Imposible to detele unknown spyware system

Discussion in 'Malware Help (A Specialist Will Reply)' started by phead, May 25, 2005.

  1. phead

    phead Private E-2

    hi,
    I have followed ALL the processes needed to clean my pc but it's impossible! i downloaded a file and it was a trojan (mcafee alert) and suddenly it was lost from the pc and couldn't do anything (probably hidden).
    Now, I get at lease 20 spyware programs in my pc (180search, ist, revenue, lop etc etc) and when i delete them they're appeared again!

    I HAVE FOLLOWED YOUR GUIDE, in safe mode with all programs you mention and updates (topic: read me first before asking for support) and nothing is happening..

    Also, when i open ie i get a top search screen and a bottom one and can't be closed!
    there is a sceenshot of my pc here:
    http://pheadweb.com/problem.JPG

    and finally my hijack log file is here:
    http://www.pheadweb.com/log.txt


    PLEASE HELP ME GETTING RID OF THIS CRAP..
    thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    With no browsers running, have HJT fix the O1 - Hosts lines immediately:
    R3 - Default URLSearchHook is missing
    O1 - Hosts: 213.219.251.78 google.com
    O1 - Hosts: 213.219.251.78 google.co.uk
    O1 - Hosts: 213.219.251.78 google.ca
    O1 - Hosts: 213.219.251.78 google.es
    O1 - Hosts: 213.219.251.78 google.de
    O1 - Hosts: 213.219.251.78 google.fr
    O1 - Hosts: 213.219.251.78 google.com.au
    O1 - Hosts: 213.219.251.79 yahoo.com
    O1 - Hosts: 213.219.251.81 astalavista.com
    O1 - Hosts: 213.219.251.81 www.astalavista.com
    O1 - Hosts: 213.219.251.81 astalavista.box.sk
    O1 - Hosts: 213.219.251.81 www.astalavista.box.sk
    O1 - Hosts: 213.219.251.81 cracks.com
    O1 - Hosts: 213.219.251.81 www.cracks.com
    O1 - Hosts: 213.219.251.80 msn.com
    O1 - Hosts: 213.219.251.80 go.com
    O1 - Hosts: 213.219.251.80 www.go.com

    Now, please follow the below directions (make sure no browsers are running) and post you log here as an attachment to your message.

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).

    Question: Do you recognize the below to be valid? My guess is that it is bad.

    O4 - HKLM\..\Run: [Jugsbooktraystyle] D:\Documents and Settings\All Users\Application Data\Infonamejugsbook\boobdelete.exe
     
    Last edited: May 25, 2005
  3. phead

    phead Private E-2

    here's the log file of hijack this
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read my previous message again. I just edited it. Complete those steps and answer my question. Also note you are not shutting down your browsers as requested. You must do this before using HJT or you can make it difficult to impossible to fix some problems.
     
  5. phead

    phead Private E-2

    I did them all.
    I deleted this line you mention but the search bar in top and bottom of the pc are still there.. And I can't close it.
    Please help,
    have a look to my log.
    thanks
     

    Attached Files:

  6. phead

    phead Private E-2

    also,
    the clock of pc is changing the time when i start my os.
    why?
    i think it's related to the virus
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have a couple browsers running. You will not be able to fix all these problems unless you exit browsers before using HijackThis.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.

    D:\WINDOWS\system32\uWDF.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O4 - HKCU\..\Run: [BLUEBLEH] D:\DOCUME~1\phead\APPLIC~1\OOZEEA~1\Media Up Flaw.exe


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    D:\WINDOWS\system32\uWDF.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
    Last edited: May 27, 2005
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also in IE, click on Tools and select Manage Browser Addons and look for anything you do not reconize.
     
  9. phead

    phead Private E-2

    hi,
    I've followed EXACTLY your guide and worked fine... FINALLY!
    All search bars are lost and IE works fine!
    I would like to thank you VERY much for your time :)
    I really appreciate it..

    The only thing that concerns me is that none anti-spyware program worked to solve this problem.. It's really sad..
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Some items are not detected for a variety or reasons:
    - they may be unknown at the time
    - they are not considered malware (at least not yet)
    - they are simply undetectable

    What you had was an addon to IE, which most programs simply assume you added yourself and thus it must be okay.
     
  11. ANHEDONIC

    ANHEDONIC Will Title For Food

    phead i would definitely recommend downloading and installing Spyware Blaster, available here at Majorgeeks... also, get yourself an external firewall, like Sygate Personal Firewall or Zone Alarm... alot of times these spyware programs try to access the internet to update themselves or send out your information, luckily, most firewalls will prompt you that a program is trying to access the internet and you can DENY it access...

    i got invested with spyware about 8 months ago... was very nerve racking getting rid of it all.... on my computer i now use the following programs (and have been completely spyware free for quite sometime now *knocks on wood*):

    Avast Antivirus (free)
    Sygate Personal Firewall (free)
    Adaware Personal (free)
    Spybot Search & Destroy (update and use immunize feature, free)
    Spyware Blaster (udpate and enable all protection)

    (you can find all these programs here at Majorgeeks)

    you also might want to consider using another browser... like Mozilla Firefox... it's much safer to use than Internet Explorer... I was hesistant to leave IE originally but having used Firefox for quite awhile now, i like it much better...
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds