Netspry, ADS234 and other spy/malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cjreeves, Nov 7, 2004.

  1. cjreeves

    cjreeves Private E-2

    The current symptoms:

    1) Netspry comes up between website transitions and file downloads.
    2) Windows tells me www.ads234.com is the current website whenever I enter a URL.
    3) REGEDIT, TASKMGR and MSCONFIG are blocked. I made copies of them in a separate folder so I can run them from there

    I followed the two guide posts and ran all of the recommended av and spyware programs in safe mode.

    Ad-Aware turned up (and fixed) the most items, including 180SOLUTIONS, ALTNETBDE, COOLWEBSEARCH, MIDADDLE, MYWAY.SPEEDBAR, STATBLASTER, IBIS TOOLBAR, TOPMOXIE, BOOKEDSPACE, VX2, ELITUM.ELITEBARBHO, DYFUCA, BLAZEFIND, IMISERVER , CLICKSPRING.

    Spybot-SD showed and fixed the DSO Exploit and I had already installed the DSO Exploit fix.

    I've been running Spybot abd Ad-Aaware for weeks and they clear up problems, but new ones keep appearing, so I'm all out of ideas.

    I held of running HJT, waiting for more advice.

    Thanks
     
  2. cjreeves

    cjreeves Private E-2

    Additional information: I am running XP PRO SP2. All security patches applied. eTrust AV. Also MSFT JVM is gone, and Sun's installed.

    I just re-ran Ad-Aware and a three new malware infections are in place since a couple of hours ago: STATBLASTER, MIDADDLE, COOLWEBSEARCH.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. cjreeves

    cjreeves Private E-2

    Answer: Yes, I had run all of the prescribed steps, except those in the "If still having problems" section.

    In the meanwhile, I purchased and ran (deep file scan) eTrust Pest Patrol from CA. It removed a number of problems. I ran Ad-Aware afterwards and it came up clean. Also, ther is now no sign of netspry, ads234, etc.

    However, the regedit, taskmgr and msinfo apps are still blocked.

    Any suggestions?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, they were in my previous message. The Symantec link and the Alternative Scans should be run. Also see: http://www.sophos.com/virusinfo/analyses/w32spybotcb.html

    If you still have a problem after that, you should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log file as an attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Make sure you have HJT version 1.98.2 and follow the guidelines on where to install it and how to post a log as an attachment.
     
  6. cjreeves

    cjreeves Private E-2

    Thank you for the advice. Last night I ran through the whole series of steps you suggested (in the "read me first beforeasking for support" thread), and somewhere along the line, the blocking of task manager has been fixed.

    -- The first three online scans (Trend Micro, Symantec, Stinger) din't turn up anything.
    -- AdAware full scan fixed VXZ malware
    -- Sybot identified teh DSO exploit
    -- CWShredder, Kill2me and about Buster were negative
    -- BitDefender fixed Win32P2P,Skybot.Gen, but detected and failed to fix Trojan.Spy.Midaddle.A, Adware.Statblaster.T, HTML.MediaTracker.A, and Trojan.Droper.Parity.Scan1
    -- Ravantivirus and TorjanScan were negative

    All seems to be OK now, so I will close this thread with thanks. I will check out HJT and follow the guidelines there. If it apperas I have anything new, I'll start a new thread.

    Thank you again
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may have some items that require manual fixing. It would be a good idea to post your log for someone to look at. I will not be around for the next 11 days.
     
  8. cjreeves

    cjreeves Private E-2


    HJT log is attached. :rolleyes: After countell hours of careful research; runnning and re-running scans and fixes; boots and re-bots .... I still have pop-ups.

    I would welcome advice. Thanks
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds