It's me again...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kelli, Jan 22, 2005.

  1. kelli

    kelli Private E-2

    Hi! It's me again. :rolleyes: I read the big article on spyware ("please read me"). Nothing helped. One spyware removal would just pick up what the other one missed. Now, everytime I open IE or My computer, the start button,...almost everything I get a message from Norton Anti-Virus that there was a High-Risk Virus removed. I then run Norton anti-virus and Live Update and it detects one (sometimes 0) and says the virus was removed. I start the process over again and it's just a big circle. Is there anything else I can do?
     
  2. kelli

    kelli Private E-2

    here's my hijack log :cool:
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Reading & running are not the same thing. It does not look like you ran ALL the steps. I see no evidence of the TrendMicro online scan being run. Did you skip anything else? Here are the procedures to be followed. Also, noone asked for a HijackThis log to be posted and you did not follow guidelines on where to install it and how to run it (what to shut down).

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have an about:blank hijack as indicated by the below lines in your log:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Family\LOCALS~1\Temp\sp.dll/sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Family\LOCALS~1\Temp\sp.dll/sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {0F4A12F6-0A27-44F7-859D-99F9DC578EA4} - (no file)
    O2 - BHO: (no name) - {B4C1551A-DE79-47A1-9FD3-A0FF49D1A6E2} - (no file)
    O2 - BHO: (no name) - {B9228A9B-820B-454C-812E-74E454F80810} - (no file)
    O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file)
    O2 - BHO: (no name) - {EA461528-061B-41B8-BC88-C1569D244CD2} - (no file)
    O2 - BHO: (no name) - {FBEA64F6-6AF2-4F85-8EE2-18CE045AA336} - C:\WINDOWS\system32\bnm.dll
    O18 - Filter: text/html - {276E9DD5-A4F0-4307-87DD-A401787944EF} - C:\WINDOWS\system32\bnm.dll
    O18 - Filter: text/plain - {276E9DD5-A4F0-4307-87DD-A401787944EF} - C:\WINDOWS\system32\bnm.dll

    Complete steps from my previous message and we will proceed to fix this.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds