Please Help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Baker Boy, Apr 17, 2006.

  1. Baker Boy

    Baker Boy Private E-2

    Hi I'm Lee. I've been having pop-up probs since letting my Norton subscription run out and continuing to use LimeWire. But it was only after I re-subscribed to Norton that the problems started - I've now removed Norton completely. I'm getting pop-ups from sites such as winfixer and amaena among others.

    I've followed the READ & RUN ME FIRST instructions as best as I could and hope I've done everything correctly. Please help because it's driving me insane. HJT log etc attached as requested.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\windows\mousepad10.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.co.uk/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.co.uk/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    O4 - HKLM\..\Run: [mousepad] C:\windows\mousepad10.exe
    O4 - HKLM\..\RunServices: [winlog] winlog.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\windows\system32\winlog.exe
    C:\WINDOWS\SYSTEM32\bk.exe
    C:\WINDOWS\GIMMYSMILEYS.dat
    C:\windows\keyboard.dat
    C:\windows\mousepad.dat
    C:\WINDOWS\newname.dat
    C:\windows\newname10.exe <--- delete any files using the starting with the text newname and ending in .exe (like newname1.exe, newname2.exe...etc)
    C:\windows\mousepad10.EXE <--- delete any files using the starting with the text mousepad and ending in .exe (like mousepad1.exe, mousepad2.exe...etc)
    C:\windows\KEYBOARD10.EXE <--- delete any files using the starting with the text KEYBOARD and ending in .exe (like KEYBOARD10.exe, KEYBOARD2.exe...etc)
    C:\windows\GIMMYSMILEYS3.EXE <--- delete any files using the starting with the text GIMMYSMILEYS and ending in .exe (like GIMMYSMILEYS10.exe, GIMMYSMILEYS2.exe...etc)
    Also look in c:\ for any of the newnameX, mousepadX, keyboardX, GIMMYSMILEYSX files and delete them too

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  3. Baker Boy

    Baker Boy Private E-2

    Thanks for the reply. I did the first part with HJT but am not familiar with Windows Explorer - I rebooted in safe mode but I can't seem to find the files that you've listed in order to delete them. What am I doing wrong? I did a search from within Explorer and that failed to locate them too. Viewing of hidden files is enabled too. Any ideas? Sorry but I'm a novice at this sort of stuff!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just continue and post the follow up HJT log and tell me your current status. Quite often HijackThis is able to delete files thus you may not find them. Those steps are really meant as a double check because we cannot be sure what HJT will actually delete.

    Doing a Search is not useful unless configure properly. Search will not look for hidden files, nor will it look in system folders by default. The view hidden files and folders setting in Windows Explorer is only for using Windows Explorer and has no effect on Windows Search. The below explains how to configure search (but you probably do not need to use it):

    Searching for Hidden Files on WinXP
     
  5. Baker Boy

    Baker Boy Private E-2

    Ok I've managed to do all that but now I don't seem able to attach my new HJT log, the attachment option is no longer at the bottom of the screen. Any ideas?

    Lee.
     
  6. Baker Boy

    Baker Boy Private E-2

    Ok I've managed to do the attachment by using IE rather than AOL, why has AOL suddenly stopped allowing me to send attachments? Is this a coincidence?

    PC seems to be running fine (apart from the above little annoyance...) and I haven't had any pop-ups yet (although my pop-up blocker says it's blocking lots).

    Should I now reinstall Norton and uninstall all the free anti-spyware/virus/pop-up blocker stuff my friend installed when I first encountered these problems? Norton was working fine until I let my subsription expire after all. Also is is safe to use LimeWire with correct protection in place?

    Many thanks for all your advice so far, I've learnt such a lot and am amazed at your knowledge!

    Cheers, Lee.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure! I don't use AOL so I have no idea what potential problems there could be with its configuration.

    I'm not sure what you are referring too. You have McAfee installed already. Why would you want to install Norton? And don't confuse an antivirus with antispyware or popup blockers. They are all differeent things.


    No P2P programs are actually safe. Having all protection software in place can help protect you but it will not give 100% protection from you downloading and installing something you should not.
     
  8. Baker Boy

    Baker Boy Private E-2

    So does it look like I'm clean now then? If so should I now do the system restore thing as per step 1 in READ & RUN ME FIRST?

    The Norton thing I'm referring to is that I had that running prior to encountering all these probs but we uninstalled it and installed McAfee instead. I was just wondering which is the best one to use.

    Lee.
     
  9. Baker Boy

    Baker Boy Private E-2

    Still wondering if I should do the System Restore thing yet? PC is running fine now so assume it's all clear of malware?

    Many thanks, Lee
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Personally no I would not reinstall Norton in place of McAfee. Did you buy McAfee or is this one of those trial programs. However, in reality I would not use McAfee or Norton. They are both just too much of a resource hog as far as I'm concerned. However the final decision is yours to make. The below link gives 3 very good free antivirus programs that are no so resource hungry. There are also recommendations for firewalls and many other steps to perform to keep you protected.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds