Please Help Me...w32.annika

Discussion in 'Malware Help (A Specialist Will Reply)' started by traderx, Jan 25, 2006.

  1. traderx

    traderx Private E-2

    Hi,

    My homepage has been hijacked with the following message and they try to route me to there "protection" software. In addition, I get this bubble periodically on the bottom right of my taskbar with a yellow exclamation point saying "Your computer is infected!"

    I have read the "Read this first" sticky and have done everything I was advised to do. I am attaching all of the logs that were generated. Could someone please help me.

    Thanks,

    Traderx

    Your private info is collected by W32.Sinnaka.A@mm
    Your IP address: 66.57.59.152

    Your Country: US, United States

    They know you're using: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)

    Operation System: OS Windows

    Risk status for futher investigation: VERY HIGH RISK

    Time of investigation: Wed Jan 25 17:24:55 PST 2006
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. traderx

    traderx Private E-2

    Chaslang

    Thank you so much for your help...After running smitRem and restarting in normal mode everything seems to be alright...

    I appreciate it...

    Traderx
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. It would be a good idea to attach the requested log though.
     
  5. traderx

    traderx Private E-2

    Chaslang,

    Maybe I spoke too soon...I noticed that there is a link for something called Spyware Strike on my Desktop, which I'm pretty sure is a suspect addition. I am attaching both the Smitfiles.txt and the report that PandaScan generated after I ran the SmitRem utility.

    TraderX
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does the icon on you Desktop allow you to right click and select Delete? Does it delete?

    You have some other issues that we need to fix but I want to see the results of the above first. Also are you having any visible malware problems?
     
  7. traderx

    traderx Private E-2

    Yes, I was able to delete it by right clicking. I don't seem to have any other visible malware problems...
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oaky is the below Favorites folder something you added and have links in? If not, delete it.
    C:\Documents and Settings\Tikku\Favorites\Health

    Empty your MS Antispyware Quarantine and also the Quarantine folder that you have in C:\Spyware Tools\Quarantine


    Also look in Add/Remove programs for RedSwoosh or RSSoft or RSEDNCLient and uninstall if found. Then delete the following folder: C:\Program Files\RSSoft

    Also delete the following folder if found: C:\Program Files\Security Toolbar
     
  9. traderx

    traderx Private E-2

    I found and removed Red Swoosh...and cleaned out my quarantine folders...the items in Favorites were links to a magazine I subscribe to...

    Anything else, Chaslang?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  11. traderx

    traderx Private E-2

    Chaslang,

    When I booted up today I got a notification from MS Antispyware that SpyAxe was trying to load. I blocked it, but is there any cause for concern, and is there anything I should do additionally to protect myself?

    TraderX
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Either use Ccleaner or do it manually using Internet Explorer, but delete all the cookies in all user accounts (I saw many for Tikku and also the Guest account - note: Guest accounts really should be disabled for security reasons.)

    After removing all of those cookies, run the steps in the below link again. Make sure you re-download the tool again (as it is updated frequently) and also re-read the steps as they change too:
    SpywareStrike, Smitfraud, SpySheriff, SpyAxe & PSGuard Removal

    Attach the requested smitfiles.txt and Panda logs. Also run the below and attach the requested log:

    Using GetRunKey
     
  13. traderx

    traderx Private E-2

    Chaslang,

    I am uploading the Smitfiles.txt and Pandascan log. When I ran the GetRunKeys file I about 18 txt files, including runkeys, runkeys1, xrkey00, xrkey01, xrkey02...

    I am only uploading the runkeys txt file, as you requested...let me know if you need more.

    TraderX
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The other extra files go away after you close the notepad window that pops up with the runkeys.txt log in it.

    The only item of concern I see in the Panda log is:

    Adware:adware/securitytoolbar Not disinfected Windows Registry

    We will need to find where this registry entry is really located. Panda is rather weak in reporting registry keys. In fact what they report is not useful at all.

    Download the Registry Search Tool

    Unzip to your Desktop and double click on regsrch.vbs
    (if you have script protection, please allow this to run)

    In the dialog that opens enter the following:

    securitytoolbar

    Press 'OK'

    The search will run for a while then alert you when it is finished. Press 'OK' and copy the contents of the WordPad window and post in this thread. If it is very long, an attachment would be better.

    Now copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixadt.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixadt.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.

    Do you use the WildTangent stuff? It is considered malware.
    C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe

    Attach a new HJT log too!
     
  15. traderx

    traderx Private E-2

    Chaslang,

    When I used the Registry Search Tool to look for securitytoolbar, nothing was found, so i have nothing to upload from that.

    I did the fixadt.reg stuff.

    Also, I think the following is not good...I remember, a long time ago, something hijacked my home page and send me to the homepage qus8l.hpwis.com... should I get rid of this line?

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qus8l.hpwis.com/

    Also, I don't really use the wild tangent stuff...I needed for some application I used a long time ago...what do I need to do to remove it?

    Thanks,

    TraderX
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well then we will probably have to ignore what Panda is giving us since they do not indicate where they are finding that item. It is probably a benign entry anyway.

    That is just an entry related to Compaq Computer (own by HP now). You can fix it if you do not want it.

    Yes! We normally do fix it but it seem like you were using it for something.

    Look in Add/Remove programs for anything from WildTangent and uninstall if found. If anything remains in your log afterwards, just have HJT fix it.

    Why did you start using MSconfig to control startups? We specifically request that not to be used while fixing problems with malware. You are blocking many things from running (some of which you need for protection - like MS AS. You also blocked WildTangent which HJT will no longer be able to fix since it does not show now.)
     
  17. traderx

    traderx Private E-2

    It was a mistake that I used ms config to control startup...I just did it the one time by clicking disable all on the startup tab of the ms config utility...I am not supposed to do that, right?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you should not do that while we are trying to fix your PC and in fact if you disable ALL, then many things you need to have working in your system will not work.

    Repeat the RegSrch tool step I gave you a few messages back but this time search for Toolbar
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds