Please Help! - Hijack/trojan and god knows what else

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by duds888, Aug 23, 2004.

  1. duds888

    duds888 Private E-2

    I have a major problem with virus’/spyware/Trojan horses or whatever it is that’s messing with my computer, I'm hoping that you guys will be able to help me out…

    On trying to set about dealing with this my first move was to search for information from a reliable source, so I followed a link from a BBC online webpage advising on how to get rid of spyware one of the links was www.spychecker.com I’m sure some of you are familiar with this website but its basically a website which lists the various spyware removal programs some of which are available for free and some of which are charged for. Each is user rated and I picked the top rated free application. I downloaded it and it turned out not to be what it said it was (or at least I didn’t recognise it as spyware removal software). Although I cannot remember the name of this application it was some kind of optimizer for downloading as when browsing the Internet dialogue boxes would ask if I wanted to use the program to upload pages. I never used it and uninstalled it from my system.

    I went back to www.spychecker.com and looked for another application – I found ‘Spyware Search & Destroy’ which I installed and ran, it seemed to be doing the job and located and removed some suspect files. It was then that things really went weird, which at the time lead me to believe it was itself a spyware program, but reading through the majorgeeks site I guess not.

    The ‘weirdness’ is as follows…

    When I turn on the CPU after it settles from booting up a message appears saying:

    cannot run 'msxmidi' and will have to close

    Trying to use the internet is difficult as once in a while you click on a link and it will take you to a completely different website – like hardcore porn! I didn’t understand how this worked until I was on the majorgeeks website (when looking at some of your links to spyware removal software programs) that I realised what was going on – not all the links were as they should be with URLS that were blatantly not the intended links - i.e. links to porn and I’m pretty sure the majorgeeks site would not be directing users to porn! Im not sure of the right term for this virus/spyware/Trojan, but its hijacking hyperlinks - it's CoolWebSearch, although I cant say it is exclusively. Other problems are as follows:..

    When trying to access folders via MyComputer the viewing windows do not display any files only that icon with coloured shapes (which I see from time-to-time on websites when pictures are still loading) can be seen and no access to folders is possible, I have since worked out that I can get to files through the ‘find’ function on the start button.

    On the favourites list I now have loads of porn sites that I have never visited.

    A shortcut to the desktop keeps appearing called 'SEX' or 'XXX'

    The worst problem however is (or was) an inability to use the computer at all. I would turn it on and then as the various .exe spyware programs began to load sooner or later a fatal exception error message would force a shutdown. The message reads as follows:

    A EXCEPTION OE HAS OCCURED AT 017F:BFFADFF
    THE CURRENT APPLICATION WILL BE TERMINATED

    I have since found a way of getting round this by using the ‘ctrl+alt+delete’ function to end task them before they fully load up.


    Using you site as guidance I have so far done the following…

    1)Ran ‘Spyware Search and Destroy’ a couple of times - deleted suspect files it flagged up.

    2)Ran ‘Adware’ numerous times - deleted suspect files it flagged up - its seems to pick up a lot but everytime it finds more.

    3)Ran 'CWShreader once

    4)Ran a ‘HijackThis’ scan (however I thought I’d seek guidance before deleting anything with this app.)



    I think that I maybe need to disable the system restore, but I have no idea how do this (you site does not give instructions for windows 98)

    I'm a little clueless about the tech side of computers so to determine my system spec I used one of the programs listed on MajorGeeks (AIDA 32, or something). I wasn't sure what is essential info or not so I have attached the whole report (sorry its quite big!).

    So guys its over to you, I really hope you can help me out because I'm clueless and being a family computer I could do without random porn loading up on explorer, if you require me to post the HijackThis log then just let me know.

    Many thanks

    duds888

    NB - UPDATE: I did a very silly thing the other day and left the computer on and connected to the Internet, because the monitor was on standby I forgot it was on. When I realised a day later there were god knows how many windows open with pop-ups and loads of error messages that said the application could not be downloaded, I just had to switch it off because I could not shut it down - I think I've really ****ed it now.
     

    Attached Files:

  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Hi,
    Windows 98 does not have System Restore, sorry for any confusion. Are your Windows Updates current? Did you run a Trojan remover? The same thread you read links to A2, which might help you, try it from safe mode.
     
  3. Canadian

    Canadian Private E-2

    does the lack of system restore also apply to windows 98 second edition?
     
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    All versions of 98, yes, you can find System Restore in newer version, Millenium, Win2K, XP.
     
  5. duds888

    duds888 Private E-2

    Ok Major Attitude I will try running in safe mode

    --but how do I do that?

    Also I dont think I have all the windows updates but when I tried to download them I was prompted for the administrator login, which I dont know? - How do I get round this?


    Finally what is that trojan horse app? what's the name - is it on the list that Kudo posted at the top of the spyware forum?
     
  6. duds888

    duds888 Private E-2

    Does anyone know the answers to the questions in my last post on this thread?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow all the steps in this Sticky thread < READ ME FIRST: Basic Spyware, Trojan And Virus Removal >

    Since you already said you have some of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs. Check by clicking on the links and comparing to what you have.

    The above thread even indicated how to boot in safe mode in step 6 of the first part. Make sure you run the online scans. Also try running this: http://www.windowsecurity.com/trojanscan/

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    You PC is very limited in capabilities. You only have 64Mb of memory and you have an old OS that is no longer supported by Microsoft. I don't even know if you can get updates on line anymore so it will be difficult to get all the updates you may need.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds