Please help . . .I'm going insane with spyware!

Discussion in 'Malware Help (A Specialist Will Reply)' started by mikearge, Mar 7, 2006.

  1. mikearge

    mikearge Private E-2

    Hi everyone,

    As the title suggests, I have a work computer that another department used to use in the evening and somewhere along the line it became rife with spyware and adware. Its driving me freaking crazy!! My biggest gripe is that I get almost constant ad popups from adserver.com.
    I have followed all of the steps in the "Read and Run Me First" section, and while my system seems to be better, I'm still getting the frustrating, almost constant ad popups. Attached are my Hijack This, BDscan and ActiveScan logs as you requested. Any help would be greatly appreciated!!

    Mike
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MGs!

    Are the following items necessary for your work:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:80
    O15 - Trusted Zone: www.westlaw.com
    O15 - Trusted Zone: http://www.westlaw.com

    You Sun Java version is way out of date.
     
  3. mikearge

    mikearge Private E-2

    I'm not sure about the first listing --> R1HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:80

    But the two Westlaw ones are necessary for work. In order to use their proprietary caselaw printing function (which they use to charge you by the page) you have to list them as a trusted site.

    Also, I will update my Sun Java now.

    Thanks
    Mike
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can wait until we fix problems if you have not started yet.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).
    If you do not use Windows Messenger (this is not the same as MSN Messenger) consider fixing it with HJT to. It can be a source of popups and almost no one uses it for anything.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\system32\w?nlogon.exe
    C:\WINDOWS\system32\YMANTE~1\alg.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:80
    R3 - URLSearchHook: (no name) - {DAB06CD5-AA12-ABBC-1686-F05A6C4A10E2} - C:\WINDOWS\system32\hiokzn.dll
    O2 - BHO: (no name) - {CAF04D9D-9C44-DD93-0F63-DE76671916A7} - C:\WINDOWS\system32\nsc.dll (file missing)
    O2 - BHO: (no name) - {DAB06CD5-AA12-ABBC-1686-F05A6C4A10E2} - C:\WINDOWS\system32\hiokzn.dll
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [Thangju] C:\WINDOWS\system32\w?nlogon.exe
    O4 - HKCU\..\Run: [Eott] "C:\WINDOWS\system32\YMANTE~1\alg.exe" -vt gms
    O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
    O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
    O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/pages/scanner/WinFixer2005ScannerInstall.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\system32\hiokzn.dll
    C:\WINDOWS\system32\nsc.dll
    C:\WINDOWS\system32\YMANTE~1\alg.exe <-- in fact, delete the whole YMANTE~1 folder (this is an abbreviated name)
    C:\WINDOWS\system32\w?nlogon.exe <--- this is not winlogon.exe which is a valid file. Look sort the folder my file name and look for something that looks like winlogon.exe but that is out of alpha order. That is the one you want to delete. If not sure, don't delete. Just tell me exactly what you find and what the file sizes and file dates are.
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. mikearge

    mikearge Private E-2

    I haven't started it yet . . .I'll wait.

    Sorry if I jumped the gun.

    Mike
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! Just do what I gave you in message # 5 and we will proceed from there.
     
  8. mikearge

    mikearge Private E-2

    Well, I followed all of your steps with some minor exceptions.

    I was unable to locate:
    C:\WINDOWS\system32\hiokzn.dll
    C:\WINDOWS\system32\nsc.dll
    C:\WINDOWS\system32\w?nlogon.exe

    I even did a search for those names (and partial names) bust simply could not find them. Maybe that's a good thing?

    Attached is my new HJT log.

    The good news is . . . so far so good. . . I haven't had a popup. I've been surfing around for 5-10 mins without an incident. Hopefully that worked.

    Thanks so much for your help. You've been a godsend!

    Mike
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First a note about Windows XP search. It will not locate hidden or system files or folders by default and must be configured properly to search for all files. However it is possible the HJT removed the files too. Here is how you setup Windows XP search:

    Searching for Hidden Files on WinXP


    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link (when you get to the point about Sun Java, update your Java version):

    How to Protect yourself from malware!
     
  10. mikearge

    mikearge Private E-2

    I forgot to tell you that when I did the search I did search all hidden/system files and folders also. So HJT must have gotten rid of them.

    Again, thank you SO MUCH for your help!!! It worked like a charm!

    All the best,

    Mike
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds