Nasty little critters on my computer!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Debs, Oct 24, 2004.

  1. Debs

    Debs Private E-2

    Hi

    My hompage has been changed to www.searchportal and I can't reset it.
    I have:
    1)Disabled System Restore
    2)Scanned with suggested software in safe mode
    a) TrendMicro found JAVA BYTEVER.A-1
    JAVA FEMAD.B
    and said they were non cleanable. I deleted them (not sure if this really got rid of them!)

    b) Symantec said I was clean
    c) AdAware log attached
    d) spybot fixed DSO.Exploit
    e) Norton Anti Virus found 2 infections: rundlg32.dll that I cannot delete
    f) CWS = clean
    g) About Buster = clean
    h) HS Remove = clean
    i) Likk2me = clean

    I have a hijack this log if needed.
    I would really appreciate some help in sorting this out once and for all!!!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. Debs

    Debs Private E-2

    I have attached my hjt log. Looks like the homepage has been sorted out but my virus scans are still picking up nasties that I can't seem to delete.

    Many thanks for your time! :)
    Debs
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the directions for using HijackThis. We asked for it be place into its own directory.
    You are running it directly from the ZIP file. You will not get any backups that way. This where you currently have it.
    C:\Documents and Settings\Debs\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    You must fix this before continuing!

    Also, we specifically tell you to shutdown browsers before scanning. You had IE running.
    C:\Program Files\Internet Explorer\iexplore.exe

    Having browsers running when using HijackThis to fix items can interfere with the ability to fix problems.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First, goto Add/Remove Programs and look for an uninstall for Spyware Begone. It is on a list of rogue/suspect spyware removers and is not doing anything useful for you. See this link: http://www.spywarewarrior.com/rogue_anti-spyware.htm
    If it does uninstall, you will not see the line below in HJT that I will suggest to fix.

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ninemsn.com.au/
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {A9ACA209-B852-40A2-86A7-C1F4DA445DAD} - C:\WINDOWS\System32\abf.dll (file missing)
    O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inetm\services.exe
    O4 - HKCU\..\Run: [Spyware Begone] C:\freescan\freescan.exe -FastScan
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O16 - DPF: {A5C76BEB-C8A9-4F59-BB90-52A821EAB9C9} (Desktop Object) - http://sib1.od2.com/common/cman/cman.dll

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\inetm <---- the whole directory

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Questions:
    Do you recognize the URLs listed below in the O17 lines? Is this your ISP?
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = nsw.bigpond.net.au,vic.bigpond.net.au
    O17 - HKLM\System\CS1\Services\VxD\MSTCP: SearchList = vic.bigpond.net.au
    O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = vic.bigpond.net.au
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = nsw.bigpond.net.au,vic.bigpond.net.au

    Here is some more info on those URLs:
    vic.bigpond.net.au = [ 139.134.5.153 ] & nsw.bigpond.net.au = [ 139.134.5.153 ]
    Domain Name: bigpond.net.au
    Last Modified: 02-Apr-2004 05: 20: 04 UTC
    Registrar ID: R00012-AR
    Registrar Name: TPP Internet
    Status: OK
    Registrant: Telstra Corporation Limited.
    Registrant ID: ACN 051775556
    Registrant ROID: C0981976-AR
    Registrant Contact Name: Domain Administrator
    Registrant Email: corpdomains@team.telstra.com
     
  6. Debs

    Debs Private E-2

    Hi

    I have done all as requested.

    When I log on I get a message saying "could not load or run C:\WINDOWS/inetm\services.exe. Make sure the file exists on your computer or remove the reference to it from the registry".

    The homepage now comes up as about:blank & Norton Anti Virus is still picking up 2 infections as before both named: rundlg32.dll (spyware Iwants...)

    I have posted my new log.

    Thank you very much for your help!!!!!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Back in message # 4, I said:
    "You are running it directly from the ZIP file. You will not get any backups that way. This where you currently have it.
    C:\Documents and Settings\Debs\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    You must fix this before continuing!"

    You still did not fix this problem. You are still running HijackThis directly from the ZIP. You are not getting any backups when doing it this way. You must correct this. Extract the EXE file from the ZIP and put it into its own folder like C:\Program Files\HJT
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure


    Now we need to reset your Web Settings:

    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com (or whatever your preference is. You had http://www.dell.com). Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    Does your Norton Anti Virus tell you where it is finding rundlg32.dll?

    Is it in C:\Windows\downloaded program files\rundlg32.dll

    We may need to edit the registry by hand if you are still getting messages about missing:
    C:\WINDOWS\inetm\services.exe
     
  9. Debs

    Debs Private E-2

    Have deleted as requested and saved HJT in own file. I have reset web settings to majorgeeks.

    The rundlg32.dll being picked up by Norton is in C:\WINDOWS\downloaded program files\rundlg32.dll

    I have tried searching for this in windows explorer but have been unable to locate to delete.

    Have posted latest hjt log.

    Thanks
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you HJT log looks clean. Most files in C:\WINDOWS\downloaded program files cannot be seen by normal methods. You have to either do this from the command prompt or by using another utility like ExplorerXP. Give ExplorerXP a run it will be a little simplier than command prompt and could be useful in the future anyway. Just navigate to the directory and right click on the file and select delete. Let me know how that works out.

    Are you still getting messages about missing:
    C:\WINDOWS\inetm\services.exe
     
  11. Debs

    Debs Private E-2

    Thanks, I have managed to delete the rundlg32.dll file and Norton antivrus comes up clean! I'm no longer getting the messages about missing: C:\WINDOWS\inetm\services.exe

    I have just attached a log from Spyware Doctor and Spybot as they are still picking stuff up, even though I delete the items they show up on subsequent scans. I'd appreciate it if you could just check it over before I get the all clear. I'm very paranoid about returning to Internet banking, oh dear!!!!

    Thanks for all your help

    Debs
     

    Attached Files:

  12. md2lgyk

    md2lgyk I can't follow the rules

    Can't help with Spyware Doctor, but the SpyBot hits are a known false positive. There's a SpyBot update (ver. 1.3.1 TX) to fix it.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Debs,

    The hits from Spyware Doctor are not valid. It is detection the information that Spybot's Immunize feature has put into your registry to place these bad addresses in your restricted zones.
     
  15. Debs

    Debs Private E-2

    I have downloaded the DSO fix for spybot, thanks for that.

    Yippee looks like everything is clean again thanks to you!

    Thanks so much for your help, you are a diamond, yippeeee, hurray, hurrah!

    Debs ;)
     
  16. brady04939

    brady04939 Private E-2

    I'm brand new to your site and I have nothing but accalade's and thank's to the people who are responsible for the basic spyware,trojan and virus removal thread. I followed the suggestion's and implemented them and purged my dell of multiple adware,trojan's etc..... like Deb's put it yippee! Hurrah! My machine is flying with minimal pop-up's and a clean drive. I will direct all my friend's to this site and am now one step closer to reaching geekdom.I'm happy for you Deb's and I know how you feel.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for the praise Brady and for the referrals. We strive to be the best. I did not notice this thread had new info in it until just now. It had slid out of view too quickly I guess.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds