Infected computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by Peterd, Jan 27, 2006.

  1. Peterd

    Peterd Private E-2

    I need help please to remove some malware. When I open IE up pops www.ix.se and also www.filost.com and http://adultfriendfinder.com. I have tried removing them but they reappear. I have AVG anti-virus and Outpost Pro firewall but these get under the wire and infect my pc. I have run all the diagnostics asked for but don't know how to interpret the results. So over to you guys. Now another has just popped up adultdatingfriends!!!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also it would be a better idea to locate HijackThis in its own folder. You have it here:
    F:\Program Files\HijackThis.exe

    It would be much better to have it here:
    F:\Program Files\HJT\HijackThis.exe

    That way, backups are more secure and when we see logs that show lines line in your Panda scan, we would know what they were for. Like the below:
    Dialer:Dialer.ABR Not disinfected F:\Program Files\backups\backup-20060126-173712-728.inf

    It looks strange as above but if HJT was installed correctly we would easily recognize the below to just be from HJT:

    F:\Program Files\HJT\backups\backup-20060126-173712-728.inf
     
  4. Peterd

    Peterd Private E-2

    Hi,

    As requested I downloaded smitRem.exe, Ran HijackThis (having moved it to a HJT folder in F:\Program Files). There were no items which matched the list. I ran smitRem and attach the txt file. I clicked on Panda on the desktop, forgetting that I had not reconnected my broadband. Windows Microsoft Anitspyware popped up to say that the IE URL for my search bar is attempting to be changed from Google to search.msn.com/spbasic.htm. I blocked this and then notced that IE had attempted to open with http://540.filost.com/randomsites/banner.aspx so we have not lost this one. I ran Panda & even though you said not to attach the file I have done as when the program was running it came up with Hacking Tools as well as spyware & dialers.

    Where do we go from here? Your help is greatly appreciated.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well it seems you forgot to attach all the new logs!
     
  6. Peterd

    Peterd Private E-2

    Sorry, closed the window but forgot to upload. Another senior moment!:eek:
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should move the F:\Program Files\backups folder under the new HJT folder you created.

    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - C:\WINDOWS\system32\vbsys2.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\system32\vbsys2.dll

    Additional step to delete startbf.inf
    - Click Start, Run, and enter cmd in the box and click OK. This opens a command prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s startbf.inf
    del startbf.inf
    exit


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).


    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log.

    Make sure to tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. Peterd

    Peterd Private E-2

    Hi Chas,

    Did all you requested and everthing seems fine at the moment. I attach the latest HJT log. Do I now do the 'disable system restore' etc step?

    While writing can I pick your brain please? In C:\Windows I have 34 $NtUninstallnnnnnn$ lines mostly from when I reformatted my hard disk and reinstalled all programs. Am I correct in thinking that I only need to keep the latest one?

    Assuming we are now finished may I thank you for all your valuable assitance. I must try not to visit any more dubious sites!

    At present I have AVG anti-virus and Outpost Pro Firewall plus Adaware, Spybot, Microsoft Anti Spyware & CCleaner. Despite all this software they don't appear to pick up the malware that has infected my pc. The Panda software does appear to pick up malware that the others didn't How do you rate it?
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Rather than rewrite what has been written many times. See some oth these links:
    http://windowsxp.mvps.org/Hotfix_backup.htm
    http://www.askdavetaylor.com/can_i_delete_the_contents_of_windows_ntuninstall.html
    http://www3.telus.net/dandemar/spack.htm

    You're welcome!

    Panda is pretty good; however, you will find that other programs also find many things that Panda does not find. That's just the way things are and it is also why we run multiple scans. The best overall tool we have found (and it also removes some of the more difficult malware problems that others may not even detect) is Spy Sweeper (which you appear to have uninstalled).

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds