasnt really found any malware in a few weeks/months
    a - squared--> detected: Trace.Registry.Radlight
    Trace.TrackingCookie
    Trace.Registry.Rad
    traces of spywarequake
    ad aware---> i think it just found cookies
    mru blaster
    c cleaner
    cleanup

    now the results for spybot were strange because its up to date and for some reason never finds anything wrong when i know there is something wrong
    , i dont have the teatimer funtion running either

    i have attached the most recent a squared log

    as for spyware symptoms i think the laptop has only crashed once sice yesterdays scans but i still have a gut feeling there is something lurking within my laptop

    let me know if you need anymore information thanks
    fergal
     

    Attached Files:

  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    I think you'd be best to run the Read ME guide and attach all the requested logs going by your A2 scan, even if A2 removed spywarequake its likely you will have more malware still as they tend to come in multiples these days.
     
  5. ferg46

    ferg46 Private First Class

    ok thanks halo but do you think i should do the run me guide or the guide for removing spyware quake,just in case im going to wait till chaslang reccomends what to do just in case i do something wrong , thanks
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may have to run the READ ME anyway but let's try the below first.


    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    How are things working now?
     
  7. ferg46

    ferg46 Private First Class

    hi chaslang , im very very busy with work untill sunday so im going to do every thing i you said then,
    thanks very much for all help so far
    il post back when i follow the instructions
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem don't forget 3 things need when you post!

    • 2 different rapport.txt logs from the two step process given
    • and then follow that up by explaining how things are working and describing any remaining problems if you have any.
    In order to allow you to keep moving ahead without waiting for me, if you still have malware problems after completing the steps with SmitFraudFix then continue on with the below procedure.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  9. ferg46

    ferg46 Private First Class

    het guys , im in the middle of following one of chaslangs guides ,
    im just after working in safe made for the first time and im after rebooting in normal mode now a pop up has just come up telling me that i have changed the way windows starts up so i pressed ok then the "system configuration utility " box has just come and im not sure which of these three boxes i am to select

    -normal startup
    -diagnostic startup
    -selective startup

    currently the selection is set at selective startup
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As stated in the READ & RUN ME in step 0, Normal Startup is what you want for most cases. If you are trying to remain in safe mode and you used MSconfig to get in safe mode then choosing Normal Startup would take you out of safe mode at the next boot up. So the question is are you trying to stay in safe mode or are you trying to get out of safe mode.
     
  11. ferg46

    ferg46 Private First Class

    hey,
    ok i have completed all the steps you told me in thread no.6 and in the very last line it says reboot in safe mode and i did that and then the pop up window appeared

    i havent started the read and run me yet as i wanted to see how things faired out after completing all the steps in post no. 6
     
  12. ferg46

    ferg46 Private First Class

    sorry if im confusing you what im trying to find out is which option under the "system config utility " and under the tab "general" do i use as normal from now on , now that i have ran the smitfraud programme

    under the selective startup selection there is this option

    - use original boot.ini or
    - use modified boot.ini

    currently the selection is at the modified option but windows is waiting for me to make this selection a permanent one and i was wondedring should i leave it ayt the modified option or change it to a different one
     
  13. ferg46

    ferg46 Private First Class

    i have been using the pc for about half an hour now and it seems to be better (i think) here is the first report as i am having trouble putting them into the same message
     

    Attached Files:

  14. ferg46

    ferg46 Private First Class

    and here id the second report , im going to be offline for about 24 hours so as soon as i can post back i will thanks
    fergal
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you are not in safe mode, you must select Normal Startup mode!

    You really should attach all 6 of the requested logs from the READ & RUN ME so we can verify that you are clean.
     
  16. ferg46

    ferg46 Private First Class

    hey guys sorry for the delay in reply i wanted to wait for a completely free day before i started the read me sticky, thank god i did its taken all day and im wrecked but still very appreciative for all the help given so a big shout out to majorgeeks , all members and particularly chaslang and the crew who have helped me so far, here is a summary of how each step went including the logs

    steps 1-5 went fine however i found it strange how spybot found and cleaned nothing also counter spy found no threats when run in normal boot mode

    the thing that worried me the most was the fact that the panda scan found many things wrong or infected in my computer and i coudnt fix them so ill post that log along with this thread and wait for the experts to decipher it
     

    Attached Files:

  17. ferg46

    ferg46 Private First Class

    the next post includes the getrunkey,shownet and hjt logs i hope there what you were looking for if not let me know and il try fix asap,

    thanks
    ferg
    :cool
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. We just have a fe minor non-malware things to do.

    BitDefender only found things in your Norton quarantine (which we requested that you empty in step 0 of the READ ME). And it also found things in System Restore which will only be fixed when we finish all malware removal and then do step 8 of the READ ME.

    Panda did not find any real problems. The dialer.su is a false positive and the other items are just cookies which are not problems.

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Now Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    After clicking Fix, exit HJT.

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.
    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     
  19. ferg46

    ferg46 Private First Class

    hi again ,i followed the instalation and uninstalation of the required programmes

    in the email i recieved i saw you asked for three logs but in the post i can only see two anyways here s three logs

    scanned in this order
    hjt ( i ticked the boxes you requested)
    runkeys
    new files



    thanks again
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  21. ferg46

    ferg46 Private First Class

    hi chaslang,

    sorry about long delay in reply i have been out of country
    things seem to be much better now
    however i uninstalled norton is2006 and installed
    avira av
    comodo firewall
    spyware terminator

    but now i recieve a pop up from the system tray telling me norton worm protection is switched of and to correct it it just brings me to the windows security control centre

    any ideas on a solution

    also from the scans i subwitted was it clear as to which progs/sites were effecting me

    once again really appreciate all help given and sorry for delay
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps you did not properly/completely uninstall Norton before installing Avira. Norton can be just as difficult to uninstall as malware.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Symantec Core LC
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteSymantec Core LC into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.

    After reboot, delete the below folder if found:
    C:\Program Files\Common Files\Symantec Shared

    Attach new logs from ShowNew and HijackThis.

    Did that fixed your problem?

    You only had one malware problem which was SpywareQuake.
     
  23. ferg46

    ferg46 Private First Class

    1)after running the first steps and rebooting the pop up still appeared

    2)i found the required folder and deleted it

    3)i have ran the required scans and should be now attached

    -havent rebotted since i performed steps 2 and 3 , as soon as i do i will post back the behaviour of laptop etc

    - thanks
    fergal
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you capture the popup into a legible image and attach it here?
     
  25. ferg46

    ferg46 Private First Class

    ok iv gotta download an image captureing programme and get back to you asap

    thanks
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I find FastStone Capture 5.3 very easy and handy. It can capture desktops, active windows, or any rectangular area you create. Works great.
     
  27. ferg46

    ferg46 Private First Class

    hi again
     
  28. ferg46

    ferg46 Private First Class

    hi again chas,

    iv installed faststone but as soon as i try to capture an image (no matter what way i try it i.e square,freehand or fullscreen) it never comes up

    the best desc i can give is


    # your computer might be at risk

    norton internet worm protection is turned off

    click this baloon to fix the problem


    the area where this symbol is # is were there is a red kinf of warning crest sign with a white cross in middle which is also the picture of the icon in my system tray

    when i click the pop up the attached window pops up

    thanks

    fergal
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks to me like Comodo Firewall did not do what it should do to make itself known to Windows Security Center. It should be showing as your firewall. Click the Recommendations button and then at the bottom of the next window, put a check in the box that says "I have a firewall solution that I'll monitor myself" Then click OK and close down security center. Reboot and see if you have anymore issues.
     
  30. ferg46

    ferg46 Private First Class

    hi chas ,

    that advice stopped the pop up thanks again i understand you must be very busy with helping other members so if you wouldnt mind if i just asked you to questions so as to prevent another attack thanks

    is running these programmes to safely protect my comp
    -avira antivir a/v
    -comodo firewall
    -spyware terminator
    -a squared
    -c cleaner
    -ad aware
    -spybot s&d
    -clean up

    as a idea of how i use the internet i would say that i surf all legitimate sites and the only grey area i could see would be the downloading of legitimate torrents (div x etc ) using u torrent

    -again i know this is off the topic of the thread and understand there are other geeks in need of your help but just wanted to het a quick reccomendation so i hopefully dont have to bother te again

    -one theory i had maybe would i be running to much programmes as sometimes my laptop does slow down for a few minutes but i was just wondering would that be normal for a 512mb ram centrino laptop to slow down if uing combo of
    -u torrent
    -wmp 11
    -firefox

    any reply much appreciated and thanks for all help
    fergal
    :)
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have added comments in purple below!
    Still not necessarily safe. Any P2P downloading can be dangerous as stated in: How to Protect yourself from malware!

    I'm not sure what you are asking me but it is not a topic for the malware forum. However my opinion is Win XP should not be run with less than 1 Gb of RAM.



    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  32. ferg46

    ferg46 Private First Class

    ok will do as stated thanks for all help chas cheers
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  34. ferg46

    ferg46 Private First Class

    hi chas , just for your information if anyone ever has that same problem i had i figured out what caused it, while i was doing my scanning with spybot it found a threat

    the threat being the non recognition of a firewall then when you fix it upon a restart the pop up a rises

    so i think its just a fault with spybot

    cheers
    ferg
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those messages from Spybot are not threats. They are warnings that your security settings have been changed from the default settings of Windows. They are normal once you have installed any other antivirus or security suite/firewall to manage your security rather than Windows Secuirty Center. They do not need to be fixed and actually cannot be fixed. Warnings are informational in purpose only.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds