iexplorer a real BROWSER now

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by pollack, Dec 16, 2004.

  1. pollack

    pollack Private E-2

    Hi!

    So I immunised my Internet Explorer after the CWS or "Home Search" trojan attack. I used Spybot S&D and Spywareblaster. I don't know if it's the result of immunisation or the preceeding infection, but there are few things that look a little strange for me:

    1. Can't "file-save" window doesn't open
    2. Can't right click
    3. Can't click a save link
    4. Can't ctrl-c, ctrl-x, ctrl-v
    5. Can't press "del" - deleting the character on the right doesn't work

    I can use java games etc. so IE behaves like a real BROWSER - i laugh :)

    please tell me - whether it's effect of inocullation, damaged IE due to infection, so I must reinstall it or am I still under some trojan?

    Thank you in advance,
    Pollack
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. pollack

    pollack Private E-2

    Yes, i 've been recently affected by HSA
    In addition, I can't access MS update page from IE, but i can access it through the start menu, but I can't update. It stops on the "searching for updates", not showing 0% yet. i downloaded q816868.exe from ms (a solution for can't write a file error) but i can't install it since it says I don't have IE 6.0 SP1, but i have IE 6.0 SP1
    I was doing Norton online scan and found no viruses.
    I am considering reinstalling windows and end this thread, but I hope I am not infected at this moment. So it won't be a never-ending job.
    What do you think?

    Sorry, wrong attachment. That was not my log ;) Mine is hijackthisproper.log
    This is my hijack log again:
     

    Attached Files:

    Last edited: Dec 16, 2004
  4. pollack

    pollack Private E-2

    let me explain the processes
    lexpps.exe and lexbces.exe should be lexmark printer drivers. they are one below the other in process explorer tree
    powergg.exe is some kind of trusted program, as had been using it for ages before i caught my first trojan
    his.dun is a shortcut to dial-up connection
    i have nvidia drivers, so nwiz.exe should be nvidia's

    also i could install and launch the norton virus check from IE
     
  5. Kodo

    Kodo SNATCHSQUATCH

  6. pollack

    pollack Private E-2

    It can't be a pest. Maybe somebody wrote a pest called Gadu-gadu, but it's a very popular and non-harmful (over 5 million Polish are using it) internet communicator. My Gadu Gadu I installed willingly and there was no project1.exe in the tasks ever. Also I uninstalled it. ;) How could anyone made a pest with the same name Gadugadu :rolleyes:
     
  7. Kodo

    Kodo SNATCHSQUATCH

    insert random joke here..j/k

    looks like that may be the case. GG.EXE looks to be legit.
     
  8. pollack

    pollack Private E-2

    I think that some IE registry settings could have been changed, maybe some files corrupted due to these attacks. There were not only CWS, but also Alexa and other trojans. I think I will just reinstall Windows, but not today, because I'm going to read Hamlet :)

    My log looks now like that:
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds